Listing Thumbnail

    Anomali

     Info
    Sold by: Anomali 
    Anomali delivers the first Intelligence-Native Agentic SOC Platform unifying a fully featured security data lake, threat intelligence, and agentic AI into a single modern experience. The platform accelerates detection, investigation, and response; delivering earlier insights, faster action, and scalable modernization across any environment.
    4.2

    Overview

    Play video

    The Anomali Intelligence-Native Agentic SOC Platform unifies a full-featured security data lake, next-generation managed threat intelligence, and Agentic AI into a single, modern security operations experience. The platform delivers agentic decision-making, embedded intelligence, and advanced analytics across the entire security lifecycle, helping organizations detect, investigate, and respond faster while reducing operational complexity. Customers can adopt either product independently or combine them for maximum impact. The platform scales seamlessly from augmenting existing SIEM investments to fully replacing legacy SIEM architectures.

    Highlights

    • Always-hot, normalized telemetry across cloud, endpoint, network, identity, and applications.
    • Curated threat intelligence applied continuously to alerts and investigations.
    • Intelligence-informed guidance that supports analyst decision-making.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    12-month contract (4)

     Info
    Dimension
    Description
    Cost/12 months
    Anomali Platform
    Anomali Platform - 3500 employees / 0.5 TB a day / 6 months storage
    $520,000.00
    Threatstream Enterprise
    Threatstream Enterprise annual subscription
    $150,000.00
    Copilot Essential
    Anomali Copilot Essential
    $83,333.00
    ThreatStream AI Enterprise - 50GB
    TS AI Enterprise with 50GB per day IOC Ingest
    $338,461.00

    Vendor refund policy

    All fees are non-cancellable and non-refundable except as required by law.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    The Customer Success Organization (CSO) provides customers with 24-hour support and additional services. CSO uses a tiered approach to allow clients to contact Anomali through their assigned operations staff member or via our support portal. With experts in all major client integration solutions and areas of security development, CSO provides clients with the knowledge necessary to address all threat intelligence related inquiries. Support@anomali.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly
    By Anomali
    By Stream.Security

    Accolades

     Info
    Top
    25
    In Log Analysis

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    6 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    Security Data Lake
    Always-hot, normalized telemetry across cloud, endpoint, network, identity, and applications.
    Threat Intelligence Integration
    Curated threat intelligence applied continuously to alerts and investigations.
    Agentic AI Capabilities
    Agentic decision-making and intelligence-informed guidance supporting analyst decision-making throughout the security lifecycle.
    Detection and Investigation Acceleration
    Advanced analytics enabling faster detection, investigation, and response across the entire security operations workflow.
    Multi-Environment Scalability
    Seamless scaling from augmenting existing SIEM investments to fully replacing legacy SIEM architectures across any environment.
    Behavioral Analytics Engine
    Applies behavioral analytics to detect threat actor tactics through Tactic Graphs, leveraging 20+ years of attack and threat data plus 1400+ incident response engagements
    Multi-Environment Threat Detection
    Unifies detection and response across endpoint, network, and cloud environments with correlated event visibility in a single dashboard
    Identity Risk Monitoring
    Continuously monitors environment for identity misconfigurations and risks, detects 100% of MITRE ATT&CK Credential Access techniques, and provides dark web intelligence on compromised credentials
    Extended Investigation Capabilities
    Supports extended log retention, search query functionality, user-defined reporting, and custom use case support for threat hunting and incident investigation
    Automated Threat Intelligence Correlation
    Automatically correlates threat landscape knowledge with security telemetry and continuously updated built-in threat intelligence
    Agentless Detection Architecture
    Agentless approach for security detection and response without requiring agent installation across cloud infrastructure.
    Real-time Configuration Monitoring
    Continuous tracking of behavior and configuration changes to provide an updated model of the environment with instant analysis of security and compliance implications.
    Threat Detection Framework
    Threat detection across Network and IAM using MITRE ATT&CK framework driven by machine learning analysis.
    Attack Chain Visualization
    Dynamic visual attack storyline that connects workloads, network data, cloud identities, and audit logs for root cause analysis.
    CloudTwin Technology
    CloudTwin technology designed to provide a precise and constantly updated model of the cloud environment for rapid response capabilities.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    No security profile
    -
    -
    -
    -
    -
    No security profile

    Contract

     Info
    Standard contract
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.2
    10 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    20%
    80%
    0%
    0%
    0%
    2 AWS reviews
    |
    8 external reviews
    External reviews are from G2  and PeerSpot .
    SangramGupta

    Proactive threat insights have transformed incident response planning and weekly SOC reporting

    Reviewed on Jun 12, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I was using Anomali  primarily for threat intelligence operations, security monitoring, and threat detection initiatives. I was part of the SOC team, and my role and responsibilities involved working with threat intelligence feeds and providing comprehensive threat reports on a weekly basis to the SOC team.

    The primary use case was threat intelligence. Before using any threat intelligence tool, the SOC team must rely on the logs they receive from their SIEM  solutions. If we integrate threat intelligence into the overall practices with Anomali , it helps us gather all the threat information beforehand so that the SIEM  engineers can schedule or create rules based on those threats or the nature of threats, making the threat hunt easier for the SIEM solutions or the SOC team. This approach is impactful for using the tool.

    What is most valuable?

    The best features I have used in Anomali include threat intelligence management. It provides a comprehensive and centralized threat intelligence feed for us. Based on a specific industry, we can gather all the threat IOCs with this tool. Those threat reports can be easily passed to the vulnerability management team, the threat hunting team, and the SOC team. Those threats are helpful for them to hunt a threat in a proactive way.

    Reporting  is another valuable feature we have used. It provides comprehensive threat reports based on IOC enrichment and correlations. Those reports are helpful whenever we provide that data to the SIEM team or SOC team.

    Anomali has positively impacted my organization by improving efficiency and reducing risks. I can provide a practical example involving monitoring indicators associated with ransomware campaigns. Anomali helps us correlate the threat intelligence with internet security technology, allowing the overall team to identify potentially relevant indicators. Without a threat intelligence tool, the SOC team would require more time to investigate or act upon the incident management plan for that threat actor. With Anomali, we benefit by obtaining threat information prior to incidents, making our threat hunts proactive and having incident response plans ready, which saves almost 40% of the time from the traditional model.

    The 40% time savings have significantly impacted my team and business. In the traditional process, the SOC team relied only on the SIEM solution and the logs it gathered. Whenever it detected any potential threat or risks, they needed to manually check and hunt for the threat, consuming significant time. With Anomali, the SOC team is already aware of the nature of the threat, the threat actor, and the IOCs. This allows us to easily develop an incident response plan or proactively hunt for that threat or vulnerability, utilizing all the data from Anomali. This reduces the time for incident response by 40 to 50% overall compared to the traditional approach.

    What needs improvement?

    I can mention one point regarding improvements for Anomali, which is more enhanced reporting flexibility. The reporting provided to us is not too detailed and could be more enhanced. Better filtering for a large intelligence dataset would also be beneficial, as when we are deep-diving into a large dataset, it does not allow us to apply extensive filtering.

    For how long have I used the solution?

    I have used Anomali for more than two years.

    What do I think about the stability of the solution?

    Anomali is stable, and I have not experienced any issues with downtime or reliability.

    What do I think about the scalability of the solution?

    Anomali handles increased workloads or data volumes well, as it can easily manage significant data related to threat actors, threat initiatives, and news.

    Which solution did I use previously and why did I switch?

    I have previously used Recorded Future , but I have not switched. I am currently using this tool because of the client's requirements.

    What was our ROI?

    There is a return on investment concerning time and effort saved by 40% after implementing Anomali.

    What other advice do I have?

    Regarding Anomali's accuracy and reliability of output, I think it is important to have someone from the security engineering side validate all the outputs from the tool. Once the output has been validated, it should be passed to the incident response team.

    If you are involved in cybersecurity practices, specifically in defensive security, responsible for threat hunting, threat intelligence, and vulnerability management or SOC operations, you can implement this tool in your system or environment. It can proactively provide you the threat feed, threat actor details, and IOCs, helping you create a better incident response plan and hunt threats proactively.

    TarunKumar11

    Strategic threat intelligence has improved detection speed and consistently reduces analyst workload

    Reviewed on Jun 04, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I have had exposure to Anomali  for over five years and have been advising many clients regarding a cyber threat intelligence platform they could use. I have recommended Anomali  to many of my clients throughout this period.

    My main use case for Anomali is rooted in the fact that there are many use cases within cyber threat intelligence, which is what Anomali stands for. This helps organizations aggregate, enrich, prioritize, and operationalize threat intelligence across its security operations. Primary use cases include security operations, threat hunting, incident response, threat intelligence, and automated blocking.

    I can provide a specific example of how I have seen Anomali used for threat hunting or incident response. A scenario I have advised on involves Anomali's use of artificial intelligence, which has made it analytical driven. It performs threat correlation, intelligence enrichment, and provides better pattern recognition through risk scoring. This makes it quite trustworthy and helps organizations prioritize intelligence through enrichment. I have seen Anomali provide strong results to businesses at large.

    Anomali helps achieve faster threat detection and faster incident response through improved productivity of analysts who would otherwise perform many tasks manually. Automation helps significantly in enrichment and correlation of indicators of compromise. This allows organizations to make better decisions with respect to threats and enhances regulatory and executive reporting.

    What is most valuable?

    Anomali's best features include its mature threat intelligence platform with a large intelligence repository, which is a major strength. It has strong feed aggregation, aggregating feeds from over 200 sources. It offers fairly reasonable automation capabilities that make it easy to operationalize threat intelligence.

    Among these features, threat intelligence operationalization stands out as making the biggest difference for organizations. It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort. Threat intelligence operationalization represents Anomali's best feature—its ability to turn raw threat intelligence into actionable security outcomes.

    Threat intelligence operationalization, combined with a comprehensive threat intelligence platform, aggregation through various feeds, automation, integration, and strong correlation with MITRE, is what organizations should primarily use Anomali for. Organizations need to use these capabilities much more coherently.

    Anomali has positively impacted my organization and my clients by helping them improve threat visibility, accelerate incident response, and make better use of their resources. Anomali has reduced incident response times by providing context around threats and indicators. It has significantly reduced analyst workload through automation and reduced the effort required for correlations. Additionally, it provides better vulnerability prioritization and much stronger visibility into cyber risk and emerging trends.

    What needs improvement?

    Anomali can be improved in various aspects. Its AI-driven automation can further advance, and AI-powered investigation summaries can improve. User experience could be enhanced through simplification of workflows. Better board-level cyber risk dashboards could provide easier visualization. Additionally, Anomali could work on simplifying the pricing structure. Although it excels in threat intelligence aggregation and operationalization, stronger GenAI capability, improved executive reporting, and a more intuitive workflow for analysts would further increase SOC efficiency and add more business value.

    Regarding Anomali's AI capabilities, governance and security are quite good. Anomali has incorporated AI and machine learning primarily to improve correlation and prioritization. These capabilities are valuable but could be more mature. The platform could achieve better threat correlation, prioritization, more anomaly detection, and allow AI to accelerate intelligence analysis while further improving quality and relevance.

    The accuracy and reliability of Anomali's AI output are fairly reasonable and good. The AI engine works well, but this capability could be improved. Better threat correlation with threat actors, certain indicators of compromise, malware, and campaigns is possible. Threat prioritization could increase, and alert noise could be reduced through further de-duplication. While reasonable, this is not the best available, and other products possibly have more AI maturity, such as Recorded Future  and CrowdStrike Falcon .

    For how long have I used the solution?

    I have been working in my current field for over twenty-five years.

    What do I think about the stability of the solution?

    Anomali is stable in my experience with no issues regarding downtime or reliability. It is an enterprise-grade platform widely used by large clients, financial institutions, and managed security service providers. It has been a mature platform for years and is designed for high availability, making it suitable for security operations centers that work 24/7. From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.

    What do I think about the scalability of the solution?

    Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data. It integrates well with firewall platforms, SIEM , and EDRs. Since it is available in cloud deployment format, it is very stable and highly available.

    How are customer service and support?

    Anomali customer support is known for being absolutely very good for enterprise customers. I would rate Anomali customer support as very good with very responsive support for critical issues. They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction. Resolution times can vary depending on the issue, and this is an area where they can further improve. Smaller customers may not receive the same level of attention as large customers do.

    I would rate Anomali customer support on a scale of one to ten as approximately an eight point five. For responsiveness, technical expertise, and implementation support, I would rate it a nine out of ten, as my experience has been quite solid.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution before Anomali. This was a solution that was not present in most of our clients' environments. My clients had point solutions, but they did not have a comprehensive solution that could correlate, and therefore no platform like this existed.

    How was the initial setup?

    Anomali follows a subscription-based model for pricing, setup cost, and licensing. Their licensing is typically a combination of the number of modules you would use. It is based on the number of analysts using Anomali, the number of intelligence feeds, and whether deployment is on-premise or SaaS. For a global enterprise, costs can range from two hundred fifty thousand to five hundred thousand dollars, and mid-size organizations might spend seventy-five thousand to one hundred thousand dollars. SaaS deployment usually costs less. Mostly it is an annual platform subscription, and multi-year deals for three to five years can provide good discounts.

    What was our ROI?

    I have seen return on investment with Anomali, with relevant metrics including money saved, fewer employees needed, and time saved. Many clients have reported SOC efficiencies in terms of reduction in mean time to detect and mean time to respond. Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs. Risk reduction matrices are also available, including the number of incidents prevented or detected in time.

    Specific metrics related to these improvements include a thirty to fifty percent reduction in manual threat analysis effort and a twenty to forty percent reduction in investigation time. Anomali also improves mean time to detect and mean time to respond by enhancing analyst activity.

    Which other solutions did I evaluate?

    Before choosing Anomali, I and my clients evaluated other options, including Recorded Future  and ThreatConnect.

    What other advice do I have?

    I would clearly recommend Anomali to organizations, as I have done in the past. Anomali is appropriate for clients who have a mature security operating center consuming multiple threat intelligence sources and want to operationalize their threat intelligence across their security ecosystem. It is not suitable for small organizations with limited security maturity but rather for large, enterprise-level grade setups. New customers should define their threat intelligence objectives, start integrating and ingesting everything in a platform like Anomali to maximize value, and regularly fine-tune and review to reduce noise from intelligence sources and feeds. Treat Anomali as a strategic intelligence platform rather than simply a feed repository. I would rate this review overall as an eight out of ten.

    Rajat Sawant

    Targeted threat intel has reduced irrelevant alerts and now streamlines supply chain investigations

    Reviewed on Jun 04, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Anomali  is that we use it as a TIP. As a TIP in my day-to-day work, we have specific rules configured for our organization. The client we work for is an FMCG client, and we have built alert cases around that, including supply chain attacks, vendors, and the technologies we use in that client. Anything triggered around those use cases will be notified to us, and then we investigate the alerts.

    Apart from this main workflow for our team, we use the Sandbox of Anomali . Specifically, our SOC team uses that, and we have integrated Anomali with our security tools including Defender and CrowdStrike in order to block the IOCs.

    What is most valuable?

    In my opinion, the best features Anomali offers include the ability for other organizations to score the intel according to their analysis, which helps us to grab more details about that alert and get more depth on that alert. Scoring the intel has helped my team significantly; for a particular incident, we were unsure whether it was impactful or not, but considering other organizations rated it high, we thought it was an important alert that should be investigated. Otherwise, it would have been overlooked as a benign event.

    Anomali has positively impacted my organization because earlier we were not using any TIP format and were just dependent on open source, which gave us tons of irrelevant alerts. Segregating those alerts was a big task, but with Anomali, we now get very specific and targeted alerts, allowing us to navigate through a handful of alerts that are applicable to us. It has saved a ton of working hours.

    What needs improvement?

    I believe Anomali could be improved by making the user interface more user-friendly. Currently, it is important to have knowledge about threat intel, but it is also crucial that even SOC team members or executive people can look at the dashboard or the tool, and it should be simple to navigate. It is not only for those who specifically work in threat intel.

    I believe easy integration with open-source tools including VirusTotal  and easy quick links to these tools would make the experience better.

    For how long have I used the solution?

    I have been using Anomali for about two years.

    What do I think about the stability of the solution?

    In my experience, Anomali is stable; I have not seen any downtime or issues. I do not see any performance lag or issues with Anomali during peak hours or high alert volumes; it performs well.

    What do I think about the scalability of the solution?

    I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same, so I do not see scalability as an issue.

    How are customer service and support?

    The customer support has been good; people are responsive when I reach out for help.

    Which solution did I use previously and why did I switch?

    I previously used a different solution; it was an internal tool created by our CISO.

    Which other solutions did I evaluate?

    Before choosing Anomali, we evaluated other options, including CloudSek and Recorded Future  features.

    What other advice do I have?

    My advice to others looking into using Anomali is that it is a good platform to start with if you do not have any TIP solution in your organization. I would rate this review eight out of ten.

    Aditya Yadav_

    Proactive threat intelligence has reduced alerts and improves attack surface visibility

    Reviewed on May 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for Anomali  was a proactive approach to integrate Anomali  Threat Intel, the TIP platform, with different security controls. The customer had two use cases: one related to the proactive approach of ingesting the IOCs into different security controls such as their IPS, IDS, email security gateways, proxy, and endpoint systems so that any malicious activity or traffic coming into their environment would be proactively blocked on all their security controls.

    We also had another use case where we wanted to get specific vulnerabilities whenever published for the specific products used within the customer's environment. Apart from that, we created some custom policies to detect any malicious activity based on the telemetry data Anomali Analytics was providing, triggering alerts and notifying us.

    I utilized Anomali security analytics to understand our attack surface so we could know how many anomalies or malicious traffic was running into our environment. That helped in running threat hunting activities and identifying users and machines interacting with malicious IPs, hashes, or any IOCs exposed over the internet. It helped us to identify machines containing some vulnerabilities; if there is a vulnerability exposed that bad actors utilize, we focus on and prioritize those assets for patching.

    We identified based on threat actors' activities if any threat actor is tightly associated with our organization type. Supporting a financial sector organization, we targeted and identified threat actors targeting financial and insurance sector organizations, helping us to proactively mitigate and secure the environment based on IOCs or attack patterns available for the specific threat actors.

    How has it helped my organization?

    Anomali positively impacts our organization, notably improving our vulnerability management program under reducing attack surface management. It supports our threat hunting activities, helping us identify gaps, create logical rules, and understand the context of threat policies on our SIEM  platforms. We successfully present quantitative data to our leadership, offering an executive summary on the attack surface and identifying various security gaps and mitigation strategies.

    In one time period, we had around 1,000 alerts related to malicious IPs or TOR activities in our platform. After implementing IOCs into our Palo Alto platform, we proactively blocked these malicious IPs from reaching our proxy, resulting in a significant drop in alerts. Previously, we faced around 100 alerts monthly for TOR activities, but following the integration with Anomali, that number reduced to just five or six cases in a month.

    What is most valuable?

    The best features Anomali offers include the TIP platform and Anomali Analytics, previously called Anomali Match, which provides a perspective to identify our attack surface. Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.

    Anomali Analytics, or Anomali Match, helped us identify scenarios where we were getting a lot of alerts on our SIEM  solution for TOR activities. Some alerts were missed, but we identified through Anomali Analytics how many interactions were happening with malicious IOCs and TOR IPs associated with vulnerabilities. We were able to identify vulnerable systems that were not patched and were interacting with those threat IPs linked to the threat actor Skinny Hunter, targeting financial sector organizations.

    We identified the IOCs within our environment, observed attack patterns for that threat actor, mapped those patterns to identify vulnerable assets, and recommended to the vulnerability management team to patch on priority.

    Anomali's dashboarding stands out; they introduced Anomali Query Language, allowing us to create dashboards identifying specific data sources and logs we push to security controls. We had Palo Alto and Check Point firewalls where we tracked data to identify how many IOCs we pushed and how many passed through or were blocked, providing deeper insights from each integrated security control due to the correlation of the TIP platform and Anomali Security Analytics .

    What needs improvement?

    Integration is quite easy; based on APIs, we can integrate different security controls without limitations, although Anomali could improve by offering more out-of-the-box connectors. There were good connectors for Zscaler and CrowdStrike, but for firewalls such as Check Point or Palo Alto, it relies on APIs. The integration was solid, and Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm , is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.

    Anomali could improve by providing more out-of-the-box solutions for integration. Some API queries fail because certain values within the queries cannot pass through the integrator. Additionally, the email notification system could be enhanced to present data better to leadership so that those in management roles can understand the logs more easily, improving visibility.

    For how long have I used the solution?

    I have been using Anomali for around the last three years for one of my clients, managing that platform as Threat Intel to integrate with their multiple security tools such as their firewalls, IPS, and IDS.

    What do I think about the stability of the solution?

    Anomali is stable and has performed reliably.

    What do I think about the scalability of the solution?

    Anomali handles our growth and expansion well, integrating with our other security platforms.

    What was our ROI?

    I do not have specific ROI numbers, but we have saved a lot of time. Previously, we needed to sift through extensive data via SIEM solutions to achieve visibility and prepare dashboards manually, but now we can identify metrics quicker.

    What's my experience with pricing, setup cost, and licensing?

    Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side. I was not part of the setup cost but know that we had to consider the costs before integrating feeds into our environment.

    Which other solutions did I evaluate?

    We evaluated Mandiant and Cybel before choosing Anomali.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2845602

    Threat intelligence has strengthened detection and response for malicious URLs and attacks

    Reviewed on May 22, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Anomali  is for threat intelligence. We have a threat stream and threat practice on that. We are checking overall and verifying malicious websites, malicious hashes, and malicious URLs that are coming to the internal organization.

    I can give a quick specific example of how I use Anomali  in my workflow. I have used Anomali to check which malicious URLs and websites are attacking our internal organization. We check the threat intelligence portal like VirusTotal  and other sources, and if the reputation of that URL is malicious, we block it in Anomali.

    What is most valuable?

    The best features Anomali offers are that it shows all the information on the particular dashboard, whether something is malicious or not and what the reputation status is.

    Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR , or threat intelligence platform—operates in multiple shifts. It has impacted our organization in a positive way by showing whether malicious activities or APTs are present. Whatever attackers are there, it shows on the dashboard and we can perform our analysis and execute remediation effectively.

    Anomali has improved our MTTR and MTDD.

    What needs improvement?

    We can enhance the dashboard and create metrics and improve the themes for incident response in particular. We could implement it through SOAR  and gather more data on SOAR.

    For how long have I used the solution?

    I have been using Anomali for about three months.

    What do I think about the stability of the solution?

    Anomali is stable.

    Which solution did I use previously and why did I switch?

    I previously used a different solution.

    What's my experience with pricing, setup cost, and licensing?

    I do not know much about the pricing, setup cost, and licensing. These aspects are taken care of by seniors and associate directors.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Anomali.

    What other advice do I have?

    I have used Anomali for the past four months in my previous organization.

    There is nothing else I would like to add about the features.

    On a scale of one to ten, I would rate Anomali an eight to nine. I would give Anomali that score because we see Anomali as a threat intelligence platform and we can work with it and improve the MTTR. I rate this product eight out of ten overall.

    View all reviews