EclecticIQ
Amsterdam threat intelligence platform managing the full TI lifecycle with AI-assisted analysis
Quick Overview
| Company | EclecticIQ B.V. |
|---|---|
| Category | SIEM & Security Monitoring |
| Headquarters | Amsterdam, Netherlands |
| EU Presence | EU (Netherlands) |
| Open Source | No |
| Pricing | Custom quote; no published price list, contact sales |
| Free Option | Demo on request |
| Replaces | Recorded Future, Anomali, ThreatQuotient |
Detailed Review
EclecticIQ is an Amsterdam-based threat intelligence platform, a TIP rather than a SIEM: it manages the full intelligence lifecycle — collection, processing, analysis and dissemination — across the STIX 2.1 standard and its own formats, with AI-assisted entity extraction and a malware-sandbox integration to turn raw feeds into something an analyst can actually act on.
It sits here as a security platform alongside the XDR and EDR tools already cross-listed in this category, rather than as a direct SIEM competitor to Logpoint or Graylog.
Where SEKOIA.IO bundles its own threat intelligence into a detection platform, EclecticIQ does the opposite: it is intelligence-first, built to sit alongside whatever SIEM or SOC tooling an organisation already runs, with MITRE ATT&CK and DISARM framework mapping and a browser extension, Threat Scout, for analysts researching indicators outside the platform itself. That makes it a fit for teams that already have detection and are missing structured, actionable intelligence to prioritise it.
EclecticIQ is headquartered in Amsterdam under EclecticIQ B.V., with additional offices in the US, UK and Singapore — the contracting entity for a European customer is worth confirming, though the Dutch parent gives it a clearer EU anchor than a vendor with no European incorporation at all. No pricing is published on the site; engagements are quoted individually rather than sold off a price list.
What EclecticIQ does well
- Full threat-intelligence lifecycle in one platform
- AI-assisted entity extraction and malware sandbox integration
- MITRE ATT&CK and DISARM framework mapping
- STIX 2.1 feeds plus a browser extension for analysts
- Dutch-incorporated (EclecticIQ B.V.), Amsterdam HQ
Where EclecticIQ falls short
- Threat intelligence platform, not a SIEM or EDR
- No published pricing — quote only
- Also runs US, UK and Singapore offices
- Most value needs an existing SIEM/SOC to feed
Standout feature. Intelligence-first rather than detection-first: built to sharpen whatever SIEM or SOC a team already runs.
Pros and Cons
Pros
- Full threat-intelligence lifecycle in one platform
- AI-assisted entity extraction and malware sandbox integration
- MITRE ATT&CK and DISARM framework mapping
- STIX 2.1 feeds plus a browser extension for analysts
- Dutch-incorporated (EclecticIQ B.V.), Amsterdam HQ
Cons
- Threat intelligence platform, not a SIEM or EDR
- No published pricing — quote only
- Also runs US, UK and Singapore offices
- Most value needs an existing SIEM/SOC to feed
Alternatives to EclecticIQ
Frequently Asked Questions
What is EclecticIQ?
EclecticIQ is an Amsterdam-based threat intelligence platform, a TIP rather than a SIEM: it manages the full intelligence lifecycle — collection, processing, analysis and dissemination — across the STIX 2.1 standard and its own formats, with AI-assisted entity extraction and a malware-sandbox integration to turn raw feeds into something an analyst can actually act on.
It sits here as a security platform alongside the XDR and EDR tools already cross-listed in this category, rather than as a direct SIEM competitor to Logpoint or Graylog.
Where is EclecticIQ based?
EclecticIQ operates from Amsterdam, Netherlands, which places it under EU (Netherlands).
What does EclecticIQ cost?
Custom quote; no published price list, contact sales. Demo on request.
Who is EclecticIQ best for?
Structured threat intelligence rather than log correlation. Intelligence-first rather than detection-first: built to sharpen whatever SIEM or SOC a team already runs.
What are the drawbacks of EclecticIQ?
Threat intelligence platform, not a SIEM or EDR. No published pricing — quote only. Also runs US, UK and Singapore offices. Most value needs an existing SIEM/SOC to feed.