Tools

Threat intelligence

8 tools compared: how each is priced, where it runs, and what to consider instead.

Tool Pricing model Free tier Open source
Censys Internet-wide scanning platform that maps public-facing infrastructure for attack-surface management and adversary-infrastructure tracking. Quote only Yes No
Flashpoint Threat-intelligence platform built on primary-source data collected from underground forums, marketplaces, and adversary communities. Quote only No No
Google Mandiant Frontline threat-intelligence and incident-response practice, now part of Google Cloud, built on data from its own breach investigations. Quote only No No
Google VirusTotal Aggregates verdicts from dozens of antivirus engines and blocklist services on submitted files and URLs, now operated by Google. Free tier + paid Yes No
GreyNoise Classifies internet-wide scanning traffic as benign, malicious, or unknown so SOC teams can filter background noise out of alerts. Free tier + paid Yes No
Intel 471 HUMINT-driven cybercrime intelligence platform built on analysts' direct engagement inside closed criminal communities. Quote only No No
LevelBlue Open Threat Exchange Free, community-contributed threat-intelligence platform of shared indicators of compromise, now operated by LevelBlue. Free Yes No
Shodan Search engine that indexes internet-connected devices and services by crawling the entire internet, used both defensively and offensively. Subscription Yes No

In the index now