Install
Tools
Threat intelligence
8 tools compared: how each is priced, where it runs, and what to consider instead.
| Tool | Pricing model | Free tier | Open source |
|---|---|---|---|
| Censys Internet-wide scanning platform that maps public-facing infrastructure for attack-surface management and adversary-infrastructure tracking. | Quote only | Yes | No |
| Flashpoint Threat-intelligence platform built on primary-source data collected from underground forums, marketplaces, and adversary communities. | Quote only | No | No |
| Google Mandiant Frontline threat-intelligence and incident-response practice, now part of Google Cloud, built on data from its own breach investigations. | Quote only | No | No |
| Google VirusTotal Aggregates verdicts from dozens of antivirus engines and blocklist services on submitted files and URLs, now operated by Google. | Free tier + paid | Yes | No |
| GreyNoise Classifies internet-wide scanning traffic as benign, malicious, or unknown so SOC teams can filter background noise out of alerts. | Free tier + paid | Yes | No |
| Intel 471 HUMINT-driven cybercrime intelligence platform built on analysts' direct engagement inside closed criminal communities. | Quote only | No | No |
| LevelBlue Open Threat Exchange Free, community-contributed threat-intelligence platform of shared indicators of compromise, now operated by LevelBlue. | Free | Yes | No |
| Shodan Search engine that indexes internet-connected devices and services by crawling the entire internet, used both defensively and offensively. | Subscription | Yes | No |