IBM Security X-Force Threat Intelligence products
Make informed security decisions with actionable threat intelligence that keeps you in front of the latest attacks
View pricing and buy
businesspeople working at an IBM Security X-Force center
Research, collaborate and act on threat intelligence

IBM® X-Force® Exchange is a cloud-based threat intelligence platform that allows you to consume, share and act on threat intelligence. It enables you to rapidly research the latest global security threats, aggregate actionable intelligence, consult with experts and collaborate with peers. IBM X-Force Exchange, supported by human and machine-generated intelligence, leverages the scale of IBM X-Force to help users stay ahead of emerging threats.

 

Read the X-Force® Threat Intelligence Index Report to understand the current threat landscape.

Learn about IBM X-Force Advanced Protection feed

Explore the editions and compare features
Benefits Access global threat intelligence
Quickly research and share information about threats from IBM X-Force research, including strategic, operational tactical intelligence (TTPs), machine-generated data, human analysis, and threat intelligence services.
Enrich indicators
Programmatically access information using STIX and TAXII standards or through a RESTful API in JSON format. Use feeds to enrich threat context, along with curated, organic indicators and IBM X-Force research.
Boost security operations
Incorporate intelligence from IBM X-Force research to improve your security operations and enable near real-time decision making in the face of cybersecurity threats and incidents.
Offerings

Explore the features of our comprehensive threat intelligence offerings

IBM X-Force Exchange

This cloud-based threat intelligence platform allows you to consume, share and act on threat intelligence. It enables you to rapidly research the latest global security threats, aggregate actionable intelligence, consult with experts and collaborate with peers.

Start the demo
IBM Advanced Threat Protection Feed

This feed is designed to help you monitor and protect your environment efficiently. It provides you with machine-readable, actionable indicators that directly integrate with your security tools—firewalls, intrusion prevention systems and SIEM—through open standards.

Read the documentation
IBM X-Force Exchange Commercial API

This API provides programmatic access to external threat intelligence to help contextualize security events. As a companion offering to the IBM X-Force Exchange collaborative platform, the API uses open standards to help speed time to action.

Read the documentation
IBM Early Warning Feed

This feed is designed to give you early warning on hundreds of new malicious domains surfaced daily through IBM's collaboration with Quad9. The unique content is available through the Advanced Threat Protection Feed and the X-Force Exchange Commercial API.

See the infographic
IBM X-Force Premium Threat Intelligence Reports

These reports provide timely access to contextual threat intelligence published and curated by the X-Force team and available through the X-Force Exchange Commercial API. There are four categories of reports, including Threat Activity, Malware, Threat Group Profiles, and Industry Analysis.

How customers use it

Research the latest threats X-Force Exchange provides access to over 900 terabytes of human and machine-generated threat intelligence through reports, advisories and collections, including support for third-party providers through bring-your-own functionality.
Integrate threat intelligence through open standards IBM X-Force threat intelligence can be integrated into existing security solutions by way of the RESTful API, including STIX over TAXII protocols to incorporate structured and unstructured data.
Automate blocking of malicious websites The Early Warning Feed provides you with a list of malicious domains to integrate with your security tools. It also provides information on deep-dive lifecycles and volumetric data, which allow you to make timely decisions before a threat propagates.

Make informed, strategic cybersecurity decisions The X-Force Premium Threat Intelligence Reports provide you with higher-order intelligence to generate strategic awareness across regions and industries, identify future trends, and characterize threat events to guide strategic decision making.

Monitor and protect your environment against cyber threats The Advanced Threat Protection Feed provides you with a list of machine-readable, actionable indicators that directly integrate with your security monitoring tools such as firewalls, intrusion prevention systems and SIEMs.

Resources Protect against DNS attacks with the X-Force Commercial API

Learn about threat intelligence use cases that leverage malicious domains to detect, respond and anticipate DNS attacks.

Watch the webinar
Threat Intelligence, Cover Your Bases!

Discover how IBM's curation and dissemination of threat intelligence can help your team research threats and collaborate.

Watch the webinar
Threat Intelligence in Practice: A Day in the Life, from Four Perspectives

Uncover the value of threat intelligence by framing it from the unique perspective of four roles in the typical enterprise.

Watch the webinar

Frequently asked questions

X-Force is a threat-centric team of hackers, responders, researchers and analysts with decades of experience. Our portfolio includes offensive and defensive products and services, fueled by a 360-degree view of threats. With a deep understanding of how threat actors think, strategize and strike, our team knows how to prevent, detect, respond to, and recover from incidents so that you can focus on business priorities. 

  • IBM® X-Force expert services are backed by more than 1,000 world-class hackers, responders, researchers and analysts that are renowned industry thought leaders and security influencers.
  • Our threat intelligence is gleaned from IBM incident response client engagements, combined with all-source threat actor analysis, and infused in all IBM Security® products and services to help clients stay ahead of attacks.
  • X-Force threat hunters use IBM’s proprietary TTP threat hunt library and the MITRE ATT&CK framework to provide proactive threat detection

Threat intelligence is a compilation of threat information that is gathered across external sources and used to prevent and mitigate cyberattacks. Threat data is organized, refined and augmented to make it actionable and to allow your cybersecurity team to understand threats and the actors behind them.
The X-Force® Threat Intelligence team delivers global threat intel applied to your security operations with detection and response content. We help streamline workflow, orchestration and applications that drive enrichment, collaboration, visualization and advanced analytics, providing:

  • Direct access to the latest threat intel from our engagements
  • High quality, prioritized, actionable intelligence for detection and response

Threat intelligence empowers cybersecurity teams to proactively defend against and rapidly respond to threats attacking their organization by helping them identify and understand their adversary, create a response plan and allocate resources strategically. Cybersecurity teams can use threat intelligence to block attacks in real time and mitigate the risk of attackers affecting their brand and reputation.

Threat intelligence is purposely built by industry experts from a wide range of backgrounds, including former government intelligence analysts, SOC analysts and private industry consultants. The team’s founding principles include strict analytic rigor, correct analysis and reproducible assessments. 

X-Force Threat Intelligence uses industry best practice frameworks such as:

  • Diamond Model Intrusion Analysis 
  • Lockheed Martin Cyber Kill Chain
  • MITRE ATT&CK

Threat intelligence is valuable to different members across the security operations center (SOC), from real-time blocking for tier 1 analysts, aiding investigation and threat hunting for more experienced analysts, to helping SOC leaders make strategic decisions.

Find out more

There are 5 types of premium reports published as premium content in the X-Force® Exchange platform:

  • Threat Activity reports provide real-time updates about discovered activity, whether from incident response investigation, IBM telemetry, open sources or other forms of collection. Security analysts can gain an immediate understanding of what X-Force knows about the attack lifecycle while executives get a quick understanding of the latest threats in their industry.
  • Early Warning Research reports provide a security analyst with early warning on malicious domains that are surfaced through X-Force's partnership with Quad9. The research provides access to threats, malicious domains, DNS activity and volumetrics to identify abnormal spikes in activity. 
  • Malware Analysis reports provide a security analyst with an in-depth description of how the malware functions, indicators of compromise, payloads, mutexes and processes. The analyst can use the information to hunt on their network or pivot to other relevant information about the threat groups who use the malware, other similar tools, and behaviors to detect on their networks.
  • Threat Group profiles provide a security analyst with the latest information about cyber threat groups, including their typical targets, history, TTPs (tactics, techniques and procedures), common attack vectors, top malware and where the threat group might be targeting next.
  • An Industry Analysis report provides executives with a baseline of threats to their industry and the future landscape so they can assess risks and assign resources based on what’s being observed, including relevant malware, threat groups and threat activity.

The Domain Name System (DNS) is the protocol that translates user-friendly domain names that people can remember to computer-friendly IP addresses.

Find out more

Quad9, a partnership between IBM, Packet Clearing House and Global Cyber Alliance, is a recursive DNS platform that blocks against malicious domains to prevent your computers and IoT devices from connecting to malware or phishing sites.

Find out more

IBM Security® X-Force® Research is a group of experts with the skills, expertise and insight to help your company transform your incident response and intelligence capabilities. We look across cybersecurity threat research on vulnerabilities, threat actors, malware and more, including data from recent industry reports and intel from the experts at IBM Security X-Force.

The X-Force Threat Intelligence portfolio supports 5 product offerings: 

  • IBM Security® QRadar® XDR Connect on Cloud Pak® for Security
  • X-Force Exchange (XFE): research portal
  • X-Force Exchange Commercial API (C-API): research portal API
  • Advanced Threat Protection Feed (ATPF): detection feed API
  • QRadar® Threat Intelligence app (TI app): QRadar add on

Each offering provides continuous threat intelligence in the form of machine generated or human generated intelligence and serves distinct use cases depending on customer needs.

Find out more

Each year, IBM Security X-Force—our in-house team of cybersecurity experts and remediators—mines billions of data points to expose today’s most urgent security statistics and trends.

IBM Security’s latest research is published in the annual X-Force Threat Intelligence Index, a comprehensive overview of the global threat landscape based on data collected throughout the previous year.

Learn more

You can find additional information and support documentation on the Swagger framework platform, which provides interactive documentation and evaluation of the RESTful API in the deployment environment.

Find out more

The Early Warning Feed is available through the Enterprise edition of the X-Force Exchange Commercial API. If you are interested in pricing information, you can contact one of our sales representatives through the “Let’s talk” chat or call us at 1 887-257-5227.

The X-Force Premium Threat Intelligence Reports are available through the Enterprise edition of the X-Force Exchange Commercial API. If you are experiencing an incident, contact X-Force to help: US hotline 1-888-241-9812; Global hotline (+001) 312-212-8034.

IBM X-Force Exchange is a cloud-based threat intelligence platform that allows you to consume, share and act on threat intelligence. It enables you to rapidly research the latest global security threats, aggregate actionable intelligence, consult with experts and collaborate with peers.

Find out more

The X-Force Exchange provides a combination of observable indicators including vulnerabilities, malware, malware families, IP reputation, URL reputation, web applications, pDNS, WHOIS information, malicious domains, and higher-order intelligence such as actors, campaigns, incidents and TTPs. X-Force Threat Intelligence provides curated analysis of threats, groups, malware and industries.

X-Force Threat Intelligence data is sourced from IBM-developed infrastructure and databases, open-source intelligence, commercial sources, the deep web, and partnerships with third-party sources.

The IBM X-Force Exchange Commercial API provides programmatic access to external threat intelligence to help contextualize security events. As a companion offering to the IBM X-Force Exchange collaborative platform, this API uses open standards to help speed time to action.

Find out more

IBM X-Force threat intelligence can be integrated into existing security solutions by using a RESTful API, including STIX over TAXII protocols to incorporate structured and unstructured data.

The Early Warning Feed is designed to help you stay ahead of threats with timely and actionable information on malicious domains, including deep-dive lifecycles on these domains and volumetric data on their activity.

Find out more

The Early Warning Feed is designed for security professionals looking to identify malicious domains as early as possible and to protect their organization from attacks that primarily exploit the domain name service (DNS), such as phishing, domain generation algorithms (DGA), tunneling and squatting.

Find out more

The Advanced Threat Protection Feed is a machine-readable threat intelligence feed that integrates with security tools such as firewalls, intrusion prevention systems and SIEMs. It provides you with programmatic access to actionable indicators categorized by our X-Force team.

The Advanced Threat Protection Feed includes actionable indicators from threat categories such as C2 servers, bots, malware sources, phishing domains, anonymization services, scanning IPs, cryptocurrency miners, X-Force curated indicators, and a block list of high frequency and benign endpoints.

An indicator is classified as actionable when it is associated with a specific threat category and an actionable score (>=5.0). X-Force’s actionable threat intelligence exhibits a 99.97% detection rate, accompanied by a 0.003% false positive rate (as tested by external parties).

The Advanced Threat Protection Feed delivers machine readable lists of actionable indicators that can be consumed directly by your security tools. The Commercial API provides a research platform for exploring all indicators, reports and advisories from the X-Force Exchange.

Related products IBM Security® QRadar® XDR
Connect your tools, automate your SOC and streamline workflows. Free up time for what matters most.
IBM Security® QRadar® SIEM
Get actionable insight into the most critical threats from intelligent security analytics that consolidate log events and network flow data.
IBM Security® QRadar SOAR
Respond to security incidents with confidence, consistency and collaboration.
Next steps
Start your trial today

Explore the latest threats with tactical, operational and strategic threat intelligence.

Learn more
Learn about IBM X-Force Advanced Protection feed

Detect and block actionable indicators of compromise (IOCs) and industry specific threats based on in-depth analysis by IBM’s team of threat researchers. (266 KB)

Learn more
Sign up to the IBM X-Force RSS feed

Understand which threats are most relevant to your organization by receiving sample reports and IOCs.

Learn more