Threat Intelligence
Threat IntelligenceThreatIntelligence
Providers using this tag (109)
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Exemplar 3 Complete, well-documented, and agent-ready
Strong 8 Solid coverage with minor gaps
Developing 31 Usable, with meaningful gaps to close
Thin 26 Limited public surface area
Emerging 25 Early or largely undocumented
Minimal 14 Almost no public developer surface
Unrated 2 Not yet scored
APIs with this tag (46)
Ranked by the provider's API Evangelist rating — the Kin Score is scored per provider, not per API, so every API of a provider shares its band. How the rating works →
Exemplar 1 Complete, well-documented, and agent-ready
Strong 4 Solid coverage with minor gaps
Developing 19 Usable, with meaningful gaps to close
Thin 11 Limited public surface area
Emerging 10 Early or largely undocumented
Minimal 1 Almost no public developer surface
Companies reaching this through an API (8)
These companies publish an API, specification or operation carrying “Threat Intelligence” but do not classify their business under it. Listed unranked and kept out of the count above, because one tagged operation is not a statement about what a company does.
Score breakdown
Related tags
Where this tag comes from
Cohort brief
Auto-generatedThe 104 providers in the APIs.io catalog tagged Threat Intelligence, scored on the Kin Score. Every figure below is computed from the catalog — nothing here is written.
| Facet | This cohort | Catalog | Difference | Scored |
|---|---|---|---|---|
| Developer Ergonomics | 38.8 | 23.4 | +15.4 | 104 |
| Operational Transparency | 26 | 14 | +12 | 104 |
| Access Clarity | 36.9 | 26.5 | +10.4 | 104 |
| Contract Quality | 29.6 | 19.8 | +9.8 | 104 |
| Discoverability | 69.9 | 61.2 | +8.7 | 104 |
| Contract Governance | 11.3 | 6.4 | +4.9 | 104 |
A facet is averaged over the members that carry it, not over the whole cohort — the “Scored” column is that count. Averaging an absent facet as zero would score our own coverage gaps as the providers’ posture.
| Artifact | This cohort | Catalog | Difference |
|---|---|---|---|
| MCP server (any) | 24% | 10% | +14 |
| MCP server (first-party) | 27% | 13% | +14 |
| Agent Skills | 0% | 0% | 0 |
| OAuth scopes | 13% | 11% | +2 |
| Security | 99% | 97% | +2 |
| Arazzo workflows | 6% | 2% | +4 |
| Governance rules | 16% | 14% | +2 |
mcp_pct counts any mcp/ artifact including ones API Evangelist derived from the provider OpenAPI; mcp_first_party_pct counts only servers the provider publishes. Prefer the latter.
- 1 Palo Alto Networks 71.1
- 2 IPinfo 67.5
- 3 Shodan 67.2
- 4 Cisco XDR 62.9
- 5 Feedly 59.4
- 6 Cisco Umbrella 59.3
- 7 GreyNoise Intelligence 59.3
- 8 DomScan 56.7
- 9 CybelAngel 54.7
- 10 Nord Security 54.7
- 1 Feedly 63.3
- 2 IRONSCALES 51.6
- 3 Nord Security 43.5
- 4 Securonix 42.5
- 5 CybelAngel 42.3
- 6 Nucleus Security 41.7
- 7 Abnormal AI 41.5
- 8 Armor 40.4
- 9 Palo Alto Networks 39.4
- 10 DomainTools 39
Work with this as data
Every tag here is available over the APIs.io API and to AI agents over MCP.