A note on what this is. Every other guide in this series reports a measurement we ran. This one does not — we have not tested these products, priced them, or run a bake-off, and nobody should read what follows as a ranking. It is a map of the categories, written so that you can tell which kind of thing you are being sold.
The threat intelligence market is confusing largely because four quite different businesses use the same phrase. Knowing which one you are talking to answers most of the questions you would otherwise ask.
The four categories
1. Public sector and national bodies
Government agencies publish advisories, catalogues and alerts, usually free and usually the highest-signal material available to a general audience.
CISA in the United States maintains the Known Exploited Vulnerabilities catalogue this series has used throughout — a machine-readable list of vulnerabilities confirmed to be under active exploitation. The UK's NCSC, the EU's ENISA and Singapore's CSA and SingCERT publish advisories for their own constituencies.
What you get: authoritative, conservative, free. What you do not: anything specific to you, and often a lag, because confirmation takes time and public attribution is a political act as well as a technical one.
For most organisations that have never bought intelligence, this tier plus an asset inventory is the entire first year of the programme.
2. Vendor research teams
Large security vendors run research arms that publish findings from their own telemetry — Microsoft, Google's Mandiant, CrowdStrike, Palo Alto Networks' Unit 42, Cisco Talos, ESET, Kaspersky, Trend Micro and others. Much of their output is free to read, because it is also marketing.
That dual purpose is not a reason to dismiss it. The research is frequently excellent and often the first public account of a campaign. It is a reason to read structurally: a vendor sees what its own products see. A company selling endpoint protection reports endpoint-heavy campaigns. That is a sampling property, not dishonesty, and it means no single vendor's picture is the whole picture.
3. Commercial intelligence platforms
Companies whose actual product is the intelligence rather than a security tool it supports — Recorded Future, Flashpoint, Intel 471, Mandiant's platform business and others. They aggregate across sources, run collection you cannot run yourself, and sell access.
This is where the real money is spent, and where buyers most often end up disappointed. The problem is rarely the product; it's a mismatch. They bought data collection when their actual gap was in analysis. A platform that surfaces ten thousand relevant items to an organisation with one analyst has made the problem worse.
The question to ask a vendor here is not "what sources do you cover". It is: what decision does this let us make on Monday that we cannot make today? If the answer requires headcount you do not have, the platform is not the constraint.
4. Community and open sources
Non-commercial and volunteer-run: MITRE ATT&CK for the behavioural framework, abuse.ch for malware and botnet tracking, Shadowserver for internet-scale scanning reports, Spamhaus for reputation data, and sector ISACs where organisations in the same industry share with each other.
ISACs deserve particular attention in this region. They are how an organisation learns that something is happening to its peers before it happens to them, and sector proximity is often a better predictor than any global feed.
What "coverage" means when a salesperson says it
Three claims come up in nearly every conversation, and each one hides the question you actually want answered.
"Millions of indicators." Indicators expire. Infrastructure is cheap and gets rotated faster than most organisations can ingest a feed. Volume of indicators measures collection, not usefulness, and a large number can indicate a low bar for inclusion rather than broad reach.
"Dark web coverage." Sometimes this means analysts in closed forums. Sometimes it means a scraper against paste sites. The two are not comparable and the phrase covers both.
"Real-time." Delivery is real-time; confirmation is not. Anything that arrives without confirmation carries a false-positive rate somebody has to absorb, and that somebody is your analyst.
What actually determines whether this works
The strongest predictor of whether an intelligence programme delivers value is not which vendor was chosen. It is whether the organisation can answer, quickly and accurately, what do we run.
Intelligence about adversaries is actionable only when you can match it against an inventory. Without one, the best feed in the world is just reading material. This is why so many programs stall in year one: the gap was never intelligence, and no purchase can fix that.
A defensible sequence, if you are starting:
- Inventory first. What software, which versions, exposed where.
- Then free public sources. The confirmed-exploited catalogue against that inventory, which is an afternoon's work and the highest-yield thing in this guide.
- Then your sector's sharing group, which costs little and is proximate to your actual risk.
- Then, if a specific decision is still unsupported, buy the thing that supports it. Not before, and not the biggest one.
And before any of it, from feed to decision sets out the filtering that free public data already does — which is the work most buyers assume they are purchasing.
What we are not telling you
We have not evaluated any of these providers, we have no commercial relationship with any of them, and we are not recommending or ranking them. The names above are examples of each category, chosen because they are widely known — not because we have assessed them against alternatives, and their inclusion is not an endorsement.
Pricing, contract structure and quality vary enormously and change constantly, so we have deliberately quoted no figures. If someone tells you the market has a clear leader, they are describing a market segment they have defined narrowly enough for that to be true.
The rest of this series is measured rather than sourced: what threat intelligence actually is works from the confirmed-exploited catalogue, and what a threat actor name buys you counts the public adversary catalogue directly.