
Threat Intelligence
Sekoia Intelligence
Structured CTI for SOC and strategic teams with contextualized threat intelligence feeds.
Sekoia Intelligence Overview
What it does
Sekoia Intelligence is a cyber threat intelligence (CTI) platform delivering analyst-validated indicators and contextualized threat knowledge, produced by Sekoia's Threat Detection and Research (TDR) team of 20+ analysts with backgrounds including France's Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) and the French Interior and Defense ministries. Intelligence is modeled in Structured Threat Information Expression (STIX) 2.1 from 450+ integrated external sources, and every indicator is reviewed by an analyst before it reaches the detection stack, with a published false positive rate below 0.015 percent.
How it works
The platform maintains a continuously updated knowledge base of more than 10 million Structured Threat Information Expression (STIX) objects covering threat actors, malware, campaigns, and vulnerabilities, explorable through graph visualization and dashboards filterable by sector, geography, and threat type. Teams consume intelligence through the analyst portal, through indicator collections with CSV and XLS import, and through filtered feeds delivered to third-party detection and intelligence tools via API, TAXII, and MISP connectors. More than 1,000 detection rules and 5,000+ enriched analyst reports operationalize the intelligence, AI-assisted insights guide investigations, and the product integrates natively with Sekoia Defend for detection and response.
Credentials and traction
Sekoia holds ISO/IEC 27001:2022 certification, a SOC 2 Type I attestation, and PCI DSS compliance, with GDPR, NIS2, and DORA documentation published in its trust center. The vendor was named a Leader in the 2024 Frost & Sullivan Frost Radar for Extended Detection and Response and is included in Forrester's Extended Detection and Response Platforms Landscape, Q1 2026. Sekoia Intelligence serves 200+ security operations teams across more than 2,000 organizations, with customers including NATO, EDF, GRDF, Pierre Fabre, and URSSAF.
Key Capabilities
mapped to solution categoriesProvides an interactive portal with contextualized dashboards, configurable alerting, search and built-in analysis.
Provides comprehensive indicators of compromise such as IPs, URLs, domains and file hashes with maliciousness ratings and enrichments like geolocation and TTPs.
Delivers tailored vulnerability and exposure intelligence highlighting actively exploited vulnerabilities with associated IoCs, TTPs and threat actors.
Supports machine-to-machine integration via JSON, APIs and STIX or TAXII, with sharing across private and public communities such as ISACs.
Auto-generates detection rules and syntax for SIEM, firewalls, IPS or IDS and EDR.
Produces finished intelligence reports at technical, operational and strategic levels.
Enriches intelligence with external telemetry such as passive DNS, sinkhole traffic and global sensor networks.
Ingests and shares intelligence via STIX/TAXII and other machine-to-machine formats and APIs.
Aggregates indicators from multiple sources into comprehensive, deduplicated coverage.
Profiles threat actors with associated TTPs and attribution context.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 12, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.