Threat intelligence EU-developed

Sekoia Intelligence

Threat intelligence product with searchable actor, campaign, malware and indicator records, analyst reports, feeds, and APIs for dissemination to security systems.

By Sekoia · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Threat intelligence
Developer or maintainer
Sekoia
Recorded country
France
Product model
Commercial
Deployment
SaaS
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Built by Sekoia.io SAS and its threat research team in France; separately licensed from Sekoia Defend.

Reported capabilities

  • Searchable CTI records connect actors, malware, campaigns, infrastructure and indicators.
  • Feeds, TAXII, MISP connectors and APIs distribute intelligence.
  • Can be purchased independently of Defend as an API-delivered CTI product.

Scope and limits

Standalone Intelligence is API-delivered; platform UI availability and Defend integration depend on subscription. This is an independently licensable product, not a duplicate platform module. Full product license terms were not publicly verified.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Official CTI docs describe searchable intelligence and explicitly state standalone API delivery, in addition to Defend-integrated availability.

    Read source
  2. license

    Official subscription documentation says Intelligence is separately licensed and can be bought without Defend. It does not publish customer software rights or full product terms.

    Read source
  3. origin

    Sekoia attributes its software and threat research platform to its own French-founded team.

    Read source
  4. country

    The legal notice gives Sekoia.io SAS registered office in Rennes, France.

    Read source
  5. maintenance

    Current official product page offers Intelligence and describes analyst-maintained records and integrations.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

TAXII Capability

Exposes intelligence collections through TAXII 2.1. Access requires an Intelligence Center API key and the corresponding service access.

STIX Capability

Uses STIX 2.1 for intelligence objects and exports contextualized indicators through its CTI feed. The documented CTI feed exports indicators rather than raw observables.

Put the tool in context.

Turn a report or indicator into a sourced intelligence record, a detection request and a useful handoff. Practical steps with MISP and OpenCTI references.

A threat intelligence workflow for CSIRTs