Back

Threat Intelligence Services: What They Do, How to Choose

Hagai Shapira
Hagai Shapira
August 14, 2026
Insights
Threat Intelligence Services: What They Do, How to ChooseBright curved horizon of a planet glowing against the dark backdrop of space.Bright curved horizon of a planet glowing against the dark backdrop of space.

Meta Title: Threat Intelligence Services: What They Do, How to Choose

Meta Description: Threat intelligence services do three jobs: adversary research, malicious-activity data, and operationalization. How to match the job to your team.

Slug: threat-intelligence-services

Threat Intelligence Services: What They Deliver and How to Choose One

A threat intelligence service sells some combination of adversary research, malicious-activity data, and the machinery to act on both. Almost no provider does all three at equal depth, and most disappointment with CTI spending traces back to buying in one of those areas while expecting the outcomes of another.

The SANS 2026 CTI Survey polled 401 qualified professionals, including 67 CISOs and CSOs: 91% of CISOs said CTI is important, but only 26% reported that it significantly influences their strategic choices. In many CTI programs, that gap traces to a mismatch between the intelligence purchased and the job to be done, followed by a failure to route what you bought into detection and hunting workflows.

TL;DR:

  • A threat intelligence service usually fits one job in the three-part taxonomy below. Providers specialize, and expecting one platform to do all three well is a procurement mistake.
  • Much of the waste happens after procurement. Perishable indicators and intelligence that never reaches a detection rule burn more budget than bad vendor selection does, especially when teams lack capacity to consume what they buy.
  • Define requirements first. Teams that start with a tool or a feed instead of priority intelligence requirements produce reports that become shelfware.
  • Buyers are consolidating around outcomes. Most respondents in Recorded Future's 2025 State of Threat Intelligence Report plan to cut duplicative intelligence vendors and keep the ones whose work reaches hunting, response, and prioritization.

The Three Jobs a Threat Intelligence Service Does

Commercial offerings usually map to this three-job taxonomy, and many providers deliberately stay narrow within a single row. Map your requirements to the job first; shortlist second.

Category What it includes Leading providers
1. Understand the Adversary Threat actors, campaigns, malware, ransomware groups, motivations, targeting patterns, and TTPs Google Threat Intelligence / Mandiant, CrowdStrike Intelligence, Microsoft Threat Intelligence, Palo Alto Unit 42, Intel 471
2. Identify Malicious Activity Malicious IPs, domains, hashes, URLs, attacker infrastructure, phishing, vulnerabilities, stolen credentials, and dark-web activity Recorded Future, Google Threat Intelligence / VirusTotal, Flashpoint, Intel 471, Team Cymru, GreyNoise, Silent Push, SpyCloud
3. Turn Intelligence into Action Detection content, hunting hypotheses, ATT&CK mappings, SIEM queries, automated enrichment, prioritization, and intelligence distribution Recorded Future, Google Threat Intelligence / Mandiant, Microsoft, CrowdStrike, ThreatConnect, Anomali, Sekoia.io

Several providers appear in more than one row, and depth within each row varies by provider and package. Read it as a map of jobs, not a ranking.

1. Understand the Adversary

Adversary-focused services answer who is likely to target you and how they operate.

At the finished-intelligence end, providers such as Google Threat Intelligence / Mandiant, CrowdStrike Intelligence, and Palo Alto Unit 42 package actor-specific campaign reporting, vulnerability-linked analysis, annual threat reports, and the incident response themes their own investigators keep encountering, including identity and cloud intrusion patterns.

Intel 471 sits further along the same row, leaning harder on automated collection paired with human intelligence gathered inside criminal communities. Collection strength and usability are separate qualities, and the second one decides whether your team ever acts on the first.

2. Identify Malicious Activity

Indicator- and infrastructure-focused services tell you what is malicious right now. Providers in this row specialize by source type, telemetry depth, and the workflows they support.

Reputation and pivoting across files, URLs, domains, and IPs remain the core use cases, and VirusTotal is the reference point most teams already know. Around that sit compromised-credential monitoring, cloud-token exposure, vulnerability intelligence, and collection from illicit communities and dark web forums, where Recorded Future and Flashpoint concentrate. Team Cymru works from a different angle, using NetFlow, passive DNS, X.509 certificates, and WHOIS to connect infrastructure that endpoint tools may not link.

Narrower specialists handle narrower problems. GreyNoise separates internet-wide scanning noise from activity more likely to matter in a specific environment, and Silent Push maps pre-breach infrastructure before it surfaces in an alert. Identity-exposure intelligence belongs in the same operational category, where SpyCloud works from recaptured identity assets pulled out of active infostealer logs, phishing output, and criminal sources. Session cookies in those sources may support session invalidation and reduce MFA-bypass risk.

3. Turn Intelligence into Action

Buyers underweight operationalization more often than any other part of the evaluation, and the gap surfaces once the subscription is already running. This row covers the work of converting intelligence into ATT&CK mappings, detection content, hunting hypotheses, and enrichment that reaches the tools that act. Threat intelligence platforms and CTI operations platforms sell into it, including ThreatConnect, Anomali, and Sekoia.io. This row is consolidating as you read it: Dataminr announced its acquisition of ThreatConnect in October 2025, valuing the platform at $290 million, and ThreatConnect now sits inside Dataminr's cyber defense line.

What matters is whether the package hands your SOC something deployable: curated detections, technique metadata, SIEM queries, enrichment that makes alerts easier to triage, and a coverage view showing which techniques you actually monitor. Treat agentic features as implementation details until a proof of concept shows they improve a workflow. Two questions separate the packages that operationalize from the ones that only claim to. Can the service align ingested intelligence to your own ATT&CK gaps? And does it enrich raw alerts with named intrusion sets and the indicators related to them?

Where Threat Intelligence Spending Goes Wrong

Many expensive failures show up after you have chosen a vendor, during operation.

Indicators are brittle. Once distributed, they can become less useful as adversaries replace burnt artifacts. Perishable artifacts are still useful for blocking and enrichment, but they are a poor substitute for context about adversary behavior.

MITRE's 11 Strategies distinguishes IOCs from CTI: indicators without adversary context are facts that inform analysis. The Bank of England's CBEST research documents where that ends up: SOC teams who once welcomed more information now want the fire hose turned down and question whether the intelligence they receive is reliable or actionable.

And purchased intelligence often never reaches a workflow. MITRE draws the budget conclusion: teams need to use or integrate purchased CTI for the spend to be worthwhile, and notes that large, advanced teams may prefer free open-source feeds and partner sharing over premium subscriptions. Teams still have to handle format normalization, deduplication, enrichment, scoring, routing, and measurement.

How to Choose a Threat Intelligence Service: Six Decision Criteria

Matching the service to your team's capacity and threat model is most of the work, so treat each criterion below as a conditional to test against your own situation.

  1. If you cannot write down your priority intelligence requirements, pause the evaluation. SANS frames PIRs as the "North Star" for many CTI activities because they stop teams from chasing the threat of the day and fielding ad-hoc requests. Research, monitoring, collection management, and detection engineering all anchor to what the business actually needs to know.
  2. If CTI is a secondary duty on your IR team, buy curated high-fidelity feeds that plug into tools you already run before you consider a full CTI platform. FIRST's maturity model describes Stage 1 teams as consuming automated feeds of observables, and that is the honest scope. More mature capabilities can come later, after the team has the capacity to task collection and evaluate finished intelligence.
  3. If you have in-house CTI analysts, interrogate depth, provenance, and source validation. CREST guidance recommends assessing the depth of a vendor's actor coverage with practitioners who can ask hard questions about the number of actors and verticals claimed. Ask how sources are collected, how conclusions are validated, and whether the vendor can answer follow-up RFIs.
  4. If persistent, targeted adversary interest is the main concern, weight adversary depth and pre-breach infrastructure mapping. Commodity indicators answer known-bad matching questions and little else, which covers opportunistic threats and runs thin against anything aimed at you specifically.
  5. Evaluate integration against your actual SIEM, EDR, and SOAR before you decide. Ask whether the intelligence automatically enriches alerts and whether the SOAR APIs work in practice, beyond the datasheet.
  6. If a proof of concept produces no deployable outcome, such as a detection or re-prioritized vulnerability, walk. Choose the platform that fits your requirements, analyst workflows, integration environment, and program trajectory.

Run these in order. In many evaluations, the first two disqualify more purchases than the later integration questions.

The Third Job in Practice: Hunting With the Intelligence You Buy

Buyers are moving toward the third job, turning intelligence into action, while many programs still leak value there. In many security operations, intelligence flows one direction: a report becomes IOC extraction and a rule, and the loop closes until the next report. Hunting, where it happens at all, often runs on a cadence disconnected from the intelligence that should drive it.

Buyer behavior reflects the correction. In Recorded Future's 2025 State of Threat Intelligence Report, a vendor-run survey of 615 practitioners and executives, 91% of respondents said they intended to increase threat intelligence spending in 2026, and most said they would cut duplicative vendors as they did it. Hunting frameworks have moved the same direction; MITRE ATT&CK training connects hypothesis development, data requirements, analytics implementation, and investigation into a single threat hunting workflow.

A managed hunting service changes that loop, using intelligence to trigger scoped hunts, historic telemetry sweeps, behavioral hypotheses, and detection tuning. That makes the third job a purchasing question as much as a staffing one, because you can buy intelligence and route it yourself, or buy the routing with it. The distinction matters because MDR covers investigation and response to agreed-upon alerts, while threat hunting searches for activity outside the confirmed-alert stream.

Daylight Security is a MASS company, meaning it offers managed agentic security services for Security Operations. AI-native MDR is the entry point into that portfolio, and Daylight delivers this loop through a separate Threat Hunting service running on the same AI-native platform and staffed by the same security experts.

IOC-based hunts use new vulnerabilities, threat intelligence, or customer inputs as triggers. They sweep historic telemetry across endpoint, identity, and cloud to establish whether the available data shows evidence of compromise. Hypothesis-based hunts start with a Daylight security expert defining a behavioral hypothesis, such as service account misuse or lateral movement patterns, which a coordinated swarm of specialized AI agents then tests in parallel.

Findings do not stop at the report. Security experts escalate unexplained activity into a full investigation, and what the hunt learns refines detection rules through the same detection engineering discipline Daylight applies to its own. Those rules then join the customer's existing tools as investigation triggers. Hunting and intelligence feed each other from there: Daylight draws on public, commercial, and dark web sources to shape what it hunts for, and hunt findings reprioritize the intelligence. Hunts run continuously on a defined frequency rather than episodically, which is the part most in-house programs struggle to sustain.

Buy for the Job, Then Route What You Buy

The distance between 91% and 26% in the SANS data measures how far purchased intelligence sits from used intelligence, more than it measures any shortfall in quality. Both halves are fixable, and they are fixable in order. Name the job before you shortlist. Then build the path from the feed to the detection rule before the contract is signed.

Most programs get the first half right eventually. The second half is where the money goes quiet, because nothing about an unused subscription announces itself. Vendor selection attracts the scrutiny, while the routing work that decides whether any of it lands rarely gets the same attention. That imbalance is what the SANS numbers are describing.

Frequently Asked Questions About Threat Intelligence Services

When Does a Standalone Feed Make More Sense Than a Platform?

A feed makes more sense whenever your team cannot operate a platform. If your practitioners cannot task collection or manage requirements, a platform's premium buys features nobody will use, while a curated feed wired into your SIEM captures most of the value at a fraction of the workflow cost. Weigh it against your CTI and SOC maturity, the complexity of your environment including cloud footprint and third-party dependencies, your regulatory context, and your threat model.

What Does a Threat Intelligence Service Actually Cost?

Public benchmarks are thin, and the most widely cited one is old. TechTarget's 2017 buyer guidance put standalone feed subscriptions at roughly $1,500 to $10,000 per month depending on the number of feeds, which is worth treating as an order of magnitude rather than a current quote. Platform contracts scale differently and can vary widely by module mix, user model, API consumption, integrations, and enterprise support. Implementation and integration work can materially affect total deployment cost, especially when SIEM, EDR, firewall, SOAR, ticketing, analyst training, and enrichment volume are part of the rollout.

Do STIX and TAXII Still Matter?

Yes, as a portability check more than a differentiator. Both are OASIS standards (V2.1 published June 2021). If portability matters, confirm STIX/TAXII export before you commit.

How Do We Measure Whether the Service Is Working?

Measure decisions: detections shipped from intelligence, hunts launched from it, vulnerabilities re-prioritized because of it, and the noise each feed adds to the queue your team already works. For prioritization, weight your program toward behaviors and TTPs. Hashes and IPs sit at the bottom of the Pyramid of Pain and cost an adversary almost nothing to rotate, while behavior-level detection is more expensive for them to evade.

Does Vendor Consolidation Change How We Should Buy?

It should. Recorded Future's survey found that 81% of respondents will consolidate duplicative vendors around providers strong in five areas: analyzing and contextualizing threats, threat hunting and proactive detection, incident response and investigation support, vulnerability research and prioritization, and strategic threat landscape reporting. Weigh that finding against its source, which is a threat intelligence vendor's own research. Standalone intelligence platforms may also be absorbed into broader detection and response stacks, so test the exit ramp during procurement: ask how an acquisition or platform merger would affect your data and existing workflows, including integrations.

Table of contents
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo

Ready to escape the dark and elevate your security?

Stop settling for escalation factories. Get AI-native detection and response with senior experts and full accountability.

Book a Demo
moutain illustration
form submission image form submission image

Ready to escape the dark and elevate your security?

Get a demo
moutain illustration