
Top picks: Hudson Rock Cybercrime Intelligence Tools, MISP TAXII Server, YETI — plus 45 more compared.
Threat IntelligenceEvaluating libtaxii alternatives comes down to matching Threat Intelligence capabilities to your environment, integrations, and budget rather than chasing feature parity. The options below are compared on what actually drives a switch: coverage, deployment fit, pricing, and real reviews from security teams. Independent and vendor-neutral: our scores and rankings are earned, never bought — sponsored placement is always labeled.
libtaxii is a free Threat Intel Platforms tool. Security professionals most commonly compare it with Hudson Rock Cybercrime Intelligence Tools, MISP TAXII Server, YETI, Filigran OpenCTI, and CatchProbe ThreatWay. All 48 alternatives are matched by shared capabilities, tags, and NIST CSF 2.0 coverage.
A closer look at the 8 most relevant alternatives and competitors to libtaxii, including their key features and shared capabilities.
Cybercrime intelligence tools for searching compromised credentials from infostealers
OpenTAXII config enabling TAXII-based threat intel sharing with MISP.
Shares 3 capabilities with libtaxii: Open Source, Cyber Threat Intelligence, Taxii
YETI is a proof-of-concept TAXII implementation that supports Inbox, Poll, and Discovery services for automated cyber threat intelligence indicator exchange.
Shares 3 capabilities with libtaxii: Open Source, Cyber Threat Intelligence, Taxii
Open-source threat intelligence platform for organizing and operationalizing CTI
Cyber threat intelligence sharing platform with TAXII/STIX support
Phishing threat intel platform detecting phishing URLs, kits & brand impersonation.
Free contextual federated search tool for threat intelligence enrichment
Q-Feeds provides curated threat intelligence feeds and a Threat Intelligence Portal designed to integrate with existing security tools such as firewalls, SIEMs, and TAXII/STIX platforms rather than replacing them. The platform delivers IP, URL, and domain threat feeds that can be consumed through pre-built integrations with firewall vendors (Fortinet, Palo Alto, Sophos XGS, OPNsense, pfSense, MikroTik) and SIEM platforms (Splunk, Microsoft Sentinel, Wazuh), as well as threat intelligence platforms (OpenCTI, MISP, EclecticIQ, Anomali ThreatStream, ThreatConnect) via TAXII/STIX 2.1. Additional capabilities offered as part of the product suite include: - Threat Lookup for querying an IOC database with MITRE ATT&CK mapping - Dark web monitoring for tracking exposure of organizational assets - External Attack Surface management for identifying internet-facing assets - Vulnerability scanning for infrastructure and web applications - Brand protection for detecting look-a-like domains and phishing attempts Q-Feeds offers a free Community Edition, with Plus and Premium tiers available for expanded access.</description> <parameter name="summary">Curated threat intel feeds and TIP integrating with firewalls, SIEMs, and TIPs
Cybercrime intelligence tools for searching compromised credentials from infostealers
OpenTAXII config enabling TAXII-based threat intel sharing with MISP.
YETI is a proof-of-concept TAXII implementation that supports Inbox, Poll, and Discovery services for automated cyber threat intelligence indicator exchange.
Open-source threat intelligence platform for organizing and operationalizing CTI
Cyber threat intelligence sharing platform with TAXII/STIX support
Phishing threat intel platform detecting phishing URLs, kits & brand impersonation.
Free contextual federated search tool for threat intelligence enrichment
n6 is a network security incident exchange system that collects, manages, and distributes threat and incident data through REST API and web interfaces for authorized users.
CyBot is a free and open source threat intelligence chat bot with a community-driven plugin framework.
OSTrICa is an open source plugin-based framework that collects and visualizes threat intelligence data from various sources to help cybersecurity professionals correlate IoCs and enhance their defensive capabilities.
Repository with projects for photo and video hashing, content moderation, and signal exchange.
ActorTrackr is an open source web application for storing, searching, and linking threat actor intelligence data from public repositories and user contributions.
A neo4j-based data management platform with command-line interface for analyzing cyber threat indicators and other data points through graph database traversal.
A data visualization and statistical analysis tool for measuring the quality and effectiveness of threat intelligence indicator feeds through various analytical tests.
nyx is a threat intelligence artifact distribution system that facilitates the sharing of threat intelligence indicators from various sources to defensive security systems with configurable criticality levels.
A threat intelligence dissemination layer for open-source security tools with STIX-2 support and plugin-based architecture.
PyIOCe is a Python-based OpenIOC editor that enables security professionals to create, edit, and manage Indicators of Compromise for threat intelligence and incident response operations.
Continuous threat intelligence and exposure management across dark, deep & clear web.
Enterprise threat intelligence platform for identifying and prioritizing threats
API platform providing historical DNS, WHOIS, and IP data for security research.
Next-gen cybersecurity platform for threat detection & digital risk mgmt.
Cyber threat intelligence platform for threat-led risk management
Global IP threat intelligence search engine with attack surface mgmt
Cyber threat intelligence platform providing actionable insights
Real-time threat intelligence platform for external cyber threat defense
AI-driven cyber threat intelligence platform for threat detection and analysis
Real-time threat intelligence platform for monitoring attacks and breaches
Enterprise cyber threat intelligence platform with remote network protection
Cyber intelligence platform for threat detection and security posture mgmt
Cyber threat intelligence platform with adversary tracking capabilities
Threat intelligence platform combining Google, Mandiant, and VirusTotal data
Orchestrated threat intelligence platform for CTI and SOC teams
Threat intelligence platform for aggregating, analyzing, and sharing CTI data
AI-powered threat intelligence platform for real-time threat intel management
Threat intelligence platform for detection, investigation, and response
XTM portfolio for threat intel, attack surface visibility & adversary simulation
AI-powered threat intelligence platform with agentic AI automation
AI-powered platform for collecting and analyzing open source threat intelligence
AI-powered threat intel platform for operationalizing CTI and cyber risk mgmt
CTI platform combining automated collection with cyber HUMINT for threat intel
Investigative analytics platform for threat intelligence and security ops
Real-time threat intel platform detecting malicious scanning & exploitation
Threat intelligence service providing alerts, analysis, and support
Threat intelligence platform with deep/dark web monitoring and OSINT data
Cyber threat intelligence platform for monitoring threats, TTPs, and IOCs
AI-driven cyber intelligence orchestration platform for threat intel & OSINT
CTI platform monitoring deep/dark web, forums & threat actors for intel
Common questions security professionals ask when evaluating alternatives and competitors to libtaxii.
The most popular alternatives to libtaxii include Hudson Rock Cybercrime Intelligence Tools, MISP TAXII Server, YETI, Filigran OpenCTI, and CatchProbe ThreatWay. These Threat Intel Platforms tools offer similar capabilities and are frequently compared by security professionals evaluating their options.
There are 48 alternatives to libtaxii listed on CybersecTools, all within the Threat Intel Platforms category. Each alternative is matched based on shared capabilities, tags, and NIST CSF coverage areas.
libtaxii is a free Threat Intel Platforms tool. You can use it at no cost. Both free and commercial alternatives are available for comparison.
libtaxii is a Threat Intel Platforms tool within the broader Threat Intelligence category. It is used by security professionals for threat intel platforms capabilities and can be compared against 48 similar tools.