Listing Thumbnail

    Cybersixgill Threat Intelligence - CTI

     Info
    Cybersixgill offers real-time threat intelligence solutions to help security teams detect and respond to imminent threats from the clear, deep, and dark web.
    4.3

    Overview

    Cybersixgill continuously collects and exposes the earliest possible indications of risk, moments after they surface on the clear, deep and dark web.

    Our proprietary algorithms extract data from a wide range of sources, including content from limited-access deep and dark web forums, underground markets, invite-only messaging groups, code repositories, paste sites and clear web platforms, as well as an unparalleled archive of indexed, searchable historical data from as early as the 1990's.

    This data is processed, correlated and enriched with machine learning techniques to create profiles and patterns of malicious threat actors and their peer networks, delivering critical insight into the nature, source and context of each threat.

    Our extensive body of threat intelligence data can be consumed through various solution offerings and integrations, each addressing critical customer pain points and use cases.

    These solutions are scalable, searchable and seamlessly integrated into existing security stacks, quickly arming enterprises, government and MSSP's alike with accurate, relevant and actionable insights to proactively block threats before they materialize into attacks.

    Highlights

    • Cybersixgill automates data collection from the widest range of sources, delivering operational threat intelligence quickly.
    • The platform offers secure access to threat intelligence through SaaS, APIs, and seamless integration with existing security operations.
    • With AI-driven analysis, Cybersixgill reduces response time, offering real-time alerts and insights from the dark web.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Cybersixgill Threat Intelligence - CTI

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (1)

     Info
    Dimension
    Description
    Cost/12 months
    Cyber Threat Intelligence Cybersixgill
    Cyber Threat Intelligence Base Package
    $155,000.00

    Vendor refund policy

    All fees are non-cancellable and non-refundable except as required by law.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Resources

    Vendor resources

    Support

    Vendor support

    For support contact info@cybersixgill.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    50
    In Device Security
    Top
    100
    In Log Analysis

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    4 reviews
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-Source Data Collection
    Automated collection from clear web, deep web, dark web forums, underground markets, invite-only messaging groups, code repositories, paste sites, and historical archives dating back to the 1990s.
    Machine Learning-Based Threat Analysis
    Proprietary algorithms and machine learning techniques process, correlate and enrich collected data to create profiles and patterns of malicious threat actors and peer networks.
    Real-Time Alert Generation
    AI-driven analysis delivers real-time alerts and insights with reduced response time for threat detection and identification.
    API and SaaS Integration
    Threat intelligence accessible through SaaS platform, APIs, and seamless integration with existing security operations and stacks.
    Searchable Historical Data Archive
    Indexed and searchable historical threat intelligence database spanning from the 1990s to present, enabling contextual threat analysis and pattern recognition.
    Multi-Source Threat Monitoring
    Monitors over 500 sources across surface, deep, and dark web including forums, data leak sites, and encrypted chat platforms to detect security risks and initial access vectors.
    Machine Learning-Based Detection
    Utilizes machine learning engine to detect and mitigate leaked credentials, secrets, and data breaches with prioritization for VIP and executive accounts.
    Modular Architecture
    Comprises three main modules (deep and dark web monitoring, data leak monitoring, and brand threat monitoring) with multiple sub-modules that can be purchased individually or in combinations based on specific use cases.
    SIEM and SOAR Integration
    Integrates with major SIEM and SOAR solution providers, Slack, and ticketing tools for streamlined alert management and incident response workflows.
    Customizable Alert Configuration
    Provides granular tagging and customizable alert rules to deliver specific actionable intelligence with instant reporting capabilities.
    Multi-Source Threat Intelligence Integration
    Integrates threat intelligence from multiple sources to provide comprehensive coverage and context for threat detection.
    Generative AI-Powered Analysis
    Utilizes fine-tuned generative AI models to deliver actionable security insights backed by global threat intelligence repositories.
    Threat Intelligence API Services
    Provides API-based threat intelligence services for programmatic access to threat data and security intelligence.
    High-Fidelity Threat Detection
    Delivers high-fidelity threat intelligence with rich contextual information to improve detection accuracy and reduce false positives.
    Alert Fatigue Reduction
    Streamlines threat detection workflows through intelligent filtering and prioritization to minimize alert volume and operational noise.

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.3
    2 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    50%
    50%
    0%
    0%
    0%
    1 AWS reviews
    |
    1 external reviews
    External reviews are from PeerSpot .
    Drmaceo Watts

    Proactive dark web intelligence has reduced breach impact and protects organizations quietly

    Reviewed on Aug 24, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Cybersixgill is dealing with cyber threat intelligence. When an organization's information was breached or found on the dark web, I was able to immediately notify them through the data lake that I had access to and I could thwart the threat by examining the information on the dark web to get a proof of concept to determine if they actually did steal or breach an organization's private information. In many cases, I was able to verify that and purchase it back using Bitcoin, so the organization could prevent having to go public with the breach.

    I typically identify the breaches on the dark web through automated alerts, manual searching, or another method. I definitely perform manual searches as well. Manual searches are something that I can always tweak to try to find the best approach to eliminate false negatives. I was able to set it up with automation, which is the best option. Automation automatically gives visibility, but manual searches had to be done as well to tweak the system until I could finally eliminate those false negatives.

    I used Cybersixgill ultimately to find stolen or compromised information that was on the dark web, and I was able to verify it and buy it back.

    Cybersixgill helps with compliance and regulatory compliance because I have all this information and I can thwart the attack from taking place before it happens. I get the chatter that is on the dark web, and with the right tweaks and the right onboarding, I am able to set up exactly what I am trying to identify before it actually happens. When there is talk or chatter on the dark web about an organization, I can get ahead of it.

    What is most valuable?

    The best feature Cybersixgill offers is cyber threat intelligence.

    What specifically stands out to me about the cyber threat intelligence feature is the speed and the depth from the data lake. Cybersixgill, which is now called Bitsight, actually had the largest data lake in the industry in my opinion of information on these bad actors. I was able to have them classified, I was able to give them rankings, and I was able to immediately know who I was dealing with. The research and the preparation was already done in reference, so it was not going back to the drawing board. I already had identities on these bad actors.

    Cybersixgill has positively impacted many organizations by being able to quickly identify what attack is taking place. Not just on the dark web, but maybe it was an impersonation attack from someone using LinkedIn, trying to pretend that they were the CEO for a major company, such as Coca-Cola, Microsoft, or IBM. To be able to stop that quickly in its tracks is a huge thing, and it is a very big plus for anyone trying to deal with anything that is bad when it comes to these bad actors and what they do today.

    I can share that it definitely caused organizations to have fewer incidents when it came to having to go public with these breaches. At this point in the game, every organization is getting breached. It is just a matter of how fast I am able to establish that breach and to find the information using the dark web, which is the Tor application that I use to get on from Cybersixgill. Once I can quickly identify the information being sold or trying to be sold on the dark web, I get proof of concept and I can then identify which bad actor group is actually using this information and selling this information. I can then quickly purchase it back to prevent them from having to go public, which lowers their reputation.

    What needs improvement?

    Cybersixgill has one of the largest data lakes around. I think the way they can be improved is to be able to initially during the onboarding, make sure that the false positives are correctly addressed to really do the tweaks that need to be done to filter through exactly what the organization is trying to accomplish and give them the outcomes they are looking for without all the extra noise or chatter.

    I just think during the onboarding, that is the most crucial part to make sure that the organizations who purchase Cybersixgill ensure that they actually have the right person or persons to go through the onboarding to make sure that the data lake feeds can be properly set up and organized so it can filter through the noise and the chatter.

    For how long have I used the solution?

    I have been working in my current field for 18 years, since 2008.

    What do I think about the stability of the solution?

    Cybersixgill is stable.

    What do I think about the scalability of the solution?

    My experience with the scalability of Cybersixgill is that it is a piece of cake. As small or as large as I want to be, Cybersixgill is able to accommodate any organization. Cybersixgill's scalability is very scalable.

    How are customer service and support?

    The customer support is top-notch and excellent.

    Which solution did I use previously and why did I switch?

    I previously used a lot of solutions that are open-sourced on the web and anyone can use them, but they are not as specific or up to speed or updated as Cybersixgill, and that is why I and everybody else uses Cybersixgill.

    How was the initial setup?

    Cybersixgill integrates easily with my existing security tools or platforms using web services API, so that is a piece of cake.

    The reporting and dashboard functionality in Cybersixgill is very intuitive.

    What was our ROI?

    I have seen a return on investment, absolutely. The return of investment was quick and easily seen within the first 90 days, and that is when an actual quarterly meeting, a QBR, would take place to be able to show that return on investment. Typically, it paid for itself in a small amount of time.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the pricing was very well priced. It was not the cheapest, but it was not the most expensive, and based on the needs of the customer, there was always a negotiation that could be done to get a slightly lower price.

    Which other solutions did I evaluate?

    Before choosing Cybersixgill, I evaluated other options, including free ones that were on the web and open-sourced.

    What other advice do I have?

    The advice I would give to others looking into using Cybersixgill is to definitely take a good look at it and make sure if they decide to purchase it, it is a good investment, but more importantly, to make sure the onboarding is done correctly to be able to tweak out all the false positive information because it is a lot of information that will be thrown at you, kind of drinking from a fire hydrant if you do not tweak it and onboard successfully. My overall review rating for Cybersixgill is 9 out of 10.

    Aditya Vikram Raj

    Centralized threat insights have enabled comprehensive dark web exposure reporting

    Reviewed on Apr 04, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our main use case for Cybersixgill during our proof of concept was to find a tool as a single pane of glass that would provide us actionable threat intelligence along with adversary reporting. We were also looking for a tool that could perform multiple functions, including dark web scanning and dark web intelligence specifically.

    When I need to prepare a report for one of my customers, I can search for that particular organization's exposure over the darknet to find what has been there, what emails have been leaked, and other relevant information by checking different dark web forums, market forums, leak sites, and any ransomware groups claiming or naming that particular organization on their leak sites.

    What is most valuable?

    The best feature that Cybersixgill offers with respect to dark web intelligence is that they provide very good screenshots of where the particular data has been taken, which allows for better visualization and understanding of the scenario, with the source being indicated through onion links that can be reverse-engineered for further investigation.

    We were really impressed by some of the features of the platform, and we were planning to integrate it into our day-to-day work, but I'm not certain whether that happened because I was serving a notice period at that time.

    What needs improvement?

    I used Cybersixgill for only three months as a proof of concept, so I do not feel I am in a position to provide meaningful suggestions for improvements.

    For how long have I used the solution?

    I used Cybersixgill for a very limited period of time, which was approximately two to three months, and this was during a product review session for our team's proof of concept.

    What other advice do I have?

    If you are looking for threat intelligence that can cater to various needs from IOC to threat advisories and along with dark web intelligence, then you should try Cybersixgill. I gave this product a rating of 8.

    View all reviews