License & Deployment Mix: 10 tools – 3 OSS, 6 commercial, 1 free public service.
Color: Blue team.
What Is This Category?
A Threat Intelligence Platform (TIP) is the operational hub a security team uses to consume external feeds (commercial, OSS, government, industry sharing groups), correlate the IOCs against the org’s own telemetry (SIEM, EDR, firewall logs), and produce actionable threat context: who is targeting whom, with what tools, via what infrastructure, against what victims.
Distinct from neighbouring categories
- SIEM & Log Analytics – consumes the SIEM’s logs and pushes enriched IOCs back to it; TIP is the knowledge graph, SIEM is the search engine
- SOAR – SOAR runs the response playbooks; TIP supplies the indicators those playbooks block / hunt on
- EDR / XDR – EDR detects; TIP curates the rules EDR detects with
- Reconnaissance & Asset Discovery – recon finds the attacker-targetable assets externally; TIP curates intelligence about who’s targeting them
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
TIP is the operational hub for any security team that consumes more than a handful of IOC feeds. The choice depends on scale, analyst preference, and budget: the OSS stack (MISP + OpenCTI + the free AlienVault OTX feed) covers most operational needs at zero license cost; the commercial TIPs (ThreatConnect, Anomali, EclecticIQ, ThreatQuotient) layer on managed delivery, premium feeds, and built-in playbook automation; and Recorded Future / Mandiant sit at the premium-tier intelligence-research layer rather than competing directly on operational TIP.
Capability Matrix
| Tool | Ingest Breadth | Graph Model | STIX 2.1 | Sharing | Playbooks |
|---|---|---|---|---|---|
| MISP | wide | partial | yes | first-class | partial |
| OpenCTI | wide | yes | first-class | yes | yes (Filigran Connectors) |
| YETI | narrower | yes | yes | partial | partial |
| ThreatConnect | wide | yes | yes | yes | yes (first-class) |
| Anomali ThreatStream | wide (premium) | yes | yes | yes | yes |
| Recorded Future | wide (research) | yes | yes | partial | partial |
| Mandiant Advantage | wide (Mandiant + VT) | yes | yes | partial | yes |
| EclecticIQ | wide | yes | yes | yes | yes |
| ThreatQuotient | wide | partial | yes | yes | yes |
| AlienVault OTX | wide (free) | – | yes | yes (community) | – |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| MISP | AGPL-3.0-only | yes | OSS web |
| OpenCTI | Apache-2.0 | yes | OSS web (Filigran) |
| YETI | Apache-2.0 | yes | OSS web |
| ThreatConnect | Proprietary | – | Commercial SaaS + on-prem |
| Anomali ThreatStream | Proprietary | – | Commercial SaaS + on-prem |
| Recorded Future | Proprietary | – | Commercial SaaS only (premium) |
| Mandiant Advantage | Proprietary | – | Commercial SaaS (Google) |
| EclecticIQ | Proprietary | – | Commercial SaaS + on-prem |
| ThreatQuotient | Proprietary | – | Commercial appliance + SaaS |
| AlienVault OTX | Proprietary | – | Free community SaaS |
SSO / OIDC
| Tool | OIDC | SAML | LDAP | SCIM | Authentik Notes |
|---|---|---|---|---|---|
| MISP | plugin | plugin | plugin | none | OidcAuth plugin; SAML via Apache; no SCIM |
| OpenCTI | native | native | plugin | none | Native; Authentik direct |
| YETI | plugin | plugin | none | none | Reverse-proxy auth |
| ThreatConnect | paid | paid | paid | paid | Enterprise tier |
| Anomali ThreatStream | paid | paid | paid | paid | Enterprise tier |
| Recorded Future | paid | paid | – | paid | Enterprise tier |
| Mandiant Advantage | paid | paid | – | paid | Google Workspace native; SAML on Enterprise |
| EclecticIQ | paid | paid | paid | paid | Enterprise tier |
| ThreatQuotient | paid | paid | paid | paid | Enterprise tier |
| AlienVault OTX | none | none | none | none | Free account; API key |
Deployment Comparison
| Tool | Deployment | Resources | Notes |
|---|---|---|---|
| MISP | Docker Compose | 4 CPU / 8 GB / DB | LAMP + Python workers |
| OpenCTI | Docker Compose | 8 CPU / 32 GB | 8+ services (platform / workers / ES / Redis / RabbitMQ / MinIO) |
| YETI | Docker Compose | Modest | Flask + ArangoDB + Redis |
| ThreatConnect | SaaS or on-prem | Heavy on-prem | Java + Postgres + ES |
| Anomali ThreatStream | SaaS or on-prem | Heavy on-prem | Python + Postgres + ES |
| Recorded Future | SaaS only | – | Cloud-managed |
| Mandiant Advantage | SaaS only | – | Cloud-managed (Google) |
| EclecticIQ | SaaS or on-prem | Heavy on-prem | Java + Cassandra + ES |
| ThreatQuotient | Appliance or SaaS | Linux appliance | RHEL / AlmaLinux base |
| AlienVault OTX | SaaS only | – | Free public service |
Composition Patterns
1. OSS-only operational TIP
MISP -- IOC ingestion, cross-community sharing, feed source for SIEM/EDR OpenCTI -- analyst graph-reasoning over the same IOC corpus + ATT&CK + actors AlienVault OTX -- free community feed pulled into MISP via the OTX connector
Output: full operational TIP at zero license cost, plus the AlienVault community feed for free indicator volume.
2. Commercial TIP with intelligence-cloud premium tier
ThreatConnect (or Anomali) -- operational TIP with managed playbooks Recorded Future -- intelligence-research / analyst-augmentation tier
Output: managed operational TIP + premium-tier analyst research. Frequent enterprise pattern.
3. European / data-sovereignty pattern
EclecticIQ on-prem -- TIP with European data residency MISP -- complement for cross-org sharing
Output: enterprise-grade TIP without US-based SaaS exposure.
Cost Tier
Approximate annual TCO for a mid-size SOC.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | MISP + OpenCTI + AlienVault OTX | $0 + operator time |
| Mid | ThreatConnect / Anomali / EclecticIQ / ThreatQuotient | $50,000-200,000 / year |
| Premium | Recorded Future / Mandiant Advantage on top | $100,000-500,000 / year |
Tools
11 tools.
AlienVault OTX
AT&T Cybersecurity’s free community threat-intel sharing platform; large free user base; freemium model.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none
Anomali ThreatStream
Commercial threat-intel platform with Optic AI tier; intelligence- as-a-service model emphasising vetted premium feeds.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
EclecticIQ
Dutch commercial TIP with European intelligence-community heritage; graph-first model; popular in EU public sector.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Intelligence X
European search engine and data archive over darknet, leaks, breach data, paste sites, WHOIS/DNS history and the public web, searched by strong selectors. Freemium with paid API and subscriptions.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, breach-data, darknet, data-archive, whois-history, search-engine
Evaluated under OSINT & Investigative Intelligence.
Mandiant Advantage
Mandiant’s threat-intel platform (now Google Threat Intelligence); deep incident-response heritage; nation-state actor research.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
MISP
Open-source Threat Intelligence Platform and IOC-sharing community; STIX-native, MISP-galaxy + warning-lists out of the box.
License: AGPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC
OpenCTI
Open-source threat-intel platform from Filigran and ANSSI; graph- first data model on a GraphQL API; STIX 2.1 native.
License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML
Recorded Future
Commercial intelligence-cloud platform; AI-driven threat research at scale; widely regarded as the premium-tier choice.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
ThreatConnect
Commercial threat-intel platform with Playbooks orchestration tier; large customer base in MSSP and Fortune 500 SOCs.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
ThreatQuotient
Commercial TIP with scoring-engine differentiator; popular in financial-services SOCs; on-prem-first heritage.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
YETI
Open-source threat-intel platform with investigation-driven UX; Python + Flask + ArangoDB; broader-than-MISP entity model.
License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: none