SOCRadar Extended Threat Intelligence (XTI) Platform
Elegant Interface and Seamless Navigation That Saves Time
Proactive Threat Detection with Seamless Setup
Catches Threats Before They Become Incidents
Great Scope of Information, Improvement in Takedown
Proactive threat intelligence has reduced incident time and improves visibility into external risks
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is for cyber threat intelligence activities related to our work, as we use it to search for potential threats to our digital infrastructure.
A specific example of how I use SOCRadar Extended Threat Intelligence for searching potential threats to my digital infrastructure is a recent incident involving a third-party data breach, where one of our staff's email addresses was involved. Through SOCRadar Extended Threat Intelligence, we were able to investigate and discovered that a staff email had been involved in a data breach. Due to that information, the platform proved to be very effective as we followed our incident response procedures, notified the staff to change her password, and investigated further.
Another way I have used SOCRadar Extended Threat Intelligence is that the platform automatically scans for potential digital targets based on certain preset values we configured in the system, giving us insight into the external threat exposure of our infrastructure. This helps us understand what we are putting out there and how the world sees that as a threat to our systems and how we can protect it.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers are the threat intelligence feature, which I find very effective, as it allows me to scan for data breach exposures in the dark web, and the Attack Surface Management feature, which helps us know what a potential attack surface is. I also use the Vulnerability Intelligence feature.
The dark web intelligence feature has helped me in threat hunting, allowing me to research my domain and digital assets, such as IP addresses and cloud buckets involved in potential leaks or data breaches. The Attack Surface Management feature gives us a comprehensive view of our digital footprint and vulnerability monitoring systems.
SOCRadar Extended Threat Intelligence has impacted my organization positively by enabling us to monitor and see exactly what our external threat exposures are, a capability we lacked before using SOCRadar Extended Threat Intelligence.
What needs improvement?
In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for three years.
What was our ROI?
Specific outcomes I have noted include a reduction in the time we spend on incidents because we now have the capability to respond more effectively.
What other advice do I have?
I would rate SOCRadar Extended Threat Intelligence an 8.5 out of 10. I advise others looking into using SOCRadar Extended Threat Intelligence to try the product, as it is very effective and a great product that I believe would be very helpful.
Credential leak alerts: relevant and truly useful
Proactive threat intelligence has transformed monitoring and now protects clients from emerging attacks
What is our primary use case?
In my current role, I am using SOCRadar Extended Threat Intelligence as a threat intelligence platform to monitor emerging cyber threats and assess their impact on our clients. Every day, I review newly disclosed CVEs, ransomware campaigns, threat actor activities, phishing campaigns, exploited vulnerabilities, and malware trends. I identify whether any of these threats are relevant to our clients by checking the affected technologies, software versions, or exposed assets. If a critical vulnerability or active exploitation is observed, I prepare an advisory containing the CVSS score, affected products, exploitation status, business impact, and recommended mitigation steps. I also enrich indicators such as malicious IPs, domain URLs, and file hashes before sharing them with the SOC team for detection and monitoring. SOCRadar Extended Threat Intelligence is also useful for tracking ransomware groups, threat actor profiles, attack trends, and industry-specific threats, allowing us to proactively inform clients before they become victims.
My primary usage of SOCRadar Extended Threat Intelligence includes threat intelligence to monitor the latest cyber threats, malware campaigns, ransomware attacks, and threat actors, then tracking attacker TTPs using the MITRE ATT&CK framework, then identifying IOCs such as malicious IPs, domain URLs, and file hashes. For example, SOCRadar Extended Threat Intelligence really helps us when a new ransomware group starts targeting the financial sector. Through SOCRadar Extended Threat Intelligence, we can provide intelligence about the group's behavior, IOCs, and then mitigate the issue effectively. The other use case is related to vulnerabilities. We are using SOCRadar Extended Threat Intelligence to track newly disclosed CVEs, then check whether these vulnerabilities are being actively exploited or not in the environment and whether they are affecting the sector of our clients or not. This is very helpful in that case. The third case associated with SOCRadar Extended Threat Intelligence is attack surface management. It helps us to discover internet-facing assets such as websites, servers, IP addresses, and subdomains, then to identify exposed services, misconfigurations, or forgotten assets that attackers could exploit. For example, we have worked on multiple such cases where SOCRadar Extended Threat Intelligence helped us to identify an exposed RDP service on a public IP that should not be accessible from the internet. This helped us to provide effective security posture and improve the security posture of the client successfully. The last use case is Digital Risk Protection. We are using SOCRadar Extended Threat Intelligence to monitor for brand protection or brand impersonation, then detecting phishing websites using the company name or logo, identifying fake mobile applications or fraudulent domains that are targeting our clients or organization.
One example where SOCRadar Extended Threat Intelligence was really very helpful was during the Fortinet SSL VPN vulnerability, which is also known as FortiBleed or FortiOS critical vulnerability. When the advisory was published, SOCRadar Extended Threat Intelligence generated intelligence about the vulnerability, including the affected FortiOS versions, the CVSS score, exploitation status, technical details, and mitigation recommendations. My first step was to review the advisory and understand the impact. I then identified which of our clients were using Fortinet firewalls and checked whether their FortiOS versions were vulnerable or not. Since the vulnerability was being actively exploited, we classified it as high priority. Then I prepared a client advisory that included a summary of the vulnerability, affected FortiOS versions, whether public exploits were available or not, the business impact, and the vendor mitigation and patching recommendations. Along with that, we informed the SOC team to closely monitor FortiGate VPN logs for indicators of compromise, such as unusual SSL VPN logins, then unexpected administrator account creation. Through this, we helped the clients, and we also ensured the clients were advised to patch immediately and review the logs for any signs of compromise.
What is most valuable?
The features of SOCRadar Extended Threat Intelligence that stand out the most for me are Vulnerability Intelligence, Dark Web Monitoring, Threat Actor Intelligence, IOC Intelligence, and Attack Surface Management because they help us proactively identify and mitigate risk before they become security incidents. Vulnerability Intelligence helps us to track newly disclosed CVEs, understand their severity, determine whether they are being actively exploited or not, and prioritize the patching. Dark Web Monitoring allows us to detect leaked employee credentials, stolen data, ransomware leak posts, and company mentions on underground forums, enabling early response. Threat Actor Intelligence provides insights into attacker groups, their tactics, techniques, and procedures, and recent campaigns, which helps us to understand potential threats targeting our clients. IOC Intelligence enables us to enrich malicious IPs, then domains, URLs, and file hashes and correlate them with known campaigns during investigations. Finally, Attack Surface Management helps us to identify internet-facing assets, exposed services, and misconfigurations so organizations can reduce their attack surface before attackers exploit them. These features are valuable because they allow us to move from a reactive approach to a proactive security posture. Instead of waiting for an alert, we can identify emerging threats, assess them, and assess which clients are affected, issue security advisories, and implement mitigation measures before an incident occurs.
SOCRadar Extended Threat Intelligence has a significant impact on our organization because my organization is providing security as a service to a lot of financial clients, primarily the banking sector. It is really important to us to provide security in both proactive and reactive ways. While working in the SOC particularly, you are entirely based on the reactive approach, where something will trigger, an alert will be there in the SIEM, and then your team will respond. But proactively, the SOC is not that helpful. For the proactive approach, we implemented SOCRadar Extended Threat Intelligence in our organization and started giving dark web monitoring as a service to a lot of our clients. As I mentioned before, many of our clients are based in the banking sector. It is really important to us that we also provide a proactive approach to security and in that way, SOCRadar Extended Threat Intelligence helped us to provide them proactive security. Basically, we monitor if any employee credentials are leaked in the darknet or dark webs and if any confidential data is leaked over the dark web and also monitor if the company name is discussed in the dark web forums and if any confidential data is leaked. In all of that, SOCRadar Extended Threat Intelligence has played a vital role for us. Hence, we continue using SOCRadar Extended Threat Intelligence as our DWM tool.
SOCRadar Extended Threat Intelligence has been a stable platform. During my day-to-day work, it has been consistently available for monitoring vulnerabilities, threat actors, ransomware campaigns, and dark web intelligence. I have not experienced any major stability issues that significantly impacted our operations. The platform delivers timely threat intelligence updates and performs reliably for daily analyst activities. Like any cloud-based platform, there may occasionally be scheduled maintenance or brief service interruptions, but I have not seen these have a significant impact on our workflow.
What needs improvement?
Overall, SOCRadar Extended Threat Intelligence is a strong platform, but there are a few areas where it could be enhanced. For example, deeper SIEM and EDR integrations to automatically enrich alerts with threat intelligence and reduce manual investigation would be beneficial. The second area for improvement would be more customizable dashboards and reporting so analysts can create reports tailored to different clients and management teams. The third area I think SOCRadar Extended Threat Intelligence can improve is IOC confidence scoring to help analysts quickly prioritize the most credible indicators and reduce false positives.
For how long have I used the solution?
It has been around 1.6 years that I have been working in cybersecurity and threat hunting and threat intelligence specifically. I started as a SOC analyst in my current organization and then got promoted to the intelligence and hunting side of the security team.
What do I think about the scalability of the solution?
In my experience, SOCRadar Extended Threat Intelligence has been highly scalable. Since it is a cloud-based SaaS platform, it can support organizations of different sizes without requiring any infrastructure management. As our organization monitors multiple clients in an MSSP environment, the platform was able to handle intelligence for different industries and environments simultaneously. We could monitor multiple organizations, then track vulnerabilities, threat actors, ransomware campaigns, and internet-facing assets from a centralized dashboard. Another aspect of its scalability is that it continuously updates threat intelligence feeds and can easily accommodate new clients or assets without major changes to the platform. This makes it suitable for both growing enterprises and MSSPs that need to manage security for multiple customers.
How are customer service and support?
Regarding customer support for SOCRadar Extended Threat Intelligence, it is really active. We have attended multiple meetings with the SOCRadar Extended Threat Intelligence original team, and they were really supportive when we were facing some issues with the integrations of SOCRadar Extended Threat Intelligence feeds in our SIEM tool. At that time, we had a meeting with the support staff. The technical team really helped us in that situation, and we were successfully able to integrate SOCRadar Extended Threat Intelligence with our SIEM tool. I think it is a very good aspect of SOCRadar Extended Threat Intelligence that their customer support is really active over time when we needed them. I rate them highly.
Which solution did I use previously and why did I switch?
As I mentioned earlier, we were not providing dark web monitoring service. This is the first time we are providing the dark web monitoring service to our clients. SOCRadar Extended Threat Intelligence is our first solution for this service.
What was our ROI?
Regarding return on investment, SOCRadar Extended Threat Intelligence has really helped us in a positive way. Earlier, our whole team was doing reactive monitoring work, basically in the SOC. After setting up SOCRadar Extended Threat Intelligence as a dark web service, half of the team is working entirely into the dark web operations. This has improved the client's security posture a lot compared to when they were only taking the SOC service. Through SOCRadar Extended Threat Intelligence, we are enabled and we got a chance to provide proactive security to the clients. In that case, SOCRadar Extended Threat Intelligence has really helped us and really helped organizations to make planned decisions about their security posture.
Which other solutions did I evaluate?
I was not directly involved in the product selection process, so I did not personally evaluate or compare multiple threat platforms before SOCRadar Extended Threat Intelligence was adopted. However, as far as I know, per the information I received from the upper management, we did consider multiple platforms such as Recorded Future, CrowdStrike Falcon Intelligence, Microsoft Defender Threat Intelligence, and Mandiant Threat Intelligence. SOCRadar Extended Threat Intelligence stood out because it offered a combination of threat intelligence, Digital Risk Protection, ASM, and dark web monitoring in one platform, along with an intuitive interface and actionable intelligence that suited our operational requirements.
What other advice do I have?
My advice for others would be positive about SOCRadar Extended Threat Intelligence because as a fresher, I used SOCRadar Extended Threat Intelligence as my first tool in the threat intelligence and dark web monitoring part. It is really easy to use and easy to understand. The features are very good for everyone to understand how dark web monitoring works, how analysts see, and what they are doing regarding the alerts that are generated by SOCRadar Extended Threat Intelligence. It is really easy to understand. The dashboard is very easy to navigate. The options are very familiar, and it really helps anyone to understand what is actually going on the platform. Compared to the other solutions, I would prefer SOCRadar Extended Threat Intelligence as a fresher.
Overall, my final thought about SOCRadar Extended Threat Intelligence is that I had a positive experience with it. It has helped us to move from a reactive to a more proactive security approach by providing timely intelligence of vulnerabilities, threat actors, and other activities of the attackers. I particularly value having threat intelligence and dark web monitoring integrated into a single platform, which streamlines investigations and improves analyst efficiency. While there is always room for improvement, particularly around deeper automation or SIEM or SOAR integrations, I believe SOCRadar Extended Threat Intelligence is a mature and reliable platform that delivers actionable intelligence and helps organizations strengthen their overall security posture. I would rate SOCRadar Extended Threat Intelligence a nine out of ten.
Threat intelligence has improved case analysis and now supports faster, more accurate responses
What is our primary use case?
The main use case for SOCRadar Extended Threat Intelligence involves analyzing security tickets, specifically with ticketing requests from the company that bought their services as a SIEM as a service, responding to Jira tickets from clients experiencing several issues regarding their security network monitoring tools such as Palo Alto and endpoint detection and response tools such as XDR.
One specific example of how my colleagues used SOCRadar Extended Threat Intelligence involved deep diving into CVE 2021-44228, named the Log4Shell vulnerability, which is commonly used for backdoor execution on web application Java vulnerabilities. Despite being an old vulnerability, it still runs on the system of a very important vendor in Italy, showcasing how threat actors continue using these methods to exploit systems.
What is most valuable?
The best features of SOCRadar Extended Threat Intelligence include the intuitive alert processing that significantly aids in understanding severity, credibility, and relevance of offenses generated by their custom rule engine, showcasing how companies invest in this type of security within SIEM solutions. The X-Force engine is crucial for real-time threat scoring of each vulnerability, despite the ever-evolving threat landscape.
Alert processing is integrated with Jira, enabling efficient ticketing and prioritization of security incidents which provide a graphical aspect that allows filtering to funnel priorities, understanding issues at their core such as detecting suspicious network traffic or anomalous behavior
SOCRadar Extended Threat Intelligence has positively impacted my organization by enhancing user experience through right-click options for further analysis. Future improvements may concern simplifying the tool, which is currently already well-structured.
What needs improvement?
I consider SOCRadar Extended Threat Intelligence a very solid solution, with some room for improvement in the user experience, but overall, it is a robust tool.
I chose a rating of eight because I feel some adjustments might enhance the user experience. This rating is based on my opinion and my learning curve in understanding these tools, noting that the program's front-end and graphical appearance already meet my expectations.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for approximately two months. During this period, I have supported my colleagues in analyzing case studies and handling security-related tickets within a SIEM-as-a-service environment. My work has focused on threat analysis, incident investigation, and helping improve security posture through practical use of the platform.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is stable.
What do I think about the scalability of the solution?
SOCRadar Extended Threat Intelligence offers a faster intuitive workflow compared to my previous experience with tools like Splunk.
How are customer service and support?
I have had the chance to communicate with customer support.
Which solution did I use previously and why did I switch?
I previously studied and practiced with Splunk, and later had the chance to understand SOCRadar Extended Threat Intelligence better, which prompted my switch.
How was the initial setup?
I do not know which cloud provider is used for our hybrid cloud deployment, but I do know they utilize platform as a service.
What other advice do I have?
In my experience, I supported my colleagues in the Ethical Hacking course while using SOCRadar Extended Threat Intelligence, and I had this brief yet fully comprehensive experience in approximately two months.
Considering how supply chain attacks are solved and their devastating impact, I believe that cybersecurity in the coming years will focus on these critical vulnerabilities, highlighted by CVE 2024-3094, which features a backdoor in the XZ library. The SolarWinds attack provides an effective example, as it exploited the Orion vulnerability, showing that supply chain security is crucial for a company to understand SLA and inquire about software and updating procedures, as it plays a role in the security of the entire infrastructure.
SOCRadar Extended Threat Intelligence's governance and security through its AI capabilities are impressive, as they aid greatly in CVE understanding and allow for network comprehension of threats, proving to be a formidable tool for open-source intelligence.
The outputs generated by SOCRadar Extended Threat Intelligence are robust and intuitive in terms of AI capabilities.
It is significant for my organization that SOCRadar Extended Threat Intelligence validates its IOC data with input from over 35,000 global users, as this ensures a constantly evolving database that keeps pace with growing threats, contributing to SOCRadar Extended Threat Intelligence's excellent reputation.
The remediation process is carried out manually, where analysts thoroughly examine files that might potentially compromise the client's system, as it is primarily the analyst's responsibility to understand each issue better.
I recommend this solution for organizations aiming to strenghten threat intelligence and improve incident response efficiency.
I have no additional thoughts about SOCRadar Extended Threat Intelligence, except to suggest it as an effective tool for any company looking to enhance their work. I assigned a rating of eight to this product based on my overall experience.
Proactive threat insight has protected clients and now saves analysts significant investigation time
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is Digital Risk Protection, brand risk monitoring, threat intelligence, supply chain attacks, supply chain monitoring, VIP monitoring, identity intelligence, and geopolitical intelligence.
I can provide a specific example of how I have used SOCRadar Extended Threat Intelligence for one of those use cases. We obtained information regarding a particular threat actor for our customer, and that threat actor was targeting other brands and companies in that particular sector. We notified our customer that this threat actor might pose a risk to them, we recommended they safeguard their defenses, and we started monitoring for that customer. The effort was successful, and we successfully thwarted that cyber threat attack against our customer, saving a significant amount of money that would have been lost as a victim.
I have additional information about my main use case and how I use SOCRadar Extended Threat Intelligence. SOCRadar provides high fidelity, suspicious, and malicious IOCs that we can straightaway input into our security tools and directly block, which is valuable. Instead of scouring the internet or social media platforms for malicious IOCs for weeks or months, which consumes considerable time, I have used SOCRadar Threat Hunting platform. In conducting proactive threat hunts, I use the information about threat actors and their TTPs provided by SOCRadar to perform proactive threat hunts on my customers' environments. We use the information provided by SOCRadar to develop detection mechanisms, which is extremely useful and has proven to be a great success story for our organization.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers include VIP monitoring, which I personally prefer, Digital Risk Protection, Brand Risk Protection, and malware intelligence. Since I am always active in the cyber threat landscape, I proactively monitor geopolitical intelligence that I find very interesting because remaining on the bleeding edge requires understanding the geopolitical landscape. SOCRadar providing geopolitical threat intelligence information is extremely useful, and these modules provide a good level of information.
SOCRadar Extended Threat Intelligence has positively impacted my organization in many ways. For instance, we successfully thwarted a cyber attack against our customer. Internally, it brings considerable motivation toward learning a cyber threat intelligence platform, which itself is a very substantial concept. We learn more about cyber threats and various concepts that I believe we cannot learn independently or would take considerable time. Rather than using a threat intelligence platform that is not SOCRadar Extended Threat Intelligence, I believe you will be able to learn such concepts without difficulties and invest your time into more useful and helpful products to develop your core skills.
Thanks to SOCRadar, we have saved more than $500,000 for our customers by protecting them from cyber attacks. SOCRadar has also saved more than 900 hours of our analysts' time, reducing the Mean Time to Detect, Mean Time to Response, and automating serious tasks within our platform. It has serious capabilities, and we appreciate that.
What needs improvement?
SOCRadar Extended Threat Intelligence could be improved by implementing an autonomous threat hunting option. I am not certain if this is currently implemented, but I would appreciate seeing that feature. Another improvement would be having SOCRadar perform backend correlation tasks. For example, if there are any objects that have been identified or captured in the platform, there should be some sort of backlink channels or backend connectivity that enhances the investigation and truly saves the analyst's time.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for approximately one and a half to two years.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is absolutely stable.
How are customer service and support?
Customer support is absolutely brilliant.
I give customer support a rating of ten because of the quality of investigation, feedback, and the amount of threat intelligence support and takedown requests handled professionally.
Which solution did I use previously and why did I switch?
We previously used OpenCTI but understood its limitations, particularly as our organization grew. We could not rely on OpenCTI due to the constant need to scale up infrastructure and manage platform availability and security, which consumed more time than focusing on threat intelligence. Therefore, we switched to SOCRadar, trusting it more than relying solely on public data.
What was our ROI?
I have seen a return on investment since we previously deployed more than six to seven employees to gather intelligence and maintain vigilance on the dark web, but now we use only one or two analysts per shift. The amount of money saved is invaluable, although I cannot provide specific metrics as I do not have that data. Time saved exceeds 900 hours since we started utilizing SOCRadar.
What other advice do I have?
SOCRadar Extended Threat Intelligence earns a rating of ten on a scale of one to ten.
I rate it a ten because of the quality of information that is always delivered when needed, and the support from SOCRadar's internal security team is absolutely brilliant. The high-fidelity information that I rely on as a cyber threat intelligence analyst is what I seek. Ultimately, you want correct information that you can work on and a platform that supports you with overall visibility and extended capabilities. When everything falls into place, that is what makes a platform deserve a score of ten.
Regarding SOCRadar Extended Threat Intelligence's AI capabilities, I believe its accuracy and reliability of output are quite accurate and reliable because most of our customers are satisfied with the services that we provide as a managed security service provider. They have never complained regarding the reporting or metrics we provide or the cyber threats that we address to keep them safe. SOCRadar's AI is absolutely brilliant in terms of creating reports, which is flexible because ultimately you need some form of automation feature that helps you write lengthy reports instead of investing human hours. I would rely on SOCRadar Extended Threat Intelligence's AI capabilities to handle that task and provide automation instead.
Regarding the freemium tiers and flexible pricing offered by SOCRadar, I believe the freemium pricing is invaluable for new companies or startups. At the starting point, when your infrastructure is small and limited, you do not have many users or an external surface to manage. The freemium tier helps you start by providing the hints and information you need to stay updated in the platform. SOCRadar can prove to be an invaluable product for new companies. However, flexible pricing and premium tiers are necessary for organizations that mature and need to reach a certain level where they should pursue enterprise pricing or professional pricing because their external surface expands and they cannot afford to miss costly cyber threats. Regarding its impact on my IT budget planning, SOCRadar does not pose any problems since some cyber threat intelligence platforms are overwhelmingly costly, and you may not always have a budget for your ideal threat intelligence platform.
I have utilized SOCRadar's unique dark web sources, and they significantly impact identifying potential threats early. Our analysts work on dark web sources, and there was a client whose name was leaked in one of the dark web forums. We proactively validated that particular data, which turned out to be a false positive created as a scareware technique by threat actors to extort money or frighten clients. Without SOCRadar, I do not believe we would have discovered the truth and might have faced a real cyber attack, costing us considerably more. SOCRadar has been instrumental in dark web related information and investigations.
We are not currently using SOCRadar's AI-driven solution with the 44 orchestrated tools. However, we are using AI to automate report scheduling.
I have utilized the managed takedown services provided by SOCRadar, and it is absolutely amazing. Ultimately, we do not have to deal with the takedown and manage all the associated hassle; SOCRadar handles everything, allowing us to remain stress-free, which is what matters.
SOCRadar validating its IOC data with input from 35,000 or more global users is very significant for my organization. There are many IOCs from over 35,000 global users providing their input with context. It is essential to have high fidelity IOCs, avoiding falsely flagged IOCs that could put our customers in danger. For my organization and customers, SOCRadar has done a fantastic job in providing high fidelity IOCs because all IOCs I have encountered from SOCRadar are highly suspicious and malicious.
I have utilized the Attack Surface Threat Assessment (ASTA) feature, and I have used it more times than I can count. I discovered more than 1,000 publicly exposed and vulnerable assets that our IT team did not maintain, which were shadow IT devices. Thanks to SOCRadar, we were able to integrate it with our internal security tools and conduct vulnerability assessments, safeguarding those publicly exposed assets.
My advice to organizations looking into using SOCRadar Extended Threat Intelligence is that if you are starting your search for a threat intelligence platform, you can confidently trust and choose SOCRadar. It is an emerging leader in the field of cyber threat intelligence with massive capabilities for growth in the future, providing high fidelity IOCs that you always seek to block on your perimeter devices. It is very cost-effective compared to other threat intelligence platforms, which is a significant advantage since not every organization has a budget for a dedicated threat intelligence platform. Furthermore, its ever-growing capabilities that include threat intelligence, geopolitical events, vulnerability intelligence, identity intelligence, brand risk protection, Digital Risk Protection, malware intelligence, and proactive threat hunting are fantastic. Overall, it is a great product. I give SOCRadar Extended Threat Intelligence an overall review rating of ten.