Overview

Product video
SOCRadar XTI is an AI-powered Extended Threat Intelligence platform that gives security teams a unified view of external risk. It combines three capabilities that are usually sold separately: Cyber Threat Intelligence (CTI), Digital Risk Protection Services (DRPS), and External Attack Surface Management (EASM).
The platform continuously collects and analyzes data across the surface, deep, and dark web (forums, marketplaces, paste sites, Telegram channels, and leaked databases), then enriches and prioritizes it with cross-source confidence scoring so analysts focus on what matters. Core modules include Dark & Deep Web Monitoring, Brand Protection, Attack Surface Management, Vulnerability Intelligence, Supply Chain Intelligence, and VIP/Fraud Protection, alongside takedown services and IOC enrichment APIs.
SOCRadar integrates with leading SIEM and SOAR platforms, enabling automated enrichment and response workflows. The result is reduced alert noise, faster investigations, and proactive defense against external threats without adding operational overhead.
Highlights
- Extended Threat Intelligence in one platform: Cyber Threat Intelligence, Digital Risk Protection, and External Attack Surface Management, with AI-driven prioritization and cross-source confidence scoring.
- Surface, deep, and dark web monitoring for leaked credentials, brand abuse, fraud, and supply-chain risk, backed by takedown services and threat-actor context.
- Custom scope, module bundles, volume and multi-year enterprise pricing are available through AWS Marketplace Private Offers. Contact sales@socradar.io to request a tailored private offer for your organization.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
SOCRadar XTI Platform (Annual) | Annual access to the SOCRadar Extended Threat Intelligence (XTI) platform. The scope is flexible and defined by the agreement (or private offer) with the customer for the contract term: one or more modules such as Cyber Threat Intelligence, Dark & Deep Web Monitoring, Brand Protection, External Attack Surface Management, or API only access (e.g., IOC enrichment and reputation APIs). Buyers license exactly what they need, from a single module or API integration up to the full platform. | $100,000.00 |
Advanced Brand Protection - Business | SOCRadar Brand Protection monitors social media, third-party apps, and the dark web to protect digital assets and brand reputation. Detects phishing domains, impersonation, and exposed credentials with real-time alerts and takedown management. Business tier: 50 IPs, 10 VIP accounts, 3 domains, 10 brand keywords, 5 mobile apps, 5 social accounts, 1 user. | $28,750.00 |
Advanced Dark Web Monitoring - Business | Advanced Dark Web Monitoring continuously scans dark web marketplaces and forums for leaked credentials and sensitive data, with early warnings and customizable alerts. Business tier: 1 domain, 1 seat; blackmarket, employee data breach, stealer/botnet tracking, hacker discussions, Telegram & Discord, ransomware activity, and VIP monitoring. | $9,100.00 |
Cyber Threat Intelligence - Essential | SOCRadar Cyber Threat Intelligence (CTI) gathers, analyzes, and acts on data from open sources, social media, and the dark web - threat hunting, threat-actor tracking, real-time alerts, and SIEM/SOAR integration. Essential tier: 1 seat, 50+ feed sources, 100 threat-hunting rules, 6000+ combolists, 1000 threat-search credits/yr, 100 malware-analysis credits/yr. | $14,750.00 |
External Attack Surface Management - Business Edition | SOCRadar External Attack Surface Management (EASM) discovers and monitors internet-facing assets (websites, cloud, APIs) with automated discovery, risk scoring, and real-time alerts to reduce exposure. Business Edition: 100 assets, 1 user. | $4,000.00 |
Vendor refund policy
All sales of the SOCRadar XTI Platform are final and non-refundable, except where required by applicable law. For billing questions, contact support@socradar.io .
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
SOCRadar provides 24/7 support to all customers. Email: support@socradar.io . Support portal: https://help.socradar.io . Subscriptions include onboarding assistance, a dedicated customer success contact. Standard response targets: critical issues within hours, standard requests within one business day.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Customer reviews
Elegant Interface and Seamless Navigation That Saves Time
Proactive Threat Detection with Seamless Setup
Catches Threats Before They Become Incidents
Great Scope of Information, Improvement in Takedown
Proactive threat intelligence has reduced incident time and improves visibility into external risks
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is for cyber threat intelligence activities related to our work, as we use it to search for potential threats to our digital infrastructure.
A specific example of how I use SOCRadar Extended Threat Intelligence for searching potential threats to my digital infrastructure is a recent incident involving a third-party data breach, where one of our staff's email addresses was involved. Through SOCRadar Extended Threat Intelligence, we were able to investigate and discovered that a staff email had been involved in a data breach. Due to that information, the platform proved to be very effective as we followed our incident response procedures, notified the staff to change her password, and investigated further.
Another way I have used SOCRadar Extended Threat Intelligence is that the platform automatically scans for potential digital targets based on certain preset values we configured in the system, giving us insight into the external threat exposure of our infrastructure. This helps us understand what we are putting out there and how the world sees that as a threat to our systems and how we can protect it.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers are the threat intelligence feature, which I find very effective, as it allows me to scan for data breach exposures in the dark web, and the Attack Surface Management feature, which helps us know what a potential attack surface is. I also use the Vulnerability Intelligence feature.
The dark web intelligence feature has helped me in threat hunting, allowing me to research my domain and digital assets, such as IP addresses and cloud buckets involved in potential leaks or data breaches. The Attack Surface Management feature gives us a comprehensive view of our digital footprint and vulnerability monitoring systems.
SOCRadar Extended Threat Intelligence has impacted my organization positively by enabling us to monitor and see exactly what our external threat exposures are, a capability we lacked before using SOCRadar Extended Threat Intelligence.
What needs improvement?
In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for three years.
What was our ROI?
Specific outcomes I have noted include a reduction in the time we spend on incidents because we now have the capability to respond more effectively.
What other advice do I have?
I would rate SOCRadar Extended Threat Intelligence an 8.5 out of 10. I advise others looking into using SOCRadar Extended Threat Intelligence to try the product, as it is very effective and a great product that I believe would be very helpful.