TAXII Capability
Exposes intelligence collections through TAXII 2.1. Access requires an Intelligence Center API key and the corresponding service access.
An independent tool index
for incident response teams
Threat intelligence EU-developed
Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems.
By Sekoia · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Built by Sekoia.io SAS and its threat research team in France; separately licensed from Sekoia Defend.
Standalone Intelligence is API-delivered; platform UI availability and Defend integration depend on subscription. This is an independently licensable product, not a duplicate platform module. Full product license terms were not publicly verified.
identity / capabilities / deployment
Official CTI docs describe searchable intelligence and explicitly state standalone API delivery, in addition to Defend-integrated availability.
Read sourcelicense
Official subscription documentation says Intelligence is separately licensed and can be bought without Defend. It does not publish customer software rights or full product terms.
Read sourceorigin
Sekoia attributes its software and threat research platform to its own French-founded team.
Read sourcecountry
The legal notice gives Sekoia.io SAS registered office in Rennes, France.
Read sourcemaintenance
Current official product page offers Intelligence and describes analyst-maintained records and integrations.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Exposes intelligence collections through TAXII 2.1. Access requires an Intelligence Center API key and the corresponding service access.
Uses STIX 2.1 for intelligence objects and exports contextualized indicators through its CTI feed. The documented CTI feed exports indicators rather than raw observables.
Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.
A threat intelligence workflow for CSIRTs