Threat intelligence · LevelBlue

LevelBlue Open Threat Exchange

Free, community-contributed threat-intelligence platform of shared indicators of compromise, now operated by LevelBlue.

Open Threat Exchange began as AlienVault OTX and is now operated by LevelBlue, the rebranded AT&T Cybersecurity, as a free, crowd-sourced threat-intelligence platform. Community members and LevelBlue's own research team publish Pulses, curated bundles of indicators of compromise such as malicious IPs, domains, file hashes, and related CVEs, that give context to an emerging threat rather than a bare list of indicators. Anyone can browse, search, discuss, and validate Pulses through the web portal, and consume the same data programmatically through a free DirectConnect REST API or a STIX/TAXII feed, with SDKs published for Python, Go, Java, and Node.js. A companion OTX Endpoint Security module lets users scan their own endpoints for the presence of catalogued indicators at no cost. Unlike most other tools in this category, OTX has no paid tier: the entire platform is free.

At a glance

Vendor LevelBlue
Pricing model Free
Free tier Yes
Deployment Cloud
Open source No
Best for Teams wanting a no-cost, community-sourced IOC feed to enrich existing security tools.

Pricing

The entire platform, web portal, API, and feeds, is free with no paid tier.

Pricing has not been verified yet — see the vendor's site.

Features

  • Community-contributed Pulses bundling related indicators of compromise
  • Free DirectConnect REST API and STIX/TAXII feed
  • SDKs for Python, Go, Java, and Node.js
  • OTX Endpoint Security for free endpoint IOC scanning
  • Discussion and validation of threat data by the community
  • Integration path into LevelBlue USM Anywhere

Profile last reviewed September 21, 2026

Alternatives

LevelBlue Open Threat Exchange in the index now

Terms to know

Related guides