ThreatRecall is the evidence-backed memory and recall layer for CTI. It doesn't replace your threat-intel platform, your agent framework, or your SIEM — it makes what you already know reachable, with provenance. Three axes, one page.
Complement, not replace. OpenCTI and MISP are systems of record for structured intel and sharing. ThreatRecall is the natural-language recall + session memory layer that sits on top and reads/writes STIX both ways.
| Capability | ThreatRecall | OpenCTI / MISP |
|---|---|---|
| Primary job | Ask "what do we know about X?" and get an evidence-backed answer | Store, correlate, and share structured indicators & reports |
| Natural-language recall over history | ✓ per-query synthesis + confidence | ✗ manual search / GraphQL |
| Evidence + confidence on every answer | ✓ cited source records | ~ data present, not answer-linked |
| STIX 2.1 interop | ✓ ingest + export (round-trip) | ✓ native |
| How they connect | STIX 2.1 ingest + bidirectional REST; export recall results back as a STIX bundle. Integration docs → | |
Same axis, built for CTI. Mem0 and Letta are strong general agent memory. None enforce TLP, require evidence, or ship a CTI data model — that was never their scope. Deeper dive: ThreatRecall vs Mem0 →
| Capability | ThreatRecall | Mem0 / Letta |
|---|---|---|
| TLP / CUI enforcementAMBER/RED never reaches the LLM | ✓ | ✗ |
| Evidence + provenance required on recall | ✓ | ✗ vector recall, no provenance |
| Signed audit log export (CSV + JSONL) | ✓ | ✗ |
| CTI data model (actor / TTP / CVE / IOC) | ✓ | ✗ custom adapters needed |
| Memory correction — reject / merge / correct | ✓ | ~ self-editing, no correction UI |
Context on top, not a log pipeline. Your SIEM ingests logs, correlates, and alerts. ThreatRecall answers "have we seen this before, and what did we conclude?" against the IOCs your dashboards surface.
| Capability | ThreatRecall | Splunk / Sentinel |
|---|---|---|
| Primary job | CTI memory + recall with evidence | Log ingest, correlation, alert triage, dashboards |
| Raw log ingest & detection rules | ✗ not a SIEM | ✓ core |
| IOC context on an alert"This IP appeared in APT29 intel last month — here's the evidence" | ✓ | ✗ enrichment add-on |
| Cross-investigation memory that persists | ✓ | ~ searches, not synthesized memory |
| How they connect | Splunk HEC ingest (beta) + webhook on notable events; Sentinel Logic Apps trigger on incident creation with write-back. Integration docs → | |
If you need a threat-intel platform, buy OpenCTI/MISP. If you need general agent memory, use Mem0/Letta. If you need a SIEM, keep Splunk/Sentinel. ThreatRecall is the layer that makes all three remember — evidence-backed recall, TLP-enforced, STIX-native, audit-ready.
Full interactive comparison: threatrecall.ai/compare · Sources verified May 2026; ThreatRecall reflects current production capabilities · support@threatrecall.ai