License & Deployment Mix: 10 tools – 3 OSS, 6 commercial, 1 free public service.

Color: Blue team.

What Is This Category?

A Threat Intelligence Platform (TIP) is the operational hub a security team uses to consume external feeds (commercial, OSS, government, industry sharing groups), correlate the IOCs against the org’s own telemetry (SIEM, EDR, firewall logs), and produce actionable threat context: who is targeting whom, with what tools, via what infrastructure, against what victims.

Distinct from neighbouring categories

  • SIEM & Log Analytics – consumes the SIEM’s logs and pushes enriched IOCs back to it; TIP is the knowledge graph, SIEM is the search engine
  • SOAR – SOAR runs the response playbooks; TIP supplies the indicators those playbooks block / hunt on
  • EDR / XDR – EDR detects; TIP curates the rules EDR detects with
  • Reconnaissance & Asset Discovery – recon finds the attacker-targetable assets externally; TIP curates intelligence about who’s targeting them

The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.

Comparison

TIP is the operational hub for any security team that consumes more than a handful of IOC feeds. The choice depends on scale, analyst preference, and budget: the OSS stack (MISP + OpenCTI + the free AlienVault OTX feed) covers most operational needs at zero license cost; the commercial TIPs (ThreatConnect, Anomali, EclecticIQ, ThreatQuotient) layer on managed delivery, premium feeds, and built-in playbook automation; and Recorded Future / Mandiant sit at the premium-tier intelligence-research layer rather than competing directly on operational TIP.


Capability Matrix

ToolIngest BreadthGraph ModelSTIX 2.1SharingPlaybooks
MISPwidepartialyesfirst-classpartial
OpenCTIwideyesfirst-classyesyes (Filigran Connectors)
YETInarroweryesyespartialpartial
ThreatConnectwideyesyesyesyes (first-class)
Anomali ThreatStreamwide (premium)yesyesyesyes
Recorded Futurewide (research)yesyespartialpartial
Mandiant Advantagewide (Mandiant + VT)yesyespartialyes
EclecticIQwideyesyesyesyes
ThreatQuotientwidepartialyesyesyes
AlienVault OTXwide (free)yesyes (community)

License Comparison

ToolLicenseOSIType
MISPAGPL-3.0-onlyyesOSS web
OpenCTIApache-2.0yesOSS web (Filigran)
YETIApache-2.0yesOSS web
ThreatConnectProprietaryCommercial SaaS + on-prem
Anomali ThreatStreamProprietaryCommercial SaaS + on-prem
Recorded FutureProprietaryCommercial SaaS only (premium)
Mandiant AdvantageProprietaryCommercial SaaS (Google)
EclecticIQProprietaryCommercial SaaS + on-prem
ThreatQuotientProprietaryCommercial appliance + SaaS
AlienVault OTXProprietaryFree community SaaS

SSO / OIDC

ToolOIDCSAMLLDAPSCIMAuthentik Notes
MISPpluginpluginpluginnoneOidcAuth plugin; SAML via Apache; no SCIM
OpenCTInativenativepluginnoneNative; Authentik direct
YETIpluginpluginnonenoneReverse-proxy auth
ThreatConnectpaidpaidpaidpaidEnterprise tier
Anomali ThreatStreampaidpaidpaidpaidEnterprise tier
Recorded FuturepaidpaidpaidEnterprise tier
Mandiant AdvantagepaidpaidpaidGoogle Workspace native; SAML on Enterprise
EclecticIQpaidpaidpaidpaidEnterprise tier
ThreatQuotientpaidpaidpaidpaidEnterprise tier
AlienVault OTXnonenonenonenoneFree account; API key

Deployment Comparison

ToolDeploymentResourcesNotes
MISPDocker Compose4 CPU / 8 GB / DBLAMP + Python workers
OpenCTIDocker Compose8 CPU / 32 GB8+ services (platform / workers / ES / Redis / RabbitMQ / MinIO)
YETIDocker ComposeModestFlask + ArangoDB + Redis
ThreatConnectSaaS or on-premHeavy on-premJava + Postgres + ES
Anomali ThreatStreamSaaS or on-premHeavy on-premPython + Postgres + ES
Recorded FutureSaaS onlyCloud-managed
Mandiant AdvantageSaaS onlyCloud-managed (Google)
EclecticIQSaaS or on-premHeavy on-premJava + Cassandra + ES
ThreatQuotientAppliance or SaaSLinux applianceRHEL / AlmaLinux base
AlienVault OTXSaaS onlyFree public service

Composition Patterns

1. OSS-only operational TIP

MISP -- IOC ingestion, cross-community sharing, feed source for SIEM/EDR OpenCTI -- analyst graph-reasoning over the same IOC corpus + ATT&CK + actors AlienVault OTX -- free community feed pulled into MISP via the OTX connector

Output: full operational TIP at zero license cost, plus the AlienVault community feed for free indicator volume.

2. Commercial TIP with intelligence-cloud premium tier

ThreatConnect (or Anomali) -- operational TIP with managed playbooks Recorded Future -- intelligence-research / analyst-augmentation tier

Output: managed operational TIP + premium-tier analyst research. Frequent enterprise pattern.

3. European / data-sovereignty pattern

EclecticIQ on-prem -- TIP with European data residency MISP -- complement for cross-org sharing

Output: enterprise-grade TIP without US-based SaaS exposure.


Cost Tier

Approximate annual TCO for a mid-size SOC.

TierToolingApprox Cost
FreeMISP + OpenCTI + AlienVault OTX$0 + operator time
MidThreatConnect / Anomali / EclecticIQ / ThreatQuotient$50,000-200,000 / year
PremiumRecorded Future / Mandiant Advantage on top$100,000-500,000 / year

Tools

11 tools.

AlienVault OTX

AT&T Cybersecurity’s free community threat-intel sharing platform; large free user base; freemium model.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none

Website

Anomali ThreatStream

Commercial threat-intel platform with Optic AI tier; intelligence- as-a-service model emphasising vetted premium feeds.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

EclecticIQ

Dutch commercial TIP with European intelligence-community heritage; graph-first model; popular in EU public sector.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

Intelligence X

European search engine and data archive over darknet, leaks, breach data, paste sites, WHOIS/DNS history and the public web, searched by strong selectors. Freemium with paid API and subscriptions.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: none · Tags: osint, breach-data, darknet, data-archive, whois-history, search-engine

Website

Evaluated under OSINT & Investigative Intelligence.

Mandiant Advantage

Mandiant’s threat-intel platform (now Google Threat Intelligence); deep incident-response heritage; nation-state actor research.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

MISP

Open-source Threat Intelligence Platform and IOC-sharing community; STIX-native, MISP-galaxy + warning-lists out of the box.

License: AGPL-3.0-only (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC

Website · Source

OpenCTI

Open-source threat-intel platform from Filigran and ANSSI; graph- first data model on a GraphQL API; STIX 2.1 native.

License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML

Website · Source

Recorded Future

Commercial intelligence-cloud platform; AI-driven threat research at scale; widely regarded as the premium-tier choice.

License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML

Website

ThreatConnect

Commercial threat-intel platform with Playbooks orchestration tier; large customer base in MSSP and Fortune 500 SOCs.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

ThreatQuotient

Commercial TIP with scoring-engine differentiator; popular in financial-services SOCs; on-prem-first heritage.

License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML

Website

YETI

Open-source threat-intel platform with investigation-driven UX; Python + Flask + ArangoDB; broader-than-MISP entity model.

License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: none

Website · Source

ResorsIT Tools Catalog Search