🚀 TG4G
DirectorySecuritythreatspan.org
🛡 Security 📍 HQ: Unknown
T

threatspan.org

Overall Rating
★★★★☆ 8.0/10
China Access
★★★ China direct-connect friendly
Quick Check
Data source
ai_crawl · Last updated 2026-06-08

⚡ Score breakdown

5-dim weighted · /10
Performance25% 8.0
Value20% 8.0
China access20% 10.0
Reputation20% 6.4
Support15% 7.5

Dimension scores are derived from public data and fields; weighted into the composite. Reference only.

Editorial Highlights

Free, MIT-licensed open source tool that runs locally and aggregates 14 categories of intelligence sources.

In-Depth Review TG4G Review ·2026-06-08 · For reference only

What It Is

ThreatSpan is a local-first SOC investigation workbench built for SOC analysts, incident responders, and home-lab defenders. After a user pastes an IP address, domain, URL, or file hash, it queries 14 reputation, threat intelligence, and infrastructure sources in parallel and presents the evidence in a keyboard-first interface. It is not positioned as endpoint protection or gateway blocking, but rather as a tool for post-alert IOC triage and forensic assistance.

Core Capabilities and Deployment

The product emphasizes “no account, no telemetry, no cloud backend.” API keys are encrypted and stored locally under ~/.threatspan/, and data does not leave the machine except when calling the data providers configured by the user. It is launched via npx threatspan@latest, runs locally at 127.0.0.1:3000, and supports Node 14+ as well as Mac, Linux, and Windows. Data sources include VirusTotal, AbuseIPDB, URLhaus, OTX, ThreatFox, MalwareBazaar, Shodan, GreyNoise, urlscan.io, DNS, WHOIS/RDAP, and others. Results are also correlated with CISA KEV, NIST NVD, and MITRE ATT&CK technique tags.

Pricing and Compliance

The main content does not disclose any pricing for ThreatSpan itself, nor does it mention a commercial edition, SLA, or payment methods; the page emphasizes that no account is required. Note that some sources, such as VirusTotal, Shodan, and GreyNoise, require users to bring their own API keys, so actual usage costs and quotas depend on third parties. No information is provided about compliance certifications such as SOC 2, ISO 27001, or GDPR.

Pros and Cons

Its strengths are privacy-friendly design, lightweight deployment, cross-platform support, and aggregation of evidence from multiple sources. It is well suited to fast triage and reduces the need for analysts to switch back and forth between different intelligence websites. The drawbacks are a lack of information about enterprise-grade capabilities: permissions management, auditing, team collaboration, centralized alerting, SIEM/SOAR integrations, and official support are not clearly specified. It also depends on a local Node environment and third-party API keys, which creates some friction for non-technical users.

Who It’s For and Access from China

ThreatSpan is suitable for analysts in small and midsize teams, incident responders, threat hunters, and security enthusiasts. Common use cases include initial IOC screening, C2 infrastructure investigation, and analysis of phishing or ransomware-related leads. The source text does not state how well it works from China, and because its effectiveness depends on multiple overseas intelligence sources, real-world usability may be affected by network connectivity and the availability of third-party APIs. Alternative or complementary tools include VirusTotal, OTX, GreyNoise, Shodan, urlscan.io, MalwareBazaar, and others.

⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on threatspan.org official site.

About this entry

threatspan.org is an Unknown Security provider. TG4G tracks its product information, an overall rating of 8.0/10, and a China-accessibility score of China direct-connect friendly. Click "Visit Official Site" to reach threatspan.org directly.

Get Started

Price not disclosed
Visit threatspan.org official site →
External link · prices subject to vendor site

Frequently Asked Questions

What is threatspan.org?
threatspan.org is a Unknown-based Security provider. Free, MIT-licensed open source tool that runs locally and aggregates 14 categories of intelligence sources.
Is threatspan.org good? Is it worth it?
threatspan.org scores 8.0/10 on TG4G — a strong rating, based in 未知. See the in-depth review below for pros, cons and China accessibility.
Is threatspan.org usable in China?
threatspan.org offers good direct-connect performance in mainland China and works in most regions without a proxy. The provider is headquartered in Unknown and primarily serves overseas markets.
How do I sign up for threatspan.org?
Visit the threatspan.org official site to complete sign-up. Registration typically requires an email (Gmail/Outlook recommended) and a payment method. Most overseas services accept credit card / PayPal / crypto. See the "Visit Official Site" button on this page for the direct link.

Browse Other Categories

View the full directory →