✍️Writing & Content58🎨Image Generation71🎬Video & Animation120🎵Audio & Music100💬Chatbots & Assistants109💻Coding & Development444📈Marketing & SEO196Productivity401🎯Design & UI/UX120📊Data & Analytics126📚Education & Research55💼Business & Finance174🏥Healthcare & Wellness22🔍Search & Knowledge20🤖AI Agent Infrastructure208🛡️AI Security & Testing32🧊3D & Spatial22🔎SEO Tools113🏡Real Estate7🗃️Data Extraction104🧠ADHD & Focus Tools11🔬Research & Academia45🧩LLM APIs & Models34⚙️Automation & Workflows45🔐Security & Privacy31📊Analytics & BI55⚖️Legal & Contracts14
Listed in Security & Privacy with 31 other toolsPart of 3022+ curated AI tools on AISO
ThreatCluster logo

ThreatCluster

Clusters 20,000+ threat intel sources into one deduplicated live feed with ATT&CK flows, IOC export and hunting queries

freemiumFree is $0 forever with no card at any point: a personalised clustered feed, 3 cluster reads and 1 entity page per day, 5 tracked interests, public RSS and MISP feeds capped at 10 items, a daily digest on 5 keywords, and a read-only REST API and `tc` CLI at 100 requests per day over a 7-day window. Researcher is $19.99/month with a 7-day free trial requiring no card, and adds unlimited cluster and entity views, unlimited alerting keywords, 3 saved feeds, 5 collections, 1 webhook and 3 alert rules, a 50-item RSS and MISP feed, a 120-request-per-minute API, bulk IOC export, KQL/SPL/Lucene hunting queries, ATT&CK Navigator export, full incident timelines, attack flows, STIX threat graphs, dark web access and ransomware leak-site tracking. Higher tiers are listed on the plan comparison.View full pricing →

About ThreatCluster

ThreatCluster ingests more than 20,000 threat intelligence sources and clusters them into a single deduplicated live feed, so an analyst reads one item per incident instead of forty near-identical articles. The feed is personalised to tracked interests rather than global: an operator adds the vendors, technologies or actors they care about and the clustering runs against that set, with trending and popular views alongside a personal feed. Each cluster expands into full incident timelines, attack flows mapped step by step to MITRE ATT&CK, interactive STIX relationship graphs, and defensive countermeasures mapped to D3FEND, which is the part that separates it from a news aggregator. Output is built for use elsewhere: public RSS and MISP feeds, bulk IOC export, ready-made hunting queries in KQL, SPL and Lucene, ATT&CK Navigator export, and a REST API with a companion `tc` CLI. Alerting runs through personalised digests, webhooks and alert rules keyed to unlimited keywords on paid tiers. Higher tiers add dark web access, ransomware leak-site tracking, credential exposure monitoring and X/Twitter intelligence. The free tier is unusually load-bearing for this category — a personalised, clustered, real-time feed with a 100-request-per-day read-only API and no card required, ever — with the paid tiers gating read volume, saved feeds, alerting and the dark web sources rather than the core feed itself.

ChatGPT already recommends ThreatCluster. Does it recommend yours?

If you're building in Security & Privacy, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Key Features

20,000+ sources clustered and deduplicated into one feed
MITRE ATT&CK attack flows and D3FEND countermeasures
Interactive STIX relationship graphs
Bulk IOC export and KQL, SPL and Lucene hunting queries
REST API and `tc` CLI, plus RSS and MISP feeds
Dark web and ransomware leak-site tracking on paid tiers

Tags

threat-intelligencemitre-attackmispiocapi
🏷️

Is ThreatCluster your tool?

This is the page buyers and AI assistants read when they look up ThreatCluster. Claim your listing for $19 one-time — no subscription, nothing to cancel — and get a Featured badge, top placement in your category, and a permanent dofollow backlink. Prefer it ongoing? Monthly is one click away on the next page.

💡

Complete Your AI Tool Stack

ThreatCluster users also rely on these tools to enhance their workflow:

💰 Affiliate disclosure: We may earn a commission if you sign up through these links at no extra cost to you.

Stay updated on Security & Privacy tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Alternatives to ThreatCluster

View all ThreatCluster alternatives →

Agent connectivity: not yet verified