TAXII Capability
Documents incoming and outgoing TAXII 2.1 feeds. Its extension notes disclose nonstandard default version filtering and STIX object-version limitations.
An independent tool index
for incident response teams
Threat intelligence EU-developed
Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations.
By EclecticIQ · Netherlands
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
EclecticIQ began its Intelligence Center platform in Amsterdam and received Dutch/EU financing for platform R&D. The vendor also disclosed an India engineering hub; the exact current engineering split is not public.
The Dutch product/R&D origin is documented, but EU-only engineering and ownership are not. A vendor license key and paid upgrade do not establish proprietary rights; full core terms need review.
identity / capabilities / maintenance
First-party 3.9 documentation contains a September 2026 release and current Intelligence Center threat-data, API and integration changes.
Read sourcedeployment
Current official installation and configuration guide covers deployment to customer hosts, including an offline installation route.
Read sourceorigin / country
The vendor and EIB identify EclecticIQ as a Dutch cybersecurity company financed to expand research and development of its own cyber platform, supporting Dutch product stewardship rather than an EU-only engineering conclusion.
Read sourceorigin
EclecticIQ disclosed an India R&D hub focused initially on endpoint/XDR and potentially broader technology, so international engineering must remain visible as a caveat.
Read sourcelicense
Official current product instructions require an instance-specific vendor license key. They establish license-controlled commercial distribution but do not expose full core rights or prove a proprietary code license.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Documents incoming and outgoing TAXII 2.1 feeds. Its extension notes disclose nonstandard default version filtering and STIX object-version limitations.
Imports and exports STIX 2.1 through configured TAXII feeds. Modified entities may receive new STIX IDs on export; the documented extension does not fully preserve STIX object versioning.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs