Loading...
Threat intel feeds are the raw and finished intelligence streams that tell your team what attackers are doing, who they are targeting, and which indicators to watch. The range runs from machine-readable IOC feeds of IPs, domains, hashes, and malicious URLs through curated threat actor reporting, dark web and cybercrime monitoring, and vulnerability intelligence. Security teams use these streams to enrich detections in the SIEM or SOAR, reorder patching, hunt proactively, and brief leadership on threats that actually matter to their sector. At one end you have broad commodity coverage. At the other, finished reporting tailored to your industry and the specific adversaries that target it.
We cover 97 Threat Intel Feeds tools, 45 free and 52 commercial.
Accuracy and depth improve over time. Last reviewed Aug 2026. Is something off? Reach out.
New to this category? What is Threat Intel Feeds?
AI-powered vulnerability intelligence database with real-time threat context
Vulnerability threat intelligence platform with risk-based scoring and CVE/CWE data
OT/IoT threat intelligence feed for vulnerability and malware detection
Investigative intelligence service for law enforcement agencies
Threat intelligence feeds for SOC teams from social, dark web & botnet sources
IP intelligence platform for proxy/VPN detection and geolocation
API service providing IP geolocation data and intelligence for security use cases
Cloud service that automates threat blocking on firewalls, routers & switches
Threat intelligence feeds providing malware and threat data in multiple formats
Enterprise threat intelligence feeds covering malware, phishing, C2, and IPs
Threat intelligence platform providing global threat visibility and IoCs
Real-time C2 infrastructure detection and disruption threat intelligence feed
A tiered cyber threat intelligence service providing detection rules from public repositories with varying levels of analysis, processing, and guidance for security teams.
Technical threat intel feed of compromised IPs/domains from cybercrime sources
Proactive C2 threat intelligence feed for detecting adversary infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
A collaborative platform that gathers and analyzes security data to help professionals identify and mitigate cyber threats.
TeamTNT is modifying its malicious shell scripts after they were made public by security researchers.
RiskAnalytics Solutions offers community projects for cyber threat intelligence sharing and collaboration.
Check the reputation of an IP address to identify potential threats.
CINSscore.com provides Threat Intelligence database with accurate IP scores and collective defense through community and Sentinel IPS unit sourced data.
Common questions about Threat Intel Feeds tools, selection guides, pricing, and comparisons.
A threat intel feed is a continuously updated stream of data about threats, delivered to your security stack. At one end you have machine-readable indicators, malicious IPs, domains, file hashes, and URLs that enrich detection and blocking. At the other end you have finished intelligence: analyst-written reports on threat actors, campaigns, and dark web chatter that humans read to make decisions.
Start with the outcome you need. To enrich detections, prioritize feed coverage, indicator freshness, false-positive rate, and STIX/TAXII integration with your SIEM. For strategic context, prioritize analyst quality, sector relevance, and language coverage for the regions and underground forums where your adversaries operate. Match the feed to your maturity, not the vendor's pitch.
A feed is a source of data. A threat intelligence platform (TIP) is where you aggregate, deduplicate, score, and operationalize feeds from many sources. Feeds are an input. A TIP is the management layer that turns multiple inputs into something your SOC can act on. Many teams run several feeds into one platform rather than relying on a single source.
Free and open-source feeds, abuse trackers, OSINT lists, and community sources, are genuinely useful for baseline blocking and enrichment, and many mature teams use them alongside paid sources. Their limits show up in freshness, context, false positives, and the absence of finished analysis. Commercial feeds earn their cost through curation, sector-specific reporting, dark web access, and lower noise. Most programs blend both.
Vulnerability intelligence is the bridge. Knowing a CVE exists is one thing. Knowing it is being actively exploited by an actor that targets your industry is what changes your patching order. Feeds drive that decision, along with detection engineering, threat hunting, and the briefings you give leadership. They turn a generic risk list into a prioritized, evidence-backed plan.