Threat intelligence EU-developed

EclecticIQ Intelligence Center

Threat intelligence platform for ingesting, structuring, analyzing, and sharing indicators and adversary context through analyst workflows, APIs, and integrations.

By EclecticIQ · Netherlands

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
EclecticIQ
Recorded country
Netherlands
Product model
Commercial
Deployment
Self-hosted
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

EclecticIQ began its Intelligence Center platform in Amsterdam and received Dutch/EU financing for platform R&D. The vendor also disclosed an India engineering hub; the exact current engineering split is not public.

Reported capabilities

  • Current Intelligence Center 3.9 release documents threat intelligence workflows and integrations.
  • Official installation guide covers customer-hosted and offline deployment.
  • The vendor requires an instance-specific license key; full current core rights terms were not publicly readable.

Scope and limits

The Dutch product/R&D origin is documented, but EU-only engineering and ownership are not. A vendor license key and paid upgrade do not establish proprietary rights; full core terms need review.

Inspect the research evidence 5 source observations
  1. identity / capabilities / maintenance

    First-party 3.9 documentation contains a September 2026 release and current Intelligence Center threat-data, API and integration changes.

    Read source
  2. deployment

    Current official installation and configuration guide covers deployment to customer hosts, including an offline installation route.

    Read source
  3. origin / country

    The vendor and EIB identify EclecticIQ as a Dutch cybersecurity company financed to expand research and development of its own cyber platform, supporting Dutch product stewardship rather than an EU-only engineering conclusion.

    Read source
  4. origin

    EclecticIQ disclosed an India R&D hub focused initially on endpoint/XDR and potentially broader technology, so international engineering must remain visible as a caveat.

    Read source
  5. license

    Official current product instructions require an instance-specific vendor license key. They establish license-controlled commercial distribution but do not expose full core rights or prove a proprietary code license.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

STIX Capability

Imports and exports STIX 2.1 through configured TAXII feeds. Modified entities may receive new STIX IDs on export; the documented extension does not fully preserve STIX object versioning.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs