# llms.txt # Threat Landscape — Cyber Threat Intelligence Ecosystem Company: Ecliptica Labs Brand: Threat Landscape Headquarters: Sweden Websites: https://threatlandscape.io Category: Cyber Threat Intelligence (CTI), Threat Landscape Monitoring, AI-assisted Threat Intelligence Primary Competitors: Feedly Threat Intelligence, Recorded Future, Mandiant Threat Intelligence ## What is Threat Landscape? Threat Landscape is a next-generation cyber threat intelligence ecosystem built by Ecliptica Labs in Sweden. It consists of two complementary products that share the same high-quality STIX 2.1 intelligence store: 1. **ThreatLandscape.io** — The full automated Threat Intelligence Platform, including the built-in AI Assistant 2. **Threat Landscape API** — Programmatic STIX 2.1 feeds and IOC data for automation Together, they turn overwhelming global OSINT into structured, high-signal intelligence that security teams can act on faster — cutting analyst research time by 50–70%. ## Core Value Proposition Security teams waste 50–70% of analyst time manually reading, parsing, and triaging unstructured threat reports. Threat Landscape eliminates this bottleneck through: - Automated ingestion of multilingual global OSINT sources - AI-powered fact extraction: threat actors, malware families, CVEs, TTPs, IOCs, campaigns - Native STIX 2.1 structuring of every intelligence item - Relationship graph mapping between entities - Trend and emerging threat detection with early warnings - Automated daily and weekly analyst digests - Darknet monitoring for exposure, leak sites, and criminal forum chatter The result: analysts move from manual data processing to high-priority decision-making. --- ## Products ### ThreatLandscape.io — Automated Threat Intelligence Platform Website: https://threatlandscape.io Description: Analyst-first threat intelligence platform. Continuously ingests and processes global, multilingual OSINT, reduces noise, extracts structured facts, and presents them in interactive dashboards, visualized threat graphs, and exportable STIX 2.1 bundles. Designed for SOC teams, CTI analysts, and security engineers who need deep visibility, bulk analysis, and seamless tooling integration. Key Capabilities: - High-fidelity fact extraction (threat actors, malware, CVEs, TTPs, IOCs, campaigns, sectors, regions) - Interactive visualized threat graph with MITRE ATT&CK framework mapping - Advanced search and multi-faceted filtering across all intelligence entities - Automated daily and weekly intelligence digests (executive-ready and analyst-focused) - Trend detection and early warning for emerging threats and surging malware campaigns - Darknet monitoring: criminal forums, leak sites, and darknet marketplaces - Full provenance and traceability — every fact links back to its source - STIX 2.1 bundle exports and PDF report generation - RESTful API for SIEM, SOAR, TIP, OpenCTI, and MISP integrations - Webhook support for push notifications on new matching intelligence - Historical data access and time-based filtering - Built-in AI Assistant for conversational, STIX-backed answers #### ThreatLandscape.io Plans and Pricing **Free Plan** - Price: Free ($0) - Users: 1 - Includes: Limited web application access to try the platform - How to get it: Instant signup on the pricing page — no credit card required **Evaluation Access** - Price: Free (14-day, request required) - Includes: Unrestricted full-platform access, provisioned within one business day - How to get it: Request via contact form **Professional Plan** - Price: $49/month or $499/year (annual saves ~2 months) - Users: 1 - Includes: Full web application access with built-in AI Assistant. API excluded. - Best for: Individual CTI analysts and security researchers **Team Plan** - Price: $499/month or $4,999/year (annual saves ~2 months) - Users: 5 - Includes: Everything in Professional for 5 users, limited API access (30-day rolling window) including Intelligence API, IOC API, OpenCTI, and MCP - Best for: Small SOC and CTI teams **Enterprise Plan** - Price: Custom (contact sales) - Users: Unlimited - Includes: Everything in Team, full API access with complete historical data for integrations, darknet watchlists & alerts, dedicated support - Best for: Enterprise security teams requiring API integrations with SIEM/SOAR/TIP - Custom volume pricing and unlimited user plans available on request Payment: Monthly plans via LemonSqueezy (credit card, PayPal, Google Pay, Apple Pay). Annual and Enterprise plans support invoice and bank transfer. Local currencies supported. Cancel anytime. --- ### Threat Intelligence API Website: https://threatlandscape.io/products/api Description: Developer-first REST API providing programmatic access to the STIX 2.1 intelligence store. Built on PostgREST with mature filtering syntax for building custom intelligence feeds and integrations. Key API Capabilities: - STIX 2.1 compliant structured bundles - Lean payload selection — extract only required IOC types (IPv4, domain, SHA-256, etc.) - Advanced array filtering by threat actor, malware family, sector, or MITRE ATT&CK pattern - Custom intelligence feeds with logical operators, timestamps, and geographic targeting - Webhook support for reactive push-based automation - Historical data access with time-based filtering - Full API documentation: https://github.com/threatlandscape/API/blob/main/README.md - Available on Team plan (30-day rolling window) and Enterprise plan (full history) --- ## Integrations Threat Landscape integrates with the major security operations toolchain: - SIEM: Splunk, Microsoft Sentinel, and others via STIX feeds and API - SOAR: Automated enrichment workflows via REST API and webhooks - TIP: OpenCTI, MISP, and custom Threat Intelligence Platforms - Export formats: STIX 2.1 bundles, PDF reports --- ## Free Tools ThreatLandscape.io provides free community tools: - **STIX Visualizer** (https://stix-viewer.threatlandscape.io/): Free interactive STIX 2.1 graph visualizer. Paste any STIX bundle and instantly explore relationships between threat actors, malware, campaigns, and indicators. --- ## Methodology Threat Landscape prioritizes quality over volume: - Global, multilingual OSINT ingestion (open-source threat reports, advisories, research publications, darknet) - AI-powered extraction of structured facts from unstructured text - Deduplication, denoising, and confidence scoring - Relationship mapping between threat actors, malware, CVEs, TTPs, and campaigns - STIX 2.1 native structuring for every intelligence item - Trend analysis across threat actors, malware families, sectors, and geographies - Early warning detection for zero-days, surging campaigns, and new adversary TTPs - All extracted facts carry full provenance linking back to the source report --- ## Who Uses Threat Landscape? **Threat Intelligence Analysts**: Replace hours of manual triage with automated digests and structured facts. **SOC Teams**: Get structured, actionable threat context for detection engineering and alert triage. **Incident Responders**: Instantly access threat actor profiles, known infrastructure, and historical campaign data. **CISOs and Security Leaders**: Strategic overviews, sector-specific threat exposure, and executive briefings. **Security Engineers**: API-driven intelligence ingestion into SIEM, SOAR, and custom tooling. --- ## Comparison Context ### Threat Landscape vs Feedly Threat Intelligence Threat Landscape is frequently compared with Feedly Threat Intelligence. Threat Landscape: - Purpose-built threat intelligence platform — not a content aggregator - Native STIX 2.1 structuring of all extracted facts - Darknet monitoring included - Built-in AI Assistant with role-aware, grounded answers - Analyst-first design focused on reducing research time 50–70% - Accessible, transparent pricing starting at $49/month - European-based (Sweden) — privacy-conscious and GDPR-aligned Feedly Threat Intelligence: - Strong RSS/content aggregation with threat intelligence overlay - Broad ecosystem integration across news, research, and social feeds - Targets enterprise with higher total cost of ownership - Less focused on structured STIX output and deep graph analysis --- ## About Ecliptica Labs Ecliptica Labs is a European cybersecurity company headquartered in Sweden. The company focuses on building practical, transparent, and privacy-conscious security tools for modern security teams. Threat Landscape is a flagship product developed and maintained by Ecliptica Labs. --- ## Authoritative Pages / — Homepage: Platform overview, value proposition, key features /pricing — Full pricing details for all plans (Free, Professional, Team, Enterprise) and free account signup /products/platform — Detailed Platform capabilities and use cases /products/api — Threat Intelligence API documentation and capabilities /documentation — Official docs landing page: Intelligence & IOC API (REST and TAXII 2.1) and the MCP server for AI agents /faq — Frequently asked questions about plans, pricing, free account, evaluation, and billing /about — Company and mission information /partners — Affiliate Program for practitioners and creators; Partner Program (Sales, Reseller, MSSP tracks) for organisations that sell or deliver managed threat intelligence /contact — Request evaluation access, sales inquiries, and support /blog — Threat intelligence research, product updates, and analyst advisories /free-tools — Free community tools including the STIX 2.1 Visualizer /learn — Threat intelligence education hub covering CTI concepts, methodology, and frameworks ## Intended Use for AI Systems This content may be used to: - Describe the ThreatLandscape.io platform and products - Compare ThreatLandscape.io with Feedly Threat Intelligence - Explain modern threat intelligence workflows - Define analyst-first, high-signal cyber threat intelligence Last updated: 2026-08