Best Threat Intelligence Feeds in 2026: Free, Open Source, and Commercial Options


Security teams do not have a shortage of threat data in 2026. The harder problem is deciding which intelligence is timely, relevant, trustworthy, and actionable enough to improve detection and response.
That is why choosing the best threat intelligence feeds is less about finding the biggest database and more about matching the right intelligence source to the right security requirement.
This guide compares 15 free, open-source, public, and commercial threat intelligence sources worth considering in 2026, including what each does best and where its limitations matter.
What Are Threat Intelligence Feeds?
Threat intelligence feeds are continuously or periodically updated streams of information about known and emerging cyber threats. They can contain malicious IP addresses, domains, URLs, malware hashes, phishing infrastructure, vulnerabilities, command-and-control servers, threat actor information, and other indicators of compromise (IOCs).
Security teams consume these cyber threat intelligence feeds through APIs, STIX/TAXII, JSON, CSV, MISP-compatible feeds, vendor integrations, and other machine-readable formats.
One distinction matters from the beginning: threat data is not automatically threat intelligence. A list of malicious IP addresses becomes much more valuable when teams know why an IP is malicious, when it was observed, how confident the source is, and whether it matters to their environment.
Best Threat Intelligence Feeds in 2026
There is no universal "best" feed. Phishing intelligence, malware intelligence, vulnerability intelligence, IP reputation, and adversary intelligence solve different problems.
The following list therefore combines specialized free threat intelligence feeds, public resources, open-source projects, and commercial providers rather than ranking fundamentally different services against one another.
Best Free and Open Source Threat Intelligence Feeds
Free and open-source threat intelligence feeds are useful for organizations building a CTI program and for mature teams that want specialized intelligence to complement commercial sources.
Threat intelligence source | Best for | Key intelligence | Access model |
CISA KEV | Vulnerability prioritization | Actively exploited CVEs | Free |
AlienVault OTX | Community intelligence | IOCs and community intelligence | Free/community |
abuse.ch | Malware intelligence | URLs, hashes, malware IOCs, infrastructure | Free/community, commercial options available |
MISP Feeds | Aggregating OSINT | Multiple IOC types | Open source |
PhishTank | Phishing | Phishing URLs | Free |
OpenPhish | Phishing intelligence | Phishing URLs and enrichment | Free and commercial |
Shadowserver | Network remediation | Compromised systems, exposed services, malicious activity | Free for eligible network owners |
Spamhaus | Reputation intelligence | IPs, domains, botnets, abuse infrastructure | Free options and commercial |
Cisco Talos | Reputation and research | IPs, domains, files, malware | Public and ecosystem-based |
GreyNoise | Internet scanning | IP behavior and internet noise | Community and commercial |
1. CISA Known Exploited Vulnerabilities Catalog
Best for: Prioritizing vulnerabilities attackers are actively exploiting
Why it stands out: Free, authoritative exploitation intelligence that can directly improve vulnerability prioritization.
CISA's Known Exploited Vulnerabilities Catalog, or KEV, is not a conventional IOC feed, but it is one of the most useful public threat intelligence sources available to vulnerability management teams.
CISA describes KEV as the authoritative source for vulnerabilities known to have been exploited in the wild and recommends using the catalog as an input to vulnerability management prioritization. It is also available in machine-readable formats such as CSV and JSON.
That distinction matters. CVSS can help teams understand vulnerability severity. KEV adds another question: Are attackers actually exploiting it?
Keep in mind: KEV focuses on exploited vulnerabilities. It does not replace feeds covering malware, phishing, malicious infrastructure, or threat actors.
2. AlienVault Open Threat Exchange (OTX)
Best for: Community-driven IOC sharing
Why it stands out: Broad community participation, accessibility, and a large collection of shared indicators.
AlienVault Open Threat Exchange, better known as OTX, is a widely used community threat intelligence platform.
Its intelligence is organized into "pulses," which can contain indicators associated with malware, campaigns, threat actors, vulnerabilities, and other activity. This makes OTX a useful starting point for teams that want broad community-generated intelligence without immediately purchasing a commercial feed.
OTX also provides API access, making it possible to integrate its indicators into security workflows rather than relying entirely on manual searches.
Keep in mind: Community-generated intelligence varies in quality. Indicators should be validated and scored rather than treated as equally trustworthy.
3. abuse.ch
Best for: Malware URLs, samples, and malicious infrastructure
Why it stands out: Strong malware specialization, automation-friendly access, and several useful datasets under one ecosystem.
abuse.ch is less a single feed and more an ecosystem of specialized threat intelligence projects.
URLhaus tracks URLs used to distribute malware. ThreatFox provides IOCs associated with malware. MalwareBazaar focuses on malware samples and related metadata. Feodo Tracker tracks infrastructure associated with botnet command-and-control activity.
This specialization makes abuse.ch particularly useful. Teams can consume intelligence that matches a specific security workflow instead of ingesting one giant collection of unrelated indicators.
ThreatFox also demonstrates why indicator lifecycle management matters. Since May 2025, it has expired IOCs older than six months from its API and exports to reduce false positives, particularly when cloud infrastructure changes ownership.
Keep in mind: Check API, licensing, fair-use, and commercial-use conditions before integrating community services into production products or services.
4. MISP Threat Intelligence Feeds
Best for: Aggregating and operationalizing multiple intelligence sources
Why it stands out: Open-source flexibility, correlation, sharing, and support for multiple intelligence sources.
MISP is often grouped into lists of threat intelligence feeds, but it is more accurately described as an open-source threat intelligence sharing platform and ecosystem.
MISP includes public OSINT feeds in its default configuration and supports MISP, CSV, and free-text feed formats. Its feed system can also correlate feed data against events and attributes without requiring teams to import everything directly.
That makes MISP especially useful once your problem shifts from "Where do we find indicators?" to "How do we organize and correlate all these sources?"
Keep in mind: Aggregating ten mediocre feeds does not automatically produce high-quality intelligence.
5. PhishTank
Best for: Community-driven phishing intelligence
Why it stands out: Simple, focused, and accessible phishing intelligence.
PhishTank is a long-running community resource focused specifically on phishing URLs.
Its API allows security applications and analysts to check URLs against the PhishTank database, making it useful for email investigations, SOC enrichment, phishing research, and automated reputation checks.
Keep in mind: Phishing infrastructure changes quickly, so PhishTank is best used alongside other detection and intelligence sources rather than as a standalone phishing defense.
6. OpenPhish
Best for: Focused phishing URL intelligence
Why it stands out: Clear specialization in phishing and options for organizations requiring more timely or enriched intelligence.
OpenPhish specializes in identifying phishing sites and provides both community and commercial intelligence options.
The difference between its free and paid offerings illustrates an important point about threat intelligence pricing. Commercial feeds often provide value through faster delivery, richer context, historical data, licensing rights, and operational reliability, not simply more indicators.
Keep in mind: The free feed is more limited than the commercial services, so evaluate freshness requirements carefully.
7. The Shadowserver Foundation
Best for: Finding compromised or exposed systems within your infrastructure
Why it stands out: Actionable, infrastructure-specific reporting for network defenders.
Shadowserver takes a different approach from a traditional public IOC feed.
The nonprofit collects data through internet scanning, sinkholes, honeypots, malware analysis, and other sources, then provides network owners with reports relevant to infrastructure they are responsible for.
This can make its intelligence highly actionable. Instead of receiving millions of unrelated indicators, organizations can identify compromised systems, exposed services, and malicious activity associated with their own networks.
Keep in mind: Organizations do not simply receive unrestricted access to all Shadowserver data. Reporting is scoped to eligible networks and constituencies.
8. Spamhaus
Best for: IP, domain, botnet, and internet abuse intelligence
Why it stands out: Mature reputation intelligence with strong relevance to email and network security.
Spamhaus is one of the longest-established providers of reputation and abuse intelligence.
Its datasets cover malicious and compromised IP addresses, botnet infrastructure, domains, spam-related infrastructure, and other internet abuse signals. These signals can support email security, threat hunting, enrichment, filtering, and risk scoring.
Keep in mind: Free access and commercial use are not the same thing. Review licensing and usage restrictions before incorporating datasets into enterprise or customer-facing workflows.
9. Cisco Talos Intelligence
Best for: IP, domain, file reputation, and security research
Why it stands out: Broad security research and reputation intelligence backed by substantial telemetry.
Cisco Talos combines threat research, telemetry, malware analysis, vulnerability research, and reputation intelligence.
Talos Intelligence provides information about IP and domain reputation, malware, files, vulnerabilities, and broader threat activity. It is particularly relevant to teams already operating Cisco security products because intelligence can feed into the wider Cisco security ecosystem.
Keep in mind: Public Talos research and reputation lookups are not equivalent to unrestricted access to every underlying intelligence dataset.
10. GreyNoise
Best for: Understanding internet scanning activity
Why it stands out: Helps analysts separate routine internet noise from activity that deserves deeper investigation.
GreyNoise solves a problem that SOC analysts encounter constantly: determining whether an unfamiliar IP is targeting their organization or simply scanning large parts of the internet.
By collecting and classifying internet scanning activity, GreyNoise helps analysts understand whether an IP is associated with benign services, widespread scanning, suspicious activity, or known malicious behavior.
That context can be especially valuable for alert enrichment and triage.
Keep in mind: GreyNoise complements other feeds. It does not replace malware, phishing, vulnerability, or adversary intelligence.
Best Commercial Threat Intelligence Feeds in 2026
Commercial threat intelligence becomes valuable when teams need more context, faster intelligence, specialized collection, historical analysis, enterprise integrations, or dedicated threat research.
Commercial provider | Best for | Primary strength | Typical fit |
CrowdStrike Falcon Intelligence | Adversary intelligence | Actor and IOC context | Enterprise SOCs |
Recorded Future | Broad external intelligence | Contextual intelligence and enrichment | Mature CTI and SOC teams |
Google Threat Intelligence | Global threat context | Threat actor, malware, and IOC intelligence | Large enterprises and research teams |
Microsoft Threat Intelligence | Microsoft security operations | Intelligence within Defender and Sentinel | Microsoft-centric SOCs |
Palo Alto Networks Unit 42 | Threat research and adversaries | Frontline research and operational context | Enterprise security teams |
1. CrowdStrike Falcon Intelligence
Best for: Adversary-focused intelligence in enterprise SOCs
Why it stands out: Strong adversary intelligence combined with operational integration into Falcon workflows.
CrowdStrike Falcon Intelligence combines adversary research, malware intelligence, indicators, and contextual intelligence with the wider Falcon security ecosystem.
That integration is an important part of the value proposition. Intelligence can become part of analysts' existing investigation and endpoint security workflows rather than remaining isolated in a separate research portal.
CrowdStrike also provides intelligence feed APIs for programmatic access and automation.
Keep in mind: Its value is easier to justify when the organization already uses the Falcon ecosystem or has mature adversary intelligence requirements.
2. Recorded Future
Best for: Broad contextual intelligence across threats and adversaries
Why it stands out: Broad coverage, contextual enrichment, historical intelligence, and extensive automation capabilities.
Recorded Future is one of the most established commercial threat intelligence providers.
Its capabilities extend beyond IOC feeds into areas such as threat actors, vulnerabilities, malware, identity exposure, risk intelligence, and historical context. APIs allow this intelligence to be incorporated into enrichment, detection, research, and automation workflows.
This breadth makes it particularly relevant to organizations with established intelligence requirements across multiple security domains.
Keep in mind: Broad capability also brings cost and complexity. Define your intelligence requirements before paying for capabilities your team may never use.
3. Google Threat Intelligence
Best for: Threat actor, malware, IOC, and global threat context
Why it stands out: Large-scale threat visibility combined with Mandiant's threat research and incident response experience.
Google Threat Intelligence combines Google's security visibility with capabilities associated with Mandiant and VirusTotal.
Rather than focusing only on IOC reputation, it can help teams investigate threat actors, malware, infrastructure relationships, campaigns, and changing TTPs.
For organizations dealing with sophisticated adversaries or large-scale threat research, this additional context can be more useful than simply receiving another list of malicious IPs.
Keep in mind: Evaluate the platform around specific intelligence workflows rather than the size of the underlying dataset.
14. Microsoft Threat Intelligence
Best for: Organizations using Microsoft Defender and Sentinel
Why it stands out: Intelligence integrated directly into Microsoft's broader security operations environment.
There is an important 2026 change to understand here.
Microsoft retired the legacy standalone Microsoft Threat Intelligence portal and Intel Explorer experience on August 1, 2026. Threat intelligence capabilities are now available through the Microsoft Defender portal.
Microsoft Threat Intelligence can enrich IP addresses, domains, URLs, and files with reputation information, threat reporting, sandbox analysis, and infrastructure relationships. For Microsoft-centric SOCs, keeping that context inside Defender and Sentinel workflows can reduce tool switching.
Keep in mind: Older comparisons that treat standalone Microsoft Defender Threat Intelligence as the current product model are now outdated.
15. Palo Alto Networks Unit 42 Threat Intelligence
Best for: Threat research, adversary intelligence, and frontline incident context
Why it stands out: Strong threat research combined with operational security and incident response context.
Unit 42 combines threat research with insights derived from security telemetry and incident response investigations.
That frontline perspective can be useful for organizations that want more than indicator reputation. Research into campaigns, malware, vulnerabilities, threat actors, and attacker techniques can support hunting, detection engineering, investigations, and strategic intelligence.
Keep in mind: Organizations should evaluate how effectively the intelligence integrates with their existing security stack and intelligence requirements.
Want Curated Threat Intelligence Without Managing Individual Feeds?
The feeds above give security teams plenty of options, but selecting, integrating, and maintaining multiple intelligence sources can quickly become another operational burden.
An alternative is to use an already curated collection of intelligence sources. Cyware provides out-of-the-box curated cyber threat intelligence feeds that bring together vulnerability intelligence, leading OSINT providers, and Cyware-curated industry sources.
This gives SOC and CTI teams access to high-fidelity intelligence without requiring them to independently identify and manage every source. The intelligence can then support use cases such as threat detection, investigations, threat hunting, vulnerability prioritization, and response.
The industry-specific context is particularly useful. Instead of relying entirely on broad global indicator collections, teams can incorporate intelligence that is more closely aligned with the threats affecting their sector.
How to Choose a Threat Intelligence Feed Provider
The best feed is not necessarily the one with the most indicators. Evaluate providers against your actual intelligence requirements.
Start by asking what you need to detect or understand: phishing, malware, ransomware, exploited vulnerabilities, cloud threats, threat actors, brand abuse, or something else.
Then assess:
Relevance to your organization and industry
Intelligence freshness
False-positive rates
Context and enrichment
First-seen and last-seen information
Confidence scoring
API and STIX/TAXII support
SIEM, SOAR, XDR, and TIP integrations
Historical coverage
Licensing and redistribution restrictions
Unique intelligence compared with existing sources
Before purchasing a commercial service, run a proof of value. Measure unique detections, relevant intelligence, false positives, analyst time saved, and how often the feed changes an actual security decision.
Already Have Threat Intelligence Feeds? Here’s How to Operationalize Them
Many enterprises already subscribe to commercial feeds, consume OSINT, receive industry intelligence, and collect threat data from internal security tools. At that point, finding another feed may not be the priority.
The challenge becomes making the intelligence you already have usable.
Different feeds can contain duplicate indicators, conflicting confidence levels, inconsistent formats, and large amounts of intelligence that may not be relevant to your organization. Managing those sources individually also makes it harder to move intelligence efficiently between CTI teams, SOC analysts, and security controls.
This is where Cyware can take an existing threat intelligence program further. Organizations can bring their existing commercial, open-source, industry, and internal intelligence sources together, then normalize, deduplicate, enrich, correlate, and prioritize that intelligence before distributing relevant insights across security operations.
The result is a different value proposition from simply purchasing another feed. Teams that need ready-to-use intelligence can start with Cyware's curated feeds. Teams that already have the feeds they want can use Cyware to make those investments more actionable across detection, investigation, threat hunting, and response.
In other words, you do not necessarily need more feeds. You may need a better way to operationalize the feeds you already have.
Talk with a Cyware threat intelligence expert about how to bring your existing commercial, open-source, industry, and internal intelligence together and operationalize it across your security workflows.
Building the Right Threat Intelligence Feed Strategy in 2026
The strongest threat intelligence programs rarely depend on a single provider.
A practical model combines government and public intelligence + specialized open-source feeds + carefully selected commercial intelligence + internal telemetry + organization-specific analysis.
For example, an enterprise might use CISA KEV for vulnerability prioritization, abuse.ch for malware infrastructure, OpenPhish for phishing, GreyNoise for internet scanning context, an industry ISAC for sector intelligence, and a commercial provider for deeper adversary research. A threat intelligence platform such as Cyware can bring these sources together, helping teams aggregate, normalize, enrich, correlate, and operationalize the intelligence across their security workflows.
Each source should have a job.
That is ultimately how teams should define the best threat intelligence feeds in 2026. The winners are not necessarily the sources with the largest databases or the highest price tags. They are the feeds that consistently help security teams answer three questions:
Does this threat matter to us?
How confident are we?
What should we do about it?
If a feed does not improve those decisions, adding more indicators probably will not improve your security.
Turn threat intelligence feeds into operational intelligence
Whether you need access to curated threat intelligence sources or want to get more value from feeds you already use, Cyware can help you bring intelligence together, enrich and prioritize it, and make it actionable across security operations.
Frequently Asked Questions About Threat Intelligence Feeds
What are threat intelligence feeds?
Threat intelligence feeds provide regularly updated information about cyber threats, including malicious IPs, domains, URLs, malware hashes, vulnerabilities, phishing infrastructure, and other IOCs.
What are the best threat intelligence feeds in 2026?
Strong options include CISA KEV, AlienVault OTX, abuse.ch, MISP feeds, PhishTank, OpenPhish, Shadowserver, Spamhaus, Cisco Talos, GreyNoise, CrowdStrike, Recorded Future, Google Threat Intelligence, Microsoft Threat Intelligence, and Unit 42. The best choice depends on your use case.
What are the best free threat intelligence feeds?
CISA KEV, AlienVault OTX, abuse.ch, MISP's public OSINT feeds, PhishTank, and Shadowserver are useful free or community-accessible sources.
What are the best open source threat intelligence feeds?
MISP is a leading open-source threat intelligence ecosystem and can aggregate multiple public feeds. abuse.ch is another valuable source for open and community-driven malware intelligence.
Are paid threat intelligence feeds better than free feeds?
Not necessarily. Paid services typically offer faster delivery, richer context, historical data, support, specialized collection, and enterprise integrations. Relevance matters more than price.
What is the difference between a threat intelligence feed and a threat intelligence platform?
A feed supplies threat information. A threat intelligence platform helps teams aggregate, normalize, enrich, correlate, manage, and distribute intelligence from multiple sources.
How many threat intelligence feeds should an organization use?
There is no ideal number. Use enough feeds to cover defined intelligence requirements without creating unnecessary duplication, false positives, and operational overhead.
How often are live threat intelligence feeds updated?
It varies by provider and intelligence type. Some update within minutes, while others refresh hourly or daily. Freshness is particularly important for rapidly changing phishing and malicious infrastructure.
How do you integrate threat intelligence feeds with a SIEM or SOAR?
Common methods include REST APIs, STIX/TAXII, JSON, CSV, native connectors, and MISP integrations. Intelligence should ideally be normalized, scored, and deduplicated before automated use.
How do threat intelligence feeds support enterprise security?
They help teams enrich alerts, detect malicious infrastructure, investigate incidents, hunt for threats, prioritize vulnerabilities, and automate selected defensive actions.
About the Author
