Threat intelligence · LevelBlue
LevelBlue Open Threat Exchange
Free, community-contributed threat-intelligence platform of shared indicators of compromise, now operated by LevelBlue.
Open Threat Exchange began as AlienVault OTX and is now operated by LevelBlue, the rebranded AT&T Cybersecurity, as a free, crowd-sourced threat-intelligence platform. Community members and LevelBlue's own research team publish Pulses, curated bundles of indicators of compromise such as malicious IPs, domains, file hashes, and related CVEs, that give context to an emerging threat rather than a bare list of indicators. Anyone can browse, search, discuss, and validate Pulses through the web portal, and consume the same data programmatically through a free DirectConnect REST API or a STIX/TAXII feed, with SDKs published for Python, Go, Java, and Node.js. A companion OTX Endpoint Security module lets users scan their own endpoints for the presence of catalogued indicators at no cost. Unlike most other tools in this category, OTX has no paid tier: the entire platform is free.
At a glance
| Vendor | LevelBlue |
|---|---|
| Pricing model | Free |
| Free tier | Yes |
| Deployment | Cloud |
| Open source | No |
| Best for | Teams wanting a no-cost, community-sourced IOC feed to enrich existing security tools. |
Pricing
The entire platform, web portal, API, and feeds, is free with no paid tier.
Pricing has not been verified yet — see the vendor's site.
Features
- Community-contributed Pulses bundling related indicators of compromise
- Free DirectConnect REST API and STIX/TAXII feed
- SDKs for Python, Go, Java, and Node.js
- OTX Endpoint Security for free endpoint IOC scanning
- Discussion and validation of threat data by the community
- Integration path into LevelBlue USM Anywhere
Profile last reviewed September 21, 2026