Browse by category

SIEM & Threat Intelligence

Discover threat intelligence platforms, SIEM, SOAR, and XDR solutions for security operations centers.

Refine results
Refine resultsClear all
Deployment
Source model
Pricing model

How to choose siem & threat intelligence tools

SIEM & Threat Intelligence tools support a defined technical workload. Start with the systems, users and operating constraints the tool must cover before comparing individual features.

What belongs in this category: A listing belongs in SIEM & Threat Intelligence when this workload is a primary product function rather than a secondary integration or marketing label.

Who uses these tools

  • Technical owners responsible for the workload
  • Operators who deploy, secure and support the system
  • Teams evaluating integrations, cost and migration risk

Capabilities to compare

  • Core workflow and platform coverage
  • Deployment, identity and integration controls
  • Administration, observability and recovery

Operating considerations

  • Compatibility with the current environment
  • Security, data location and access boundaries
  • Migration effort, support and total operating cost

Selection checklist

  1. Write down the production workload, scale and failure scenarios.
  2. Test the most important integration and an export or recovery path.
  3. Verify current limits, licensing and support in official documentation.
Decision resources

Continue the technical evaluation

Use the resources that match your decision stage. Profile data and linked sources were refreshed through September 27, 2026.

Evaluation methodology · Corrections process

4 results in SIEM & Threat Intelligence

Elastic

Elastic Security brings SIEM and endpoint signals onto the Elasticsearch platform.

SIEM & Threat IntelligenceSelf-hostedOpen source

Elastic Cloud is Elastic's hosted Elasticsearch service, offered as fully managed Serverless or resource-based Hosted deployments across AWS, GCP and Azure, covering search, observability and SIEM/security use cases.

SIEM & Threat IntelligenceSelf-hostedOther license

Recorded Future is a modular threat intelligence platform covering cyber threats, vulnerabilities, third-party risk and brand protection; acquired by Mastercard in 2024.

SIEM & Threat IntelligenceOther license
Splunk

Splunk offers a data platform for search and analysis, with a separate Enterprise Security product for SecOps.

SIEM & Threat IntelligenceSelf-hostedWebOther license