Loading...
Threat intel feeds are the raw and finished intelligence streams that tell your team what attackers are doing, who they are targeting, and which indicators to watch. The range runs from machine-readable IOC feeds of IPs, domains, hashes, and malicious URLs through curated threat actor reporting, dark web and cybercrime monitoring, and vulnerability intelligence. Security teams use these streams to enrich detections in the SIEM or SOAR, reorder patching, hunt proactively, and brief leadership on threats that actually matter to their sector. At one end you have broad commodity coverage. At the other, finished reporting tailored to your industry and the specific adversaries that target it.
We cover 97 Threat Intel Feeds tools, 45 free and 52 commercial.
Accuracy and depth improve over time. Last reviewed Aug 2026. Is something off? Reach out.
New to this category? What is Threat Intel Feeds?
A publicly available dataset of security incidents designed to support cybersecurity research and threat analysis.
Repository containing IoCs related to Volexity's threat intelligence blog posts and tools.
Aggregator of FireHOL IP lists with HTTP-based API service and Python client package.
Public access to Indicators of Compromise (IoCs) and other data for readers of Security Scorecard's technical blog posts and reports.
Gathers Threat Intelligence Feeds from publicly available sources and provides detailed output in CSV format.
Repository containing MITRE ATT&CK and CAPEC threat intelligence datasets formatted in STIX 2.0 standard for cybersecurity analysis and threat intelligence sharing.
A collection of disposable and temporary email address domains used for spamming or abusing services.
CyberOwl aggregates and summarizes daily security advisories from multiple CERT organizations and threat intelligence sources into consolidated reports.
A daily collection of IOCs from various sources, including articles and tweets.
A collection of APT and cybercriminals campaigns with various resources and references.
AbuseIPDB offers tools and APIs to report and check abusive IPs, enhancing network security.
Daily feed of bad IPs with blacklist hit scores for cybersecurity professionals to stay informed about malicious IP addresses.
A database of Tor exit nodes with their corresponding IP addresses and timestamps.
The Cybersecurity and Infrastructure Security Agency (CISA) is a government agency that provides alerts, advisories, and resources to help protect the United States' critical infrastructure from cyber threats.
A comprehensive list of APT groups and operations for tracking and mapping different names and naming schemes used by cybersecurity companies and antivirus vendors.
Dataplane.org is a nonprofit organization providing free data, tools, and analysis to increase awareness of Internet trends, anomalies, threats, and misconfigurations.
OpenPhish provides real-time phishing trends, detecting new phishing URLs and targeting various brands.
Maldatabase is a threat intelligence platform providing malware datasets and threat intelligence feeds for malware data science and threat intelligence.
A project sharing malicious URLs used for malware distribution to help protect networks.
FraudGuard is a service that provides real-time internet traffic analysis and IP tracking to help validate usage and prevent fraud.
A project that detects malicious SSL connections by identifying and blacklisting SSL certificates used by botnet C&C servers and identifying JA3 fingerprints to detect and block malware botnet C&C communication.
WiGLE.net is a platform that collects and provides data on WiFi networks and cell towers, with over 1.3 billion networks collected.
Common questions about Threat Intel Feeds tools, selection guides, pricing, and comparisons.
A threat intel feed is a continuously updated stream of data about threats, delivered to your security stack. At one end you have machine-readable indicators, malicious IPs, domains, file hashes, and URLs that enrich detection and blocking. At the other end you have finished intelligence: analyst-written reports on threat actors, campaigns, and dark web chatter that humans read to make decisions.
Start with the outcome you need. To enrich detections, prioritize feed coverage, indicator freshness, false-positive rate, and STIX/TAXII integration with your SIEM. For strategic context, prioritize analyst quality, sector relevance, and language coverage for the regions and underground forums where your adversaries operate. Match the feed to your maturity, not the vendor's pitch.
A feed is a source of data. A threat intelligence platform (TIP) is where you aggregate, deduplicate, score, and operationalize feeds from many sources. Feeds are an input. A TIP is the management layer that turns multiple inputs into something your SOC can act on. Many teams run several feeds into one platform rather than relying on a single source.
Free and open-source feeds, abuse trackers, OSINT lists, and community sources, are genuinely useful for baseline blocking and enrichment, and many mature teams use them alongside paid sources. Their limits show up in freshness, context, false positives, and the absence of finished analysis. Commercial feeds earn their cost through curation, sector-specific reporting, dark web access, and lower noise. Most programs blend both.
Vulnerability intelligence is the bridge. Knowing a CVE exists is one thing. Knowing it is being actively exploited by an actor that targets your industry is what changes your patching order. Feeds drive that decision, along with detection engineering, threat hunting, and the briefings you give leadership. They turn a generic risk list into a prioritized, evidence-backed plan.