Comparisec
Submit reviewFor vendors
Threat IntelligenceThreatConnect
AdequateStrongAdequateStrong
4.4

VendorsThreat IntelligenceThreatConnect

ThreatConnect logo

ThreatConnect

ThreatConnect

Founded 2012·US·PE-backed
4.4

Combined score

G2
4.3100
Gartner
4.5120

Editorial verdict

ThreatConnect has built the only platform that genuinely combines a threat intelligence platform with a SOAR capability in one product, eliminating the integration overhead of connecting separate TIP and SOAR tools. The Collective Analytics Layer that aggregates intelligence from all ThreatConnect customers creates a community intelligence layer that improves with scale, and the ISAC and threat sharing community support reflects a platform designed for collaborative defence rather than siloed intelligence consumption.

The proprietary intelligence depth that Recorded Future, Mandiant, and CrowdStrike generate from unique telemetry sources is not something ThreatConnect produces natively. Organisations that need both TIP and SOAR capabilities in one platform will find ThreatConnect compelling. Organisations that want best-of-breed in each category separately will find purpose-built alternatives stronger in each.

The verdict: ThreatConnect is right for organisations participating in ISACs or threat sharing communities wanting combined TIP and SOAR with community intelligence. Organisations wanting best-of-breed TIP should evaluate Recorded Future and best-of-breed SOAR should evaluate Swimlane Turbine.

Last reviewed: May 2026

G2

4.3100 reviews

Gartner

4.5120 reviews
Gartner MQ: Challenger (Gartner TI MQ 2024)

Threat Intelligence assessment

PROTECTIONAdequate
Intelligence depth
3 / 5
Threat actor coverage
4 / 5
OPERATIONSStrong
Workflow integration
5 / 5
Feed freshness
4 / 5
ANALYTICSAdequate
Attribution & analysis
3 / 5
TRUST & ECOSYSTEMStrong
Source quality & accuracy
4 / 5

Strongest: Workflow integration

Watch out for: Attribution & analysis

Strengths & limitations

Strengths

Best TIP platform for SOAR integration — native playbook builder in threat intelligence platform
CAL (Collective Analytics Layer) — community intelligence sharing across customers
Strongest workflow automation for operationalising threat intelligence in SOC

Watch out for

Intelligence breadth narrower than Recorded Future — best when supplementing existing feeds
Complex to configure for organisations new to threat intelligence programs
Less suited for executive-facing intelligence reporting

Best for

SOC teams wanting the strongest TIP platform for operationalising and orchestrating threat intelligence into SOAR workflows.

Not suitable for: Organisations wanting raw intelligence breadth — ThreatConnect is better for operationalising intelligence you already have.

Compliance coverage

SOC 2
HIPAA
NIST CSF
PCI-DSS
GDPR
NIS2
ISO 27001
Essential Eight
AU Privacy Act
CMMC
DORA
CIS Benchmarks

Switching intelligence

Switching from

Common migration paths based on review data

Also considering

Vendors typically shortlisted alongside

← Back to Threat IntelligenceCompare with other Threat Intelligence vendors →

Quick facts

Pricing modelper user/year; TIP platform licensing
Pricing range$15,000-100,000+/year
Free trialNo
Min seatsNo minimum
Deployment time2-4 weeks
Complexity3 / 5
Pricing transparency2 / 5
AU presenceNo
IRAP assessedNo
Open sourceProprietary

Deployment

ModelsSaaS, On-premises
OS supportCloud-native, On-premises
CloudAWS, Azure
SupportPhone, Email, Dedicated CSM
Data residencyUS, EU

Company

ThreatConnect

Founded 2012 · 200-400 employees · PE-backed

HQ: US

$30M+ ARR est.

Certifications

SOC 2 Type II, ISO 27001, FedRAMP

Integrations

SplunkMicrosoft SentinelIBM QRadarCrowdStrikePalo Alto XSOARServiceNowMISP300+ integrations