• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. ThreatBook Advanced Threat Intelligence
Logo of ThreatBook Advanced Threat Intelligence

ThreatBook Advanced Threat Intelligence

byThreatBook
in Security Threat Intelligence Products and Services (Transitioning to Cyber Threat Intelligence Technologies)
5.0

Overview

Service Information on ThreatBook Advanced Threat Intelligence

Updated 13th October 2025

What is ThreatBook Advanced Threat Intelligence?

ThreatBook Threat Intelligence Platform - NGTIP is a software designed to provide organizations with insights and analysis on cyber threats by aggregating, correlating, and contextualizing threat intelligence data from multiple sources. The software offers automated threat detection, situational awareness, and risk assessment capabilities to help users identify and respond to security incidents. It integrates with security infrastructure, delivers timely intelligence feeds, and supports investigation processes by providing threat indicators, contextual data, and analysis tools. The software aims to enhance cybersecurity operations by enabling proactive threat identification and supporting decision-making for security teams in complex digital environments.

ThreatBook Advanced Threat Intelligence Pricing

The ThreatBook Threat Intelligence Platform NGTIP software uses a subscription-based pricing model, typically structured around different service tiers that offer varying levels of features and data volume. Pricing may be influenced by the number of users, the scope of threat intelligence feeds accessed, and integration capabilities with other systems. Custom pricing options may be available for enterprises with specific requirements.

Overall experience with ThreatBook Advanced Threat Intelligence

Manager, IT Security and Risk Management
500M - 1B USD, IT Services
FAVORABLE

“SIEM and SOAR integration enhanced, but API handling needs monitoring”

5.0
Jul 14, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.
There are no reviews in this category.
CRITICAL

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top ThreatBook Advanced Threat Intelligence Alternatives

Logo of CloudSEK XVigil
1. CloudSEK XVigil
4.8
(369 Ratings)
Logo of Cyble Vision
2. Cyble Vision
4.8
(330 Ratings)
Logo of Recorded Future Intelligence Platform
3. Recorded Future Intelligence Platform
4.6
(278 Ratings)
View All Alternatives

About Company

Company Description

Updated 5th July 2024

ThreatBook is a provider of cyber threat detection and response services. We developed new approaches to deliver high-fidelity, efficient, and actionable security intelligence. We integrated these capabilities with a full life cycle threat detection system and incident response mechanisms to enhance protection across cloud, network, and endpoints. This helps enterprises respond to threats efficiently, reduce complexity, and improve security operations.

Company Details

Updated 26th February 2025
Company type
Private
Year Founded
2015
Head office location
Beijing, China
Number of employees
501 - 1000
Website
https://threatbook.cn/next/en

Do You Manage Peer Insights at ThreatBook?

Access Vendor Portal to update and manage your profile.

Peer Discussions

ThreatBook Advanced Threat Intelligence Reviews and Ratings

5.0

(101 Ratings)

Rating Distribution

5 Star
99%
4 Star
1%
3 Star
0%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?
  • Manager, IT Security and Risk Management
    50M-1B USD
    IT Services
    Review Source

    SIEM and SOAR integration enhanced, but API handling needs monitoring

    5.0
    Jul 14, 2026
    We expanded ThreatBook TIP across 5 regional SOC hubs (Vietnam, Thailand, Indonesia, India, HQ. Dongguan) over 22 months after. the initial deployment proved effective. The platform now handles 8M+ daily API lookups with <150ms response and 99.7% uptime, feeding real-time IOC enrichment to our SIEM, SOAR and DNS filtering across all hubs. Campaign-level intelligence on APT groups targeting Southeast Asian consumer electronics companies enabled proactive blocking during Q1-Q2 red-team exercises 3 credential harvesting campaigns impersonating regional payment portals intercepted weeks before user impact. Custom intelligence requests around brand impersonation and supply chain firmware threats receive analyst responses within 4-6 hours with actionable context. STIX/TAXII federation across 5 hubs eliminated 45+ analyst-hours/week of manual IOC sharing. An essential platform for consumer electronics companies operating across diverse regional threat landscapes.
  • Manager, IT Security and Risk Management
    50M-1B USD
    IT Services
    Review Source

    SIEM and SOAR integration enhanced, but API handling needs monitoring

    5.0
    Jul 14, 2026
    We expanded ThreatBook TIP across 5 regional SOC hubs (Vietnam, Thailand, Indonesia, India, HQ. Dongguan) over 22 months after. the initial deployment proved effective. The platform now handles 8M+ daily API lookups with <150ms response and 99.7% uptime, feeding real-time IOC enrichment to our SIEM, SOAR and DNS filtering across all hubs. Campaign-level intelligence on APT groups targeting Southeast Asian consumer electronics companies enabled proactive blocking during Q1-Q2 red-team exercises 3 credential harvesting campaigns impersonating regional payment portals intercepted weeks before user impact. Custom intelligence requests around brand impersonation and supply chain firmware threats receive analyst responses within 4-6 hours with actionable context. STIX/TAXII federation across 5 hubs eliminated 45+ analyst-hours/week of manual IOC sharing. An essential platform for consumer electronics companies operating across diverse regional threat landscapes.
  • Read All 105 Reviews

    Get unlimited access to verified peer reviews and insights

    Read unlimited Gartner-vetted product reviews
    View and share valuable product insights
    Download full product profiles
    Review products you use today

Recommended Gartner Insights

  • Magic Quadrant for Security Threat Intelligence Products and Services (Transitioning to Cyber Threat Intelligence Technologies)
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

User Sentiment About ThreatBook Advanced Threat Intelligence
Reviewer Insights for: ThreatBook Advanced Threat Intelligence
Deciding Factors: ThreatBook Advanced Threat Intelligence Vs. Market Average
Performance of ThreatBook Advanced Threat Intelligence Across Market Features

ThreatBook Advanced Threat Intelligence Likes & Dislikes

Like

1.Real-time IOC enrichment. at scale 8Mdaily API lookups <150ms 99.7% uptime across 5 regional SOCs, STIX/TAXII push eliminating 45 analyst-hours/week. manual cross-hub IOC sharing. Regional hubs receive locally-prioritized IOCs within 90sec of HQ detection, 3 credential harvesting campaigns impersonating Vietnam/Indonesia payment portals intercepted weeks before user impact via campaign-level analyst briefings. 2.Campaign-level analyst briefings for Southeast Asian. consume. electronics threats APT groups targeting smartphone brands across VN/TH/ID mapped with full ATT&CK chain attribution context, enabling proactive SIEM rule deployment 2-3 weeks before annual red-team exercises. 4 regional-specific threat packages (Vietnam UPI fraud, Thailand banking trojans, Indonesia fake OTA, India counterfeit accessories) reducing regional analyst OSINT time 60%. 3.Supply chain firmware threat intelligence 800 component suppliers monitored against threat actor infrastructure, 9 early warnings in 8 months flagging BEC targeting camera/display module vendors and APT C2 embedded in firmware update channels. TIP attributionATTACK per IOC enabling SOC skip manual OSINT triage saving 30 analyst-hours/week across all hubs.

Like

1.Real-time IOC enrichment. at scale 8Mdaily API lookups <150ms 99.7% uptime across 5 regional SOCs, STIX/TAXII push eliminating 45 analyst-hours/week. manual cross-hub IOC sharing. Regional hubs receive locally-prioritized IOCs within 90sec of HQ detection, 3 credential harvesting campaigns impersonating Vietnam/Indonesia payment portals intercepted weeks before user impact via campaign-level analyst briefings. 2.Campaign-level analyst briefings for Southeast Asian. consume. electronics threats APT groups targeting smartphone brands across VN/TH/ID mapped with full ATT&CK chain attribution context, enabling proactive SIEM rule deployment 2-3 weeks before annual red-team exercises. 4 regional-specific threat packages (Vietnam UPI fraud, Thailand banking trojans, Indonesia fake OTA, India counterfeit accessories) reducing regional analyst OSINT time 60%. 3.Supply chain firmware threat intelligence 800 component suppliers monitored against threat actor infrastructure, 9 early warnings in 8 months flagging BEC targeting camera/display module vendors and APT C2 embedded in firmware update channels. TIP attributionATTACK per IOC enabling SOC skip manual OSINT triage saving 30 analyst-hours/week across all hubs.

Like

1.Real-time IOC enrichment. at scale 8Mdaily API lookups <150ms 99.7% uptime across 5 regional SOCs, STIX/TAXII push eliminating 45 analyst-hours/week. manual cross-hub IOC sharing. Regional hubs receive locally-prioritized IOCs within 90sec of HQ detection, 3 credential harvesting campaigns impersonating Vietnam/Indonesia payment portals intercepted weeks before user impact via campaign-level analyst briefings. 2.Campaign-level analyst briefings for Southeast Asian. consume. electronics threats APT groups targeting smartphone brands across VN/TH/ID mapped with full ATT&CK chain attribution context, enabling proactive SIEM rule deployment 2-3 weeks before annual red-team exercises. 4 regional-specific threat packages (Vietnam UPI fraud, Thailand banking trojans, Indonesia fake OTA, India counterfeit accessories) reducing regional analyst OSINT time 60%. 3.Supply chain firmware threat intelligence 800 component suppliers monitored against threat actor infrastructure, 9 early warnings in 8 months flagging BEC targeting camera/display module vendors and APT C2 embedded in firmware update channels. TIP attributionATTACK per IOC enabling SOC skip manual OSINT triage saving 30 analyst-hours/week across all hubs.