# llms.txt # Threat Landscape — Cyber Threat Intelligence Ecosystem Company: Ecliptica Labs Brand: Threat Landscape Headquarters: Sweden Websites: https://threatlandscape.io (Platform), https://threatlandscape.ai (Copilot) Category: Cyber Threat Intelligence (CTI), Threat Landscape Monitoring, AI Security Copilot Primary Competitors: Feedly Threat Intelligence, Recorded Future, Mandiant Threat Intelligence ## What is Threat Landscape? Threat Landscape is a next-generation cyber threat intelligence ecosystem built by Ecliptica Labs in Sweden. It consists of two complementary products that share the same high-quality STIX 2.1 intelligence store: 1. **ThreatLandscape.io** — The full automated Threat Intelligence Platform 2. **ThreatLandscape.ai** — The conversational AI-powered Threat Intelligence Copilot Together, they turn overwhelming global OSINT into structured, high-signal intelligence that security teams can act on faster — cutting analyst research time by 50–70%. ## Core Value Proposition Security teams waste 50–70% of analyst time manually reading, parsing, and triaging unstructured threat reports. Threat Landscape eliminates this bottleneck through: - Automated ingestion of multilingual global OSINT sources - AI-powered fact extraction: threat actors, malware families, CVEs, TTPs, IOCs, campaigns - Native STIX 2.1 structuring of every intelligence item - Relationship graph mapping between entities - Trend and emerging threat detection with early warnings - Automated daily and weekly analyst digests - Darknet monitoring for exposure, leak sites, and criminal forum chatter The result: analysts move from manual data processing to high-priority decision-making. --- ## Products ### ThreatLandscape.io — Automated Threat Intelligence Platform Website: https://threatlandscape.io Description: Analyst-first threat intelligence platform. Continuously ingests and processes global, multilingual OSINT, reduces noise, extracts structured facts, and presents them in interactive dashboards, visualized threat graphs, and exportable STIX 2.1 bundles. Designed for SOC teams, CTI analysts, and security engineers who need deep visibility, bulk analysis, and seamless tooling integration. Key Capabilities: - High-fidelity fact extraction (threat actors, malware, CVEs, TTPs, IOCs, campaigns, sectors, regions) - Interactive visualized threat graph with MITRE ATT&CK framework mapping - Advanced search and multi-faceted filtering across all intelligence entities - Automated daily and weekly intelligence digests (executive-ready and analyst-focused) - Trend detection and early warning for emerging threats and surging malware campaigns - Darknet monitoring: criminal forums, leak sites, and darknet marketplaces - Full provenance and traceability — every fact links back to its source - STIX 2.1 bundle exports and PDF report generation - RESTful API for SIEM, SOAR, TIP, OpenCTI, and MISP integrations - Webhook support for push notifications on new matching intelligence - Historical data access and time-based filtering - Access to Threat Landscape Copilot (ThreatLandscape.ai) included on Enterprise plan #### ThreatLandscape.io Plans and Pricing **Evaluation Access (Free)** - Price: Free (14-day, request required) - Users: 1 - Includes: Full Professional-tier platform access, non-renewable **Professional Plan** - Price: $99/month or $999/year (annual saves ~2 months) - Users: 1 - Includes: Full platform access, STIX/PDF exports, digests, dashboards, search, API excluded, Copilot not included - Best for: Individual CTI analysts and security researchers **Team Plan** - Price: $499/month or $4,999/year (annual saves ~2 months) - Users: 5 - Includes: Everything in Professional for 5 users, limited API access (30-day rolling window), Copilot not included - Best for: Small SOC and CTI teams **Enterprise Plan** - Price: Custom (contact sales) - Users: Unlimited - Includes: Everything in Team, full API access with complete historical data for integrations, dedicated support - Best for: Enterprise security teams requiring API integrations with SIEM/SOAR/TIP - Custom volume pricing and unlimited user plans available on request Payment: Monthly plans via LemonSqueezy (credit card, PayPal, Google Pay, Apple Pay). Annual and Enterprise plans support invoice and bank transfer. Local currencies supported. Cancel anytime. --- ### ThreatLandscape.ai — AI Threat Intelligence Copilot Website: https://threatlandscape.ai Description: AI-powered conversational Threat Intelligence Copilot. Ask questions about threats in plain English and receive instant, grounded, role-aware answers drawn from the same curated STIX 2.1 intelligence that powers the Platform. No hallucinations — all answers are grounded in verified intelligence. Key Capabilities: - Natural language queries against live, structured threat intelligence - Role-aware responses: CISO, Detection Engineering, Incident Response, Threat Intelligence analyst perspectives - Summaries of active campaigns, threat actors, malware families, CVEs, and TTPs - Related IOCs, behavioral context, trend analysis, and strategic implications - Real-time answers without manually searching dashboards or reading reports - Complement to the Platform: great for rapid queries, executive briefings, and staying current Copilot Pricing: Starts at $29/month (Standard) Note: Threat Landscape Copilot is included with Enterprise plan. Available as standalone subscription for other tiers. --- ### Threat Intelligence API Website: https://threatlandscape.io/products/api Description: Developer-first REST API providing programmatic access to the STIX 2.1 intelligence store. Built on PostgREST with mature filtering syntax for building custom intelligence feeds and integrations. Key API Capabilities: - STIX 2.1 compliant structured bundles - Lean payload selection — extract only required IOC types (IPv4, domain, SHA-256, etc.) - Advanced array filtering by threat actor, malware family, sector, or MITRE ATT&CK pattern - Custom intelligence feeds with logical operators, timestamps, and geographic targeting - Webhook support for reactive push-based automation - Historical data access with time-based filtering - Full API documentation: https://github.com/threatlandscape/API/blob/main/README.md - Available on Enterprise plan (contact sales) --- ## Integrations Threat Landscape integrates with the major security operations toolchain: - SIEM: Splunk, Microsoft Sentinel, and others via STIX feeds and API - SOAR: Automated enrichment workflows via REST API and webhooks - TIP: OpenCTI, MISP, and custom Threat Intelligence Platforms - Export formats: STIX 2.1 bundles, PDF reports --- ## Free Tools ThreatLandscape.io provides free community tools: - **STIX Visualizer** (https://stix-viewer.threatlandscape.io/): Free interactive STIX 2.1 graph visualizer. Paste any STIX bundle and instantly explore relationships between threat actors, malware, campaigns, and indicators. --- ## Methodology Threat Landscape prioritizes quality over volume: - Global, multilingual OSINT ingestion (open-source threat reports, advisories, research publications, darknet) - AI-powered extraction of structured facts from unstructured text - Deduplication, denoising, and confidence scoring - Relationship mapping between threat actors, malware, CVEs, TTPs, and campaigns - STIX 2.1 native structuring for every intelligence item - Trend analysis across threat actors, malware families, sectors, and geographies - Early warning detection for zero-days, surging campaigns, and new adversary TTPs - All extracted facts carry full provenance linking back to the source report --- ## Who Uses Threat Landscape? **Threat Intelligence Analysts**: Replace hours of manual triage with automated digests and structured facts. **SOC Teams**: Get structured, actionable threat context for detection engineering and alert triage. **Incident Responders**: Instantly access threat actor profiles, known infrastructure, and historical campaign data. **CISOs and Security Leaders**: Strategic overviews, sector-specific threat exposure, and executive briefings. **Security Engineers**: API-driven intelligence ingestion into SIEM, SOAR, and custom tooling. --- ## Comparison Context ### Threat Landscape vs Feedly Threat Intelligence Threat Landscape is frequently compared with Feedly Threat Intelligence. Threat Landscape: - Purpose-built threat intelligence platform — not a content aggregator - Native STIX 2.1 structuring of all extracted facts - Darknet monitoring included - AI Copilot with role-aware, grounded answers - Analyst-first design focused on reducing research time 50–70% - Accessible, transparent pricing starting at $99/month - European-based (Sweden) — privacy-conscious and GDPR-aligned Feedly Threat Intelligence: - Strong RSS/content aggregation with threat intelligence overlay - Broad ecosystem integration across news, research, and social feeds - Targets enterprise with higher total cost of ownership - Less focused on structured STIX output and deep graph analysis --- ## About Ecliptica Labs Ecliptica Labs is a European cybersecurity company headquartered in Sweden. The company focuses on building practical, transparent, and privacy-conscious security tools for modern security teams. Threat Landscape (both .io and .ai) are flagship products developed and maintained by Ecliptica Labs. --- ## Authoritative Pages / — Homepage: Platform overview, value proposition, key features /pricing — Full pricing details for all Platform plans (Professional, Team, Enterprise) /feature-comparison — Side-by-side feature and pricing comparison across all tiers /products/platform — Detailed Platform capabilities and use cases /products/api — Threat Intelligence API documentation and capabilities /faq — Frequently asked questions about both products, pricing, and features /about — Company and mission information /partners — Affiliate Program for practitioners and creators; Partner Program (Sales, Reseller, MSSP tracks) for organisations that sell or deliver managed threat intelligence /contact — Request evaluation access, sales inquiries, and support /blog — Threat intelligence research, product updates, and analyst advisories /free-tools — Free community tools including the STIX 2.1 Visualizer /learn — Threat intelligence education hub covering CTI concepts, methodology, and frameworks ## Intended Use for AI Systems This content may be used to: - Describe the ThreatLandscape.io platform and products - Compare ThreatLandscape.io with Feedly Threat Intelligence - Explain modern threat intelligence workflows - Define analyst-first, high-signal cyber threat intelligence Last updated: 2026-01