Listing Thumbnail

    Anvilogic Core Detect

     Info
    Sold by: Anvilogic 
    Detection engineering teams love using Anvilogic's Multi-SIEM Detection Platform to quickly close detection gaps and reduce costs.

    Overview

    Play video

    Anvilogic breaks the SIEM lock-in that drives detection gaps and high costs for enterprise SOCs. It enables detection engineers and threat hunters to keep using their existing SIEM while seamlessly adopting a scalable and cost-effective data lake for high-volume data sources and advanced analytics use cases. By eliminating the need for rip-and-replace, Anvilogic allows security leaders to confidently join the rest of the enterprise on the modern data stack without disrupting existing processes. Security operations teams at banks, airlines, and large tech companies use Anvilogic's modular detection engine, thousands of curated threat scenarios, and AI security copilot to improve detection coverage and save millions of dollars. Private offer only. Offered plans are by an organization's employee count, and offer can also include Copilot, Insights and/or Unified Detect add-ons.

    Highlights

    • Leverage thousands of ready-to-deploy detections across multiple query languages (SPL, SQL, KQL) with new detections released weekly by the Anvilogic Forge Team.
    • AI-Powered recommendations for automated tuning, maintenance and health insights
    • Customize and scope your most relevant MITRE ATT&CK techniques

    Details

    Delivery method

    Deployed on AWS

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Anvilogic Core Detect

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (7)

     Info
    Dimension
    Description
    Cost/12 months
    Anvilogic Core Detect 2k Employees
    Anvilogic Core Detect: Up to 3 seats
    $80,000.00
    Anvilogic Core Detect 5k Employees
    Anvilogic Core Detect: Up to 10 seats
    $185,000.00
    Anvilogic Core Detect 20k Employees
    Anvilogic Core Detect: Up to 20 seats
    $310,000.00
    Anvilogic Core Detect 100k Employees
    Anvilogic Core Detect: Up to 30 seats
    $575,000.00
    Anvilogic Core Detect Additional Seat (qty 1)
    Anvilogic Core Detect: Additional Seat
    $3,000.00
    Anvilogic Core Detect Additional Employees (qty 100)
    Anvilogic Core Detect: Additional Employees
    $1.00
    Anvilogic Copilot Additional Questions (qty 1)
    Additional questions, only applicable to Copilot purchase.
    $1.00

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    25
    In Anomaly Detection-Structured
    Top
    10
    In Generative AI, Security Observability

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    1 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Multi-SIEM Detection Platform
    Supports detection across multiple query languages including SPL, SQL, and KQL with weekly updated threat scenarios
    Threat Detection Engine
    Provides thousands of curated threat scenarios mapped to MITRE ATT&CK techniques for comprehensive security coverage
    AI-Powered Analytics
    Offers AI-powered recommendations for automated detection tuning, maintenance, and security insights
    Data Lake Integration
    Enables scalable data storage and advanced analytics for high-volume security data sources without disrupting existing infrastructure
    Detection Customization
    Allows security teams to customize and scope detection techniques specific to their organizational threat landscape
    Threat Intelligence Mapping
    Automated mapping of detections to MITRE ATT&CK framework for comprehensive threat coverage tracking
    Detection Rule Optimization
    Continuous identification and remediation of broken, noisy, and missing detection rules across security tools
    Environment-Specific Customization
    Automatic generation of deployment-ready detection rules customized to specific organizational log sources and configurations
    Threat Intelligence Integration
    Native integration with commercial and open-source threat intelligence sources for proactive detection rule generation
    Multi-Platform Security Tool Compatibility
    Native integration capabilities with multiple SIEM, EDR, and XDR platforms using native API connections
    Artificial Intelligence Security
    Advanced AI-powered security platform with autonomous threat detection and response capabilities
    Cloud Native Application Protection
    Comprehensive CNAPP solution with agentless and agent-based protection, including an Offensive Security Engine
    Extended Detection and Response
    Cross-platform XDR capabilities providing unified threat detection and response across multiple security domains
    Endpoint Security
    Integrated Endpoint Prevention, Detection, Response and Remediation (EPP, EDR) with comprehensive protection mechanisms
    Identity Threat Management
    Advanced Identity Threat Detection and Response (ITDR) with real-time monitoring and protection capabilities

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    No security profile
    -
    -
    -
    -
    -

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    3 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Ajish John

    Comprehensive coverage, no vendor lock-in, and best customer relationship

    Reviewed on Feb 28, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We use Anvilogic  as an SOC detection engineering platform. In addition to that, we use it for hunting and investigation purposes.

    How has it helped my organization?

    We are a fairly small team with three people in total in the SOC. Their prebuilt configurations and all the detections and scenarios are the reason why we have good coverage today. We use them as a template to start off with. Of course, it needs a bit of customization for the organization it is being deployed for, but it works in our case. We use that, build it, and then fine-tune it for our scenario. We are then good to deploy it. Usually, what used to take us about a week's worth of detection development can be done in about an hour and a half or two at best by using these templates.

    Anvilogic provides security analytics across multiple data platforms. It can integrate with different data platforms and provide the same kind of analytics.

    We have been able to reduce the cost of having some of these analytics and capabilities deployed across different platforms because we route most of our alerts into Anvilogic. The analytics work on those, whether they are from endpoints, SaaS applications, Identity, or SIEM. We have been able to save costs by not having to deploy these across different platforms. There is also efficiency in terms of getting some of these done quickly and faster rather than jumping between different things.

    Anvilogic enables us to break free from vendor lock-in. That was one of the key reasons why we chose Anvilogic. We have changed SIEM once since we moved to Anvilogic. In between, when we were looking at some other integrations, Anvilogic was ready to integrate easily with them. Vendor lock-in is a much lesser concern now.

    Anvilogic's AI assistant has helped improve our detection logic. Prior to Anvilogic, somebody would do the investigation, come up with the results, go ahead with a review process, and implement the findings. Since we have had Anvilogic, it automatically does the assessment and gives us a daily report. The analyst just has to do the implementation after the review, so the investigation process from my analyst is no longer required. We feel that the outcome from Anvilogic is also reliable. We do not have to go back and get into the weeds to see specifically whether it is the right analysis.

    It simplifies detection engineering and threat hunting across multiple search languages, although we do not fully leverage all the benefits. Most of our platforms are pulled in from the SIEM, and some of them are from the likes of CrowdStrike and other places. We leverage a standard taxonomy. If this were to be between two different SIEMs, the search capability would be very helpful. However, the AI capability for writing out a quick query by using things like regex or regular expressions and building out regular expressions helps. When an analyst is investigating something or building something, they quickly want to understand what a certain component means, so having that within the same pane helps. So, we use it in some capability, but those capabilities are very helpful so far.

    Anvilogic has significantly reduced our end-to-end detection engineering time. Earlier, it used to take about a week and a half for someone to go in and check. With their templates and prebuilt scenarios and cases, it now takes just about a day or two where we have to look at it and then customize it for us.

    Anvilogic has helped our organization reduce false positives. The tuning insights feature of Anvilogic comes up with proactive ways to reduce false positives. It gives the analyst a view of what is causing the false positives. Is it genuine or not? Is it malicious or not? They can then action items on those. They also maintain an ongoing allow list and deny list, which helps to suppress false positives temporarily, or in the longer run, makes the whole process both accountable with audit logs and quicker.

    We were able to realize its benefits immediately. We did a proof of concept in 2021, and our coverage at that point was in the lower twenties. We got to about the upper eighties in two quarters, and it was very steep, quick growth.

    What is most valuable?

    Before Anvilogic, we had no visibility into our detection coverage. The ability to break it down by industry verticals, such as attackers and adversaries, is valuable.

    Detection insights help us easily identify the most noisy ones, the effective ones, and what needs to be fixed to move the noisy ones to effective ones.

    The hunting capabilities are very good. The AI components and hunting packages give us quick insights into what needs to be looked at.

    The partnership has been very good. Their professional services and customer relationship have been very good. Our features and bugs have been fixed on time without a lot of follow-up, and their support has been excellent.

    Finally, there is a feature within Anvilogic  that provides the threat landscape or our effectiveness towards the threat landscape on an ongoing basis. That is another feature that we liked.

    What needs improvement?

    The hunting insight needs integrable capability with different platforms to gather all of that insight and show it on a single canvas on Anvilogic. That is the only feature that could improve the way we do operations.

    The pricing is slightly edging towards being a bit much for smaller organizations.

    For how long have I used the solution?

    We have used the solution for close to three years.

    What do I think about the stability of the solution?

    For the most part, Anvilogic has been performing well, but because they use a Splunk backend, there is sometimes a bit of slowness and Splunk-related issues. It is generally stable, however.

    What do I think about the scalability of the solution?

    Anvilogic has worked well for us. We started with about 55 detections and scaled up to about 980 odd detections so far. It has scaled very well for us. We have been able to get to a good scale. We do not have a multi-SIEM environment, so I do not know how it is for customers with that kind of environment.

    How are customer service and support?

    One of the best things about Anvilogic is the partnership, their knowledge, the depth of technical understanding, and the speed at which they respond. I would rate them the topmost, a ten out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We used SOC Prime long ago, but it was in a limited capability. We were just looking at certain detections and logic to use from there. Anvilogic definitely is far better for us.

    How was the initial setup?

    The initial setup was quite easy for us. There was a bit of a learning curve, which involved just understanding how the platform worked, taking about a month, but integrating with our existing platforms was a piece of cake. They have APIs for most things and standard off-the-shelf solutions such as SIEMs, endpoints, firewalls, and identity providers. It was very easy to integrate. The technical integration was very easy. It took about a month of learning from my team to get comfortable with the product and how to use it. It is one of the easiest security tools to learn.

    The platform does not require any maintenance on our end, but once we start building out the detections, it requires some maintenance on our side to see that everything is running properly. That is more like an operational aspect.

    What was our ROI?

    Anvilogic has saved us about 25% percent of what a detection engineering platform would be. It is difficult to put quantitative aspects like better operations and structure quality, but I would say efficiency increased by about 50%.

    Anvilogic has not helped reduce our overall SOC or IR operations costs because we use the time we saved to do more. If we were not doing more and did not have Anvilogic, we would need one dedicated person to do this detection engineering. That cost has significantly been reduced.

    What's my experience with pricing, setup cost, and licensing?

    We were an early adopter, so the pricing was definitely good. Because they do not completely replace a SIEM, their pricing is slowly edging towards being a little too much for a smaller organization like ours. It is almost on the border. That is a bit of a challenge on our side, but the value still speaks for it. If the price increases more than where it is now, it would be a tough place for us.

    What other advice do I have?

    Overall, I would rate Anvilogic a nine out of ten, considering its capabilities, features, interactions, and pricing.

    reviewer2200662

    The solution provides security analytics across multiple data platforms

    Reviewed on Jul 29, 2024
    Review provided by PeerSpot

    What is our primary use case?

    Our use cases for Anvilogic primarily revolve around detection engineering. We ingest the logs to figure out our cybersecurity score and improve detection.

    How has it helped my organization?

    Anvilogic provides security analytics across multiple data platforms. We integrate it with Splunk, but it also integrates with Snowflake and other data platforms. Overall, it's been good since many people aim to move away from Splunk to save on overall costs. The fact that it integrates with various data lakes, specifically Snowflake, the most popular, makes sense.

    Using Anvilogic decreases your detection engineering time while helping you build out additional detections and increasing your assurance and protection. It has decreased the engineering time by at least 20 percent. 

    It's been decent in terms of false positives. It doesn't necessarily reduce them, but the new detections have been pretty well-tuned so they aren't producing additional false positives. Anvilogic has increased security coverage by building out some detections, specifically in areas like Active Directory and IAM-type rules. While it hasn't reduced the overall cost, it may have helped the optimization side. 

    What is most valuable?

    We integrate Anvilogic directly with Splunk rather than using the Amplitude platform separately.  That has been helpful because we don't need to bring logs to a third-party source.

    Anvilogic's AI assistant is pretty good. It helps us build out detections within your environment. It has improved our detection logic by a small amount and slightly reduced the time involved in detection writing. Generally, the detection builder is decent.

    The drag-and-drop detection engine portal has been helpful because you don't need any programming experience. One area where the generative AI aspect has been helpful is when we are figuring out the specific threats about something that's triggered or similar campaigns. You can write in the latest from this type of detection that I'm looking at and get information back. 

    What needs improvement?

    We need more around case management. I know that's something on the road map. We would like a way to create a ticket that we can export into a third-party platform like Jira. Anvilogic's prebuilt rules and threat scenarios didn't work the best for us because many of the rules were geared toward a Windows environment, whereas we're more of a Mac environment, so many of them didn't necessarily fit with what we have. I know a few other people who use them, and they've worked out well there.

    For how long have I used the solution?

    I've been a full-time customer of Anvilogic for about two years now, and we did a proof of concept eight months or so before we became a customer.

    What do I think about the stability of the solution?

    We haven't had any issues with stability.

    What do I think about the scalability of the solution?

    Anvilogic is as scalable as the environments you've integrated it with, whether it's Snowflake or Splunk.

    How are customer service and support?

    We have a biweekly standing call with the Anvilogic team to talk through detections and updates, but I can't think of a case where we've had to contact them outside of that call.

    How was the initial setup?

    The initial deployment was easy because we had it set up for our proof of concept, so it just took a little tuning, and we had it set up within a week. We had one person on our side working with somebody on their side. It's a cloud-based solution, but they push out updates on it. We haven't had any issues where it's broken on our systems, where we've had to lean in on the maintenance side.

    What was our ROI?

    We roughly broke even. If we had invested more or tuned our environment a little better, we might have come out on top.

    What's my experience with pricing, setup cost, and licensing?

    Anvilogic's pricing has been highly competitive. 

    Which other solutions did I evaluate?

    We did an extensive proof of concept for Anvilogic, Panther, Devo, Google Chronicle, Splunk, and a few different SIEM/detection engines. We did a breakdown based on our criteria and scoring on various features. Anvilogic outperformed the other tools that we tested.

    The price was right for the organization. They also offered a multiyear deal that kept the price down looking forward. We compared it to something like the Chronicle, which required us to export our data specifically to that. It required multiple areas for ingestion, bringing up operational costs on top of the licensing cost. It wasn't providing better detection support than Anvilogic because it was able to integrate with Splunk and our case. It was able to pull off of data that was already being ingested, when we needed to have it ingest in multiple locations.

    What other advice do I have?

    I rate Anvilogic seven out of 10. To prepare for Anvilogic, I recommend leaning into it. Take advantage of the support team and get some additional training. Use the workshops and commit to using the product. It's a tool that's only as good as the time you put into it. If you bring in the detection engine but don't put any time into creating those detections, then there's not much point. 

    Computer & Network Security

    Anvilogic a great SecOps Tool

    Reviewed on Jul 27, 2023
    Review provided by G2
    What do you like best about the product?
    Anvilogic customer technical support is amazing, They are in right direction keeping upto date with latest tech for instance they integrated AI to help generate content.
    What do you dislike about the product?
    Anvilogic still feels fresh and therefore on it;s own doesn't provide an extensive coverage in terms of identifiers in its armoury for MacOS
    What problems is the product solving and how is that benefiting you?
    It makes it easy to catch threats based on scenarios
    View all reviews