Threat Intelligence Feeds You Can Trust
Whether you’re hunting threats, enriching alerts, or building detection rules, these curated feeds offer actionable data from trusted sources. Weโve grouped them by type, free and paid, with direct links and access notes.
Free Feeds
- AlienVault OTX: IOCs, malware pulses. API + web portal.
- AbuseIPDB: Malicious IPs. API + dashboard.
- CIRCL MISP Feeds: MISP-compatible IOC sharing.
- Feodo Tracker: C2 servers, banking malware.
- URLhaus: Malicious URLs. CSV + API.
- MalwareBazaar: Malware samples. API + search.
- ThreatFox: IOC repository. API + CSV.
- GreyNoise: Internet noise vs. real threats. Limited free API.
- OpenPhish: Phishing URLs. CSV feed.
Paid Platforms
- Recorded Future: Threat intel, risk scoring. API + dashboards.
- Anomali ThreatStream: Aggregation + enrichment.
- Intel 471: Dark web, actor tracking.
- Flashpoint: Deep/dark web, fraud intel.
- CrowdStrike Falcon X: Malware analysis, actor profiles.
- Kaspersky Threat Feeds: APTs, malware, vulnerabilities.
How to Use These
- Integrate into SIEMs or TIPs like MISP, Splunk, Sentinel.
- Automate alert enrichment via APIs.