Best Threat Intelligence Software - Page 9

How Many Threat Intelligence Software Products Does G2 Track?

Total Products under this Category: 222

Category Stats (Sep 2026)

  • Average Rating: 4.59/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Darktrace / EMAIL (+1.92%) - Among all products in this category, Darktrace / EMAIL recorded the largest rating increase compared to last month

Last updated: September 29, 2026

How Does G2 Rank Threat Intelligence Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,700+ Authentic Reviews
  • 222+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Threat Intelligence Software

G2 Grid® for Threat Intelligence Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Recorded Future, Ivanti Autonomous Endpoint Management, Cyble, CloudSEK, ZeroFox, SOCRadar Extended Threat Intelligence, and CTM360.

Underlying data: [Grid® JSON](https://www.g2.com/categories/threat-intelligence/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=recorded-future&focus%5B%5D=ivanti-autonomous-endpoint-management&focus%5B%5D=cyble&focus%5B%5D=cloudsek&focus%5B%5D=zerofox&focus%5B%5D=socradar-extended-threat-intelligence&focus%5B%5D=ctm360-ctm360)

Threatlens Core

ThreatLens Core is an enterprise-grade, AI-augmented threat intelligence and security operations automation platform that enhances existing SIEM, EDR, and XDR environments. It operates as an intelligence and orchestration overlay—enriching alerts, correlating indicators of compromise (IOCs), mapping adversary behavior to MITRE ATT&CK, and generating guided response playbooks. ThreatLens Core helps security teams reduce alert fatigue, accelerate investigations, and improve mean time to respond (MTTR) without replacing their current security stack. Unlike traditional SOAR tools that rely heavily on manual playbook engineering, ThreatLens Core uses a constrained, multi-agent architecture to automate investigation workflows with policy guardrails and human-in-the-loop controls. How ThreatLens Core Works ThreatLens Core integrates directly with platforms such as: • Splunk • Microsoft Sentinel • IBM QRadar • CrowdStrike • SentinelOne • Microsoft Defender It ingests security telemetry and performs: • Alert enrichment using commercial and partner threat intelligence • Cross-case IOC correlation and threat graph analysis • Automated MITRE ATT&CK technique mapping • Structured incident summarization • Risk scoring and prioritization • AI-assisted response playbook generation All outputs are evidence-backed, auditable, and designed to support analyst decision-making. Built-in Sandbox Integration ThreatLens Core supports automated sandbox analysis to validate suspicious files and malware artifacts. Capabilities include: • API-based sandbox file submission • Behavioral detonation analysis • Extraction of process, network, and registry indicators • Automatic IOC generation and correlation • MITRE ATT&CK behavior mapping This eliminates manual upload workflows and reduces investigation time for malware-driven alerts. Key Benefits • Reduce alert noise and false positives • Improve MTTD and MTTR • Standardize investigation workflows • Increase analyst productivity • Operationalize threat intelligence • Enable governed, AI-augmented automation How ThreatLens Core is Different ThreatLens Core is not a SIEM replacement. It is not a black-box automation engine. It delivers intelligence before automation—using AI-augmented multi-agent workflows with built-in guardrails, audit logging, and controlled execution boundaries. For organizations searching for: • “AI for SOC automation” • “Threat intelligence platform with sandbox integration” • “SOAR alternative with AI” • “IOC correlation and MITRE ATT&CK mapping tool” • “Alert enrichment platform for SIEM” ThreatLens Core provides a structured, governed approach to modern security operations.

Average Rating: 4.5/5.0

Total Reviews: 1

How Do G2 Users Rate Threatlens Core?

  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind Threatlens Core?

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About Threatlens Core?

AI-generated summary from verified user reviews

Pros
  • Users value the real-time alerts of Threatlens Core, enhancing their ability to proactively manage cyber threats effectively.
  • Users appreciate the centralized and intelligence-driven view of cyber threats in real time with Threatlens Core.
  • Users appreciate the ease of use of Threatlens Core, simplifying complex security data for effective threat prioritization.
  • Users value the centralized and intelligence-driven view of cyber threats that Threatlens Core provides, enhancing proactive responses.
  • Users value the real-time monitoring of Threatlens Core, which enhances proactive risk identification and response efficiency.
Cons
  • Users face a difficult learning curve with Threatlens Core, particularly in configuring integrations and understanding workflows.
  • Users find integration issues with Threatlens Core, requiring time for optimal configuration and a slight learning curve.

What Are Recent G2 Reviews of Threatlens Core?

ThreatQ

ThreatQuotient improves security operations by fusing together disparate data sources, tools and teams to accelerate threat detection and response. ThreatQuotient’s data-driven security operations platform helps teams prioritize, automate and collaborate on security incidents; enables more focused decision making; and maximizes limited resources by integrating existing processes and technologies into a unified workspace. The result is reduced noise, clear priority threats, and the ability to automate processes with high fidelity data. ThreatQuotient’s industry leading data management, orchestration and automation capabilities support multiple use cases including incident response, threat hunting, spear phishing, alert triage and vulnerability prioritization, and can also serve as a threat intelligence platform. ThreatQuotient is headquartered in Northern Virginia with international operations based out of Europe, MENA and APAC. For more information, visit www.threatquotient.com.

Average Rating: 3.5/5.0

Total Reviews: 2

How Do G2 Users Rate ThreatQ?

  • Security Validation: 10.0/10 (Category avg: 9.1/10)
  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 10.0/10 (Category avg: 8.7/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind ThreatQ?

  • Seller: ThreatQuotient
  • Year Founded: 2013
  • HQ Location: Ashburn, US
  • Twitter: @ThreatQuotient
    2,276 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    28 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Are Recent G2 Reviews of ThreatQ?

What Are G2 Users Discussing About ThreatQ?

ThreatsEye

ThreatsEye is a Cyber Threat Intelligence and Digital Risk Protection platform that helps organizations continuously identify, investigate, and respond to external cyber threats. The platform provides a unified view of an organization’s external risk exposure by combining Dark Web Monitoring, Compromised Credentials and Data Breach Intelligence, Attack Surface Management, Brand and Phishing Protection, Threat Actor Intelligence, Vulnerability Intelligence, and IOC Monitoring.

Average Rating: 4.5/5.0

Total Reviews: 1

Who Is the Company Behind ThreatsEye?

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of ThreatsEye?

VMRay

Sandboxing reinvented against the threats of today - and tomorrow. At VMRay, our purpose is to liberate the world from undetectable digital threats. Led by reputable cyber security pioneers, we develop best-of-breed technologies to detect and analyze unknown, evasive, and sophisticated threats that others miss. We empower organizations to accelerate analysis and response, automate security tasks, and build their own threat intelligence by providing the world’s best detection and analysis platform for malware and phishing threats. ___ The target audience for VMRay encompasses a wide range of organizations, including enterprises such as top technology firms, banks and financial organizations, leading manufacturing companies, accounting and consulting firms, managed security service providers (MSSPs), and government entities. These users face the daunting challenge of safeguarding sensitive data against increasingly sophisticated cyber threats. VMRay's unique technologies, based on the world’s most advanced sandbox which employs a hypervisor-based approach, enables users to observe malicious samples in a completely invisible environment. This capability not only enhances the accuracy and depth of threat detection but also ensures that security teams can analyze threats without interference from evasive tactics employed by cyber threat actors. By meticulously sorting, filtering, and prioritizing results, VMRay delivers clear and actionable reports that eliminate the noise often associated with advanced threat analysis. This clarity is crucial for security teams, as it allows them to focus on the highest-priority insights without being overwhelmed by irrelevant data. Furthermore, VMRay's integration capabilities enable seamless integrations with existing security tools, such as Endpoint Detection and Response (EDR) systems, Security Orchestration, Automation, and Response (SOAR) platforms, and Threat Intelligence platforms enhancing overall operational efficiency of SOC and CTRI teams, incident responders and threat hunters. In addition to its technological prowess, VMRay places a strong emphasis on privacy and data control. Unlike many competitors, VMRay does not share customer analysis reports, indicators of compromise (IOCs), and any kind of data with third parties, ensuring that sensitive information remains confidential. Customers have the flexibility to choose their data hosting locations (in Germany and the USA) and durations, which is particularly beneficial for organizations that must comply with stringent privacy regulations. This commitment to privacy, combined with VMRay's innovative solutions, positions the company as a trusted partner for organizations seeking to bolster their cyber resilience and enhance SOC maturity. Ultimately, VMRay's dedication to continuous innovation, coupled with its focus on delivering reliable and clear threat analysis, makes it a formidable player in the malware analysis landscape. By addressing the complexities of modern cyber threats with precision and clarity, VMRay empowers organizations to navigate the challenges of cybersecurity with confidence, ensuring they are well-equipped to defend against both current and future threats.

Average Rating: 4.6/5.0

Total Reviews: 7

How Do G2 Users Rate VMRay?

  • Ease of Use: 9.0/10 (Category avg: 9.1/10)

Who Is the Company Behind VMRay?

  • Seller: VMRay
  • Year Founded: 2013
  • HQ Location: Bochum, DE
  • Twitter: @vmray
    4,092 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    126 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 86% Large, 14% Small

What Do G2 Reviewers Say About VMRay?

AI-generated summary from verified user reviews

Pros
  • Users value the automation integrations of VMRay, enhancing their threat analysis and incident response efficiency.
  • Users commend the stellar customer support of VMRay, highlighting the team's responsiveness and expertise.
  • Users highlight the deployment ease of VMRay, appreciating its robust architecture and effective threat detection capabilities.
  • Users value the detailed analysis features of VMRay, benefiting from enhanced interaction and automation integration.
  • Users value the ease of use of VMRay, appreciating its intuitive interface and seamless integration capabilities.
Cons
  • Users find the difficult learning curve of VMRay challenging due to its less intuitive interface.
  • Users find the difficult setup of VMRay frustrating, especially with unclear processing failures for samples.
  • Users find VMRay expensive, but many believe it is worth the cost for its value and effectiveness.
  • Users report experiencing poor detection performance, occasionally missing important findings during scans with VMRay.
  • Users feel the need for a more intuitive interface to enhance the learning curve for VMRay.

What Are Recent G2 Reviews of VMRay?

VulnCheck Exploit and Vulnerability Intelligence

A next-generation Cyber Threat Intelligence platform, which provides exploit and vulnerability intelligence directly into the tools, processes, programs, and systems that need it to outpace adversaries.

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate VulnCheck Exploit and Vulnerability Intelligence?

  • Security Validation: 10.0/10 (Category avg: 9.1/10)
  • Intelligence Reports: 10.0/10 (Category avg: 9.1/10)
  • Endpoint Intelligence: 8.3/10 (Category avg: 8.7/10)
  • Ease of Use: 10.0/10 (Category avg: 9.1/10)

Who Is the Company Behind VulnCheck Exploit and Vulnerability Intelligence?

  • Seller: VulnCheck
  • Year Founded: 2021
  • HQ Location: Lexington, US
  • LinkedIn® Page: www.linkedin.com
    50 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Do G2 Reviewers Say About VulnCheck Exploit and Vulnerability Intelligence?

AI-generated summary from verified user reviews

Pros
  • Users commend the accuracy of VulnCheck's information, finding it robust and valuable for enhancing security assessments.
  • Users commend the constructive customer support of VulnCheck, enhancing their integration experience and overall value provided.
  • Users highlight the ease of integration of VulnCheck, benefiting from a well-documented process and helpful support.
  • Users value the easy integration capabilities of VulnCheck, enhancing their security platform experience with accurate intelligence.
  • Users value the reliable and accurate intelligence provided by VulnCheck, enhancing their overall security capabilities.

What Are Recent G2 Reviews of VulnCheck Exploit and Vulnerability Intelligence?

AhnLab TIP (Threat Intelligence Platform)

AhnLab TIP is the brain behind our security platforms, helping users make informed decisions with our actionable and high-fidelity threat intelligence. Why AhnLab TIP • Actionable Threat Intelligence A generic threat information curated and analyzed in AhnLab TIP becomes the actionable cyber threat intelligence that drives an accelerated response. It allows users to effectively address unidentified and imminent cyber threats in a timely manner. • Fueling Strategic Planning AhnLab TIP delivers different types of threat intelligence – including groundbreaking research, threat actor profiling, dark web leaks, and more – to predict upcoming cyber threats and prevent them from materializing. This empowers organizations to make intel-driven security decisions at the board-level and implement priority-driven budgeting. • Customer-Specific Intelligence AhnLab TIP performs an ongoing monitoring of - media coverage, social media, open and closed sources, and more – to help customers learn about security issues related to their organizations at any given moment. The platform notifies users upon identifying relevant issues so they can respond in minutes. Key Features • Threat Lookup Users can search for various threat information spanning - IOCs, threat types, threat actors, behavioral information, and more – to fuel a unified view of cyber threats and intel-driven security decisions. The feature effectively bridges the gap between cyber threats and actual detection & response by granting a greater situational awareness. • Cloud Sandbox Analysis AhnLab TIP runs malware on a virtual environment for its dynamic cloud sandbox analysis. Then, it sifts through the malware by performing a memory dump and behavior analysis to understand the risk it can pose to the organization. • Threat Actor Profiling Our researchers never stop investigating global adversaries. AhnLab TIP continuously delivers relevant data, threat intelligence feed, and content to empower users to better understand different threat actors and confidently design security strategies. • Closed Source Analytics AhnLab TIP performs around-the-clock monitoring of closed sources such as underground forums, deep web, and dark web to aggregate real-time data and unlock threat intelligence for customers. This helps them understand what is happening underneath the surface web and how it can specifically affect their businesses. • News Clipping By providing global security current events and links to threat actors’ blogs or websites, AhnLab TIP drives users to defend against social engineering attacks and execute a swift response to asset-born cyber threats.

Who Is the Company Behind AhnLab TIP (Threat Intelligence Platform)?

  • Seller: AhnLab
  • Year Founded: 1995
  • HQ Location: Seongnam-si, KR
  • Twitter: @AhnLab_SecuInfo
    2,971 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    691 employees on LinkedIn®

AI-OS by OwlSense

AI-OS by OwlSense is an advanced open-source intelligence (OSINT) platform designed to help organizations detect, analyze, and respond to emerging digital threats. It empowers security teams, agencies, and enterprises to uncover hidden risks, monitor disinformation, and build resilience against malicious campaigns. Key Capabilities: Early Threat Detection: Identify fault lines and recognize early indicators of coordinated disinformation or destabilizing activities. Campaign Exposure: Trace individuals and networks behind harmful narratives to improve accountability and enable faster response. Counter Radicalization: Detect and analyze indoctrination methods, profiling key influencers and their reach. Comprehensive Media Analysis: Process text, audio, video, and images to deliver a complete intelligence picture. Behavioral Insights: Apply psychometric and behavioral profiling to anticipate risks and support proactive decision-making. AI-OS by OwlSense provides a holistic intelligence framework, helping organizations stay ahead of evolving online threats.

Who Is the Company Behind AI-OS by OwlSense?

AtlasCyber

AtlasCyber is an agentic threat intelligence platform that detects, investigates, and correlates cyber activity across IT, OT, and industrial environments. It analyzes network and security data to identify anomalous behavior, lateral movement, suspicious communications, and indicators of compromise. AtlasCyber combines behavioral detection, threat hunting, network forensics, campaign correlation, ATT&CK mapping, confidence-scored findings, and automated incident reporting. It deploys in cloud, on-premises, connected, segmented, and air-gapped environments. AtlasCyber helps teams understand threats faster, scope incidents, and move from detection to action.

Who Is the Company Behind AtlasCyber?

Augur

Seclytics delivers the industry's only science based platform, that hunts adversaries in the wild, during their setup stages, and delivers accurate, verifiable and actionable Attack Predictions our customers use to prevent their attacks outright, and integrate our highest value pivots that connect the dots other technologies miss. This saves them time, money and provides operational efficiencies unavailable from other solutions.

Who Is the Company Behind Augur?

CardinalOps

Powered by automation and MITRE ATT&CK, the CardinalOps platform continuously assesses and strengthens the detection coverage of your existing SIEM and other detection tools to enable a smarter, more resilient defense. It improves detection engineering productivity by more than 10x and integrates with your existing tools including Splunk, Microsoft Sentinel, IBM QRadar, Google Chronicle, CrowdStrike, and Sumo Logic.

Who Is the Company Behind CardinalOps?

Cavalier

Cavalier™ by Hudson Rock is a cutting-edge cyber intelligence platform designed to give organizations unprecedented visibility into compromised credentials and infected endpoints affecting employees, customers, and third-party vendors. At its core, Cavalier relies on one of the world’s most comprehensive databases of data stolen by infostealer malware, a fast-growing threat vector behind ransomware attacks, account takeovers, and corporate breaches. Unlike traditional dark web monitoring tools that only surface leaked credentials after they appear in dumps or marketplaces, Cavalier provides real-time intelligence on compromised identities and machines as soon as they are exfiltrated. This proactive approach allows security teams to identify which accounts, corporate assets, or partners are at risk before adversaries can exploit them. Cavalier is built for versatility and scale. Security and threat intelligence teams use it to continuously monitor digital exposure, cyber insurance providers rely on its data to assess policyholder risks, Managed Security Service Providers integrate it to enhance client protection, and third-party risk management platforms enrich their scoring models with Cavalier’s unique intelligence. The platform delivers actionable insights through both an intuitive interface and robust APIs, making it easy to integrate into existing SOC workflows, SIEMs, or other security solutions. With coverage that spans millions of infected endpoints worldwide, Cavalier equips organizations with the context and foresight needed to reduce breach risk, improve incident response, and strengthen resilience against today’s most persistent cyber threats. In short, Cavalier is the go-to solution for organizations seeking to prevent account takeovers, ransomware, and supply chain attacks before they happen.

Who Is the Company Behind Cavalier?

Censys Adversary Investigations

Adversary Infrastructure Moves. So Should You. Censys Adversary Investigation turns first-party scanning into a curated, real-time map of attacker infrastructure. Start with a certificate, domain, IP, or other signal and uncover the full campaign of related adversary infrastructure. Cut investigation times from hours to minutes. Censys ARC tracks adversaries recycled infrastructure signals and reuse patterns. Search and filter by threat types like C2 servers, phishing servers, botnet servers, and webshells, with evidence tied directly to a first-party scan of the service or endpoint. Build a node-based pivot map to document your investigation trail, visualize relationships, and track adversary infrastructure as campaigns evolve. Engineer detections at the top of the pyramid of pain, not the bottom, higher-fidelity detections, lower alert fatigue. Use Censys ARC threat intelligence as a malicious infrastructure feed, or build Collections that become tailored feeds for adversaries. Website https://censys.com/product/adversary-investigation/

Who Is the Company Behind Censys Adversary Investigations?

  • Seller: Censys
  • Year Founded: 2017
  • HQ Location: Ann Arbor, Michigan, United States
  • Twitter: @censysio
    12,386 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    188 employees on LinkedIn®
Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 22, 2025