We ran hands-on proofs of concept on 5 cyber threat intelligence services, scoring each against the same 33 criteria across 8 categories, using a shared probe set of historical IOCs, 6 threat actors, and 4 exploited CVEs. The most counterintuitive result is that free AlienVault OTX matched CrowdStrike, the priciest platform here, on automation.
See how the 5 services scored, where each one leads, and how to combine them into a layered threat intelligence program:
Cyber threat intelligence services compared
ConfirmedPartial or behind a separate tierAbsent*CrowdStrike is scored at product-family level since its capabilities span 4+ subscriptions (see methodology).
Scores by category
ConfirmedPartial or behind a separate tierAbsentThese 5 services represent 5 distinct threat intelligence archetypes, so the benchmark identifies positioning rather than declaring a single winner: each product performs a different job in a threat intelligence program.
Key findings
Price and tier do not predict capability in the same direction across all 8 categories:
- The free platform matched the premium leaders on automation interfaces. AlienVault OTX exposes REST APIs, SDKs and TAXII at no cost, and scores full marks on integration and API, the same 4 of 4 as CrowdStrike and Feedly, while CrowdStrike gates its STIX/TAXII feed behind Premium and X-Force returns 403 on API calls from its free tier.
- The coverage leader moved CVE intelligence to a separate product. CrowdStrike confirmed 30 of the 33 criteria, with 0 absent capabilities and 1 structural gap. CVE data and the ExPRT.AI score live in the separate Falcon Exposure Management SKU rather than in Adversary Intelligence. In terms of CVE depth, the freemium X-Force and Feedly are more integrated than the most expensive product in the benchmark.
- The lowest score does not mean the worst product. GreyNoise confirmed 10 criteria and scored absent on 16. Its confirmed marks cluster in one place: classifying scanning IPs as benign, malicious, suspicious, or unknown, which none of the other 4 services does. The 16 absent criteria are attribution, malware, dark web, and finished intelligence.
- The most complete freemium platform is being retired. X-Force offered the most complete freemium experience in the benchmark, but IBM has announced an end-of-life date of Aug. 31, 2026, with customers transitioning to Palo Alto Cortex.1
- The OSINT aggregator scored second. Feedly confirmed 19 capabilities through AI-based IoC and TTP extraction, EPSS-scored vulnerability intelligence, and the widest export and delivery range of the 5.
CrowdStrike Falcon Adversary Intelligence
Figure 1. CrowdStrike Falcon Adversary Intelligence main view
CrowdStrike covers all 33 criteria at the product family level, though 3 are partially available. We tested it on a Premium trial in the EU-1 region.2 The trial did not require MFA, though sessions dropped after about an hour. CrowdStrike’s CTI capabilities are not a single product but a family, spanning Adversary Intelligence (base), Adversary Intelligence Premium, Counter Adversary Operations (CAO) Elite, Recon and Recon+, and Exposure Management. The score is measured at the product-family level for that reason.
Data sources
The base is first-party Falcon sensor telemetry combined with Counter Adversary Operations and OverWatch research, plus Recon collection across open, deep, and dark web.
Figure 2. CrowdStrike Falcon dashboard enables adding restricted pages
Recon monitors millions of restricted pages, criminal forums, and encrypted platforms, the one service here that reaches underground sources inside the product family.
Coverage and intelligence types
The malware module lists 4,207 malware families, each with capabilities (RAT, InfoStealer, credential harvesting, botnet), target systems, associated adversaries, and filters for vulnerabilities, kill chain, and MITRE.
Figure 3. The malware module
MalQuery searches 3.5B+ files and Falcon Sandbox runs in the base tier. Brand monitoring, domain and social-media impersonation (Recon) and exposed-credential detection with Falcon Identity Protection forced reset (Recon) both exist here and in no other tested service. The single gap is vulnerability intelligence. CVE data and the ExPRT.AI score sit in the separate Exposure Management SKU, so bridging an adversary to a CVE needs two subscriptions.
Analysis and enrichment
Every adversary profile carries a MITRE ATT&CK matrix and kill chain tab directly in the interface, base tier, with no API call and no Premium wall. No other tested service renders ATT&CK natively. OTX returns it through the API alone, X-Force reserves it for Premium content and Feedly derives it through aggregation.
Figure 4. ATT&CK Matrix per adversary
Intel Explorer joins adversary, malware, vulnerability and report, and the Indicator Graph API exposes those relationships. IOC risk uses malicious_confidence buckets (high, medium, low, unverified), which are coarser than X-Force’s numeric 1 to 10 scale.
287 named adversaries, each with a structured profile covering origin, motivation, target industries, and 30+ target countries. In our probes, APT28 alias mapping (STRONTIUM, Forest Blizzard, Sofacy, Sednit, Pawn Storm, BlueDelta) matched our answer key exactly.
Attribution
The console listed 287 named adversaries (public materials cite 281+ for 2026), each structured with origin, motivation, target industries and countries, intel-report count, and community ID.
Figure 5. CrowdStrike Falcon Adversaries
The FANCY BEAR profile (APT28) ran from a first-seen date of 2007 to last-seen April 2026, marked state-sponsored, origin Russian Federation, 30+ target countries, with full alias reconciliation: STRONTIUM, Forest Blizzard, Sofacy, Sednit, Pawn Storm, Iron Twilight, BlueDelta, and APT28, matching our answer key exactly.
Figure 6. Summary of threat intelligence with fancy bear
Labyrinth Chollima mapped to Lazarus and Carbon Spider to FIN7; LockBit, Scattered Spider, and MuddyWater were searchable by community ID. All of this is base tier.
Platform
Faceted adversary search plus platform-wide FQL and a SearchIndicators API cover query needs; the Intelligence hub carries dashboards, bookmarks, and notifications, with Recon monitoring rules for brand and identity alerts.
The Reports module contains 429 completed intelligence reports (filtered by adversary, MITRE, industry, country, and malware), plus the 2025 Threat Hunting Report; the full library is Premium.
No other tested service offers RFI access (5 a year, Premium) or an assigned analyst (CAO Elite). Because CTI shares a console with Falcon EDR/XDR, NG-SIEM, Investigate, and Fusion SOAR, an existing Falcon customer can access it through the same console as EDR/XDR, NG-SIEM, Investigate, and Fusion SOAR.
Integration and API.
An OAuth2 REST API (Create API client, api.eu-1 base) ships with two official SDKs, FalconPy for Python and PSFalcon for PowerShell, the most mature programmatic access of the 5.
Figure 7. CrowdStrike Falcon OAuth2 REST API clients list
Fusion SOAR is native and the intel feed exports STIX/TAXII/JSON, though the STIX/TAXII feed is Premium. On the free-automation axis alone, OTX is stronger.
Reporting
The tool spans strategic, operational, tactical and sector reports, with report PDF, API, STIX/TAXII and email or SIEM delivery. The Reports module holds 429 finished intelligence reports (filters for adversary, MITRE, industry, country, and malware) plus the 2025 Threat Hunting Report; the full library is Premium.
Figure 8. CrowdStrike Falcon finished Recon reports
Operational scenarios
Recon+ delivers end-to-end managed takedown (fake accounts, phishing, domains) with CSC Global one-click, the sole in-platform takedown across the 5. OverWatch managed hunting, Fusion SOAR, FalconPy and YARA/SNORT support intel-led hunting (Premium). CrowdStrike loses both partial marks to packaging: vulnerability prioritization (ExPRT.AI) sits in Exposure Management, and Recon supply-chain monitoring focuses on partner and supplier impersonation rather than full vendor-risk rating.
Where it leads and where it costs
Two of the 3 partial marks come from CVE intelligence sitting in a separate SKU. The third is supply-chain coverage, which stops at partner and supplier impersonation and does not extend to vendor-risk rating. The real trade-offs are SKU fragmentation across 4+ subscriptions, the highest total cost of the 5, no free feed layer, and coarser risk scoring than X-Force or GreyNoise.
Best for: Mature SOC and CTI teams with an attribution-centered threat intelligence program (APT tracking, campaigns, ATT&CK) and budget for digital risk protection, especially existing Falcon EDR/XDR customers. Budget-constrained teams or those needing a single narrow capability should look elsewhere.
Feedly Threat Intelligence
The AI-OSINT aggregation layer, and the second-highest score of the 5. We tested it on a 30-day Threat Intelligence trial (“Playground”) with passwordless magic-link login. Feedly produces no first-party telemetry. Its Leo AI reads sources and its Threat Graph holds 10M+ articles, 681M+ IoCs, 300K+ CVEs, 979 threat actors, 12K+ malware families and 800 TTPs. Pricing runs about $19.2K a year for Standard and $38.4K for Advanced, with the MCP Server and advanced API in Advanced or Enterprise.
Data sources
The Today board sorts articles into AI-curated categories (vulnerabilities, cyberattacks, threat intel, security news, vendor advisories) and deduplicates coverage of one event across many sources, collapsing a card marked “+426 feeds” into a single item. Behind it sit 10,000+ curated, clear, and dark web sources plus millions of raw feeds. Feedly runs no sensor network of its own, the 1 absent mark in this category, and reaches the dark web through aggregation of published sources.
Figure 9. Feedly Threat Intelligence Workspace
Coverage and intelligence types
Leo extracts IoCs from article text automatically: a GodDamn Ransomware card was tagged “IoC > 4 IPs and 18 hashes” and a jscrambler supply-chain card “5 email addresses and 5 hashes,” pulling 4 IoC types structurally, something pulse tags and reputation lookups cannot do.
Figure 10. Threat Intel board
No other tested service puts CVSS, EPSS, KEV, and exploitation status on a single screen.
Figure 11. CVE Item detail
The two gaps are brand tracking (partial, keyword-based) and leaked credentials (absent).
Analysis and enrichment
Leo tags articles with ATT&CK techniques (“33 TTPs,” “24 TTPs,” “TA0004”) and exports them to Navigator, and the Real-Time Threat Graph is a working relationship graph across article, IoC, CVE, TTP, actor, and malware. Raw IP and hash reputation are not their own engines; they cross-reference VirusTotal and GreyNoise. There is no formal article risk score; scoring stays on the vulnerability side through EPSS and CVSS.
Attribution
Threat Actor Insights Cards cover 979 actors, with alias reconciliation and links to targets, TTPs, malware, and CVEs. However, the content is OSINT-derived rather than first-party, so Feedly compiles attribution rather than authoring it.
Platform
AI Feeds take boolean queries, Ask AI takes natural language, and Team Boards carry watchlist alerts. Finished intelligence is machine-generated through Ask AI and Insights Cards, which scored partial against a criterion written for analyst-authored libraries. RFI and analyst-on-demand are absent.
Integration and API
A STIX 2.1 REST API, 11+ SIEM/SOAR connectors (Anomali, MISP, Cortex XSOAR, EclecticIQ, ThreatQ, ThreatConnect, Sentinel, Splunk, OpenCTI), multi-format export and delivery to Slack, Teams, email and newsletter are all present. The MCP Server, for AI-assisted CTI automation, appears in no other tested service.
Reporting
Report Builder and Ask AI generate executive summaries, vulnerability advisories, actor TTP briefs and newsletters, so the product outputs ready deliverables rather than raw data.
Operational scenarios
The Vulnerability Dashboard is the integrated EPSS/KEV prioritization in the main product of any tested service. IoC matching feeds SOAR and TIP with context, and an MCP-driven ServiceNow ticket path exists. The Vulnerability Dashboard is the single, integrated EPSS/KEV prioritization, built into the main product rather than an add-on.
Figure 12. Feedly Threat Intelligence vulnerabilities board
Where it leads and where it falls short
Feedly scored absent on 4 criteria: first-party sensor telemetry, a leaked-credential database, RFI access, and takedown service. Its 4 attribution criteria scored partial because the actor data is compiled from published research rather than generated in-house.
Best for: Self-service CTI teams that want to speed up OSINT triage, track CVEs and TTPs, and produce ready intelligence deliverables. Treat it as a compiler layer on top of primary sources, not a replacement for them.
IBM X-Force Exchange (retiring soon)
⚠ IBM has announced the end of life for X-Force Exchange on Aug 31, 2026, with QRadar and threat intelligence capabilities transitioning to Palo Alto Cortex. An architecture built on it needs a migration path from the start.
Figure 13. IBM X-Force Exchange dashboard
X-Force scored 16 confirmed, 12 partial, and 5 absent, the highest confirmed count among the free and freemium tiers tested. We tested it on the free Freemium tier with an IBMid.3 First login forced email-OTP MFA enrollment and a terms-of-service acceptance. The tier model splits capability by price. Freemium gives the portal and sample reports with no API, Essentials adds the REST API, enrichment, and TAXII, Standard adds a bulk feed, and Premium unlocks threat-group, industry, malware, and ATT&CK depth.
Data sources
The feed combines IBM’s own research teams, a ReversingLabs malware partnership, IP, URL, vulnerability, and signature feeds, and Quad9 DNS telemetry. Volume sits below OTX’s roughly 20M IOCs a day. The SUNBURST domain returned a single Botnet C2 classification against the 1,487 tags the same indicator drew on OTX. The dark web is absent from the platform; real monitoring runs in separate X-Force IRIS services.
Coverage and intelligence types
The Conti C2 IP (162.244.80.235) returned a numeric Risk 1/10 after aging, a categorization history (marked “Unsuspicious” at the time of testing, after a 2022 analyst review removed the malware tag), a 31-event timeline, ASN and subnet, WHOIS, and passive DNS. The SUNBURST domain4 came back Risk 10/10, Botnet C2, with the FBI Cyber Division sinkhole recorded in WHOIS, against the 1,487-tag noise the same indicator drew on OTX. The signature capability is the X-Force Database, 260K+ vulnerabilities: a Log4Shell search cross-referenced 50 vulnerabilities, 200 signatures, 200 exploiting IPs, 5 threat-group profiles, 11 malware analyses, and 3 industries, without any additional SKU. The WannaCry hash returned family, type, platform, 97% community coverage, and ReversingLabs Titanium data with first- and last-seen dates. Leaked credentials are absent, and the brand is partial.
Coverage and intelligence types
The Conti C2 IP (162.244.80.235) returned a numeric Risk 1/10 after aging, a categorization history (marked “Unsuspicious” today after a 2022 analyst review removed the malware tag), a 31-event timeline, ASN and subnet, WHOIS and passive DNS.
Figure 14. IBM X-Force Conti C2 IP
The SUNBURST domain4 returned Risk 10/10, Botnet C2, with the FBI Cyber Division sinkhole recorded in WHOIS, against the 1,487 tags the same indicator drew on OTX.
Figure 15. SUNBURST URL search
The signature capability is the X-Force Database, 260K+ vulnerabilities: a Log4Shell search cross-referenced 50 vulnerabilities, 200 signatures, 200 exploiting IPs, 5 threat-group profiles, 11 malware analyses, and 3 industries, without any additional SKU.
Figure 16. Log4Shell tracking
The WannaCry hash returned family, type, platform, 97% community coverage, and ReversingLabs Titanium data with first- and last-seen dates. Leaked credentials are absent, and brand is partial.
Figure 17. WannaCry malware report
Analysis and enrichment
The numeric Risk 1 to 10 score carries an analyst-review temporal timeline, the single numeric scoring model in a free tier. OTX offers no numeric score, and GreyNoise uses 4 categories. ATT&CK is not on the IOC page; it appears in Premium content, and there is no visual link graph.
Attribution
Structured Threat Group and IRIS ITG profiles exist, and the 2026 advisory stream is current (APT28 PRISMEX, Early Warning). But Freemium shows samples alone, deep profiles are Premium, and most large APTs have no dedicated profile under IBM’s ITG naming, so alias reconciliation falls to the analyst. This trails CrowdStrike’s 287-adversary profiles with UI-native ATT&CK.
Platform
Faceted search (10+ types plus a risk filter), a vulnerability-focused Watchlist, Collections, and Notifications make the free portal the most mature of the freemium and community tiers. The gap is analyst access: no RFI in the product.
Reporting
The finished intelligence library runs to 8+ report types (Threat Group, OSINT, Malware, Industry, Threat Index) and stays current through 2026, with a Financial Services industry profile breaking down sector and geography. Move to Operational scenarios, rewritten as: CVSS exploitability scoring and cross-reference are present. EPSS is absent, and there is no productized path from the CVE list to the patch order.
Figure 18. Financial Services industry profile report
Integration and API
Per-report STIX 2 export works in Freemium, and QRadar integration is native, but the API and TAXII start at Essentials and the bulk feed at Standard, so the free tier returns 403 on API calls. X-Force gives away the interface and charges for automation. OTX does the reverse.
Operational scenarios
Dark web monitoring, leaked credentials, takedowns, and RFIs are outside the platform, some of them in separate X-Force IR and TI services. Threat hunting relies on Collections, STIX export, and QRadar, with bulk operationalization tied to the paid API.
Where it leads and where it falls short
The XFDB vulnerability database, the numeric-risk enrichment, and the current finished-intel library place X-Force above OTX and below CrowdStrike, in the middle-upper band. Weaknesses: the end-of-life date, paid automation, no in-platform action layer, and Premium-gated attribution. The Aug 2026 end-of-life date sets the useful horizon.
Best for: Analysts who need free, structured IOC enrichment and vulnerability research inside the IBM/QRadar ecosystem, until migration.
GreyNoise
Figure 19. Landing dashboard of GreyNoise
GreyNoise scored 10 confirmed, 7 partial, and 16 absent, the lowest confirmed count of the 5 and the narrowest scope. We tested the free Community tier5 through Auth0 login with no MFA. GreyNoise classifies a single indicator type. For a given IP it returns whether the address is mass-scanning the internet, a classification of malicious, benign, suspicious, or unknown, and the tags describing what it targets.
The data comes from its own Global Observation Grid: 5,000+ sensors across about 80 countries, 500M to 1B sessions a day, and 50M+ observed IPs. A last_seen:1d query on the test day returned 699,076 active scanner IPs. The tier model gates lookback depth rather than features. Community gives a 10-day window and basic enrichment, with RIOT, the cve: facet, and longer windows in upper tiers. 17 of the 33 criteria are reachable on Community.
Data sources
GreyNoise owns its scanning telemetry, which OTX’s crowdsourced feed and Feedly’s aggregation do not, and which sits on a different axis from CrowdStrike’s endpoint telemetry. The rest of the category is narrow: the source is one type (scanning IPs), IP-geo metadata is technical rather than a regional threat profile, and dark web is out of scope.
Figure 20. Search results for last_seen:1d
Coverage and intelligence types
GreyNoise scored 0 confirmed, 2 partial, and 3 absent here, its lowest category. GreyNoise handles a single indicator type, IP addresses, plus IP-linked CVE, tag, and JA4 data, with no native hash, domain, or URL reputation. A query for 8.8.8.8 (Google DNS) correctly returned NOT OBSERVED, since a DNS server is not a scanner. The cve: facet is gated above Community. The Trends view lists CVEs under mass exploitation at the time of query, with no CVSS, EPSS, or patch data attached.
Figure 21. CVE-mapped trending exploitation
Analysis and enrichment
A malicious IP (139.59.140.35) returned a classification timeline, 34 tags, a spoofable flag, geo (Germany, Hesse, Frankfurt, AS14061 DigitalOcean), carrier, and rDNS, more per-IP context than any other tested service returned. Risk uses a categorical 4-class model (malicious, benign, suspicious, unknown) with RIOT known-good matching rather than a numeric score; on the test day, the live distribution ran to malicious 84K, benign 20K, suspicious 68K, and unknown around 528K. There is no ATT&CK mapping.
Attribution
All 4 criteria scored absent. There are no named APTs, and the actor tags name benign scanners such as Shodan and Censys.
Platform
GNQL is a Lucene-based query language across IP, classification, tags, actor, CVE, and metadata fields, the only query language among the 5, with Lucene syntax across IP, classification, tags, actor, CVE, and metadata fields. Alerts (a saved GNQL query to email), a query-based blocklist and a Trends dashboard cover monitoring, though the dashboard is limited. Finished intelligence and RFI are both absent.
Integration and API
Fifty-plus integrations span SIEM, SOAR, TIP and firewall (Splunk, Sentinel, QRadar, Tines, ThreatConnect, MISP, OpenCTI, Palo Alto, Fortinet), three API tiers (Community, Enterprise, On-Prem) ship with the official pygreynoise SDK, and every GNQL query doubles as a firewall-compatible live blocklist URL. The gap is native STIX/TAXII, which needs a MISP or OpenCTI bridge.
Reporting
Export runs to JSON and CSV plus the blocklist URL and Alerts delivery, and data is near real-time, but there is no report format and no finished-intel or sector reporting.
Operational scenarios
The core scenario is cutting SOC alert noise by classifying known scanners as benign before they reach the SIEM, plus bulk IP analysis. None of the other 4 does this. The Trends exploitation signal complements probability-based scores, with the full product in a paid add-on. Takedown and supply-chain are out of scope.
Figure 22. Search results for benign last_seen:1d
Where it leads and where it falls short
GreyNoise misses 16 criteria that it never set out to meet. The weaknesses against a full-platform expectation are scope limited to IPs, no attribution, no finished intel or RFI, no numeric risk score, and no native STIX/TAXII. It works as a layer, not a platform.
Best for: A complementary layer in front of an existing SIEM or threat intelligence stack: alert triage, bulk IP analysis, and “is this CVE actually being exploited?” checks. It cannot serve as a standalone threat intelligence platform, and it does not claim to.
AlienVault OTX
Figure 23. AlienVault OTX main dashboard
The free feed and automation engine, run by LevelBlue (formerly AT&T Cybersecurity / AlienVault). We tested the Community tier console,6 the most frictionless access of the 5, with no credit card, no trial counter, no MFA, and a persistent session. An API key is one click from Settings, and DirectConnect documents the REST API, SDKs, and TAXII server.
Data sources
OTX carries about 20M IOCs a day from roughly 200K participants, with 95M indicators browsable. All 4 historical IOC probes were found. The Conti C2 IP (162.244.80.235, CISA AA21-265A) returned a malicious verdict, ASN AS19624, passive DNS with first- and last-seen dates, and 28 pulses.
Figure 24. Conti C2 IP analysis
First-party research is thin. Alien Labs vetted pulses that dissolve into the community stream, and curated first-party intelligence sits in the paid USM product. Dark web is absent from the free core; it lives in the separate USM Anywhere dark web monitoring AlienApp with SpyCloud.
Coverage and intelligence types
Every historical probe returned 28 to 50 pulse matches against 95M browsable indicators. The free Submit Sample page runs static and dynamic sandbox analysis on files and URLs with YARA support, a workable alternative to paid sandboxes.
Figure 25. Files and URL submission for analysis
Vulnerability data is a partial skeleton (a CVE indicator page with Exploits 40 and Targeted Products 373, plus CVSS in the API) with no EPSS, KEV, or prioritization. Brand and leaked credentials are both absent.
Analysis and enrichment
There is no structured actor profile, no tunable risk score, no visual graph, and ATT&CK data is available in the API but not in the UI. Community aliases matched our answer key: Sofacy for APT28, Anunak for FIN7, Muddled Libra for Scattered Spider, UTA0218 for the PAN-OS activity, and Lace Tempest for MOVEit. Against that, the SUNBURST domain carried 1,487 tags, the WannaCry killswitch entry held LLM-generated fake labels, most actor pulses date from 2015 to 2017, and the LockBit adversary tag was empty. Without a numeric risk score, automated triage is difficult.
Attribution
Adversary tags and pulses exist, and the aliases are good, but there is no structured profile, and most of the content is outdated.
Platform
There is a dashboard and a pulse subscription, but no asset or keyword monitoring, a finished intelligence library, or an RFI. OTX is a feed source rather than a research console.
Integration and API
This part is the single clear advantage of OTX across the 5. A REST API, Python, Java and Go SDKs, a native TAXII server and STIX/JSON/CSV/OpenIOC/MAEC export make it the single service across the 5 to open complete programmatic access at no cost.
Figure 26. AlienVault OTX DirectConnect API
The API returns richer data than the UI, including ATT&CK IDs and malware families. An undocumented rate limit is the practical constraint. Bulk queries timed out, 4 of 13 in the first round, and needed retry and backoff.
Reporting
Strong IOC feed export in multiple formats, but no report delivery and no sector or customizable reporting.
Operational scenarios
Threat hunting is operationalized through the free API, osquery-based OTX Endpoint and pulse subscriptions feeding SIEM blocklists. Takedown, vulnerability prioritization and supply-chain are all absent, sitting in separate paid LevelBlue, USM, SpyCloud or Tenable products.
Where it leads and where it falls short
Ten criteria are absent from the free core (dark web, leaked credentials, brand, takedown, finished intel, RFI, sector reports, vulnerability prioritization and supply chain), most of them present in separate paid LevelBlue, USM or SpyCloud products; OTX is the free baseline of that family. Weaknesses: zero full marks in analysis and attribution, high community noise with no risk score, and an undocumented API rate limit. OTX feeds machines well; it does not support human decision-making on its own.
Best for: Teams that need a free, high-volume IOC feed into a SIEM, MISP or TIP, plus no-cost automation and hunting. OTX feeds machines well; it does not support human decision-making on its own.
Which service fits which scenario
- You run Falcon EDR/XDR and track APTs: CrowdStrike, for single-console adversary intelligence, ATT&CK and campaign context.
- You need dark web, leaked-credential, takedown or analyst-on-demand coverage: CrowdStrike Recon/Recon+/CAO Elite, the sole option among the 5.
- Your SOC drowns in alerts from scanning IPs: GreyNoise in front of the SIEM to classify noise and cut false positives.
- You must prioritize thousands of disclosed vulnerabilities: Feedly (EPSS + KEV + CVSS in one card) or X-Force’s XFDB while it lasts; validate with GreyNoise’s exploitation observations.
- You have no budget but need threat intelligence feeds and automation: OTX’s free API, SDKs and TAXII server.
- You need finished reports and newsletters without hiring analysts: Feedly’s Report Builder and Ask AI.
The layered stack: how the 5 services combine
Across the 5 services our probes produced 83 full, 47 partial and 35 absent marks, and no single product amounts to a complete threat intelligence program. A realistic architecture treats them as complementary layers rather than rivals:
- Free feed base: OTX supplies raw IOC volume and no-cost automation into the SIEM/TIP.
- Noise filter: GreyNoise sits in front of the SIEM, suppressing benign scanner alerts and flagging active exploitation.
- Aggregation and delivery: Feedly compiles OSINT, extracts IoCs/TTPs and produces reports; its enrichment cross-references GreyNoise and VirusTotal.
- Research and enrichment: X-Force covers free structured lookups and vulnerability research until Aug 2026, after which its slot needs a successor.
- Premium attribution and digital risk: CrowdStrike tops the stack for named-adversary intelligence, dark web monitoring, takedowns and analyst access.
The right question is not “which threat intelligence platform is best?” but “which layer am I filling with which product, and what replaces X-Force after its end of life?”
Cyber threat intelligence benchmark methodology
We benchmarked five cyber threat intelligence services: AlienVault OTX (Community), IBM X-Force Exchange (Freemium), CrowdStrike Falcon Adversary Intelligence (Premium trial), GreyNoise (Community), and Feedly Threat Intelligence (30-day trial).
Every service was scored against the same 33 criteria across 8 categories and queried with an identical probe set. The 8 categories map onto the threat intelligence lifecycle. Data sources and coverage measure collection, analysis, and attribution measure the analysis stage, and integration, reporting, and operational scenarios measure distribution and action.
Category 1: Data sources and collection (4 criteria)
Where the intelligence originates, before any processing.
- DK-01 — OSINT and technical feed coverage: breadth of open-source and technical feeds ingested.
- DK-02 — Dark and deep web access: forums, marketplaces, leak sites, and encrypted platforms.
- DK-03 — First-party sensor network and original research: telemetry the vendor generates itself, as opposed to material it collects from others.
- DK-04 — Language and geographic coverage: regional and multilingual reach of collection.
This category separates producers from compilers. A last_seen:1d query on GreyNoise returned 699,076 active scanner IPs from its own sensor grid on the test day, while Feedly’s coverage rests on 10,000+ curated sources with no sensor network of its own.
Category 2: Coverage and intelligence types (5 criteria)
Which threat types the service covers, tested against the probe set rather than against the datasheet.
- KP-01 — IOC coverage and volume: IPs, domains, hashes, and URLs.
- KP-02 — Malware and tooling intelligence: families, sandbox analysis, and YARA support.
- KP-03 — Vulnerability intelligence: CVE data, scoring, and exploitation context.
- KP-04 — Brand and digital risk: typosquatting, impersonation, and domain monitoring.
- KP-05 — Leaked credentials and exposed data: breach and credential exposure lookups.
This is the category where archetype boundaries appear most sharply. A query for 8.8.8.8 on GreyNoise returned NOT OBSERVED, which is the correct answer for a DNS server rather than a scanner, and also demonstrates that the product handles a single indicator type.
Category 3: Analysis and enrichment (4 criteria)
How much interpretation the service adds to a raw indicator.
- AN-01 — IOC enrichment depth: what a single indicator lookup returns.
- AN-02 — Risk scoring and prioritization: numeric, categorical, or absent.
- AN-03 — MITRE ATT&CK mapping: whether techniques are mapped, and whether the mapping is in the interface or the API.
- AN-04 — Relationship and graph analysis: pivoting across entities, and whether a visual graph exists.
The Conti C2 IP probe made the differences legible. X-Force returned a numeric Risk 1/10 after aging, a categorization history, a 31-event timeline, ASN and subnet, WHOIS, and passive DNS. OTX returned a malicious verdict, ASN AS19624, passive DNS, and 28 pulses against 157 tags.
Category 4: Attribution and actor tracking (4 criteria)
Whether the service names adversaries, and on what methodological basis.
- AT-01 — Named adversary and APT tracking: structured actor profiles.
- AT-02 — Campaign and operation tracking: named campaigns with timelines.
- AT-03 — TTP profiles and attribution methodology: the reasoning that connects activity to an actor, plus alias reconciliation.
- AT-04 — Sector and geographic threat profiling: which industries and countries an actor targets.
This category produced the widest spread of the eight. The six-actor probe was scored against the answer key, so a service that listed an alias set matching the key scored differently from one that returned an empty adversary tag.
Category 5: Platform and usability (4 criteria)
Whether the product is a data source or a console an analyst can work in.
- PL-01 — Search and query language: operators, facets, or a real query language.
- PL-02 — Dashboard, watchlist, and alerting: monitoring surfaces and notification rules.
- PL-03 — Finished intelligence library: analyst-written reports available inside the product.
- PL-04 — RFI and analyst access: the ability to ask a human analyst a question.
PL-03 and PL-04 are the two criteria where free and paid tiers diverge most consistently across the five products.
Category 6: Integration and API (4 criteria)
How the intelligence reaches the rest of the security stack.
- EN-01 — STIX and TAXII support: native server, REST-delivered STIX, or bridge required.
- EN-02 — SIEM, SOAR, and TIP integration: available connectors.
- EN-03 — REST API coverage, SDKs, and documentation: programmatic surface and official client libraries.
- EN-04 — Feed distribution and formats: export formats and delivery channels.
We tested this category by hand where the tier permitted. On OTX we pulled an API key from Settings and ran the indicator probes through DirectConnect, which returned ATT&CK IDs, adversary tags, and malware families that the UI did not display. On CrowdStrike we created an OAuth2 API client against the api.eu-1 base. On X-Force the Freemium tier returned 403, so per-report STIX export was the extent of what worked without payment.
Category 7: Reporting and finished intelligence (4 criteria)
The layer that separates processed intelligence from raw data.
- RP-01 — Report types: strategic, operational, and tactical coverage.
- RP-02 — Publication frequency and timeliness: how current the library is.
- RP-03 — Customization and sector-specific reporting: industry and region breakdowns.
- RP-04 — Export and delivery: formats and delivery channels for finished output.
Category 8: Operational scenarios (4 criteria)
Whether the intelligence turns into action inside a SOC or incident response workflow.
- OP-01 — Takedown and remediation service: managed removal of malicious infrastructure.
- OP-02 — Vulnerability prioritization workflow: a productized path from CVE list to patch order.
- OP-03 — Threat hunting and IOC operationalization: feeding indicators into hunting, blocklists, and SIEM.
- OP-04 — Third-party and supply-chain risk intelligence: vendor and partner exposure.
OP-04 was the weakest criterion across the whole benchmark, with no product reaching a confirmed mark.
What is cyber threat intelligence?
Cyber threat intelligence (CTI) refers to the collection and analysis of raw data on current and emerging threats, yielding actionable insights that help security teams prevent, detect, and respond to cyberattacks. CTI services gather threat data from sources such as sensor networks, open source intelligence, dark web forums, and vulnerability databases, then process it into threat indicators, actor profiles, and reports that inform decisions.
Cyber threat intelligence helps organizations anticipate future threats rather than react to security incidents after damage occurs. It shifts businesses toward proactive cyber defense: identifying exposed assets to reduce the attack surface, spotting emerging hacker trends before an attack, and prioritizing security investments against the specific threats targeting their industry.
Types of threat intelligence
Threat intelligence can be categorized into 4 frameworks, and a mature threat intelligence program consumes all 4:
- Strategic threat intelligence offers a high-level view of the cyber threat landscape for executives and translates technical complexities into commercial risk for relevant stakeholders. Example from our benchmark: IBM’s Threat Index and CrowdStrike’s Threat Hunting Report.
- Tactical threat intelligence focuses on attackers’ tactics, techniques and procedures (TTPs), typically mapped to MITRE ATT&CK. Example: CrowdStrike’s per-adversary ATT&CK matrices and Feedly’s automatic TTP extraction.
- Operational threat intelligence covers specific campaigns and attacks in progress, giving incident response teams real-time context. Example: X-Force threat analysis reports and Early Warning campaigns.
- Technical threat intelligence consists of indicators of compromise (IOCs) such as IPs, domains, hashes and URLs that feed automated detection. Example: OTX pulses and GreyNoise IP classifications.
The threat intelligence lifecycle
The threat intelligence lifecycle has 6 stages that transform raw data into actionable threat intelligence:
- Requirements: define what the security team and stakeholders need to know.
- Data collection: gather raw data from feeds, sensors, OSINT and the dark web.
- Processing: normalize, deduplicate and structure the collected data.
- Analysis: convert processed data into assessments, scores and reports.
- Distribution: deliver intelligence to the people and tools that act on it, such as SIEM, SOAR and firewalls.
- Feedback: stakeholders report what worked, informing adjustments so the program adapts to evolving threats.
Our 8 benchmark categories map onto this lifecycle: data sources and coverage measure collection, analysis and attribution measure the analysis stage, and integration, reporting and operational scenarios measure distribution and action.
Why integrate threat intelligence with security operations?
- Early warnings: combining threat intelligence feeds with a SIEM classifies high-risk activity as it appears in logs, before an incident escalates.
- Fewer false positives: high-fidelity alerts, such as GreyNoise’s benign-scanner classification, minimize alert fatigue so security analysts investigate real threats.
- Faster incident response: immediate context on malware operations and threat actors enhances incident response capabilities and helps isolate breached systems before lateral movement.
- Threat-informed patching: thousands of software vulnerabilities are disclosed annually; exploitation-aware scores (EPSS, KEV, ExPRT.AI, GreyNoise observations) prioritize the ones being exploited.
- Informed resource allocation: organizations using threat intelligence can direct cybersecurity resources toward the attack vectors and potential threat actors relevant to their sector.
FAQs
None of the 5 wins outright. CrowdStrike leads coverage (30 of 33 criteria) but costs the most and splits capabilities across 4+ SKUs. Feedly leads self-service aggregation, X-Force leads free research (until its Aug 2026 EOL), GreyNoise leads IP triage and OTX leads free automation. Most organizations combine 2-3 of them in layers.
For IOC feeds, enrichment lookups and hunting, yes: OTX, GreyNoise Community and X-Force Freemium cover those at no cost. Finished intelligence, dark web monitoring, leaked-credential detection, takedowns and analyst access appeared in paid tiers alone, mostly in the CrowdStrike family.
By classifying activity before analysts see it. In our tests, GreyNoise labeled known scanners such as Shodan and Censys as benign, X-Force aged a former Conti C2 IP down to Risk 1/10 after analyst review, and Feedly deduplicated 426 feeds covering one event into a single card.
Cite this benchmark
Pick the format that matches where you're publishing. Pasting the link version into your CMS preserves the backlink.
@misc{dogan2026,
author = {Dogan, Sedat and PhD., Ezgi Arslan,},
title = {{Top 5 Cyber Threat Intelligence Services Benchmarked}},
year = {2026},
month = aug,
howpublished = {\url{https://aimultiple.com/cyber-threat-intelligence-services}},
note = {AIMultiple. Retrieved August 31, 2026}
}Results and timestamps of 14 data points. Download the data used in this article as a ZIP file containing 2 CSV files.
Reference Links
- Has 20 years of experience as a white-hat hacker and development guru, with extensive expertise in programming languages and server architectures.
- Is a board advisor at a VC investing in early-stage technology firms and at Ödeal, a regional digital payment platform serving 125,000 merchants.
- Has led the technology infrastructure and cybersecurity of seven national elections, and has been recognized in the cybersecurity Hall of Fame by global technology leaders including Twitter.


























Be the first to comment
Your email address will not be published. All fields are required. Comments are left in their original language.