2 min read

CrowdStrike and Palo Alto Networks Partner on Open Threat Intelligence Sharing Standard

CrowdStrike and Palo Alto Networks have announced a strategic partnership to develop unified threat intelligence sharing standards, marking a rare collaboration between two of the cybersecurity industry’s fiercest competitors. The initiative, called the Open Threat Exchange Protocol (OTEP), aims to create a universal format for sharing indicators of compromise, attack patterns, and threat actor profiles across vendor platforms.

Why Competitors Are Joining Forces

The cybersecurity industry has long struggled with fragmented threat intelligence. Each major vendor maintains proprietary threat databases and uses different formats for cataloging indicators of compromise. This fragmentation means that when one vendor detects a new threat, the intelligence often takes days or weeks to reach customers of other platforms.

“Our adversaries share tools and tactics freely on underground forums,” said George Kurtz, CEO of CrowdStrike. “If they collaborate in real time, our industry must do the same. The days of treating threat intelligence as a competitive moat are over.”

How OTEP Works

OTEP builds on existing standards like STIX and TAXII but introduces several innovations. The protocol supports real-time streaming of threat data, includes machine-readable confidence scores for each indicator, and provides a standardized taxonomy for describing attack techniques that maps directly to the MITRE ATT&CK framework.

Critically, OTEP is designed to preserve vendor confidentiality. Participating companies can share threat indicators without revealing proprietary detection methodologies or customer-specific information.

Industry Support Growing

Since the announcement, more than 40 cybersecurity companies have expressed interest in joining the OTEP consortium. Microsoft, Google Cloud Security, and Fortinet have confirmed their participation, while several government agencies including CISA and the UK National Cyber Security Centre have offered to serve as advisors.

The partnership has also attracted support from the Forum of Incident Response and Security Teams (FIRST), which will help coordinate the development of OTEP governance structures.

Potential Impact

If widely adopted, OTEP could dramatically reduce the time between threat detection and industry-wide protection. Current estimates suggest that it takes an average of 12 days for a newly discovered threat indicator to propagate across major vendor platforms. OTEP aims to reduce that window to under four hours.

Skeptics Remain

Not everyone is convinced the partnership will succeed. Some analysts note that previous attempts at industry-wide threat sharing, including the Cyber Threat Alliance formed in 2014, have produced mixed results. The challenge lies in ensuring that companies contribute meaningful intelligence rather than sharing only low-value data while hoarding their best insights.

“The test will be whether participants share their crown jewels or just their table scraps,” said Katie Nickels, a threat intelligence strategist. “The incentive structures need to reward genuine collaboration.”

The first OTEP specification draft is expected to be published for public comment in September 2026, with a target for initial implementation by early 2027.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.