IBM X-Force Exchange

No phone app

  • Recognised40% of the score20
  • Phone app26% of the score0
  • Documented20% of the score92
  • Free plan14% of the score100
Free plan
Yes
Runs on
api, Web

Summary

IBM X-Force Exchange is a cloud-based threat intelligence platform for researching security threats, gathering intelligence, and collaborating with peers. Reports provide context for IP addresses, URLs, malware hashes, web applications, signatures, and vulnerabilities. Logged-in users can search, comment, create collections, and share research; collections can be public or private and hold reports, comments, IP or URL data, and other content. A QRadar plug-in supports IP and URL lookups from events and lets users submit material from searches, offenses, and rules to collections. API documentation covers IP and URL category feeds, reports, vulnerability feeds, and TAXII feeds, using JSON and STIX/TAXII formats. API use requires a purchased premium subscription, and freemium API keys no longer have access. The free plan provides limited portal access, and guests cannot use all website features. The GUI requires a supported browser and a direct internet connection. IBM describes its API Enterprise license as suitable for security operations centers and managed security service providers.

Who it is for

X-Force Exchange may suit security teams researching threat indicators and sharing findings. IBM describes the API Enterprise license for security operations centers and managed security service providers.

What is good

  • Reports cover IPs, URLs, malware hashes, and vulnerabilities.
  • Collections can be public or private.
  • QRadar plug-in supports IP and URL lookups.
  • API formats include JSON and STIX/TAXII.

What to know first

  • Freemium API keys no longer access the API.
  • API use requires a purchased premium subscription.
  • Guest users cannot use all portal features.
  • GUI requires a supported browser and direct internet connection.

Samsung Mobile US Press review

IBM X-Force Exchange: the full review

X-Force Exchange supports threat research and collaboration through reports, collections, and QRadar integration. The free plan is limited, and API access requires a purchased premium subscription.

IBM X-Force Exchange is a cloud-based threat intelligence platform for security analysts who need to investigate indicators and share findings. It is most compelling for QRadar users; teams seeking automated access to its intelligence need a purchased API subscription.

Overview

Exchange brings threat reports, indicator context and shared research into a browser-based service. Reports cover IP addresses, URLs, malware hashes, web applications, signatures and vulnerabilities, helping analysts connect an indicator to broader threat context. Its value is strongest when that research feeds a QRadar investigation or a paid intelligence workflow; the free portal is a narrower option for manual research.

Logged-in users can search, comment, share and organize research in collections. Collections can combine IP or URL data with reports and comments, and can be public or private. That supports preserving and circulating findings, while guest users cannot access every website feature.

Key features

QRadar investigation

The QRadar plug-in can search Exchange for IP addresses, URLs, CVEs and web applications found in QRadar. Analysts can look up IP and URL information from events and submit material from searches, offenses and rules to collections. This makes Exchange a practical companion for QRadar-centered work; teams using other SIEMs should not expect the same plug-in workflow.

Feeds and API

The API documentation covers IP and URL category feeds, vulnerability feeds, reports and TAXII feeds. Its subscription tiers range from indicator enrichment to curated protection feeds and insights on threat groups, campaigns, industries and malware. JSON and STIX/TAXII support provide formats for integrating intelligence, while the Advanced Threat Protection Feed supplies machine-readable indicators for security tools such as firewalls, intrusion prevention systems and SIEMs.

These capabilities are for paid use: Freemium API keys no longer access the X-Force API, and obtaining API access requires purchasing a premium subscription through IBM. The API accepts HTTPS using TLS 1.2 or newer and rejects older connections. Keys and passwords are tied to a user ID and do not expire; the password is shown only when generated, so it must be retained then.

Pricing

Exchange uses a freemium model. The Freemium plan costs 0.00 USD per free and includes limited access to the portal, with no X-Force API access. It can suit someone who wants to explore threat information manually, but it is not a free route to feed ingestion or API-driven automation.

API access requires a purchased premium subscription, and the API tiers cover differing levels of intelligence capability. IBM also offers a 30-day trial of either dedicated Premium Threat Intelligence feed product. Commercial API or ATP feed customers can open IBM Support tickets; other questions can be emailed to [email protected]. The free plan's access limits and the paid requirement for automation make it a poor fit for teams expecting a full operational feed workflow at no cost.

Platforms

Exchange is a cloud service identified as platform independent. Its GUI works on a workstation or mobile device with a supported browser and direct internet connection. The API is available to compatible third-party applications, so it can serve automated workflows beyond the browser when paired with a commercial license.

Who it's for

Exchange suits analysts who investigate threat indicators, need a shared place for findings, or work in QRadar and want to bring Exchange context into SIEM investigations. IBM identifies its API Enterprise license for security operations centers and managed security service provider use cases. The free portal is more appropriate for limited research than for teams that require ongoing API access; users needing automated feeds must budget for a paid subscription.

Pros and cons

  • QRadar workflow: The plug-in supports lookups from events and lets users send investigation material into collections, linking indicator research with QRadar work.
  • Organized collaboration: Public or private collections can hold indicators, reports and comments, giving teams a way to preserve and share research.
  • Multiple integration formats: JSON and STIX/TAXII support, plus machine-readable ATP indicators, serve teams integrating threat data into security tools.
  • Free tier is constrained: Freemium provides limited portal access but no X-Force API, ruling it out for free automated ingestion.
  • Guest access is restricted: Visitors cannot use all website features, so meaningful collaboration requires logged-in users.

Alternatives

Threat Intelligence Platforms is a useful category starting point if you want to compare a broader range of options. Consider OpenAEV instead if on-premise attack simulation and tabletop exercises are closer to your needs; its Community Edition is free forever and includes community support. ThreatForge offers an open-source, self-hosted Community Edition under AGPL-3.0-or-later, making it an option for teams prioritizing that model.

SOCRadar Extended Threat Intelligence Platform is worth considering for priced dark-web monitoring plans, including an Essential plan at 600.00 USD per month for one domain and one seat. Flashpoint Ignite, Security Vision TIP and Anomali Platform are other paid alternatives. AhnLab V3 Internet Security is a paid Windows product, while Bitsight External Attack Surface Management is a paid API and web offering.

Verdict

Choose IBM X-Force Exchange if your team needs shared indicator research, particularly inside QRadar, or can fund a commercial API workflow. Its combination of threat context, collections and QRadar lookups is the main reason to choose it; the lack of free API access is the clearest reason to look elsewhere if automated intelligence is a requirement.

IBM X-Force Exchange plans and pricing

All plans
Freemium Free Limited access to the X-Force Exchange portal · no X-Force API access ibm.com · 30 Sept 2026

Compared on threat intelligence platforms

Free plan
Yesexchange.xforce.ibmcloud.com
Indicator enrichment
Yesexchange.xforce.ibmcloud.com
STIX/TAXII support
Yesexchange.xforce.ibmcloud.com
Report management
Yesexchange.xforce.ibmcloud.com
Workflow automation
Yesexchange.xforce.ibmcloud.com
Case management
Yesexchange.xforce.ibmcloud.com
Deployment
cloudexchange.xforce.ibmcloud.com

Facts

Purpose
IBM X-Force Exchange is a cloud-based threat intelligence platform for researching security threats, aggregating actionable intelligence and collaborating with peers.ibm.com · 30 Sept 2026
Threat lookup
The QRadar plug-in can search Exchange information for IP addresses, URLs, CVEs and web applications found in QRadar.ibm.com · 30 Sept 2026
Collections
Collections can hold IP or URL data, reports, comments and other research content, and can be public or private.ibm.com · 30 Sept 2026
Collaboration
The platform includes searching, commenting, collections and sharing for logged-in users.xfe-integration.xforce.ibm.com · 30 Sept 2026
API capabilities
The API documentation describes access to IP and URL category feeds and reports, vulnerability feeds, and TAXII feeds.xfe-development.xforce.ibm.com · 30 Sept 2026
API access
Using the API requires purchasing a premium subscription through an IBM sales representative or the X-Force Threat Intelligence page.xfe-development.xforce.ibm.com · 30 Sept 2026
API security
The API accepts HTTPS connections supporting TLS 1.2 or newer and rejects other connections.xfe-development.xforce.ibm.com · 30 Sept 2026
API credentials
API keys and passwords are specific to the user's ID, do not expire, and the password is shown only when generated.xfe-development.xforce.ibm.com · 30 Sept 2026
QRadar integration
The Exchange plug-in lets QRadar users look up IP and URL data from events and submit data from searches, offenses and rules to collections.ibm.com · 30 Sept 2026
Feed integration
The Advanced Threat Protection Feed provides machine-readable indicators for integration with security tools such as firewalls, intrusion prevention systems and SIEMs through open standards.ibm.com · 30 Sept 2026
Limits
Guest users cannot use all features of the X-Force Exchange website.ibm.com · 30 Sept 2026
Support
Customers with a commercial ATP feed or Commercial API license can open IBM Support tickets; other inquiries can be emailed to [email protected].ibm.com · 30 Sept 2026
Availability
IBM identifies X-Force Exchange as platform independent, and its documented GUI requirements include a workstation or mobile device with a supported browser and a direct internet connection.ibm.com · 30 Sept 2026
Threat data
X-Force Exchange reports include context for IP addresses, URLs, malware hashes, web applications, signatures and vulnerabilities.ibm.com · 30 Sept 2026
API formats
The API supports JSON and STIX/TAXII for accessing and integrating threat intelligence.ibm.com · 30 Sept 2026
Trial
IBM Support says users can sign up for a 30-day trial of either dedicated Premium Threat Intelligence feed product.ibm.com · 30 Sept 2026
API limit
IBM says Freemium API keys no longer have access to the X-Force API.ibm.com · 30 Sept 2026
Platform requirements
The Exchange GUI requires a workstation or mobile device with a supported browser and a direct internet connection; the Commercial API requires a compatible third-party application.ibm.com · 30 Sept 2026
Audience
IBM describes the API Enterprise license as suitable for security operations centers and managed security service provider use cases.ibm.com · 30 Sept 2026

Best IBM X-Force Exchange alternatives

See all 20

Where it ranks on Samsung Mobile US Press

Is IBM X-Force Exchange yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources