Threat intelligence for lean security teams
ThreatSight brings IOC scanning, curated threat feeds, continuous monitoring and AI-assisted triage into one platform, so a small team can see what matters and act on it fast.
One platform, end to end
From a single lookup to continuous monitoring and integrations with the tools you already run.
IOC scanning
Look up IPs, domains, URLs, file hashes and phone numbers against aggregated intelligence with a clear score.
Curated threat feeds
Continuously ingested feeds, normalized and de-duplicated into a shared indicator corpus with sightings history.
Monitors & alerts
Watchlist, keyword and CVE monitors with batched email and signed webhook alerts.
AI triage
One click turns raw evidence into a verdict, a confidence level and recommended next steps.
TAXII 2.1 & REST API
Pull intelligence into your SIEM or SOAR over TAXII 2.1, or automate with an HMAC-authenticated API.
Built for teams
Multi-tenant isolation, role-based access, mandatory two-factor sign-in and a full audit log.
AI triage, grounded in evidence
Powered by Claude. The model reasons over what ThreatSight already knows about an indicator, not over guesses.
Gather the evidence
Feed hits, sightings over time, scores and analyst comments are collected for the indicator.
Fence untrusted input
Third-party and community text is isolated and treated as data, so it cannot steer the model.
Verdict and next steps
You get a verdict, the reasoning behind it and concrete actions, ready to act on or hand off.
Cloud or self-hosted
Same product, two ways to run it.
ThreatSight Cloud
- Ready in minutes, nothing to operate
- Shared, continuously updated intelligence
- Team workspaces with role-based access
ThreatSight On-Prem
- Runs inside your own network
- Syncs intelligence from the cloud over TAXII
- For regulated and air-gap-minded environments
Get early access
ThreatSight is onboarding its first teams. Tell us a little about your environment and we'll get back to you.
tseno@threat-sight.com