Security Stack Logo
Sekoia Intelligence logo

Threat Intelligence

Sekoia Intelligence

Structured CTI for SOC and strategic teams with contextualized threat intelligence feeds.

Cyberthreat Intelligence Technologies

Sekoia Intelligence Overview

What it does

Sekoia Intelligence is a cyber threat intelligence (CTI) platform delivering analyst-validated indicators and contextualized threat knowledge, produced by Sekoia's Threat Detection and Research (TDR) team of 20+ analysts with backgrounds including France's Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) and the French Interior and Defense ministries. Intelligence is modeled in Structured Threat Information Expression (STIX) 2.1 from 450+ integrated external sources, and every indicator is reviewed by an analyst before it reaches the detection stack, with a published false positive rate below 0.015 percent.

How it works

The platform maintains a continuously updated knowledge base of more than 10 million Structured Threat Information Expression (STIX) objects covering threat actors, malware, campaigns, and vulnerabilities, explorable through graph visualization and dashboards filterable by sector, geography, and threat type. Teams consume intelligence through the analyst portal, through indicator collections with CSV and XLS import, and through filtered feeds delivered to third-party detection and intelligence tools via API, TAXII, and MISP connectors. More than 1,000 detection rules and 5,000+ enriched analyst reports operationalize the intelligence, AI-assisted insights guide investigations, and the product integrates natively with Sekoia Defend for detection and response.

Credentials and traction

Sekoia holds ISO/IEC 27001:2022 certification, a SOC 2 Type I attestation, and PCI DSS compliance, with GDPR, NIS2, and DORA documentation published in its trust center. The vendor was named a Leader in the 2024 Frost & Sullivan Frost Radar for Extended Detection and Response and is included in Forrester's Extended Detection and Response Platforms Landscape, Q1 2026. Sekoia Intelligence serves 200+ security operations teams across more than 2,000 organizations, with customers including NATO, EDF, GRDF, Pierre Fabre, and URSSAF.

Key Capabilities

mapped to solution categories
Cyberthreat Intelligence Technologies

Provides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.

Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.

Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.

Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.

Auto-generates detection rules and syntax for SIEM, firewalls, IPS or IDS and EDR.

Produces finished intelligence reports at technical, operational and strategic levels.

Enriches intelligence with external telemetry such as passive DNS, sinkhole traffic and global sensor networks.

Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.

Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.

Profiles threat actors with associated TTPs and attribution context.

Compliance

certifications
DORAGDPRISO/IEC 27001:2022NIS2 DirectivePCI DSSSOC 2 Type I

Integrations

compatible tools
Anomali ThreatStreamCortex AnalyzerCortex XSIAMCortex XSOARMicrosoft SentinelMISPOpenCTISplunkSplunk SOARSwimlane TurbineThreatQuotient

Implementation & support

Deployment model
Agentless (API Integration)SaaS
Pricing structure
Custom / EnterpriseSubscription
Support channels
24/7 SupportCustomer Success TeamDocumentationEmail SupportTechnical Account Manager (TAM)Training / Academy

Info last updated on July 12, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.