Best Threat Intelligence Software - Page 8

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 211

Category Stats (Sep 2026)

  • Average Rating: 4.58/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: UpGuard Breach Risk (+0.92%) - Among all products in this category, UpGuard Breach Risk recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 211+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Recorded Future, Ivanti Neurons for Unified Endpoint Management, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=recorded-future&focus%5B%5D=ivanti-neurons-for-unified-endpoint-management&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

FORESIET Threat Intelligence

Foresiet is a SaaS based AI-enabled "Integrated" Digital Risk protection platform. It is a powerful Threat intelligence solution that can effectively predict the cyber-attacks that the customer is pre-exposed to, automatically assess and quantify the risk, and recover from Breach Epidemic.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate FORESIET Threat Intelligence?

  • Security Validation: 8.3/10 (Category avg: 9.0/10)
  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 8.3/10 (Category avg: 8.6/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind FORESIET Threat Intelligence?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of FORESIET Threat Intelligence?

Google Threat Intelligence

Mandiant Advantage is a multi-vendor XDR platform that delivers Mandiant’s transformative expertise and frontline intelligence to security teams of all sizes.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Google Threat Intelligence?

  • Seller: Google
  • Year Founded: 1998
  • HQ Location: Mountain View, CA
  • Twitter: @google
    31,899,995 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    341,888 employees on LinkedIn®
  • Ownership: NASDAQ:GOOG

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Google Threat Intelligence?

What Are G2 Users Discussing About Google Threat Intelligence?

HuntingAlice

HuntingAlice is an intent-first AI prospecting and B2B lead generation platform. Instead of building static contact lists, HuntingAlice powers modern prospecting by detecting real public buying signals from people who match your ICP. It uses deep, always-on listening across LinkedIn and professional networks to surface in-market prospects right when they show intent, then turns those signals into outreach-ready leads with clear trigger context. HuntingAlice helps you: - Automate vibe prospecting with AI, reducing time spent on manual research and list building - Generate higher-quality B2B leads by focusing on in-market buyers - Increase reply rates and improve win rates with context-driven outreach HuntingAlice is built for outbound and proactive prospecting teams: - Sales and Business Development - SDR/BDR teams - Partnerships and alliances teams - Startup founders doing founder-led sales - Lead generation agencies

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate HuntingAlice?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind HuntingAlice?

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of HuntingAlice?

HYAS Insight

HYAS Insight provides threat and fraud response teams with never-before-seen visibility into everything you need to know about an attack. This includes the origin, current infrastructure being used, alerts when new relevant infrastructure is created, and any infrastructure likely to be used against you in the future. Top Fortune 500 companies rely on our exclusive data sources and nontraditional collection mechanism to power their security and fraud investigations.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate HYAS Insight?

  • Security Validation: 10.0/10 (Category avg: 9.0/10)
  • Intelligence Reports: 8.3/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 8.3/10 (Category avg: 8.6/10)
  • Ease of Use: 8.3/10 (Category avg: 9.1/10)

Who Is the Company Behind HYAS Insight?

  • Seller: HYAS
  • Year Founded: 2015
  • HQ Location: Vancouver, , CA
  • Twitter: @hyasinc
    1,114 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of HYAS Insight?

Infoblox Threat Defense

Infoblox Threat Defense provides preemptive security using a combination of predictive threat intelligence and ML- based algorithmic detections to stop threats before they reach users, devices or cloud workloads.

Average Rating: 4.8/5.0

Total Reviews: 6

How Do G2 Users Rate Infoblox Threat Defense?

  • Intelligence Reports: 8.3/10 (Category avg: 9.1/10)
  • Ease of Use: 9.7/10 (Category avg: 9.1/10)

Who Is the Company Behind Infoblox Threat Defense?

  • Seller: Infoblox
  • Company Website:
  • Year Founded: 1999
  • HQ Location: Santa Clara, California
  • Twitter: @Infoblox
    11,290 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,303 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Medium, 33% Small

What Do G2 Reviewers Say About Infoblox Threat Defense?

AI-generated summary from verified user reviews

Pros
  • Users value the instant threat detection of Infoblox Threat Defense, ensuring robust security without hindering performance.
  • Users value the instant threat detection of BloxOne Threat Defense, enhancing security without compromising performance.
  • Users value the instant threat detection of Infoblox Threat Defense, ensuring robust protection without performance delays.
  • Users commend the automation capabilities of Infoblox Threat Defense, enhancing security through advanced analytics and machine learning.
  • Users value the advanced analytics and automation of Infoblox Threat Defense, enhancing security through effective threat detection.
Cons
  • Users find the complex setup of Infoblox Threat Defense challenging, requiring extra effort to configure correctly.
  • Users note that Infoblox Threat Defense can be quite expensive compared to other options, affecting budget considerations.

What Are Recent G2 Reviews of Infoblox Threat Defense?

What Are G2 Users Discussing About Infoblox Threat Defense?

Kaspersky Threat Intelligence

A single access point for all human-readable threat intelligence data — designed for both IT and OT — where services work together to reinforce each other. Kaspersky Threat Intelligence Portal provides access to all human-readable threat intelligence data through a unified web interface, where services work together to enhance each other. By combining all knowledge and experience, using data processing and analysis technologies, the portal helps financial organizations effectively counter the modern cyber threat landscape. • Provides a single access point to reliable and up-to-date threat intelligence for early attack prevention and incident investigation • Delivers a relevant threat landscape considering industry and regional specifics • Strengthens file analysis processes through sandboxing, attack attribution, and file similarity detection • Helps to protect brand reputation by tracking digital assets and threats across darknet resources • Provides reports on threats related to APT groups, financially motivated cybercriminals and industrial organizations

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate Kaspersky Threat Intelligence?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Kaspersky Threat Intelligence?

  • Seller: Kaspersky
  • Year Founded: 1997
  • HQ Location: Moscow
  • Twitter: @kasperskylabind
    1,291 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    4,576 employees on LinkedIn®
  • Phone: 1-866-328-5700

Who Uses This Product?

  • Company Size: 100% Small

What Do G2 Reviewers Say About Kaspersky Threat Intelligence?

AI-generated summary from verified user reviews

Pros
  • Users praise Kaspersky Threat Intelligence for its effective malware protection, automatically detecting and removing viruses efficiently.
  • Users value the automatic virus removal feature of Kaspersky Threat Intelligence, ensuring comprehensive protection against threats.
Cons
  • Users report inefficient scanning that increases RAM and battery usage, affecting overall system performance.
  • Users experience resource-intensive performance with Kaspersky, leading to increased RAM and battery usage during scans.

What Are Recent G2 Reviews of Kaspersky Threat Intelligence?

Phantom Threat Intelligence

Phantom is the AI-powered threat intelligence platform offering real-time attack insights, proactive defense and advanced monitoring of public and hidden sources for compromised credentials, breached data and attack trends, helping security teams stay ahead of cyber threats.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Phantom Threat Intelligence?

  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Phantom Threat Intelligence?

  • Seller: Velstadt
  • Year Founded: 2018
  • HQ Location: Kyiv, UA
  • Twitter: @velstadt_com
    594 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Phantom Threat Intelligence?

AI-generated summary from verified user reviews

Pros
  • Users value the timely alerts from Phantom, enhancing early detection and response to geo-political threats.
  • Users value the automation in monitoring and early detection, enhancing responsiveness to geopolitical threats.
  • Users value the strong monitoring capabilities of Phantom, enhancing early detection of threats and actionable insights.
  • Users value the fast response time of Phantom Threat Intelligence, enhancing early detection and proactive security measures.
  • Users value the high-quality threat intelligence of Phantom, enhancing visibility and early detection of threats.

What Are Recent G2 Reviews of Phantom Threat Intelligence?

Pulsedive

Pulsedive is a brand-new analyst-centric threat intelligence platform that can provide users with comprehensive community threat intelligence to help identify known threats. Pulsedive is currently consuming over 40 OSINT feeds, equating to over one million IPs, domains, and URLs that are searchable for free at https://pulsedive.com. A dedicated solution is available for enterprise customers who want to consume vendor threat intelligence and manage their internal and private data without sharing to the community.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Pulsedive?

  • Seller: Pulsedive
  • Year Founded: 2017
  • HQ Location: New Jersey, US
  • Twitter: @pulsedive
    3,268 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Pulsedive?

What Are G2 Users Discussing About Pulsedive?

PurpleOps

PurpleOps is an AI-powered cyber threat intelligence platform that turns thousands of daily alerts into prioritized, actionable intelligence. It combines dark web monitoring, ransomware tracking, compromised credentials intelligence, CVE prioritization, and supply chain risk monitoring in a single platform. Two built-in AI agents — JINX for autonomous tier-1 triage and BUGSY for natural-language investigation — eliminate up to 90% of alert noise, so security teams focus only on real threats. Built for MSSPs with full multi-tenant architecture, and for enterprise SOC teams. ISO 27001, ISO 27017, and ISO 27018 certified. Cloud-native SaaS — onboarding takes under 5 minutes with no hardware to deploy.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate PurpleOps?

  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 6.7/10 (Category avg: 9.1/10)

Who Is the Company Behind PurpleOps?

  • Seller: PurpleOps
  • Year Founded: 2023
  • HQ Location: N/A
  • LinkedIn® Page: linkedin.com
    1 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of PurpleOps?

Quantum Armor

Quantum Armor is an Attack Surface Management (ASM) platform. It lets your company have an instant snapshot of your cyber security posture and provides tips to reduce your exposure to potential data breaches. By reducing your attack surface, you minimise the risk of a cyber security incident and protect your business against malicious actors.

Average Rating: 4.5/5.0

Total Reviews: 3

How Do G2 Users Rate Quantum Armor?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Quantum Armor?

  • Seller: Silent Breach
  • Year Founded: 2017
  • HQ Location: New York, US
  • Twitter: @SilentBreach
    4,745 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    17 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Small

What Are Recent G2 Reviews of Quantum Armor?

What Are G2 Users Discussing About Quantum Armor?

Searchlight Cyber

ABOUT SEARCHLIGHT CYBER: Searchlight Cyber is a preemptive cybersecurity company helping organizations reduce exploitable exposure before attackers act. Its Preemptive Threat Exposure Management (PTEM) platform combines continuous attack surface visibility, exploitability validation, pre-disclosure security research, and real-world attacker intelligence, enabling security teams to identify and prioritize the threats that matter most. Founded in 2017 with a mission to stop criminals acting with impunity, Searchlight is used by some of the world’s largest enterprises, government and law enforcement agencies, and managed security service providers. THE PLATFORM: Preemptive Threat Exposure Management (PTEM) Searchlight’s platform validates what's exploitable on your attack surface and observes the attackers preparing against it, so threats get resolved before an attack begins. PRODUCT 1/3: Searchlight Exposure (Exposure Management) Searchlight Exposure delivers continuous, verified attack surface monitoring – scanning hourly, not daily – so you can detect exposures as they emerge. Exposure combines automated discovery, deep enrichment, and proprietary vulnerability research to reduce your window of exposure and help your organization stay ahead of threats. PRODUCT 2/3: Searchlight Threat (Monitor) Gain continuous visibility into attacker activity with Searchlight Threat. Our Monitor module scans the clear, deep, and dark web for leaked credentials, exploit development, and chatter in hacking forums – automatically matching findings against your organization's information and alerting you first, so you can act before attackers do. Searchlight also offers cyber risk quantification through Intangic Grounded in 7+ years of breach data across 20,000 companies, drawing on real-time dark web intelligence and adversary tactics, Intangic replaces static scoring models with insurance-validated predictive analysis – preemptively signaling to organizations when they are actively being targeted and benchmarking that risk against industry peers. Built for insurance carriers, risk committees, and security teams alike, Intangic makes cyber risk quantifiable, insurable, and trackable, giving leaders the evidence to act early and report measurable outcomes.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Searchlight Cyber?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Searchlight Cyber?

  • Seller: Searchlight Security
  • Year Founded: 2017
  • HQ Location: Port Solent, GB
  • Twitter: @SLCyberSec
    1,160 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    76 employees on LinkedIn®
  • Ownership: Private

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of Searchlight Cyber?

SentinelOne Singularity Threat Intelligence

SentinelOne's Singularity Threat Intelligence is a comprehensive cybersecurity solution designed to provide organizations with real-time, actionable insights into emerging threats. By integrating advanced threat intelligence directly into the Singularity Platform, it enables proactive defense mechanisms against sophisticated cyber attacks. Key Features and Functionality: - Real-Time Threat Intelligence: Delivers up-to-date information on the latest cyber threats, ensuring organizations can respond swiftly to potential risks. - Seamless Integration: Integrates directly with the Singularity Platform, enhancing existing security measures without the need for additional tools. - Automated Response: Utilizes AI-driven automation to detect, analyze, and respond to threats, reducing the need for manual intervention. - Comprehensive Coverage: Monitors endpoints, cloud workloads, and IoT devices, providing a holistic view of the organization's security posture. Primary Value and Problem Solved: Singularity Threat Intelligence empowers organizations to stay ahead of cyber adversaries by providing timely and relevant threat data. This proactive approach minimizes the risk of breaches, reduces response times, and enhances overall security resilience. By automating threat detection and response, it alleviates the burden on security teams, allowing them to focus on strategic initiatives rather than routine threat management.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate SentinelOne Singularity Threat Intelligence?

  • Security Validation: 10.0/10 (Category avg: 9.0/10)
  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 10.0/10 (Category avg: 8.6/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind SentinelOne Singularity Threat Intelligence?

  • Seller: SentinelOne
  • Year Founded: 2013
  • HQ Location: Mountain View, CA
  • Twitter: @SentinelOne
    57,863 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,426 employees on LinkedIn®
  • Ownership: NASDAQ: S

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About SentinelOne Singularity Threat Intelligence?

AI-generated summary from verified user reviews

Pros
  • Users highlight the high detection efficiency of SentinelOne, enabling effective processing of threats and enhanced focus on priorities.
  • Users appreciate the advanced threat detection capabilities of SentinelOne, enabling efficient responses and reduced focus on security issues.
Cons
  • Users note a difficult learning curve when adapting to the complex features of SentinelOne Singularity Threat Intelligence.

What Are Recent G2 Reviews of SentinelOne Singularity Threat Intelligence?

Silobreaker

Silobreaker is a technology company that builds solutions that unify data, contextual analysis, and human expertise to deliver decision-grade intelligence when and where it matters most. Continually refined for both leadership and analysts operating across business resilience, enterprise security, threat, and risk disciplines, the Silobreaker intelligence layer uses a proprietary search and entity database to automate the production of intelligence across cyber, geopolitical, and physical domains. Using Silobreaker's priority intelligence requirements (PIR)-driven workflows, agentic automation, MCP-enabled integrations, and executive-ready reporting, governments and global enterprises can anticipate threats, protect assets and people, accelerate decision-making, and steer through uncertainty with confidence.

Average Rating: 4.3/5.0

Total Reviews: 2

How Do G2 Users Rate Silobreaker?

  • Intelligence Reports: 8.3/10 (Category avg: 9.1/10)
  • Ease of Use: 7.5/10 (Category avg: 9.1/10)

Who Is the Company Behind Silobreaker?

  • Seller: Silobreaker
  • Year Founded: 2005
  • HQ Location: London, GB
  • Twitter: @Silobreaker
    1,945 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    68 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 50% Small

What Are Recent G2 Reviews of Silobreaker?

Threat Intelligence Platform

A Threat Intelligence Platform (TIP) for Growing Teams Our comprehensive solution with premium feeds, enrichment, and automation that accelerates proactive defense at a fraction of the cost of other TIPs.

Average Rating: 4.5/5.0

Total Reviews: 1

Who Is the Company Behind Threat Intelligence Platform?

  • Seller: Cyware
  • Year Founded: 2016
  • HQ Location: Jersey City, New Jersey, United States
  • Twitter: @CywareCo
    4,468 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    253 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Threat Intelligence Platform?

Threatlens Core

ThreatLens Core is an enterprise-grade, AI-augmented threat intelligence and security operations automation platform that enhances existing SIEM, EDR, and XDR environments. It operates as an intelligence and orchestration overlay—enriching alerts, correlating indicators of compromise (IOCs), mapping adversary behavior to MITRE ATT&CK, and generating guided response playbooks. ThreatLens Core helps security teams reduce alert fatigue, accelerate investigations, and improve mean time to respond (MTTR) without replacing their current security stack. Unlike traditional SOAR tools that rely heavily on manual playbook engineering, ThreatLens Core uses a constrained, multi-agent architecture to automate investigation workflows with policy guardrails and human-in-the-loop controls. How ThreatLens Core Works ThreatLens Core integrates directly with platforms such as: • Splunk • Microsoft Sentinel • IBM QRadar • CrowdStrike • SentinelOne • Microsoft Defender It ingests security telemetry and performs: • Alert enrichment using commercial and partner threat intelligence • Cross-case IOC correlation and threat graph analysis • Automated MITRE ATT&CK technique mapping • Structured incident summarization • Risk scoring and prioritization • AI-assisted response playbook generation All outputs are evidence-backed, auditable, and designed to support analyst decision-making. Built-in Sandbox Integration ThreatLens Core supports automated sandbox analysis to validate suspicious files and malware artifacts. Capabilities include: • API-based sandbox file submission • Behavioral detonation analysis • Extraction of process, network, and registry indicators • Automatic IOC generation and correlation • MITRE ATT&CK behavior mapping This eliminates manual upload workflows and reduces investigation time for malware-driven alerts. Key Benefits • Reduce alert noise and false positives • Improve MTTD and MTTR • Standardize investigation workflows • Increase analyst productivity • Operationalize threat intelligence • Enable governed, AI-augmented automation How ThreatLens Core is Different ThreatLens Core is not a SIEM replacement. It is not a black-box automation engine. It delivers intelligence before automation—using AI-augmented multi-agent workflows with built-in guardrails, audit logging, and controlled execution boundaries. For organizations searching for: • “AI for SOC automation” • “Threat intelligence platform with sandbox integration” • “SOAR alternative with AI” • “IOC correlation and MITRE ATT&CK mapping tool” • “Alert enrichment platform for SIEM” ThreatLens Core provides a structured, governed approach to modern security operations.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Threatlens Core?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Threatlens Core?

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Threatlens Core?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time alerts of Threatlens Core, enhancing their ability to proactively manage cyber threats effectively.
  • Users appreciate the centralized and intelligence-driven view of cyber threats in real time with Threatlens Core.
  • Users appreciate the ease of use of Threatlens Core, simplifying complex security data for effective threat prioritization.
  • Users value the centralized and intelligence-driven view of cyber threats that Threatlens Core provides, enhancing proactive responses.
  • Users value the real-time monitoring of Threatlens Core, which enhances proactive risk identification and response efficiency.
Cons
  • Users face a difficult learning curve with Threatlens Core, particularly in configuring integrations and understanding workflows.
  • Users find integration issues with Threatlens Core, requiring time for optimal configuration and a slight learning curve.

What Are Recent G2 Reviews of Threatlens Core?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025