Skip to main content

Career Education

Threat intelligence tools help security teams collect, organise, analyse and apply information about cyber threats. They can reveal malicious infrastructure, investigate suspicious files, monitor emerging vulnerabilities, study attacker behaviour and enrich security alerts with additional context.

The category includes much more than threat intelligence platforms. Security teams may use community feeds, malware-analysis services, vulnerability catalogues, internet-scanning databases, adversary knowledge bases and intelligence features built into SIEM or endpoint-security platforms.

No single tool provides a complete picture. VirusTotal may help an analyst investigate a suspicious file, while MITRE ATT&CK explains the behaviours associated with an intrusion. MISP or OpenCTI can organise intelligence, GreyNoise can provide context about internet scanning, and CISA’s Known Exploited Vulnerabilities catalogue can help prioritise patching.

The right combination depends on the organisation’s assets, sector, staffing, technology and intelligence requirements. This guide covers the threat intelligence tools every security team should know, what each is best used for and how they fit into security monitoring, SOC operations, threat detection and incident response.

What Are Threat Intelligence Tools?

Threat intelligence tools are technologies and information resources used to collect, process, analyse, share or operationalise knowledge about cyber threats.

Some tools supply raw indicators such as malicious IP addresses, domains, URLs and file hashes. Others connect those indicators with malware families, campaigns, vulnerabilities and attacker tactics.

A threat intelligence platform may combine several feeds, remove duplicates, enrich indicators and distribute selected intelligence to defensive systems. A malware-analysis service may examine files or URLs, while an internet-intelligence platform helps analysts investigate exposed infrastructure.

Frameworks and databases also belong in the threat intelligence toolkit. MITRE ATT&CK organises adversary behaviour, while vulnerability resources such as the NVD and CISA KEV catalogue help teams understand and prioritise security weaknesses.

These tools should ultimately support decisions. Collecting millions of indicators has little value unless the organisation can determine which ones are relevant, reliable and actionable.

Threat Feeds, Platforms and Analysis Tools

Security teams sometimes use the terms feed, platform and tool interchangeably, but they serve different purposes.

A threat feed is a regularly updated stream of information. It may contain domains, IP addresses, hashes, vulnerabilities or phishing URLs. Feeds are useful inputs, but they often need validation and enrichment.

A threat intelligence platform, commonly called a TIP, combines information from several sources. It may normalise formats, remove duplicates, manage confidence and distribute intelligence to other security systems.

An analysis tool helps analysts investigate a particular object or behaviour. VirusTotal, for example, can provide information about a suspicious file, domain or URL.

A knowledge base organises known information so analysts can understand patterns. MITRE ATT&CK is a leading example because it structures adversary behaviour into tactics and techniques.

Most mature security operations use several of these categories together rather than attempting to replace everything with one product.

Threat Intelligence Tools at a Glance

Tool or resourceMain purposeBest suited to
MITRE ATT&CKOrganising adversary tactics and techniquesThreat analysis, hunting and detection engineering
MISPSharing and correlating indicators and intelligenceCommunities, incident teams and intelligence sharing
OpenCTIBuilding a connected threat-intelligence knowledge baseStrategic, operational and technical intelligence
VirusTotalInvestigating files, URLs, domains and indicatorsMalware triage, enrichment and hunting
Open Threat ExchangeCommunity-created threat intelligenceAccessible feeds and collaborative research
GreyNoiseAnalysing internet scanning and exploitation activityAlert enrichment and internet-edge monitoring
CISA KEVIdentifying vulnerabilities under active exploitationVulnerability prioritisation
NVDResearching standardised vulnerability informationVulnerability management and technical research
CensysDiscovering and investigating internet-facing assetsExposure management and infrastructure analysis
Microsoft Defender TIInvestigating external threat infrastructureThreat hunting, triage and incident response
Microsoft Sentinel TICorrelating intelligence with SIEM dataMicrosoft-based SOC operations
Splunk threat intelligenceMatching threat indicators with security eventsSplunk-based monitoring and investigations
ThreatConnectManaging intelligence and operational workflowsMature intelligence and response programmes

The table is not a ranking. Each tool solves a different part of the intelligence problem.

1. MITRE ATT&CK

MITRE ATT&CK is one of the most important resources for threat intelligence and security operations. It is a knowledge base of adversary tactics and techniques drawn from real-world observations.

ATT&CK helps analysts describe what attackers do during an intrusion. Its tactics represent broad objectives, such as gaining initial access, establishing persistence, collecting information or moving through an environment. Techniques explain how those objectives may be achieved.

The framework provides a common language for intelligence analysts, threat hunters, detection engineers and incident responders. Two reports may use different names for an attacker or malware family but still describe similar techniques. Mapping the activity to ATT&CK makes the behaviour easier to compare.

Security teams can use ATT&CK to review whether their logs and security controls provide visibility into relevant adversary techniques. Detection engineers can create analytics around those behaviours, while threat hunters can use them to develop search hypotheses.

ATT&CK is not a detection product and does not prove attribution. Many attackers use the same techniques. It should be used to organise and compare evidence, not to conclude that one group is responsible simply because a technique matches.

2. MISP

MISP is an open-source threat intelligence platform designed for collecting, storing, correlating and sharing cyber-security indicators and threat information.

It is widely associated with information-sharing communities, incident-response teams and organisations that need structured intelligence exchange. Users can create events containing indicators, contextual information, relationships and tags.

MISP supports different sharing models. Intelligence can remain private, be shared with selected communities or be distributed more broadly according to the organisation’s rules.

Its correlation capabilities can reveal that an indicator appears across several incidents or reports. Analysts may discover that a domain, file hash or email address has already been connected with other malicious activity.

MISP is particularly useful when the organisation wants control over its own intelligence-sharing infrastructure. However, open-source licensing does not make the platform effortless or cost-free. It still requires secure hosting, maintenance, integration, access management and people who understand intelligence quality.

MISP is often a strong choice for teams focused on indicators of compromise and collaborative intelligence sharing.

3. OpenCTI

OpenCTI is an open-source cyber threat intelligence platform designed to structure, store, organise and visualise technical and non-technical threat information.

Its knowledge-graph model is an important feature. Instead of treating every indicator as an isolated record, OpenCTI can represent relationships among threat actors, intrusion sets, malware, campaigns, vulnerabilities, reports, assets and observables.

This makes it useful for organisations that need to connect strategic, operational and technical intelligence. An analyst can move from a threat actor to associated campaigns, techniques, malware and infrastructure while preserving source and confidence information.

OpenCTI uses connectors to import and export information. These connectors may bring in threat feeds, reports, vulnerabilities, sightings and alerts or send intelligence to security tools.

The platform can support intelligence production, investigations, threat hunting and knowledge management. It is generally more useful when a team wants to build a connected intelligence repository rather than maintain a simple indicator list.

As with MISP, successful deployment requires governance. The organisation needs clear naming, confidence, source, retention and sharing rules. Otherwise, the knowledge graph can accumulate conflicting or outdated relationships.

MISP vs OpenCTI

MISP and OpenCTI overlap, but their strengths are slightly different.

MISP has strong capabilities for event-based indicator sharing and community collaboration. It is frequently used when organisations need to exchange structured threat information quickly.

OpenCTI places greater emphasis on building a connected knowledge base containing actors, campaigns, techniques, vulnerabilities and reports alongside technical indicators.

Some organisations use both. MISP may support indicator exchange, while OpenCTI provides broader intelligence analysis and visualisation. Others select one platform based on team size, workflows and integration requirements.

The better option is the one that fits the organisation’s intelligence process. A platform should not be selected only because it has more features.

4. VirusTotal

VirusTotal is one of the best-known tools for investigating suspicious files, URLs, domains and IP addresses.

An analyst can search for a file hash and review information collected from several security engines and analysis sources. VirusTotal may also provide relationships, behaviour, metadata, contacted infrastructure and community information.

This makes it valuable during alert triage. If an endpoint tool detects an unfamiliar file, the analyst can use the hash to gather additional context and determine whether the item has been associated with known malware.

VirusTotal Intelligence adds more advanced search and hunting capabilities. Analysts can search across historical datasets using properties such as file type, metadata, detection results and behavioural characteristics.

YARA-based hunting features can help qualified researchers identify files matching defined patterns. These functions are more suitable for trained malware analysts and threat hunters than ordinary end users.

VirusTotal results require interpretation. A file being detected by one engine does not automatically prove that it is malicious, while a file receiving no detections does not prove that it is safe.

Teams must also follow organisational data-handling rules. Suspicious confidential files should not be submitted to an external analysis service without approval.

5. Open Threat Exchange

Open Threat Exchange, commonly known as OTX, is a community-powered threat intelligence service.

Its intelligence is organised into collections known as pulses. A pulse can contain indicators associated with a campaign, malware family, vulnerability or other cyber threat.

Security teams can follow relevant contributors, search indicators and use the OTX API to synchronise intelligence with monitoring tools. This makes it a useful starting point for small organisations, students and teams that need accessible community intelligence.

OTX’s collaborative model provides broad visibility, but community intelligence varies in quality and depth. One pulse may contain detailed research and reliable indicators, while another may provide limited context.

Teams should therefore review source reputation, dates and supporting information before using an indicator for blocking or high-impact decisions.

OTX is often most useful for enrichment, research and initial investigation rather than as an unquestioned source of truth.

6. GreyNoise

GreyNoise focuses on internet-wide scanning and exploitation activity.

Publicly reachable systems constantly receive traffic from automated scanners, bots, researchers and malicious actors. Some of this traffic is targeted, but much of it is opportunistic background activity that reaches large numbers of internet addresses.

GreyNoise collects and analyses this activity. Its intelligence can help analysts understand whether an IP address is part of common internet scanning, associated with malicious behaviour or potentially more relevant to a particular investigation.

This context can reduce alert fatigue. A SOC analyst investigating a connection attempt can determine whether the source is widely scanning the internet or whether it deserves greater attention.

GreyNoise can also help teams monitor emerging exploitation activity at the network edge. However, classification should not replace investigation. Widespread scanning can still exploit a vulnerable system, while an unknown address is not automatically safe.

The tool is most valuable when integrated into alert-enrichment and internet-exposure workflows.

7. CISA Known Exploited Vulnerabilities Catalogue

The CISA Known Exploited Vulnerabilities catalogue, usually called the KEV catalogue, is one of the most valuable vulnerability-prioritisation resources.

It lists vulnerabilities for which there is evidence of active exploitation. This provides information that a severity score alone cannot supply.

A vulnerability may receive a high technical severity score without being used widely by attackers. Another weakness with a lower score may be actively exploited against internet-facing systems. KEV helps teams recognise the practical difference.

Security teams should combine the catalogue with their own asset inventory and exposure information. A listed vulnerability becomes urgent when the organisation uses the affected product and the system is accessible to attackers or supports an important service.

KEV does not replace vulnerability scanning, risk assessment or vendor guidance. It provides an important threat-intelligence input that helps teams prioritise remediation.

8. National Vulnerability Database

The National Vulnerability Database, or NVD, is a standards-based repository of vulnerability-management data maintained by NIST.

It provides information connected with Common Vulnerabilities and Exposures identifiers, including descriptions, affected products and impact metrics. Security teams use it to research vulnerabilities and integrate standardised data into vulnerability-management processes.

NVD and CISA KEV should be used together rather than treated as competitors. NVD provides broad vulnerability information, while KEV identifies a smaller group confirmed as actively exploited.

Neither database knows the organisation’s internal context. Teams must still determine whether the affected product is present, whether the vulnerable component is exposed and what business impact exploitation could create.

NVD is particularly useful for technical research, automation and consistent communication about vulnerabilities across different tools and teams.

9. Censys

Censys provides searchable information about internet-facing hosts, web properties and certificates.

Security teams can use it to investigate infrastructure connected with a threat, identify exposed services and understand how systems appear from the public internet.

During an investigation, an analyst might use Censys to study a suspicious IP address, search for related certificates or identify other infrastructure with similar properties.

Defenders can also monitor their own internet-facing assets. This may reveal an unexpected service, forgotten system or certificate relationship that is not visible in an internal inventory.

Censys should be used responsibly and within legal and organisational boundaries. Its value for defenders is exposure visibility and infrastructure analysis—not unauthorised access.

Internet-intelligence platforms do not replace internal asset management. They show an external view that should be compared with the organisation’s own records.

10. Microsoft Defender Threat Intelligence

Microsoft Defender Threat Intelligence is a platform for investigating external threat infrastructure and supporting triage, hunting, vulnerability management and incident response.

It can provide information about internet infrastructure and relationships involving domains, IP addresses, certificates, hosting and other threat artefacts.

Security analysts can use it to investigate an indicator found during an alert, explore related infrastructure and determine whether it has connections with known malicious activity.

It can be particularly useful for organisations already using Microsoft’s security ecosystem because intelligence can support workflows across Defender and Sentinel.

The tool should still be considered one source among several. Vendor visibility reflects the data available to that provider and may not describe the entire threat landscape.

11. Microsoft Sentinel Threat Intelligence

Microsoft Sentinel is a SIEM platform with threat-intelligence ingestion and operationalisation capabilities.

It can import intelligence through supported connectors, including STIX and TAXII sources, and correlate indicators with security events collected from the organisation’s environment.

Security teams can use this intelligence to create analytics rules, enrich incidents, conduct threat hunting and build workbooks showing intelligence activity.

Sentinel is not a full replacement for every dedicated TIP. Its strength is applying intelligence directly to security monitoring and investigation within a Microsoft-based SOC.

Organisations should manage indicator expiry and confidence carefully. Importing large volumes of low-quality intelligence can increase processing costs and produce noisy detections.

12. Splunk Threat Intelligence

Splunk Enterprise Security can ingest threat intelligence and correlate it with organisational events.

The platform can maintain collections of indicators and compare them with network, endpoint, identity and other security data. When a match occurs, analysts receive additional context for investigation.

This is valuable for organisations already using Splunk as the centre of their security monitoring. Intelligence can become part of searches, detections and case investigation instead of remaining in a separate portal.

As with any SIEM integration, the quality of the result depends on the quality of the data. Indicators need timestamps, confidence and retention controls.

Sending every public feed into Splunk without filtering can increase storage and alert noise. Teams should begin with sources connected to their intelligence requirements.

13. ThreatConnect

ThreatConnect is a commercial platform combining threat intelligence management with security workflows and operational features.

It supports intelligence objects, indicators, relationships, APIs and playbooks. Its intelligence-requirement capabilities can help teams connect collection and analysis with defined organisational priorities.

ThreatConnect may suit mature security teams that need intelligence management, workflow automation, collaboration and case-related functions within a supported commercial platform.

Commercial platforms can reduce some hosting and integration burden, but they do not remove the need for analysts. The organisation must still evaluate sources, manage confidence and decide how intelligence should influence security operations.

Product selection should be based on tested workflows rather than a long feature list.

STIX and TAXII Tools

STIX and TAXII are not threat feeds or analysis platforms, but every threat intelligence team should understand them.

STIX is a structured language for representing cyber threat information. It can describe indicators, malware, attack patterns, campaigns, threat actors and relationships.

TAXII is a protocol for exchanging cyber threat intelligence between systems. A TIP, SIEM or another security product may use TAXII to retrieve STIX-formatted intelligence from a server.

These standards improve interoperability, but they do not guarantee quality. A properly formatted indicator can still be outdated or incorrect.

Security teams should therefore treat STIX and TAXII as methods for structuring and transporting intelligence—not as evidence that the intelligence is reliable.

How SOC Teams Use Threat Intelligence Tools

A SOC commonly uses threat intelligence for alert enrichment, prioritisation, detection engineering and threat hunting.

When an alert includes a domain, hash or IP address, analysts can check it against VirusTotal, OTX, GreyNoise or a TIP. The additional context may show whether the indicator is connected with malware, widespread scanning or a known campaign.

MITRE ATT&CK can help analysts understand the behaviour represented by the alert. Sentinel or Splunk can correlate intelligence directly with internal events.

Threat hunters may use ATT&CK techniques and OpenCTI relationships to develop hypotheses. Internet-intelligence tools can then provide supporting infrastructure context.

The objective is not to use every tool during every alert. Teams should create repeatable workflows showing which sources are appropriate for different questions.

How Incident Responders Use the Tools

Incident responders use threat intelligence tools to identify the scope and likely consequences of an intrusion.

VirusTotal may provide information about a detected file. A TIP can identify related domains and hashes, while ATT&CK can organise observed attacker behaviour.

Censys or Defender TI may help investigate external infrastructure. MISP can store and share newly discovered indicators, while SIEM integrations can search the organisation’s historical logs for additional matches.

Intelligence should influence response decisions. If the malware is associated with credential theft, responders should investigate accounts and sessions rather than only deleting the file.

Evidence from the incident should also return to the intelligence repository so that future detection and sharing improve.

Free vs Commercial Threat Intelligence Tools

Free and open-source tools can provide substantial capability. MITRE ATT&CK, MISP, OpenCTI, OTX, CISA KEV and NVD can support many intelligence tasks without commercial licence fees.

However, free does not mean costless. Hosting, maintenance, integration, training and analyst time may be significant.

Commercial products may provide curated intelligence, technical support, managed infrastructure and integrations. They can reduce operational effort, but expensive intelligence is not automatically relevant or accurate.

A small team may gain more value from a few trusted free resources integrated into an existing SIEM than from a complex commercial TIP it cannot maintain.

The correct comparison is total operational value—not simply licence price.

How to Choose the Right Tools

Begin with intelligence requirements. Identify which decisions, detections and investigations need improvement.

A team struggling with malware triage may prioritise VirusTotal. One overwhelmed by internet scanning alerts may benefit from GreyNoise. An organisation building a sharing community may select MISP, while a mature intelligence team may need OpenCTI or a commercial TIP.

Consider integration with the existing SIEM, endpoint platform, case-management system and identity tools. Intelligence that remains in a separate portal may be ignored during urgent investigations.

Evaluate source transparency, update frequency, retention controls, confidence scoring, access management and privacy. Run a proof of concept using realistic internal workflows.

The goal is not to own the largest toolset. It is to create a small, connected collection that supports measurable security outcomes.

Common Threat Intelligence Tool Mistakes

The first mistake is subscribing to too many feeds. Large volumes of duplicated indicators create noise and maintenance work.

Another mistake is automatically blocking every indicator. Shared infrastructure, expired domains and false positives can disrupt legitimate services.

Teams may also trust vendor scoring without understanding its evidence or rely too heavily on one provider’s visibility.

Platforms can become passive repositories when nobody owns analysis or operational action. Intelligence collected without requirements rarely produces lasting value.

Finally, analysts should not upload sensitive files or internal information to external services without approval. Threat research must follow organisational privacy and data-handling rules.

Building a Practical Toolset

A new or small security team can start with MITRE ATT&CK for behavioural understanding, VirusTotal for indicator research, CISA KEV and NVD for vulnerability context, and one community source such as OTX.

If the organisation needs structured sharing, MISP is a logical next step. OpenCTI becomes useful when the team needs a connected knowledge base covering actors, campaigns, techniques and infrastructure.

Internet-facing asset monitoring may justify Censys, while GreyNoise can improve context around scanning traffic. Existing Sentinel or Splunk environments should use their built-in threat-intelligence capabilities before another overlapping platform is purchased.

The toolset should grow only when a new requirement cannot be met effectively by the current workflow.

Frequently Asked Questions

What are threat intelligence tools?

They are technologies and resources used to collect, analyse, organise, share or apply information about cyber threats.

What is the best free threat intelligence tool?

There is no single best option. MITRE ATT&CK supports behavioural analysis, VirusTotal supports indicator research, and MISP or OpenCTI supports intelligence management.

Is VirusTotal a threat intelligence tool?

Yes. It provides information and search capabilities for files, URLs, domains, IP addresses and related threat data.

Is MITRE ATT&CK a threat intelligence platform?

No. It is a knowledge base and framework for organising adversary tactics and techniques. It does not perform the same ingestion and management functions as a TIP.

What is the difference between MISP and OpenCTI?

MISP is particularly strong for structured event and indicator sharing. OpenCTI emphasises a connected knowledge graph covering technical and non-technical intelligence.

What tools help prioritise vulnerabilities?

CISA KEV identifies vulnerabilities confirmed as actively exploited, while NVD provides broader standardised vulnerability information.

What is the purpose of GreyNoise?

GreyNoise analyses internet scanning and exploitation traffic, helping security teams distinguish widespread background activity from potentially more relevant events.

Can threat intelligence tools block attacks automatically?

Some can send indicators to firewalls, SIEM platforms or endpoint tools. Automatic blocking should use validated, sufficiently confident intelligence.

Does a small business need a threat intelligence platform?

Not always. Government alerts, vendor intelligence and features already built into existing security products may be sufficient.

How many threat intelligence tools should a SOC use?

There is no ideal number. A SOC should use the smallest connected set that supports its intelligence requirements, monitoring and incident-response workflows.

Conclusion

Threat intelligence tools help security teams transform scattered threat data into useful cyber defence.

MITRE ATT&CK provides a common language for attacker behaviour. MISP and OpenCTI organise and share intelligence, while VirusTotal and OTX support indicator investigation.

GreyNoise provides context around internet scanning. CISA KEV and NVD strengthen vulnerability prioritisation, and Censys helps teams understand internet-facing infrastructure.

Microsoft Defender Threat Intelligence, Sentinel, Splunk and ThreatConnect connect intelligence with SOC operations, hunting and incident response.

No single tool is sufficient. The most effective approach combines a small number of complementary resources and connects them to defined decisions.

Security teams should begin with intelligence requirements, test realistic workflows and measure whether each tool improves detection, prioritisation or response.

When tools are selected carefully and supported by skilled analysis, threat intelligence becomes more than a collection of feeds. It becomes a practical capability that helps the organisation recognise relevant threats earlier, investigate incidents faster and build stronger cyber defence.

Leave a Reply

Your email address will not be published. Required fields are marked *