Skip to content
Z Zendikt
Category

Threat Intelligence Software

Independent ranking of threat intelligence platforms and feeds, with verified deal pricing, separate vendor-trust dimensions.

Products tracked: 10
Last verified: 2026-05-10
Re-verified every 90 days
Editorial verdict
Read full deep-dive

Recorded Future remains the most comprehensive commercial threat intelligence platform, but the Mastercard acquisition (announced September 2024 at $2.65B, closed Q1 2025) has put its product strategy in transition and customers are watching closely. Mandiant carries the deepest incident-driven adversary research but post-Google integration has visibly slowed independent product velocity. CrowdStrike Falcon Intelligence is the easy choice for shops already running Falcon EDR, with the July 2024 outage as the only meaningful trust caveat. Dragos owns OT/ICS intelligence with no real competitor at its depth, while DomainTools and Silobreaker fit specialized DNS-anchored and OSINT-led research workflows. The category structural shift in 2026: standalone TIPs are getting squeezed between hyperscaler-native intel (Google SecOps/Mandiant, Microsoft Defender TI) and EDR-bundled intel (CrowdStrike, SentinelOne).

All 10 products, ranked

Sort: Editorial rank · · ·
  1. #1

    Recorded Future

    G2 4.6 (320)

    Broadest commercial threat intelligence platform.

    Recorded Future operates the broadest commercial threat intelligence collection in the category, spanning open web, dark web, technical sources, and proprietary research via the Insikt Group analyst team. The Intelligence Cloud serves SOC, vulnerability management, brand protection, third-party risk, and geopolitical intelligence workflows from a single platform. Mastercard announced acquisition in September 2024 for $2.65B (closed Q1 2025); the post-Mastercard product strategy is still being clarified and customers are watching for any narrowing of focus toward payments-aligned use cases.

    Pricing
    ○ Quote-only
    Vendor trust
    6.4/10
    Best fit
    500-100,000+
    Reviews analyzed
    320
    Interested in Recorded Future?
  2. #2

    Mandiant Threat Intelligence

    G2 4.5 (240)

    Deepest adversary research, now integrated into Google SecOps.

    Mandiant carries the deepest incident-driven adversary research in the industry, the result of two decades of high-profile breach response engagements (Target, Sony, SolarWinds, Colonial Pipeline, MGM). Google Cloud acquired Mandiant in March 2022 for $5.4B and has progressively integrated the team into Google Security Operations alongside Chronicle SIEM through 2023 and 2024. The combined intel feed is now consumed natively by Google SecOps customers and as a standalone subscription for non-Google SecOps shops. The trade-off: some customers disclose a visible slowdown in independent Mandiant product velocity post-acquisition as the team has been folded into the broader Google security organization.

    Pricing
    ○ Quote-only
    Vendor trust
    7.0/10
    Best fit
    1,000-100,000+
    Reviews analyzed
    240
    Interested in Mandiant Threat Intelligence?
  3. #3

    Flashpoint

    G2 4.4 (140)

    Dark-web and underground forum intelligence specialist.

    Flashpoint operates the strongest human-collection team focused on dark-web markets, closed forums, encrypted channels (Telegram, Discord, Signal), and underground actor communities. The January 2022 acquisition of Risk Based Security added vulnerability intelligence (VulnDB) to the product, giving Flashpoint a combined illicit-community plus vulnerability intel posture few competitors match. Flashpoint sits in a private-equity portfolio, which surfaces in some customer complaints about commercial aggression and contract terms.

    Pricing
    ○ Quote-only
    Vendor trust
    6.3/10
    Best fit
    500-50,000+
    Reviews analyzed
    140
    Interested in Flashpoint?
  4. #4

    CrowdStrike Falcon Intelligence

    G2 4.6 (380)

    Native intel for Falcon EDR customers.

    CrowdStrike Falcon Intelligence (and the higher-tier Falcon Adversary Intelligence Premium, formerly Falcon X) feeds adversary research, IOCs, and curated threat actor profiles directly into the Falcon endpoint and identity platform. For organizations already running Falcon EDR, the integration is the strongest in market, IOCs flow into detections without extra plumbing. The July 19, 2024 global Falcon driver issue (which affected roughly 8.5 million Windows devices) is the load-bearing trust caveat for any CrowdStrike buyer in 2026 and the company response to the incident is part of any serious vendor-risk review.

    Pricing
    ◐ Partial
    Vendor trust
    7.3/10
    Best fit
    500-100,000+
    Reviews analyzed
    380
    Interested in CrowdStrike Falcon Intelligence?
  5. #5

    Anomali

    G2 4.3 (180)

    TIP heritage with feed aggregation and SIEM-anchored correlation.

    Anomali combines a long-standing TIP (ThreatStream) with feed aggregation, correlation against historic log data (Match), and a security analytics layer added in 2022 and 2023. The platform fits organizations that want to ingest dozens of intel feeds (commercial, ISAC, open source), normalize them in STIX/TAXII, and push curated IOCs into SIEM/SOAR. Brand momentum has been quieter than Recorded Future in recent years, but the analyst workflow remains mature.

    Pricing
    ○ Quote-only
    Vendor trust
    6.8/10
    Best fit
    500-25,000+
    Reviews analyzed
    180
    Interested in Anomali?
  6. #6

    ThreatConnect

    G2 4.3 (160)

    TIP plus cyber-risk quantification in one platform.

    ThreatConnect runs a long-standing TIP combined with an unusual add-on, RQ (Risk Quantification), which translates threat exposure into estimated dollar loss values for executive reporting. The Polarity acquisition (2023) added contextual analyst overlay tooling. ThreatConnect is one of the few TIPs that bridges technical CTI and risk-leader narratives, which makes it interesting for organizations under board-level cyber-risk pressure.

    Pricing
    ○ Quote-only
    Vendor trust
    7.0/10
    Best fit
    500-50,000+
    Reviews analyzed
    160
    Interested in ThreatConnect?
  7. #7

    ThreatQuotient ThreatQ

    G2 4.4 (120)

    Lean TIP focused on threat library curation and customization.

    ThreatQuotient runs ThreatQ, a TIP focused on curated threat libraries, scoring, and lightweight automation. The product positions as analyst-team-led rather than feature-stacked, the customization surface is broad and the deployment footprint smaller than Recorded Future or Anomali. The 2020 Series C ($32M) and partnership with Securonix give it credibility in mid-market security operations, though brand reach is narrower than larger TIPs.

    Pricing
    ○ Quote-only
    Vendor trust
    7.2/10
    Best fit
    200-10,000+
    Reviews analyzed
    120
    Interested in ThreatQuotient ThreatQ?
  8. #8

    Dragos

    G2 4.6 (90)

    OT/ICS threat intelligence specialist.

    Dragos owns OT/ICS (operational technology and industrial control systems) threat intelligence in a way no general-purpose vendor matches. The Dragos Platform combines OT-aware asset discovery with threat detection driven by WorldView intelligence (the largest OT-focused threat research team in industry, tracking 25+ industrial threat groups). Dragos closed a $200M Series D in October 2022 at a $1.7B valuation, and the post-Colonial Pipeline regulatory tailwind has kept demand strong through 2026 in energy, manufacturing, water, and critical-infrastructure verticals.

    Pricing
    ○ Quote-only
    Vendor trust
    7.6/10
    Best fit
    1,000-100,000+
    Reviews analyzed
    90
    Interested in Dragos?
  9. #9

    Silobreaker

    G2 4.4 (80)

    OSINT-heavy intelligence platform with geopolitical depth.

    Silobreaker is a UK-based OSINT-led intelligence platform with particularly strong open-source, geopolitical, and strategic intelligence coverage. The platform indexes hundreds of thousands of open and dark sources daily and applies entity extraction, graph relationships, and analyst-led publishing. Fits intelligence units inside financial services, defense contractors, and risk consultancies that need to publish narrative intelligence products (not just SOC-style IOCs).

    Pricing
    ◐ Partial
    Vendor trust
    7.4/10
    Best fit
    500-25,000+
    Reviews analyzed
    80
    Interested in Silobreaker?
  10. #10

    DomainTools Iris Investigate

    G2 4.5 (110)

    DNS and domain-anchored intelligence investigation.

    DomainTools Iris Investigate is the category leader for domain, DNS, WHOIS, passive DNS, and infrastructure pivot investigations. Where a general TIP gives an IOC indicator, DomainTools gives full historical infrastructure context: registrant history, name-server pivots, SSL fingerprints, hosting relationships. The Farsight Security acquisition (2021) brought DNSDB passive DNS depth in-house. Best-fit as a specialist tool layered into a broader intel stack rather than a primary TIP.

    Pricing
    ◐ Partial
    Vendor trust
    7.7/10
    Best fit
    500-50,000+
    Reviews analyzed
    110
    Interested in DomainTools Iris Investigate?

How we rank threat intelligence software

Evaluated 22 threat intelligence platforms and feeds against six weighted dimensions: intel quality and coverage (25%), ease of use and analyst workflow (20%), value (20%), customer support (15%), integrations breadth (10%), and scalability (10%). Pricing data verified February through April 2026 across 540+ buyer-disclosed deals (anonymous, normalized to annual USD by employee band). Review intelligence pulled from G2, Capterra, Gartner Peer Insights, Reddit (r/cybersecurity, r/AskNetsec, r/sysadmin), and Trustpilot; editorial publishes only patterns that recur at 15 percent prevalence or higher across the corpus. Vendor trust scores are computed independently from product scores and weight pricing transparency, contract fairness, post-incident behavior, post-acquisition customer treatment, executive stability, and roadmap honesty. Trust events are surfaced where they materially affect buyer outcomes (acquisitions, outages, layoffs, divestitures). Verified pricing medians are bucketed by employee band and require at least 12 deal data points before publication. Compliance certifications are verified against public trust portals (SOC 2 Type 2, ISO 27001, GDPR, HIPAA, CCPA, PCI DSS, FedRAMP); we flag in-process FedRAMP separately from authorized. We did not accept vendor briefings, demo credits, or any form of sponsorship for this ranking. Where a vendor declined a fact-check window the entry notes this. Editorial independence is the entire point of Zendikt; rankings are determined by analyst consensus and never by commercial relationships.

See full deep-dive →
What you get on this category
  • 10 products with full intelligence profile
  • Verified pricing crowdsourced from real buyers
  • Vendor trust scores independent of product quality
  • review patterns from G2, Capterra, Reddit, Trustpilot
  • Quarterly re-verification of all data