Best Threat Intelligence Software - Page 13

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 211

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: UpGuard Breach Risk (+0.92%) - Among all products in this category, UpGuard Breach Risk recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 211+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Recorded Future, Ivanti Neurons for Unified Endpoint Management, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=recorded-future&focus%5B%5D=ivanti-neurons-for-unified-endpoint-management&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

SecIntel Threat Intelligence

Spotlight Secure Threat Intelligence Platform links security intelligence to policy enforcement for rapid protection against advanced threats.

Who Is the Company Behind SecIntel Threat Intelligence?

Seclookup Threat Feeds

SecLookup is a real-time threat intelligence platform offering domain scanning, DNS/WHOIS lookup, SSL analysis, and malicious URL detection. It provides a REST API for integrating threat data into SIEM systems and security workflows it delivers sub-200ms responses with 99.9% uptime. Ideal for SOC teams, MSSPs, and security researchers. Seclookup Also provide threat intelligence feeds for Enterprise customers.

Who Is the Company Behind Seclookup Threat Feeds?

Securin Vulnerability & Threat Intelligence

Most vulnerability scanners hand you thousands of "critical" findings and treat a theoretical bug the same as one three ransomware crews are actively using this week. Securin Signals turns that noise into a decision: it scores every CVE on real-world exploitation, ransomware ties, and threat-actor use, not CVSS severity in isolation, so your team fixes what attackers are actually targeting instead of working through a backlog sorted by guesswork. Under the hood is the Securin Risk Index (0–10), an AI-driven score built from the VTI database, 1,500+ sources including 100+ vendor feeds, CISA KEV, dark-web and OSINT signals, and 9M+ open-source components. Signals catches active exploitation a median of 11 days before CISA's KEV catalog lists it, and it currently surfaces 1,749 known-exploited CVEs that CISA KEV doesn't have, 76% Critical or High, 136 tied to ransomware. Weakness Chaining also flags when several low-severity CWEs combine into a high-impact exploit path, which single-CVE scoring misses. What this replaces: cycles burned on the roughly 90% of CVSS-Critical findings with no real-world threat behind them. What it adds: an auditable, defensible reason for every prioritization call, and a stack-agnostic layer that works alongside Qualys, Tenable, Nessus, Wiz, or whatever scanner you're already running, no rip-and-replace. The underlying VTI database is also licensed directly by other cybersecurity vendors as a threat intelligence source for their own platforms, rather than end teams using Signals themselves. Best for: vulnerability management and SOC teams who need to justify prioritization decisions to auditors or the board, and cybersecurity vendors looking to license real-world threat intelligence rather than build it in-house.

Who Is the Company Behind Securin Vulnerability & Threat Intelligence?

  • Seller: Securin
  • Year Founded: 2021
  • HQ Location: Albuquerque, US
  • Twitter: @Securin_io
  • LinkedIn® Page: www.linkedin.com
    231 employees on LinkedIn®

SnapAttack Enterprise

SnapAttack is the enterprise-ready cloud platform that helps security leaders answer their most pressing question: “Are we protected?” By rolling cyber intel, adversary emulation, detection engineering, threat hunting, and purple teaming into a single, easy-to-use product with a no-code detection builder interface, SnapAttack enables you to get more from your technologies, more from your teams, and makes staying ahead of the threat not only possible - but also achievable. We Also remove barriers to efficient, effective, and integrated threat detection with the world’s first purple teaming platform. SnapAttack creates high-confidence behavioral detections for your existing security tools, transforming the once lengthy and manual research process to the simplified task of searching and deploying a quality detection.

Who Is the Company Behind SnapAttack Enterprise?

  • Seller: SnapAttack
  • HQ Location: San Francisco, California, United States
  • LinkedIn® Page: www.linkedin.com
    9,979 employees on LinkedIn®

Stairwell

Stairwell: Automated Threat Detection and Investigation Most security tools monitor what runs. Stairwell preserves what lands. Stairwell is an automated threat detection and investigation platform that continuously collects executable and script files as they hit disk across an enterprise, stores them in a private cloud vault, and re-analyzes them against a corpus of 1.6 billion known malicious objects. Because analysis happens out-of-band in the cloud, there is no endpoint performance impact. Stairwell also extends visibility into places traditional EDR often cannot reach, including OT environments, legacy systems, and shared infrastructure. The problem Stairwell solves is simple: logs tell you something happened, but they do not give you the file back. Telemetry often ages out after 30 to 90 days, leaving analysts without evidence when a new threat is disclosed. Stairwell changes that by maintaining a complete historical file inventory. When new intelligence emerges, Stairwell reprocesses past and present files so teams can immediately determine whether a file ever touched their environment, which machines saw it, and when even if it was deleted months ago. For SOC analysts, Stairwell eliminates much of the manual investigation burden. Analysts can submit a hash, IOC, or YARA rule and search the full current and historical file inventory at enterprise scale. Its Mal-Eval engine identifies file similarity rather than relying only on exact hash matches, helping surface undocumented variants of known malware families. Run to Ground turns a single alert into a mapped view of related files, impacted machines, and historical occurrences without constant pivoting across EDR, SIEM, and threat intelligence tools. For security leaders, Stairwell delivers broader coverage and stronger privacy. It captures the blind spot between what merely lands and what actually executes. Unlike shared platforms such as VirusTotal, Stairwell’s vault is fully private, so customer files are not exposed to the broader threat intelligence community - critical for financial services, healthcare, and government organizations. Stairwell complements existing security stacks, with integrations for CrowdStrike, Palo Alto Cortex, and Google Security Operations. Its agentic investigation layer, Constellation, can take one IOC and autonomously map connected threats, related variants, and affected assets in roughly 200 seconds. Founded by Mike Wiacek, co-founder of Google Chronicle and founder of Google’s Threat Analysis Group, Stairwell is built on a core idea: defenders should be able to search every file in their environment, past and present, faster than attackers can mutate to evade detection.

Who Is the Company Behind Stairwell?

  • Seller: Stairwell
  • Year Founded: 2019
  • HQ Location: Sunnyvale, US
  • LinkedIn® Page: www.linkedin.com
    66 employees on LinkedIn®

StealthMole

StealthMole is an AI-powered dark web intelligence platform that specializes in digital investigation, risk assessment, and threat monitoring. By aggregating and analyzing data from the deep and dark web, StealthMole equips governments, law enforcement agencies, and enterprises with the tools necessary to identify and mitigate digital risks and criminal activities. The platform's advanced AI capabilities enable users to uncover hidden threats, trace data relationships, and visualize investigations, thereby enhancing cybersecurity measures and protecting sensitive information. Key Features and Functionality: - Darkweb Tracker: A comprehensive digital forensics tool that allows investigators to search for threat information, map data relationships, and visualize investigations on an intuitive interface. - Credential Protection: Identifies and alerts users to account credentials that have been leaked on the dark web due to security breaches, enabling prompt action to address vulnerabilities. - Dark Web Monitoring: Provides continuous surveillance to detect and list organizations whose data has been compromised and exposed on the deep and dark web, facilitating efficient and accurate responses to data leaks. Primary Value and Problem Solved: StealthMole addresses the critical need for proactive cybersecurity by offering real-time insights into hidden digital threats. By consolidating vast amounts of data from obscure online sources, the platform enables organizations to detect potential breaches early, respond swiftly to incidents, and fortify their defenses against cybercriminal activities. This proactive approach significantly reduces the time and resources required for threat detection and mitigation, thereby safeguarding valuable assets and sensitive information.

Who Is the Company Behind StealthMole?

  • Seller: StealthMole
  • HQ Location: Singapore, SG
  • Twitter: @stealthmole_int
    124,833 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    17 employees on LinkedIn®

Strider Technologies

Strider Technologies is a strategic intelligence firm that leverages artificial intelligence and open-source data to help organizations protect their intellectual property and technology assets. By analyzing vast amounts of publicly available information, Strider identifies and mitigates risks associated with state-sponsored intellectual property theft, targeted talent acquisition, and supply chain vulnerabilities. Their solutions empower companies, universities, research institutions, and government agencies to proactively secure their innovations and maintain a competitive edge in the global market.

Who Is the Company Behind Strider Technologies?

The Security Bulldog

The Security Bulldog lowers costs and speeds remediation of vulnerabilities for enterprise cybersecurity teams using a proprietary AI-based intelligence platform, originally developed for the intelligence community. Cyber teams are so overwhelmed that they don’t have time to save time as they struggle with the same problem: they wake up in the morning and spend two to three hours finding out what broke, does it affect them, and, if it does, how to fix it. Our proprietary natural language processing engine collects, analyses, and contextualizes the data they need in a human-friendly way to reduce cognitive burden, improve decision making, and quicken remediation.

Who Is the Company Behind The Security Bulldog?

ThreatCluster

ThreatCluster is a real-time cyber threat intelligence aggregation and clustering platform. It monitors over 14,000 security sources globally, using artificial intelligence to deduplicate data and filter out noise.

Who Is the Company Behind ThreatCluster?

Threat Detection Marketplace

SOC Prime operates the world's largest and most advanced platform for detection engineering, transforming how security teams discover, build, and respond to threats through real-time threat intelligence, AI-powered workflows, and advanced detection engineering. The company pioneered tagging Sigma rules with MITRE ATT&CK, enabling security teams to improve coverage of adversary tactics and techniques. Trusted by 11,000+ organizations worldwide, SOC Prime helps security teams anticipate, detect, validate, and respond to cyber threats faster, more efficiently, and with greater precision. SOC Prime's detection intelligence spans 40+ SIEM, EDR/XDR, and Data Lake platforms, with new detections and platform support added on an ongoing basis. Driven by its advanced cybersecurity solutions, Prime Core, Prime Architect, Prime Hunt, and Prime Detect, SOC Prime enables organizations to risk-optimize their cybersecurity posture while improving the ROI of their SOC investments. The SOC Prime Platform consists of the following products: Prime Core empowers security teams with access to a comprehensive library of over 1,000,000+ detection algorithms, enriched with threat intelligence, metadata, expert insights, and AI-driven context. The platform's Active Threats module enables security teams to discover and respond to active threats faster by surfacing detailed threat information, attack insights, and actionable detections generated by both human experts and AI, allowing teams to quickly understand impact and relevance. Prime Architect is built for autonomous, threat-informed workflows, powered by AI. The AI-assisted workspace brings together threat research, investigation, and detection engineering in a single environment, where security teams can leverage the AI agent through custom prompts or Agentic AI tools purpose-built for detection engineering and threat research. Generate Sigma rules from threat intelligence, refine detection logic, visualize attack flows, and translate detections across multiple security platforms. Prime Architect helps security teams move faster from threat intelligence to deployment-ready detections. Prime Hunt enables security professionals to audit their MITRE ATT&CK coverage, identify blind spots, automate threat search across environment, and prioritize logging of critical security signals. Using AI to correlate events surfaced through this search, Prime Hunt infers attack chains, enabling searches of potential attack patterns to determine whether newly identified threats had previously existed in the environment. By leveraging Prime Hunt, SOC teams can focus directly on incident investigation rather than analyzing overwhelming volumes of alerts, and validate adversary TTPs against stored log sources in a matter of hours. Prime Detect runs thousands of Sigma rules directly on streaming events before data reaches the SIEM, with real-time visibility and in-flight tagging and enrichment. Using AI, Prime Detect correlates real-time event streams against newly identified threats to form attack chains, surfacing potential attack sequences.

Who Is the Company Behind Threat Detection Marketplace?

  • Seller: SOC Prime
  • Year Founded: 2015
  • HQ Location: Boston, US
  • Twitter: @SOC_Prime
    5,581 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    97 employees on LinkedIn®

ThreatHarvest

ThreatHarvest is a threat intelligence platform for SMBs and overworked IT teams. We help organizations identify leaked credentials, exposed infrastructure, third-party compromise, and emerging external risks, with transparent plans starting at just $99/mo. ThreatHarvest simplifies external intelligence by focusing strictly on what matters to your operations. Traditional threat intelligence platforms (TIPs) often result in noisy, raw data dumps designed for massive enterprise security teams. ThreatHarvest changes that equation. By filtering threat data against your organization's unique identifiers (domains, IPs, vendors, etc.), we automatically separate critical, actionable threats from purely informational background noise. Instead of endless spreadsheets, you get a clean, state-saved workflow to quickly review, update, and manage your findings. Core Capabilities * External Exposure Monitoring: Gain visibility into how your organization looks to attackers. Discover leaked account passwords, exposed services, security certificate issues, and unintended attack surfaces (Shadow IT) so you can shrink your window of exposure. * Active Threat Detection: Monitor billions of records across dark web leaks, ransomware blogs, threat feeds, and underground messaging channels to catch emerging risk and compromise indicators. * Situational Awareness & Brand Protection: Guard your reputation with proactive monitoring for domain spoofing, brand impersonation, and supply chain incidents. The ThreatHarvest Difference * Automated Intelligence: Gain continuous 24/7 external visibility without needing to hire a dedicated security analyst. ThreatHarvest monitors the background so you can focus on daily IT operations. * No “Contact Us” Walls: We are actively fighting the enterprise bloat that plagues the cybersecurity market. We offer transparent pricing, a frictionless buying process, and no long-term contracts. * Built for SMBs: ThreatHarvest delivers the core value of a cost-effective threat intelligence platform calibrated for IT managers and business owners who run security without a dedicated SOC. * Independent & US-Built: Designed, developed, and supported in Kansas. We value reliability, straightforward communication, and outcome-focused performance.

Who Is the Company Behind ThreatHarvest?

Threat Hunting & Intelligence Portal

A continuously updated threat intelligence platform tracking threat actors and their infrastructure as new activity emerges. Each entry includes targeted sectors and platforms, cross-validated against results from multiple leading security engines. Delivered as regular IOC feeds in CSV, JSON, and PDF — built for SOC teams and threat hunters who need indicators converted into ready-to-use hunting hypotheses, not raw noise. Flexible plans scale from individual analysts to enterprise SOC teams.

Who Is the Company Behind Threat Hunting & Intelligence Portal?

ThreatModeler Platform

ThreatModeler integrates with cloud service providers and automatically builds threat modeling programs using cloud configuration data

Who Is the Company Behind ThreatModeler Platform?

  • Seller: ThreatModeler Software
  • Year Founded: 2010
  • HQ Location: Jersey City New Jersey ,United States
  • Twitter: @ThreatModeler
    1,380 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    86 employees on LinkedIn®
Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025