SOCRadar Extended Threat Intelligence (XTI) Platform
Proactive threat intelligence has reduced incident time and improves visibility into external risks
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is for cyber threat intelligence activities related to our work, as we use it to search for potential threats to our digital infrastructure.
A specific example of how I use SOCRadar Extended Threat Intelligence for searching potential threats to my digital infrastructure is a recent incident involving a third-party data breach, where one of our staff's email addresses was involved. Through SOCRadar Extended Threat Intelligence, we were able to investigate and discovered that a staff email had been involved in a data breach. Due to that information, the platform proved to be very effective as we followed our incident response procedures, notified the staff to change her password, and investigated further.
Another way I have used SOCRadar Extended Threat Intelligence is that the platform automatically scans for potential digital targets based on certain preset values we configured in the system, giving us insight into the external threat exposure of our infrastructure. This helps us understand what we are putting out there and how the world sees that as a threat to our systems and how we can protect it.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers are the threat intelligence feature, which I find very effective, as it allows me to scan for data breach exposures in the dark web, and the Attack Surface Management feature, which helps us know what a potential attack surface is. I also use the Vulnerability Intelligence feature.
The dark web intelligence feature has helped me in threat hunting, allowing me to research my domain and digital assets, such as IP addresses and cloud buckets involved in potential leaks or data breaches. The Attack Surface Management feature gives us a comprehensive view of our digital footprint and vulnerability monitoring systems.
SOCRadar Extended Threat Intelligence has impacted my organization positively by enabling us to monitor and see exactly what our external threat exposures are, a capability we lacked before using SOCRadar Extended Threat Intelligence.
What needs improvement?
In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for three years.
What was our ROI?
Specific outcomes I have noted include a reduction in the time we spend on incidents because we now have the capability to respond more effectively.
What other advice do I have?
I would rate SOCRadar Extended Threat Intelligence an 8.5 out of 10. I advise others looking into using SOCRadar Extended Threat Intelligence to try the product, as it is very effective and a great product that I believe would be very helpful.
Proactive threat intelligence has transformed monitoring and now protects clients from emerging attacks
What is our primary use case?
In my current role, I am using SOCRadar Extended Threat Intelligence as a threat intelligence platform to monitor emerging cyber threats and assess their impact on our clients. Every day, I review newly disclosed CVEs, ransomware campaigns, threat actor activities, phishing campaigns, exploited vulnerabilities, and malware trends. I identify whether any of these threats are relevant to our clients by checking the affected technologies, software versions, or exposed assets. If a critical vulnerability or active exploitation is observed, I prepare an advisory containing the CVSS score, affected products, exploitation status, business impact, and recommended mitigation steps. I also enrich indicators such as malicious IPs, domain URLs, and file hashes before sharing them with the SOC team for detection and monitoring. SOCRadar Extended Threat Intelligence is also useful for tracking ransomware groups, threat actor profiles, attack trends, and industry-specific threats, allowing us to proactively inform clients before they become victims.
My primary usage of SOCRadar Extended Threat Intelligence includes threat intelligence to monitor the latest cyber threats, malware campaigns, ransomware attacks, and threat actors, then tracking attacker TTPs using the MITRE ATT&CK framework, then identifying IOCs such as malicious IPs, domain URLs, and file hashes. For example, SOCRadar Extended Threat Intelligence really helps us when a new ransomware group starts targeting the financial sector. Through SOCRadar Extended Threat Intelligence, we can provide intelligence about the group's behavior, IOCs, and then mitigate the issue effectively. The other use case is related to vulnerabilities. We are using SOCRadar Extended Threat Intelligence to track newly disclosed CVEs, then check whether these vulnerabilities are being actively exploited or not in the environment and whether they are affecting the sector of our clients or not. This is very helpful in that case. The third case associated with SOCRadar Extended Threat Intelligence is attack surface management. It helps us to discover internet-facing assets such as websites, servers, IP addresses, and subdomains, then to identify exposed services, misconfigurations, or forgotten assets that attackers could exploit. For example, we have worked on multiple such cases where SOCRadar Extended Threat Intelligence helped us to identify an exposed RDP service on a public IP that should not be accessible from the internet. This helped us to provide effective security posture and improve the security posture of the client successfully. The last use case is Digital Risk Protection. We are using SOCRadar Extended Threat Intelligence to monitor for brand protection or brand impersonation, then detecting phishing websites using the company name or logo, identifying fake mobile applications or fraudulent domains that are targeting our clients or organization.
One example where SOCRadar Extended Threat Intelligence was really very helpful was during the Fortinet SSL VPN vulnerability, which is also known as FortiBleed or FortiOS critical vulnerability. When the advisory was published, SOCRadar Extended Threat Intelligence generated intelligence about the vulnerability, including the affected FortiOS versions, the CVSS score, exploitation status, technical details, and mitigation recommendations. My first step was to review the advisory and understand the impact. I then identified which of our clients were using Fortinet firewalls and checked whether their FortiOS versions were vulnerable or not. Since the vulnerability was being actively exploited, we classified it as high priority. Then I prepared a client advisory that included a summary of the vulnerability, affected FortiOS versions, whether public exploits were available or not, the business impact, and the vendor mitigation and patching recommendations. Along with that, we informed the SOC team to closely monitor FortiGate VPN logs for indicators of compromise, such as unusual SSL VPN logins, then unexpected administrator account creation. Through this, we helped the clients, and we also ensured the clients were advised to patch immediately and review the logs for any signs of compromise.
What is most valuable?
The features of SOCRadar Extended Threat Intelligence that stand out the most for me are Vulnerability Intelligence, Dark Web Monitoring, Threat Actor Intelligence, IOC Intelligence, and Attack Surface Management because they help us proactively identify and mitigate risk before they become security incidents. Vulnerability Intelligence helps us to track newly disclosed CVEs, understand their severity, determine whether they are being actively exploited or not, and prioritize the patching. Dark Web Monitoring allows us to detect leaked employee credentials, stolen data, ransomware leak posts, and company mentions on underground forums, enabling early response. Threat Actor Intelligence provides insights into attacker groups, their tactics, techniques, and procedures, and recent campaigns, which helps us to understand potential threats targeting our clients. IOC Intelligence enables us to enrich malicious IPs, then domains, URLs, and file hashes and correlate them with known campaigns during investigations. Finally, Attack Surface Management helps us to identify internet-facing assets, exposed services, and misconfigurations so organizations can reduce their attack surface before attackers exploit them. These features are valuable because they allow us to move from a reactive approach to a proactive security posture. Instead of waiting for an alert, we can identify emerging threats, assess them, and assess which clients are affected, issue security advisories, and implement mitigation measures before an incident occurs.
SOCRadar Extended Threat Intelligence has a significant impact on our organization because my organization is providing security as a service to a lot of financial clients, primarily the banking sector. It is really important to us to provide security in both proactive and reactive ways. While working in the SOC particularly, you are entirely based on the reactive approach, where something will trigger, an alert will be there in the SIEM, and then your team will respond. But proactively, the SOC is not that helpful. For the proactive approach, we implemented SOCRadar Extended Threat Intelligence in our organization and started giving dark web monitoring as a service to a lot of our clients. As I mentioned before, many of our clients are based in the banking sector. It is really important to us that we also provide a proactive approach to security and in that way, SOCRadar Extended Threat Intelligence helped us to provide them proactive security. Basically, we monitor if any employee credentials are leaked in the darknet or dark webs and if any confidential data is leaked over the dark web and also monitor if the company name is discussed in the dark web forums and if any confidential data is leaked. In all of that, SOCRadar Extended Threat Intelligence has played a vital role for us. Hence, we continue using SOCRadar Extended Threat Intelligence as our DWM tool.
SOCRadar Extended Threat Intelligence has been a stable platform. During my day-to-day work, it has been consistently available for monitoring vulnerabilities, threat actors, ransomware campaigns, and dark web intelligence. I have not experienced any major stability issues that significantly impacted our operations. The platform delivers timely threat intelligence updates and performs reliably for daily analyst activities. Like any cloud-based platform, there may occasionally be scheduled maintenance or brief service interruptions, but I have not seen these have a significant impact on our workflow.
What needs improvement?
Overall, SOCRadar Extended Threat Intelligence is a strong platform, but there are a few areas where it could be enhanced. For example, deeper SIEM and EDR integrations to automatically enrich alerts with threat intelligence and reduce manual investigation would be beneficial. The second area for improvement would be more customizable dashboards and reporting so analysts can create reports tailored to different clients and management teams. The third area I think SOCRadar Extended Threat Intelligence can improve is IOC confidence scoring to help analysts quickly prioritize the most credible indicators and reduce false positives.
For how long have I used the solution?
It has been around 1.6 years that I have been working in cybersecurity and threat hunting and threat intelligence specifically. I started as a SOC analyst in my current organization and then got promoted to the intelligence and hunting side of the security team.
What do I think about the scalability of the solution?
In my experience, SOCRadar Extended Threat Intelligence has been highly scalable. Since it is a cloud-based SaaS platform, it can support organizations of different sizes without requiring any infrastructure management. As our organization monitors multiple clients in an MSSP environment, the platform was able to handle intelligence for different industries and environments simultaneously. We could monitor multiple organizations, then track vulnerabilities, threat actors, ransomware campaigns, and internet-facing assets from a centralized dashboard. Another aspect of its scalability is that it continuously updates threat intelligence feeds and can easily accommodate new clients or assets without major changes to the platform. This makes it suitable for both growing enterprises and MSSPs that need to manage security for multiple customers.
How are customer service and support?
Regarding customer support for SOCRadar Extended Threat Intelligence, it is really active. We have attended multiple meetings with the SOCRadar Extended Threat Intelligence original team, and they were really supportive when we were facing some issues with the integrations of SOCRadar Extended Threat Intelligence feeds in our SIEM tool. At that time, we had a meeting with the support staff. The technical team really helped us in that situation, and we were successfully able to integrate SOCRadar Extended Threat Intelligence with our SIEM tool. I think it is a very good aspect of SOCRadar Extended Threat Intelligence that their customer support is really active over time when we needed them. I rate them highly.
Which solution did I use previously and why did I switch?
As I mentioned earlier, we were not providing dark web monitoring service. This is the first time we are providing the dark web monitoring service to our clients. SOCRadar Extended Threat Intelligence is our first solution for this service.
What was our ROI?
Regarding return on investment, SOCRadar Extended Threat Intelligence has really helped us in a positive way. Earlier, our whole team was doing reactive monitoring work, basically in the SOC. After setting up SOCRadar Extended Threat Intelligence as a dark web service, half of the team is working entirely into the dark web operations. This has improved the client's security posture a lot compared to when they were only taking the SOC service. Through SOCRadar Extended Threat Intelligence, we are enabled and we got a chance to provide proactive security to the clients. In that case, SOCRadar Extended Threat Intelligence has really helped us and really helped organizations to make planned decisions about their security posture.
Which other solutions did I evaluate?
I was not directly involved in the product selection process, so I did not personally evaluate or compare multiple threat platforms before SOCRadar Extended Threat Intelligence was adopted. However, as far as I know, per the information I received from the upper management, we did consider multiple platforms such as Recorded Future, CrowdStrike Falcon Intelligence, Microsoft Defender Threat Intelligence, and Mandiant Threat Intelligence. SOCRadar Extended Threat Intelligence stood out because it offered a combination of threat intelligence, Digital Risk Protection, ASM, and dark web monitoring in one platform, along with an intuitive interface and actionable intelligence that suited our operational requirements.
What other advice do I have?
My advice for others would be positive about SOCRadar Extended Threat Intelligence because as a fresher, I used SOCRadar Extended Threat Intelligence as my first tool in the threat intelligence and dark web monitoring part. It is really easy to use and easy to understand. The features are very good for everyone to understand how dark web monitoring works, how analysts see, and what they are doing regarding the alerts that are generated by SOCRadar Extended Threat Intelligence. It is really easy to understand. The dashboard is very easy to navigate. The options are very familiar, and it really helps anyone to understand what is actually going on the platform. Compared to the other solutions, I would prefer SOCRadar Extended Threat Intelligence as a fresher.
Overall, my final thought about SOCRadar Extended Threat Intelligence is that I had a positive experience with it. It has helped us to move from a reactive to a more proactive security approach by providing timely intelligence of vulnerabilities, threat actors, and other activities of the attackers. I particularly value having threat intelligence and dark web monitoring integrated into a single platform, which streamlines investigations and improves analyst efficiency. While there is always room for improvement, particularly around deeper automation or SIEM or SOAR integrations, I believe SOCRadar Extended Threat Intelligence is a mature and reliable platform that delivers actionable intelligence and helps organizations strengthen their overall security posture. I would rate SOCRadar Extended Threat Intelligence a nine out of ten.
Threat intelligence has improved case analysis and now supports faster, more accurate responses
What is our primary use case?
The main use case for SOCRadar Extended Threat Intelligence involves analyzing security tickets, specifically with ticketing requests from the company that bought their services as a SIEM as a service, responding to Jira tickets from clients experiencing several issues regarding their security network monitoring tools such as Palo Alto and endpoint detection and response tools such as XDR.
One specific example of how my colleagues used SOCRadar Extended Threat Intelligence involved deep diving into CVE 2021-44228, named the Log4Shell vulnerability, which is commonly used for backdoor execution on web application Java vulnerabilities. Despite being an old vulnerability, it still runs on the system of a very important vendor in Italy, showcasing how threat actors continue using these methods to exploit systems.
What is most valuable?
The best features of SOCRadar Extended Threat Intelligence include the intuitive alert processing that significantly aids in understanding severity, credibility, and relevance of offenses generated by their custom rule engine, showcasing how companies invest in this type of security within SIEM solutions. The X-Force engine is crucial for real-time threat scoring of each vulnerability, despite the ever-evolving threat landscape.
Alert processing is integrated with Jira, enabling efficient ticketing and prioritization of security incidents which provide a graphical aspect that allows filtering to funnel priorities, understanding issues at their core such as detecting suspicious network traffic or anomalous behavior
SOCRadar Extended Threat Intelligence has positively impacted my organization by enhancing user experience through right-click options for further analysis. Future improvements may concern simplifying the tool, which is currently already well-structured.
What needs improvement?
I consider SOCRadar Extended Threat Intelligence a very solid solution, with some room for improvement in the user experience, but overall, it is a robust tool.
I chose a rating of eight because I feel some adjustments might enhance the user experience. This rating is based on my opinion and my learning curve in understanding these tools, noting that the program's front-end and graphical appearance already meet my expectations.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for approximately two months. During this period, I have supported my colleagues in analyzing case studies and handling security-related tickets within a SIEM-as-a-service environment. My work has focused on threat analysis, incident investigation, and helping improve security posture through practical use of the platform.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is stable.
What do I think about the scalability of the solution?
SOCRadar Extended Threat Intelligence offers a faster intuitive workflow compared to my previous experience with tools like Splunk.
How are customer service and support?
I have had the chance to communicate with customer support.
Which solution did I use previously and why did I switch?
I previously studied and practiced with Splunk, and later had the chance to understand SOCRadar Extended Threat Intelligence better, which prompted my switch.
How was the initial setup?
I do not know which cloud provider is used for our hybrid cloud deployment, but I do know they utilize platform as a service.
What other advice do I have?
In my experience, I supported my colleagues in the Ethical Hacking course while using SOCRadar Extended Threat Intelligence, and I had this brief yet fully comprehensive experience in approximately two months.
Considering how supply chain attacks are solved and their devastating impact, I believe that cybersecurity in the coming years will focus on these critical vulnerabilities, highlighted by CVE 2024-3094, which features a backdoor in the XZ library. The SolarWinds attack provides an effective example, as it exploited the Orion vulnerability, showing that supply chain security is crucial for a company to understand SLA and inquire about software and updating procedures, as it plays a role in the security of the entire infrastructure.
SOCRadar Extended Threat Intelligence's governance and security through its AI capabilities are impressive, as they aid greatly in CVE understanding and allow for network comprehension of threats, proving to be a formidable tool for open-source intelligence.
The outputs generated by SOCRadar Extended Threat Intelligence are robust and intuitive in terms of AI capabilities.
It is significant for my organization that SOCRadar Extended Threat Intelligence validates its IOC data with input from over 35,000 global users, as this ensures a constantly evolving database that keeps pace with growing threats, contributing to SOCRadar Extended Threat Intelligence's excellent reputation.
The remediation process is carried out manually, where analysts thoroughly examine files that might potentially compromise the client's system, as it is primarily the analyst's responsibility to understand each issue better.
I recommend this solution for organizations aiming to strenghten threat intelligence and improve incident response efficiency.
I have no additional thoughts about SOCRadar Extended Threat Intelligence, except to suggest it as an effective tool for any company looking to enhance their work. I assigned a rating of eight to this product based on my overall experience.
Proactive threat insight has protected clients and now saves analysts significant investigation time
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is Digital Risk Protection, brand risk monitoring, threat intelligence, supply chain attacks, supply chain monitoring, VIP monitoring, identity intelligence, and geopolitical intelligence.
I can provide a specific example of how I have used SOCRadar Extended Threat Intelligence for one of those use cases. We obtained information regarding a particular threat actor for our customer, and that threat actor was targeting other brands and companies in that particular sector. We notified our customer that this threat actor might pose a risk to them, we recommended they safeguard their defenses, and we started monitoring for that customer. The effort was successful, and we successfully thwarted that cyber threat attack against our customer, saving a significant amount of money that would have been lost as a victim.
I have additional information about my main use case and how I use SOCRadar Extended Threat Intelligence. SOCRadar provides high fidelity, suspicious, and malicious IOCs that we can straightaway input into our security tools and directly block, which is valuable. Instead of scouring the internet or social media platforms for malicious IOCs for weeks or months, which consumes considerable time, I have used SOCRadar Threat Hunting platform. In conducting proactive threat hunts, I use the information about threat actors and their TTPs provided by SOCRadar to perform proactive threat hunts on my customers' environments. We use the information provided by SOCRadar to develop detection mechanisms, which is extremely useful and has proven to be a great success story for our organization.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers include VIP monitoring, which I personally prefer, Digital Risk Protection, Brand Risk Protection, and malware intelligence. Since I am always active in the cyber threat landscape, I proactively monitor geopolitical intelligence that I find very interesting because remaining on the bleeding edge requires understanding the geopolitical landscape. SOCRadar providing geopolitical threat intelligence information is extremely useful, and these modules provide a good level of information.
SOCRadar Extended Threat Intelligence has positively impacted my organization in many ways. For instance, we successfully thwarted a cyber attack against our customer. Internally, it brings considerable motivation toward learning a cyber threat intelligence platform, which itself is a very substantial concept. We learn more about cyber threats and various concepts that I believe we cannot learn independently or would take considerable time. Rather than using a threat intelligence platform that is not SOCRadar Extended Threat Intelligence, I believe you will be able to learn such concepts without difficulties and invest your time into more useful and helpful products to develop your core skills.
Thanks to SOCRadar, we have saved more than $500,000 for our customers by protecting them from cyber attacks. SOCRadar has also saved more than 900 hours of our analysts' time, reducing the Mean Time to Detect, Mean Time to Response, and automating serious tasks within our platform. It has serious capabilities, and we appreciate that.
What needs improvement?
SOCRadar Extended Threat Intelligence could be improved by implementing an autonomous threat hunting option. I am not certain if this is currently implemented, but I would appreciate seeing that feature. Another improvement would be having SOCRadar perform backend correlation tasks. For example, if there are any objects that have been identified or captured in the platform, there should be some sort of backlink channels or backend connectivity that enhances the investigation and truly saves the analyst's time.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for approximately one and a half to two years.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is absolutely stable.
How are customer service and support?
Customer support is absolutely brilliant.
I give customer support a rating of ten because of the quality of investigation, feedback, and the amount of threat intelligence support and takedown requests handled professionally.
Which solution did I use previously and why did I switch?
We previously used OpenCTI but understood its limitations, particularly as our organization grew. We could not rely on OpenCTI due to the constant need to scale up infrastructure and manage platform availability and security, which consumed more time than focusing on threat intelligence. Therefore, we switched to SOCRadar, trusting it more than relying solely on public data.
What was our ROI?
I have seen a return on investment since we previously deployed more than six to seven employees to gather intelligence and maintain vigilance on the dark web, but now we use only one or two analysts per shift. The amount of money saved is invaluable, although I cannot provide specific metrics as I do not have that data. Time saved exceeds 900 hours since we started utilizing SOCRadar.
What other advice do I have?
SOCRadar Extended Threat Intelligence earns a rating of ten on a scale of one to ten.
I rate it a ten because of the quality of information that is always delivered when needed, and the support from SOCRadar's internal security team is absolutely brilliant. The high-fidelity information that I rely on as a cyber threat intelligence analyst is what I seek. Ultimately, you want correct information that you can work on and a platform that supports you with overall visibility and extended capabilities. When everything falls into place, that is what makes a platform deserve a score of ten.
Regarding SOCRadar Extended Threat Intelligence's AI capabilities, I believe its accuracy and reliability of output are quite accurate and reliable because most of our customers are satisfied with the services that we provide as a managed security service provider. They have never complained regarding the reporting or metrics we provide or the cyber threats that we address to keep them safe. SOCRadar's AI is absolutely brilliant in terms of creating reports, which is flexible because ultimately you need some form of automation feature that helps you write lengthy reports instead of investing human hours. I would rely on SOCRadar Extended Threat Intelligence's AI capabilities to handle that task and provide automation instead.
Regarding the freemium tiers and flexible pricing offered by SOCRadar, I believe the freemium pricing is invaluable for new companies or startups. At the starting point, when your infrastructure is small and limited, you do not have many users or an external surface to manage. The freemium tier helps you start by providing the hints and information you need to stay updated in the platform. SOCRadar can prove to be an invaluable product for new companies. However, flexible pricing and premium tiers are necessary for organizations that mature and need to reach a certain level where they should pursue enterprise pricing or professional pricing because their external surface expands and they cannot afford to miss costly cyber threats. Regarding its impact on my IT budget planning, SOCRadar does not pose any problems since some cyber threat intelligence platforms are overwhelmingly costly, and you may not always have a budget for your ideal threat intelligence platform.
I have utilized SOCRadar's unique dark web sources, and they significantly impact identifying potential threats early. Our analysts work on dark web sources, and there was a client whose name was leaked in one of the dark web forums. We proactively validated that particular data, which turned out to be a false positive created as a scareware technique by threat actors to extort money or frighten clients. Without SOCRadar, I do not believe we would have discovered the truth and might have faced a real cyber attack, costing us considerably more. SOCRadar has been instrumental in dark web related information and investigations.
We are not currently using SOCRadar's AI-driven solution with the 44 orchestrated tools. However, we are using AI to automate report scheduling.
I have utilized the managed takedown services provided by SOCRadar, and it is absolutely amazing. Ultimately, we do not have to deal with the takedown and manage all the associated hassle; SOCRadar handles everything, allowing us to remain stress-free, which is what matters.
SOCRadar validating its IOC data with input from 35,000 or more global users is very significant for my organization. There are many IOCs from over 35,000 global users providing their input with context. It is essential to have high fidelity IOCs, avoiding falsely flagged IOCs that could put our customers in danger. For my organization and customers, SOCRadar has done a fantastic job in providing high fidelity IOCs because all IOCs I have encountered from SOCRadar are highly suspicious and malicious.
I have utilized the Attack Surface Threat Assessment (ASTA) feature, and I have used it more times than I can count. I discovered more than 1,000 publicly exposed and vulnerable assets that our IT team did not maintain, which were shadow IT devices. Thanks to SOCRadar, we were able to integrate it with our internal security tools and conduct vulnerability assessments, safeguarding those publicly exposed assets.
My advice to organizations looking into using SOCRadar Extended Threat Intelligence is that if you are starting your search for a threat intelligence platform, you can confidently trust and choose SOCRadar. It is an emerging leader in the field of cyber threat intelligence with massive capabilities for growth in the future, providing high fidelity IOCs that you always seek to block on your perimeter devices. It is very cost-effective compared to other threat intelligence platforms, which is a significant advantage since not every organization has a budget for a dedicated threat intelligence platform. Furthermore, its ever-growing capabilities that include threat intelligence, geopolitical events, vulnerability intelligence, identity intelligence, brand risk protection, Digital Risk Protection, malware intelligence, and proactive threat hunting are fantastic. Overall, it is a great product. I give SOCRadar Extended Threat Intelligence an overall review rating of ten.
Centralized threat intelligence has streamlined daily investigations and ongoing hunting activities
What is our primary use case?
Investigating indicators of compromise, searching for threat actor reports and threat activity, and performing threat hunting activities are the main use cases I have for SOCRadar Extended Threat Intelligence in my day-to-day work.
I primarily use SOCRadar Extended Threat Intelligence for detecting an alert during monitoring or something that has been reported on the network, in searching for malicious indicators of some type, including IP addresses or some URLs.
Another interesting case with SOCRadar Extended Threat Intelligence is searching for credential compromises on the Dark Web, which is something that was commonly used and continues to be used.
What is most valuable?
The best features offered by SOCRadar Extended Threat Intelligence include the centralized platform, having all the reports at hand, all the functionalities related to CTI-type tools, which are indeed useful for investigations and threat hunting, and the tool is very easy to use.
SOCRadar Extended Threat Intelligence makes my work or my team's work more efficient by reducing the time it takes to do a search based on a specific domain for some client to whom we provide the service, allowing us to search for all the information related to that domain and different types of indicators or valuable information.
SOCRadar Extended Threat Intelligence positively impacts my organization significantly by providing reports and high-level executive reporting that gives interesting visibility to top management or personnel with decision-making capacity, without requiring major additional effort to obtain this information.
What needs improvement?
SOCRadar Extended Threat Intelligence could improve regarding the licensing scheme, which is credit-based, especially for specific activities, as it would be beneficial to have some flexibility in how these credits are consumed.
For how long have I used the solution?
I have been working in the cybersecurity field for more than five years. I have been using SOCRadar Extended Threat Intelligence for about three years, mainly in my previous experience at Grupo Radica, where I worked in the SOC area and we used the tool to deliver the service.
What do I think about the stability of the solution?
I consider SOCRadar Extended Threat Intelligence to be a stable solution.
What do I think about the scalability of the solution?
SOCRadar Extended Threat Intelligence can be adapted to the organization's needs by maintaining a flexible licensing scheme and even with its multi-tenant capabilities to provide a service from a security scheme.
How are customer service and support?
My experience with SOCRadar Extended Threat Intelligence's customer support has been acceptable, as they have met the agreed timelines and scope.
Which solution did I use previously and why did I switch?
I only used OSINT sources and open sources before SOCRadar Extended Threat Intelligence, and we decided to switch basically because of the reach that the solution has.
What was our ROI?
I do not have the exact figure for return on investment with the platform, but there is a significant reduction in the effort of conducting threat hunting and threat investigations manually.
What's my experience with pricing, setup cost, and licensing?
My experience with the price, implementation cost, and licensing of SOCRadar Extended Threat Intelligence has been good.
Which other solutions did I evaluate?
At the time, I evaluated a solution called Polaris and a solution called Vadar before choosing SOCRadar Extended Threat Intelligence.
What other advice do I have?
I would advise other people who are considering using SOCRadar Extended Threat Intelligence to focus on the versatility of the tool, on its entire scope and all the coverage it has in the different types of intelligence it handles, from the executive point of view to the operational one, and to adapt it to their internal processes based on that. I would rate this product a 9 out of 10.
Threat intelligence has strengthened dark web monitoring and automated credential exposure response
What is our primary use case?
I primarily use SOCRadar Extended Threat Intelligence for monitoring data credential leaks and password leaks, handling exposures, and managing GitHub public repository, SSL expiry, and attack surface along with public repositories exposures and cyber threat intelligence, as well as feeding threat intel feeds to my other tools such as LogRhythm and EDR, XDR.
For instance, I created a use case involving my company's domain name and email ID where if any user with my company's email ID gets exposed on the dark web and deep web, I receive an alert so I can validate whether the credential is currently active or not and take necessary actions.
Regarding public repository exposure, if any of our company employees push their data to public platforms such as GitHub, we get alerts based on critical keywords which allows me to analyze how critical the exposure is to our organization. For SSL expiry, I validate certificates on domains and subdomains based on their expiry, ensuring they are either self-signed or public SSL, which helps us reach out to the domain users and owners for renewal.
What is most valuable?
I find all the features of SOCRadar Extended Threat Intelligence, including those related to internal threat actors and ongoing threats, to be impressive as they offer crucial IOCs, allowing me to proactively extract and block any threat actors targeting specific organizations.
Exporting any IOCs detail from SOCRadar Extended Threat Intelligence is straightforward, as they come in CSV format, allowing me to easily categorize them by IPs, domains, or URLs and quickly integrate them into my other tools for action.
The dashboard and reporting features are very user-friendly, and I have personalized my dashboard to include daily and weekly alerts related to IPs, top most threat actors, and the most infected users.
SOCRadar Extended Threat Intelligence has positively impacted my organization by enabling me to feed higher severity IOCs to other tools, automatically blocking malicious threat actors roaming in the market, while generating reports related to CVEs that we share with our vendors and respective teams for vulnerability validation and remediation.
What needs improvement?
I have noticed exposures of credentials that do not show the correct password, as I receive alerts repeatedly for my credentials. Since SOCRadar Extended Threat Intelligence crawls the dark web and picks up any data being sold that includes my credentials, I believe there should be an improvement to avoid repeated notifications for already remediated records.
For how long have I used the solution?
I have been working in cyber security for more than five years.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is stable.
What do I think about the scalability of the solution?
Its scalability is good as it effectively covers broader threats.
How are customer service and support?
Customer support for SOCRadar Extended Threat Intelligence is good.
Which solution did I use previously and why did I switch?
We previously used other tools, including one named Cybel, but we switched to SOCRadar Extended Threat Intelligence because it covers a broader range of threats and features and is more user-friendly.
Which other solutions did I evaluate?
We evaluated Cybel as another option before choosing SOCRadar Extended Threat Intelligence.
What other advice do I have?
We have utilized SOCRadar Extended Threat Intelligence's unique dark web sources and have noticed significant impacts in identifying potential threats early.
I have utilized SOCRadar Extended Threat Intelligence's managed takedown services to initiate the takedown of impersonate domains not owned by us, which is a valuable feature for our organization.
In the phishing workflow, we have submitted impersonate domains and origin senders, and SOCRadar Extended Threat Intelligence has facilitated their takedown, aiding in our internal threat remediation.
I would rate this product an eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Continuous threat intelligence has strengthened attack surface control and protected leaked credentials
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is to monitor the attack surface and then to monitor credential leakage and Digital Risk Protection like impersonation domain and impersonation web, and data breach. I also use SOCRadar Extended Threat Intelligence to integrate IOCs to SIEM, to firewall, and to EDR.
One specific example of how I use SOCRadar Extended Threat Intelligence for credential leakage or digital protection is when I receive an alert about password leakage, and from there I can see whose password is leaked and sold on the dark web, and then I can tell the user and ask them to change the password.
I can add that another example is about SOCRadar Extended Threat Intelligence having Attack Surface Management where I can monitor vulnerabilities on our public-facing assets, and SOCRadar Extended Threat Intelligence will scan our assets regularly and report to us if there are vulnerabilities. I can check the vulnerabilities and then fix and patch them as recommended by SOCRadar Extended Threat Intelligence.
Regarding SOCRadar Extended Threat Intelligence's AI capabilities, I believe it has good governance and security since SOCRadar Extended Threat Intelligence has an NDA in place, meaning I trust them to handle our sensitive data.
I have utilized SOCRadar Extended Threat Intelligence's unique dark web sources, which include IOCs such as malicious IPs and domains, and I can integrate these sources into our security tools like SIEM and firewall to identify potential threats early and block them.
I have utilized the managed takedown services provided by SOCRadar Extended Threat Intelligence when there are impersonation cases involving domains, websites, or social media accounts, allowing us to take down malicious accounts or sites.
How has it helped my organization?
SOCRadar Extended Threat Intelligence has positively impacted my organization because it provides tools that alert us if there is credential leakage or vulnerabilities on our public-facing assets, and I can also read news about the dark web. SOCRadar Extended Threat Intelligence provides dark web news that helps me learn about industry trends and data breaches other companies face, allowing us to protect our assets.
What is most valuable?
The best features SOCRadar Extended Threat Intelligence offers are its Threat Intelligence capabilities, which I believe are great, along with many integration supports for third-party tools like EDR, SIEM, and firewall, making it useful to enrich our security tools. SOCRadar Extended Threat Intelligence also has sandboxing tools that are useful for checking if a file attachment is clean or malicious, and if it is malicious, I can see the behavior of the file to take appropriate action, such as blocking the sender. Additionally, the attack surface feature is very good because SOCRadar Extended Threat Intelligence provides risk ratings for our company, allowing us to fix vulnerabilities and address open ports.
The sandboxing tool has helped my team when we have suspicious files, such as email attachments or files downloaded from the internet that we do not know if the source is trusted. We use the sandboxing tools to test the files to check if they are malicious.
What needs improvement?
Regarding improvements for SOCRadar Extended Threat Intelligence, I believe the integration can be improved, and there should be more regular updates for new IOCs and observable data that exist on the dark web.
About reporting, I need SOCRadar Extended Threat Intelligence to add customizable reporting so I can adjust the content of the reports instead of just using templates.
The reason I give it an 8.5 is that the standout feature is the fast notification regarding data leakage, but the negative aspect is the lack of customizable reporting. Another concern is about credit usage; I need credits to add assets, and there is a limitation, so perhaps SOCRadar Extended Threat Intelligence can remove that limitation.
For how long have I used the solution?
I started using SOCRadar Extended Threat Intelligence in 2023, approximately three years ago.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is stable.
What do I think about the scalability of the solution?
For scalability, I can simply purchase additional credits to increase my asset limits, making it easy to scale my licenses.
How are customer service and support?
The customer support is good, as SOCRadar Extended Threat Intelligence provides 24/7 global support that responds quickly and effectively when I encounter problems.
I would rate the customer support a 9 due to its quality.
Which solution did I use previously and why did I switch?
Previously, I used Anomali ThreatStream and CTM360. All of them are good, but I switched primarily due to pricing, as Anomali is more expensive. Each tool has its pros and cons; Anomali excels as a Threat Intelligence Platform for correlating multiple threat feeds, while SOCRadar Extended Threat Intelligence is better at Attack Surface management and Digital Risk Protection.
How was the initial setup?
The setup is straightforward, and the licensing is flexible as it uses credits.
What was our ROI?
I have seen a return on investment because I can prevent data breaches, which would be more costly than the price of SOCRadar Extended Threat Intelligence. It also enhances my security tools when using the IOCs from SOCRadar Extended Threat Intelligence, saving both time and money.
What's my experience with pricing, setup cost, and licensing?
Regarding my experience with pricing, I notice that SOCRadar Extended Threat Intelligence increases the price every year, which I believe is not ideal as it continues to rise. The setup is straightforward, and the licensing is flexible as it uses credits.
Which other solutions did I evaluate?
Before choosing SOCRadar Extended Threat Intelligence, I evaluated other options, including CTM360 and Anomali.
What other advice do I have?
My advice for others considering SOCRadar Extended Threat Intelligence is to buy the correct amount of licenses since SOCRadar Extended Threat Intelligence is strict regarding licensing. If you purchase credits that cover fewer assets than you have, you will not cover all your assets, which could jeopardize your company's security.
The freemium tier offered by SOCRadar Extended Threat Intelligence is beneficial for exploring its features as you can try it for free before considering purchasing credits for your company.
I believe SOCRadar Extended Threat Intelligence is already good and does not require additional improvements that we have not mentioned. My overall review rating for SOCRadar Extended Threat Intelligence is 8.5 out of 10.
Brand monitoring and threat hunting have strengthened our protection across clients and social media
What is our primary use case?
My main use case for SOCRadar Extended Threat Intelligence is to monitor my clients, check if any suspicious activities are observed over the internet or on the black market, and I also use it for brand monitoring. It is a helpful tool for us.
A specific example of how I have used SOCRadar Extended Threat Intelligence for brand monitoring or catching suspicious activities is that we get alerts from SOCRadar Extended Threat Intelligence itself, such as for the Facebook impersonating accounts. We do not see these things normally, but when we get alerts, we know someone has created a channel regarding our brand and it is a misuse. For black market purposes, we receive alerts, obtain them, and check the credentials, and this way we work.
I use SOCRadar Extended Threat Intelligence not just for threat intelligence but also for my own research on threat hunting, which is a good specific feature in SOCRadar Extended Threat Intelligence where I can check any domain, any IP, or any username to see if any data is available over the domain.
How has it helped my organization?
SOCRadar Extended Threat Intelligence has positively impacted our organization by helping us stay in good posture and shows us how many users have been impacted. It helps us make our business strong regarding brand monitoring, PII exposure, black market activities, and checking user data on social media, enabling us to stay protected and ahead. For example, during the FortiBleed event, we checked if it was related to us or our client, we observed this and informed them to check all their users, and we were able to log in, which was crucial. We are not merely waiting for an attack; we can significantly lessen the impact.
What is most valuable?
In my opinion, the best features SOCRadar Extended Threat Intelligence offers are brand monitoring, CTI, and currently the executive one.
Out of those features, I find myself using brand monitoring the most because it depends on the client scenario based on mostly clients focusing on what impact is on their brand, such as Facebook or any social media or any fake accounts. They do not usually go for the CTI, so we often use these tools as advanced brand protection.
I appreciate the new feature where we can add social media accounts ourselves, allowing us to receive alerts if we do not observe any alert, and we can add accounts manually when we see Facebook or Instagram accounts. We can initiate the takedown, which I observed to be an excellent feature. For the executive feature, you can take down from the forum, which is also good for VIP users.
The noise minimization capabilities within the agentic phishing workflow are very good; if someone creates a domain, that does not automatically mean we must get an alert. The AI agentic modifies the rule, and it only gets triggered based on impactful events; thus, we avoid most false positives, ensuring we get alerts when necessary.
What needs improvement?
I think SOCRadar Extended Threat Intelligence can be improved by adding good keywords, as keywords are critical. Additionally, they need to enhance AI-generated scores for parked or normal domains because sometimes we receive impersonating domains based solely on the AI score. There also need to be time adjustments since I work in India but receive alerts based on UST time, which sometimes causes delays that impact our business.
The reporting feature is good now, though I would say the timing of the alerts can be improved since sometimes there are delays, and they scan by themselves for a day before we receive alerts.
For how long have I used the solution?
I have been using SOCRadar Extended Threat Intelligence for the past three years.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is stable.
What do I think about the scalability of the solution?
The scalability of SOCRadar Extended Threat Intelligence is rated at nine.
How are customer service and support?
I would rate customer support at ten.
Which solution did I use previously and why did I switch?
We previously used CyberArk and Cybel, but the solutions were not satisfactory, so we moved to SOCRadar Extended Threat Intelligence.
How was the initial setup?
My experience with pricing, setup cost, and licensing is very good; I can quickly check how many tokens are required for domain utilization and make budget adjustments. It is wonderful and allows for easy minor changes.
What was our ROI?
I have seen a return on investment; for example, with user creations, many people create numerous accounts, but not everyone uses SOCRadar Extended Threat Intelligence. We focused on one or two main accounts and made use of the webhook feature to get alerts on Teams for critical updates. This way, our costs regarding users have diminished, and we can monitor significant events.
Which other solutions did I evaluate?
We did not evaluate other options before choosing SOCRadar Extended Threat Intelligence; we just appreciated SOCRadar Extended Threat Intelligence's features.
What other advice do I have?
My advice to others looking into using SOCRadar Extended Threat Intelligence is to use the demo first, check your keywords, run them, and see how it goes because SOCRadar Extended Threat Intelligence helps us with its ease of use, making it a wonderful and simple tool that is efficiently strong and easy to understand. I would rate this product at nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized threat intelligence has improved our visibility and accelerated incident response
What is our primary use case?
I used SOCRadar Extended Threat Intelligence at my previous company, Gurok Holding, based in Kutahya, for 5 years.
Socradar Cyber Threat Intelligence Aggregates automated feeds on Indicators of Compromise (IOCs), active cyber campaigns, global ransomware trends, and detailed threat actor profiles ,External Attack Surface Management (EASM) ,Advanced Dark Web Monitoring and finally Supply Chain Support ...
We integrated our sources, websites, IP addresses, and some sources with SOCRadar Extended Threat Intelligence. We used threat intelligence, vulnerabilities, and monitored and analyzed the current threats and resolve status.
I remember that there was one threat on our web server, and our web server and SOCRadar Extended Threat Intelligence notified us about the threat and vulnerabilities. We resolved it with SOCRadar Extended Threat Intelligence.
Once, one of the IP addresses we were using for email was blacklisted, and Socradar warned us immediately.
We primarily use Azure and Vodafone and onpremise servers for SOCRadar Extended Threat Intelligence.
SOCRadar Extended Threat Intelligence includes dark web intelligence. When you define your VIP addresses such as email or management board email address or some VIP email address, you can see if there is a breach or password or company-related email breaches. This is a very useful feature.
We integrated SOCRadar Extended Threat Intelligence with FortiGate firewall. We have a lot of FortiGate firewall and FortiGate Analyzer and McAfee SIEM, which is now rebranded as Trellix. We integrated these with SOCRadar Extended Threat Intelligence.
The integration with FortiGate and Trellix made our threat response processes faster and more efficient because we are feeding global threat intelligence. It is very useful for SIEM. You can define in McAfee or Trellix SIEM a global threat intelligence source, and you can see a lot of different sources' threats from SOCRadar Extended Threat Intelligence. Because Trellix also has its own threat intelligence source, you can add more threat intelligence from SOCRadar Extended Threat Intelligence. This is very useful.
We utilized the Attack Surface Threat Assessment, ASTA feature. It is very useful. We used Trend Micro Email Gateway, and I also integrated it with SOCRadar Extended Threat Intelligence. It is a very useful feature.
We can save time on a lot of features because with previous solutions, we were unable to see all of the threats in a central point. This was the main problem for us. There are a lot of sources, and you need to look at every source. With SOCRadar Extended Threat Intelligence, you can integrate all of the sources in a central location, and you can see all of the threats. There is also a ticket management system where you can see the problem threat, and you can add comments on what you have done and whether it is resolved or not. This is very useful, especially for management purposes.
How has it helped my organization?
It increases your efficiency and speed, allowing you to respond to threats in a timely manner.
What is most valuable?
You can find out new threats and security incidents with SOCRadar Extended Threat Intelligence. You can see the new vulnerabilities when you are using your products. This is very useful.
SOCRadar Extended Threat Intelligence has improved security in my organization, but there are some problems. Sometimes there are too many alarms, which can become quite tiring.
We have a lot of information infrastructures, and SOCRadar Extended Threat Intelligence has improved our security, but we do experience some alert fatigue. There are a lot of web servers. We also integrated SOCRadar Extended Threat Intelligence with the SIEM. We can see together, and we can see all of the threats and new threats, especially.
If you integrate all internal sources, IP addresses, and services to SOCRadar Extended Threat Intelligence, you can view all of the sources together in a single monitor and area. You can also view all the tickets and vulnerabilities and threats. This is very useful.
What needs improvement?
I can see that the AI capabilities of SOCRadar Extended Threat Intelligence now seem very limited, but I think that over time, it will be improved.
Sometimes the output of SOCRadar Extended Threat Intelligence is very accurate, but sometimes you need to check whether it is real or not. There are some problems with accuracy.
For how long have I used the solution?
I have used SOCRadar Extended Threat Intelligence 5 years in Gurok Holding.
What do I think about the stability of the solution?
SOCRadar Extended Threat Intelligence is very stable.
What do I think about the scalability of the solution?
Threat intelligence scalability of SOCRadar Extended Threat Intelligence is very good. You can resize to any needs. You can add more resources, and this is dependent on the price. There is no problem. You can add 100 IPs or 1,000 IPs. There is no problem.
How are customer service and support?
Customer support for SOCRadar Extended Threat Intelligence is very good. There are some levels: level one, level two, or level three. When you open a ticket, they generally answer immediately.
One time I had a problem and I opened a support ticket for SOCRadar Extended Threat Intelligence. The customer support responded to me in one hour because there was a problem with the SOCRadar GUI. They resolved it in a very quick time.
Which solution did I use previously and why did I switch?
McAfee Global Threat Intelligence (GTI) ,McAfee GTI was more focused on its own platform, while Socradar had a much wider range of options.
How was the initial setup?
The initial setup takes time; you need to create a good inventory and prioritize items according to their importance. If your preparation is correct and sufficient, the setup will be quick.
What about the implementation team?
We did it together with the Socradar team.
What was our ROI?
The primary driver of SOCRadar's ROI is the prevention of major security incidents—such as data breaches, ransomware, and third-party supply chain compromises.You can automate many processes, reduce the number of people involved, and get more accurate results.
What's my experience with pricing, setup cost, and licensing?
Every year, we request the price, from SOCRadar Extended Threat Intelligence. They ask what you have, the source and IP address or domain. We can take our infrastructure and environment and check if there is a new source or something else. They can make a special price for us because we were long-time customers.
Which other solutions did I evaluate?
I cannot remember whether I evaluated other options before choosing SOCRadar Extended Threat Intelligence. It was a very long time, maybe six or seven years ago.
What other advice do I have?
8
It is a very good tool and very useful.
The tiers and flexible pricing of SOCRadar Extended Threat Intelligence sometimes change because we are a very long customer for SOCRadar. Our company started using SOCRadar Extended Threat Intelligence maybe six or seven years ago. Due to this reason, SOCRadar makes special discounts for us.
I have not utilized the managed takedown services provided by SOCRadar Extended Threat Intelligence. I remember there was some domain related to our services, and we talked about the takedown of the domain. They requested an extra price for this service.
According to me, SOCRadar Extended Threat Intelligence is a very good product with competitive pricing. I rate this review an 8 out of 10.
Unified threat intelligence has strengthened visibility and prioritizes response to external risks
What is our primary use case?
Our main use case is in Cyber Threat Intelligence, CTI, and we use SOCRadar Extended Threat Intelligence to monitor the surface, deep, and dark web for emerging threats, leaked credentials, brand impersonation, and threat actor activity. For example, we use the platform to identify exposed credentials related to our organization, assess the potential business impact, prioritize the risk, and coordinate remediation with the security team before the information could be exploited.
I have been using SOCRadar Extended Threat Intelligence since the beginning of our project. I was involved from the initial implementation. I have used the platform throughout the project to support threat intelligence activity, monitor the threat landscape, and strengthen our cybersecurity capabilities.
What is most valuable?
One of the biggest advantages of our main use case with SOCRadar Extended Threat Intelligence is having multiple threat intelligence capabilities consolidated in a single platform. It provides continuous visibility and external detections, helping us prioritize risk based on their potential business impact and enable faster, more informed decision-making. It also improves collaboration between threat intelligence, SOC, and incident response teams by providing actionable and contextualized intelligence.
The features that stand out the most in SOCRadar Extended Threat Intelligence are the External Attack Surface Management, Dark Web Monitoring, Digital Risk Protection, and threat intelligence capability. I also appreciate the platform's ability to provide contextual intelligence, monitor leaked credentials, and brand impersonation, and deliver actionable alerts that help prioritize remediation efforts. Another strength is having these capabilities integrated into a single platform. It makes it easy to investigate threats, assess business impact, and support fast decision-making for security teams.
SOCRadar Extended Threat Intelligence has improved our organization's visibility into external cyber threats and helped us identify potential risks early. This has enabled us to prioritize remediation efforts based on risk and business impact rather than reacting after an incident occurs. For example, by identifying exposed credentials and monitoring external attack surface changes, we were able to notify the appropriate team, reduce exposure, and strengthen our overall security posture. It has also supported faster investigation and more informed decision-making through actionable threat intelligence.
What needs improvement?
Overall, my experience with SOCRadar Extended Threat Intelligence has been positive. One area of improvement would be expanding customizing options for dashboard and reports, allowing organizations to tailor the view more closely to different stakeholders. I also think additional integration with third-party security tools and more flexible automation capabilities would further streamline security operations. As the threat landscape evolves, continuously expanding threat intelligence coverage and enrichment would also add value.
For how long have I used the solution?
I have been working in the cybersecurity field for over three years. During this time, I have gained experience in cybersecurity, cyber threat intelligence, security operation, governance, vulnerability management, digital forensics, and supporting security initiatives across the banking and financial service sector.
What's my experience with pricing, setup cost, and licensing?
I am not directly involved in licensing and the budget planning, so I cannot comment on the price from a personal perspective regarding SOCRadar Extended Threat Intelligence. However, my impression is that having freemium options and flexible licensing can help organizations evaluate the platform before making a large investment. This can reduce adoption risk and make it easy to justify the business value based on real-world use cases and outcomes.
What other advice do I have?
In my experience, the AI capabilities of SOCRadar Extended Threat Intelligence have generally been accurate and reliable when used to support threat intelligence and prioritizing. The information has been trustworthy, especially when combined with the contextual threat intelligence and the analysis validation. As with any AI-driven capability, I consider it a decision support tool rather than a replacement for human analysis. But it has helped improve efficiency and accelerate investigations.
I have utilized SOCRadar Extended Threat Intelligence's unique dark web sources as part of our cyber threat intelligence activity. This source has helped improve our visibility into potential threats, including leaked credentials, exposed data, threat actor discussions, and IOCs, indicators of compromise. The main impact has been the ability to identify potential risks early, validate the exposure, and provide actionable intelligence to security teams, so they can take preventive measures before a threat escalates into a security incident.
I provided an overall rating of eight for this review.