Loading...
Threat intel feeds are the raw and finished intelligence streams that tell your team what attackers are doing, who they are targeting, and which indicators to watch. The range runs from machine-readable IOC feeds of IPs, domains, hashes, and malicious URLs through curated threat actor reporting, dark web and cybercrime monitoring, and vulnerability intelligence. Security teams use these streams to enrich detections in the SIEM or SOAR, reorder patching, hunt proactively, and brief leadership on threats that actually matter to their sector. At one end you have broad commodity coverage. At the other, finished reporting tailored to your industry and the specific adversaries that target it.
We cover 97 Threat Intel Feeds tools, 45 free and 52 commercial.
Accuracy and depth improve over time. Last reviewed Aug 2026. Is something off? Reach out.
New to this category? What is Threat Intel Feeds?
Subscription threat intel service with reports, translations & security notifications.
AI-based domain & IP threat scoring API for security product integration.
ML-based URL & domain classification API for threat and content scoring.
AI-powered URL classification & IP reputation feed/API for security vendors.
Suite for abuse desk mgmt, email blocklisting & threat intel for ISPs.
Real-time threat intel platform with IP/domain reputation scoring and low false positives.
Real-time threat intel feeds sourced from honeypots & ISP abuse reports.
IP address blocklist service for identifying and blocking fraudulent IPs
Real-time IP fraud detection and risk scoring API for identifying malicious IPs
API service for detecting proxies, VPNs, Tor nodes, and malicious IPs
Database for detecting proxies, VPNs, Tor nodes, and high-risk IP addresses
Daily threat intel feed identifying malicious IPs with abuse classifications
Threat intelligence feeds covering 100+ attack types with 5-min updates
Domain reputation threat intelligence feeds for malicious domain detection
AI-driven threat intel feeds for automated blocking on 20+ firewall vendors
Curated phishing threat intelligence feed with predictive detection
Behavior-based threat intel feed delivering malware IOCs with context
Weekly threat intelligence briefings published by VerSprite
Cyber threat intelligence feeds for SOC and threat intelligence teams
Threat intelligence library with 30,000+ threats mapped to MITRE ATT&CK
AI-powered threat intelligence feed for automated DDoS protection
Database for detecting VPNs, proxies, Tor exits, and anonymization services
CTI services combining human expertise and AI for threat analysis
API for monitoring ransomware sites to detect org compromises & extortion
Common questions about Threat Intel Feeds tools, selection guides, pricing, and comparisons.
A threat intel feed is a continuously updated stream of data about threats, delivered to your security stack. At one end you have machine-readable indicators, malicious IPs, domains, file hashes, and URLs that enrich detection and blocking. At the other end you have finished intelligence: analyst-written reports on threat actors, campaigns, and dark web chatter that humans read to make decisions.
Start with the outcome you need. To enrich detections, prioritize feed coverage, indicator freshness, false-positive rate, and STIX/TAXII integration with your SIEM. For strategic context, prioritize analyst quality, sector relevance, and language coverage for the regions and underground forums where your adversaries operate. Match the feed to your maturity, not the vendor's pitch.
A feed is a source of data. A threat intelligence platform (TIP) is where you aggregate, deduplicate, score, and operationalize feeds from many sources. Feeds are an input. A TIP is the management layer that turns multiple inputs into something your SOC can act on. Many teams run several feeds into one platform rather than relying on a single source.
Free and open-source feeds, abuse trackers, OSINT lists, and community sources, are genuinely useful for baseline blocking and enrichment, and many mature teams use them alongside paid sources. Their limits show up in freshness, context, false positives, and the absence of finished analysis. Commercial feeds earn their cost through curation, sector-specific reporting, dark web access, and lower noise. Most programs blend both.
Vulnerability intelligence is the bridge. Knowing a CVE exists is one thing. Knowing it is being actively exploited by an actor that targets your industry is what changes your patching order. Feeds drive that decision, along with detection engineering, threat hunting, and the briefings you give leadership. They turn a generic risk list into a prioritized, evidence-backed plan.