
Overview

Product video
The Anomali Intelligence-Native Agentic SOC Platform unifies a full-featured security data lake, next-generation managed threat intelligence, and Agentic AI into a single, modern security operations experience. The platform delivers agentic decision-making, embedded intelligence, and advanced analytics across the entire security lifecycle, helping organizations detect, investigate, and respond faster while reducing operational complexity. Customers can adopt either product independently or combine them for maximum impact. The platform scales seamlessly from augmenting existing SIEM investments to fully replacing legacy SIEM architectures.
Highlights
- Always-hot, normalized telemetry across cloud, endpoint, network, identity, and applications.
- Curated threat intelligence applied continuously to alerts and investigations.
- Intelligence-informed guidance that supports analyst decision-making.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Anomali Platform | Anomali Platform - 3500 employees / 0.5 TB a day / 6 months storage | $520,000.00 |
Threatstream Enterprise | Threatstream Enterprise annual subscription | $150,000.00 |
Copilot Essential | Anomali Copilot Essential | $83,333.00 |
ThreatStream AI Enterprise - 50GB | TS AI Enterprise with 50GB per day IOC Ingest | $338,461.00 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
The Customer Success Organization (CSO) provides customers with 24-hour support and additional services. CSO uses a tiered approach to allow clients to contact Anomali through their assigned operations staff member or via our support portal. With experts in all major client integration solutions and areas of security development, CSO provides clients with the knowledge necessary to address all threat intelligence related inquiries. Support@anomali.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Reviews
Functionality
Ease of use
Customer service
Cost effectiveness
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Proactive threat intelligence has reduced alerts and improves attack surface visibility
What is our primary use case?
My main use case for Anomali was a proactive approach to integrate Anomali Threat Intel, the TIP platform, with different security controls. The customer had two use cases: one related to the proactive approach of ingesting the IOCs into different security controls such as their IPS, IDS, email security gateways, proxy, and endpoint systems so that any malicious activity or traffic coming into their environment would be proactively blocked on all their security controls.
We also had another use case where we wanted to get specific vulnerabilities whenever published for the specific products used within the customer's environment. Apart from that, we created some custom policies to detect any malicious activity based on the telemetry data Anomali Analytics was providing, triggering alerts and notifying us.
I utilized Anomali security analytics to understand our attack surface so we could know how many anomalies or malicious traffic was running into our environment. That helped in running threat hunting activities and identifying users and machines interacting with malicious IPs, hashes, or any IOCs exposed over the internet. It helped us to identify machines containing some vulnerabilities; if there is a vulnerability exposed that bad actors utilize, we focus on and prioritize those assets for patching.
We identified based on threat actors' activities if any threat actor is tightly associated with our organization type. Supporting a financial sector organization, we targeted and identified threat actors targeting financial and insurance sector organizations, helping us to proactively mitigate and secure the environment based on IOCs or attack patterns available for the specific threat actors.
How has it helped my organization?
Anomali positively impacts our organization, notably improving our vulnerability management program under reducing attack surface management. It supports our threat hunting activities, helping us identify gaps, create logical rules, and understand the context of threat policies on our SIEM platforms. We successfully present quantitative data to our leadership, offering an executive summary on the attack surface and identifying various security gaps and mitigation strategies.
In one time period, we had around 1,000 alerts related to malicious IPs or TOR activities in our platform. After implementing IOCs into our Palo Alto platform, we proactively blocked these malicious IPs from reaching our proxy, resulting in a significant drop in alerts. Previously, we faced around 100 alerts monthly for TOR activities, but following the integration with Anomali, that number reduced to just five or six cases in a month.
What is most valuable?
The best features Anomali offers include the TIP platform and Anomali Analytics, previously called Anomali Match, which provides a perspective to identify our attack surface. Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
Anomali Analytics, or Anomali Match, helped us identify scenarios where we were getting a lot of alerts on our SIEM solution for TOR activities. Some alerts were missed, but we identified through Anomali Analytics how many interactions were happening with malicious IOCs and TOR IPs associated with vulnerabilities. We were able to identify vulnerable systems that were not patched and were interacting with those threat IPs linked to the threat actor Skinny Hunter, targeting financial sector organizations.
We identified the IOCs within our environment, observed attack patterns for that threat actor, mapped those patterns to identify vulnerable assets, and recommended to the vulnerability management team to patch on priority.
Anomali's dashboarding stands out; they introduced Anomali Query Language, allowing us to create dashboards identifying specific data sources and logs we push to security controls. We had Palo Alto and Check Point firewalls where we tracked data to identify how many IOCs we pushed and how many passed through or were blocked, providing deeper insights from each integrated security control due to the correlation of the TIP platform and Anomali Security Analytics .
What needs improvement?
Integration is quite easy; based on APIs, we can integrate different security controls without limitations, although Anomali could improve by offering more out-of-the-box connectors. There were good connectors for Zscaler and CrowdStrike, but for firewalls such as Check Point or Palo Alto, it relies on APIs. The integration was solid, and Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm , is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
Anomali could improve by providing more out-of-the-box solutions for integration. Some API queries fail because certain values within the queries cannot pass through the integrator. Additionally, the email notification system could be enhanced to present data better to leadership so that those in management roles can understand the logs more easily, improving visibility.
For how long have I used the solution?
I have been using Anomali for around the last three years for one of my clients, managing that platform as Threat Intel to integrate with their multiple security tools such as their firewalls, IPS, and IDS.
What do I think about the stability of the solution?
Anomali is stable and has performed reliably.
What do I think about the scalability of the solution?
Anomali handles our growth and expansion well, integrating with our other security platforms.
What was our ROI?
I do not have specific ROI numbers, but we have saved a lot of time. Previously, we needed to sift through extensive data via SIEM solutions to achieve visibility and prepare dashboards manually, but now we can identify metrics quicker.
What's my experience with pricing, setup cost, and licensing?
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side. I was not part of the setup cost but know that we had to consider the costs before integrating feeds into our environment.
Which other solutions did I evaluate?
We evaluated Mandiant and Cybel before choosing Anomali.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Threat intelligence has strengthened detection and response for malicious URLs and attacks
What is our primary use case?
My main use case for Anomali is for threat intelligence. We have a threat stream and threat practice on that. We are checking overall and verifying malicious websites, malicious hashes, and malicious URLs that are coming to the internal organization.
I can give a quick specific example of how I use Anomali in my workflow. I have used Anomali to check which malicious URLs and websites are attacking our internal organization. We check the threat intelligence portal like VirusTotal and other sources, and if the reputation of that URL is malicious, we block it in Anomali.
What is most valuable?
The best features Anomali offers are that it shows all the information on the particular dashboard, whether something is malicious or not and what the reputation status is.
Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR , or threat intelligence platform—operates in multiple shifts. It has impacted our organization in a positive way by showing whether malicious activities or APTs are present. Whatever attackers are there, it shows on the dashboard and we can perform our analysis and execute remediation effectively.
Anomali has improved our MTTR and MTDD.
What needs improvement?
We can enhance the dashboard and create metrics and improve the themes for incident response in particular. We could implement it through SOAR and gather more data on SOAR.
For how long have I used the solution?
I have been using Anomali for about three months.
What do I think about the stability of the solution?
Anomali is stable.
Which solution did I use previously and why did I switch?
I previously used a different solution.
What's my experience with pricing, setup cost, and licensing?
I do not know much about the pricing, setup cost, and licensing. These aspects are taken care of by seniors and associate directors.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Anomali.
What other advice do I have?
I have used Anomali for the past four months in my previous organization.
There is nothing else I would like to add about the features.
On a scale of one to ten, I would rate Anomali an eight to nine. I would give Anomali that score because we see Anomali as a threat intelligence platform and we can work with it and improve the MTTR. I rate this product eight out of ten overall.
Threat intelligence workflows have become faster and provide richer indicators for investigations
What is our primary use case?
What we do is query those feeds looking for all kinds of indicators of compromise: IP, URL, and other indicators of compromise. They are evaluated according to the score given by Anomali, and we also do other processing for those indicators, validations for those indicators. After that analysis, they are integrated with the different security controls: firewalls, IPS, proxy, and among others.
We also use it for hunting topics and security bulletins.
What is most valuable?
Anomali has positively impacted my organization significantly; it has been a great help. Anomali is a very versatile platform, quite effective, and very fast when it comes to downloading and maintaining the information of the indicators of compromise. Additionally, it has a large amount of information about those indicators of compromise, such as their score and evaluation, and it also brings where they come from and tries to attach vectors to those indicators, which makes threat intelligence and security bulletins much easier. All the information that it provides makes it much easier to analyze and generate valuable information.
What needs improvement?
Regarding the web interface, there are several problems when it comes to administration. These integrators publish a web interface that after a while generates quite a few errors and the service has to be restarted quite a lot in order to administer it, which is not efficient.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
Which other solutions did I evaluate?
What other advice do I have?
Centralized threat intelligence has streamlined dark web monitoring and real‑time IOC detection
What is our primary use case?
My main use case for Anomali is that it helps me with intelligence gathering and dark web monitoring. It has good functionality of integration with other solutions like Google Mandiant and Flashpoint, which are other CTI solutions. It also integrates with other SIEM solutions such as Splunk, allowing us to push all the indicators of compromise and IOCs to the SIEM solution. We can customize based on the confidence score of this indicator; for instance, if the confidence score is over 75, we push it to Splunk for real-time sightings within the network. I think it's one of the awesome tools I've worked with to date.
A specific example of how I've used Anomali for intelligence gathering or integration with Splunk is that Anomali captures all the latest intel from various sources, whether forums, open sources, articles published on social media, or researchers posting their findings in their blogs. It collects all the TTPs, IOCs, and captures them to publish within Anomali. We push those indicators to Splunk via an API-based integration for real-time checks within the network if there are any sightings or hits.
Regarding my main use case with Anomali, while much of it is confidential, one unique capability is Anomali's TAXII/STIX based integration with different platforms. For instance, we recently integrated with the CISA platform run by the US government, which provides us with the latest advisories. They push all the results into Anomali, creating a single UI that helps us avoid jumping into various sources to find intel, which I think is a unique feature of Anomali.
What is most valuable?
The best features Anomali offers are that it acts as an application that pulls data from different solutions. As I mentioned earlier, we utilize Mandiant, Flashpoint, and other CTI solutions. Using Anomali, I push all the results into it, providing a single UI to see what Flashpoint and Google Mandiant are providing rather than jumping into different platforms, which can be time-consuming. Anomali helps us stay on a single platform and provides the required results.
The user interface in Anomali is very good. I have worked in Anomali for five years and think they have a great UI for writing queries and finding specific results much more efficiently than in other solutions where you need to scroll down through different widgets. Anomali has a query-based language, similar to SQL, that helps us dig out specific results, whether vulnerability-related or concerning threat actors and TTPs. We can also perform string-based searches. I think it's an awesome feature. Furthermore, regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Anomali has positively impacted my organization by reducing the time required to find intel specific to our needs. We can create our own queries specific to our organization and pull out results related to any posts within the dark web or any activities from threat actors targeting us. This capability enables us to create saved searches that provide exact results. I estimate that Anomali has saved me about 30% of my time.
What needs improvement?
In terms of improvements, I think Anomali has a good UI and integration capabilities. However, one area for improvement is providing a heat map of cyberattacks around the world. It would be helpful to have a list of which countries are facing the most attacks or experiencing major data breaches, and I think those areas could be enhanced.
One more improvement I would mention is regarding compromised credential monitoring. Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials. Expanding in that area could significantly enhance its utility.
For how long have I used the solution?
I have been using Anomali for around five years now.
What do I think about the stability of the solution?
Anomali is stable. The good thing is that they have a health check page, and if any issues arise, they notify us. We can continuously track the real-time status of Anomali platform through this webpage.
What do I think about the scalability of the solution?
Anomali's scalability is good; it performs well.
How are customer service and support?
Customer support from Anomali is reliable; they provide support regularly during incidents or any requirements and are responsive to our needs.
Which solution did I use previously and why did I switch?
I have not previously used a different solution; this is the only one I have used in the last five years.
What was our ROI?
I have seen a return on investment from using Anomali.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing involved a yearly, two-year contract; I can't specify the setup cost, but it was aligned with our budget, so I consider it good.
Which other solutions did I evaluate?
I did evaluate other options before choosing Anomali, but I can't recall the names of the specific ones.
What other advice do I have?
My advice for others considering Anomali is to go for it, depending on your organization. Whether it is retail, finance, or service-based, decide on your PIRs and use cases to evaluate if Anomali covers those adequately.
Any new customers looking for a solution should consider Anomali as a great option. However, it depends on the organization; whether retail, finance, product-based, or service-based, you should evaluate the use cases for yourself, conduct a POC, and see if it meets all your needs. I would rate this solution an 8 out of 10.
Enables automated threat intelligence sorting and enhances proactive threat hunting capabilities
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
What other advice do I have?
My company is a customer of Anomali.
I would recommend it to other people.
I would advise making sure you don't pick it without testing other products and have your use cases well thought out and documented before testing, so you know it will solve the problems you're trying to address. Keep an open mind with it and realize that whatever you can dream of, you can probably do with the platform.
Overall, I would rate Anomali an eight out of ten.