Our primary use case for ThreatBook Threat Intelligence Platform (TIP) is reducing noise in SIEM logs, detecting the compromised hosts, and providing strategic threat statistics.
ThreatBook Threat Intelligence Platform (TIP) serves as a sophisticated cybersecurity tool that empowers users with real-time threat analysis, helping organizations anticipate and mitigate cybersecurity risks efficiently.
| Product | Mindshare (%) |
|---|---|
| ThreatBook Threat Intelligence Platform (TIP) | 1.5% |
| Recorded Future | 6.7% |
| CrowdStrike Falcon | 4.5% |
| Other | 87.3% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Threat Intelligence Platforms (TIP) | Jun 24, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Jun 24, 2026 | Download |
| Comparison | ThreatBook Threat Intelligence Platform (TIP) vs Recorded Future | Jun 24, 2026 | Download |
| Comparison | ThreatBook Threat Intelligence Platform (TIP) vs CrowdStrike Falcon | Jun 24, 2026 | Download |
| Comparison | ThreatBook Threat Intelligence Platform (TIP) vs Check Point Security Management | Jun 24, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Anomali | 4.0 | 3.7% | 92% | 12 interviewsAdd to research |
| Recorded Future | 4.2 | 6.7% | 100% | 18 interviewsAdd to research |
This platform offers comprehensive threat intelligence capabilities designed to support cybersecurity teams in quickly identifying threats and automating responses. TIP aggregates vast threat data, providing enhanced visibility into potential attacks. Its integration capabilities allow seamless connections with existing security infrastructures, improving overall defensive measures and enhancing incident response strategies.
What are the most valuable features?In industries like finance and healthcare, ThreatBook TIP supports tailored implementations, addressing sector-specific threats through targeted intelligence feeds. Its adaptable architecture ensures that users can customize the platform to meet industry-specific challenges effectively, resulting in improved risk management and strategic threat handling.
| Author info | Rating | Review Summary |
|---|---|---|
| Security Technician at ZhongTianKeJi | 5.0 | I use ThreatBook TIP to reduce SIEM log noise and detect compromised hosts. Its forecasting feature improves threat detection and operational efficiency. More platform integrations are needed. Before choosing it, I evaluated Anomali and EclecticIQ. There are no specific ROI numbers. |
| Security Technician at ZhongTianKeJi | 5.0 | We use ThreatBook to effectively monitor network traffic, detect abnormal behaviors, and provide contextual intelligence for threat hunting. Its low false positives and valuable features like compromise detection enhance our incident response, though improvements could include ITSM integration. |
| Security Technician at ZhongTianKeJi | 4.5 | We use ThreatBook TDP to monitor network traffic, detect attacks, and support threat investigation with high accuracy. Its features reduce noise and incident response time. While integration with our ITSM system is desired, we see no ROI yet. |
| Product Specialist at a tech vendor with 51-200 employees | 4.5 | I use ThreatBook for comprehensive oversight of our assets, allowing immediate response to threats and saving time on successful attack identification. Its fast visibility improved our security posture, though I'd appreciate an internal host isolation feature for compromised assets. |
Our primary use case for ThreatBook Threat Intelligence Platform (TIP) is reducing noise in SIEM logs, detecting the compromised hosts, and providing strategic threat statistics.
The best features ThreatBook Threat Intelligence Platform (TIP) offers are its significant improvement in the efficiency of our cybersecurity operation and the accuracy of our threat detection, along with the key value of its forecasting capability that provides insight into emerging threats.
The forecasting capability of ThreatBook Threat Intelligence Platform (TIP) has helped our team by constantly updating all the incidents, threat actors, and the cybersecurity trends related to our company and industry, and it has also aided us in writing and submitting a threat intelligence report to our customer and the board.
ThreatBook Threat Intelligence Platform (TIP) has positively impacted our organization by helping us generate the strategic threat focus reports and aiding us in decision-making, leading to improved cybersecurity operation efficiency.
ThreatBook Threat Intelligence Platform (TIP) could be improved by providing more integrations to support additional platforms.
Adding more integrations to support more options would enhance ThreatBook Threat Intelligence Platform (TIP).
I have been using ThreatBook Threat Intelligence Platform (TIP) for two years.
ThreatBook Threat Intelligence Platform (TIP) is very stable and excellent.
The scalability of ThreatBook Threat Intelligence Platform (TIP) is excellent; however, our current scale does not require expansion yet.
ThreatBook customer service is outstanding, with the team always responding promptly to our needs.
The customer support deserves a rating of 10.
Positive
ThreatBook Threat Intelligence Platform (TIP) is the first solution I have used.
The initial setup with ThreatBook Threat Intelligence Platform (TIP) was simple and smooth, with no difficulties.
I do not have specific numbers regarding the return on investment from using ThreatBook Threat Intelligence Platform (TIP).
My experience with pricing, setup cost, and licensing is that it is cost-effective and the price is reasonable, with very good overall value and quality.
Before choosing ThreatBook Threat Intelligence Platform (TIP), I evaluated other options such as Anomali and EclecticIQ. I chose ThreatBook Threat Intelligence Platform (TIP) because of the high accuracy of its IOC and their threat intelligence capability in the APAC region, resulting in the best performance after the POC.
ThreatBook Threat Intelligence Platform (TIP) has proven to be an excellent solution, and I highly recommend it without any needed improvements or extra features.
I rate ThreatBook Threat Intelligence Platform (TIP) a 10 out of 10 because of its performance, stability, high-accuracy threat intelligence, and excellent overall performance at a reasonable price.
We use ThreatBook to monitor the east-west and north-south network traffic and detect abnormal behaviors and provide contextual intelligence to support our threat hunting and incident response.
ThreatBook helps with threat hunting and incident response by providing very high accurate threat intelligence, aggregating all the alerts from attacker perspectives, and showing all the attack paths, which helped us easily do the attribution and threat investigation.
ThreatBook has very low false positives, allowing us to focus on the real threats and reduce a lot of work on noise reduction.
We purchased ThreatBook through the AWS Marketplace.
ThreatBook has positively impacted our organization by allowing us to detect all alerts and threats effectively. In the past, we needed to search logs from various sources, including terminals, DI servers, and firewalls, collecting a lot of logs and searching the internet for contextual information about threat actors. After using ThreatBook TDP, all alerts and contexts are easily displayed on the dashboard, making it very helpful for us.
During the incident response scenario, ThreatBook saves us over 80% of the time for each incident. We usually took about one day or two days for attribution and understanding how the attacker attacked us, but after using ThreatBook TDP, we usually take around one or two hours to finish all these tasks. Additionally, their AI techniques save a lot of time, allowing me to ask in natural language for explanations about the meaning and target of the attacker.
The most useful feature that ThreatBook offers is compromise detection, as it directly shows the number of compromised hosts on the dashboard so we can quickly identify which devices have been compromised. Another valuable feature is the intelligent aggregation.
The intelligent aggregation feature can gather all the alerts into incidents and show the attack paths and attack timeline from threat actor perspectives, providing a clear picture of the attack and how it occurred. This is really helpful for our threat hunting.
To improve ThreatBook, it would be great if TDP could integrate with our ITSM system to streamline tasks and incident management, which I hope will be provided in the future.
I chose a rating of nine to 9.5 instead of a perfect ten because while everything is perfect, we use an ITSM system, and it would be better if TDP could integrate with that system.
I have been using ThreatBook TDP for nearly three years.
ThreatBook is totally stable.
ThreatBook's scalability supports cluster mode and cascade mode, making it quite easy for us to manage since we have many offices in different regions.
Their customer success team is excellent, and the engineers understand both the product and our network environment as well as our operational requirements, hence it's excellent.
I would rate the customer support absolutely as ten.
Positive
We did not use any dedicated NDR solution before ThreatBook, but we conducted a lot of research and compared several NDR vendors prior to purchasing.
The initial setup with ThreatBook is very easy with no issues arising.
ThreatBook integrates well with other AWS services we use, working smoothly with our existing AWS infrastructure.
The configuration process requires almost nothing to be configured after the first setup, and the ThreatBook implementation team helped us fine-tune the detection rules based on our environment, so nearly nothing is done from our side.
We’ve seen strong ROI through reduced incident response times, increased threat visibility, and less time wasted on false positives.
The procurement process is easy because it operates on a subscription model; when I need it, I just pay for it.
The metering and billing experience is clear and straightforward, with the bill being very clear, showing no extra fees, and all costs displayed on the bills.
The pricing is a little bit high for the NDR market, but it is absolutely worth it given the high quality capabilities, and the licensing is flexible as I can pay based on my requirements.
We are just customers and do not have any business relationship with the vendor other than that. I was not offered a gift card or incentive for this review.
I think if you have never used an NDR solution, it's very important to choose a low false positive and high accuracy NDR solution. I want to emphasize that ThreatBook TDP is the best choice for you, and you can trust it.
My overall rating for ThreatBook is nine to 9.5 out of ten.
Mainly, we use ThreatBook TDP to monitor the east-west and north-south network traffic, detect abnormal behaviors, and provide contextual intelligence to support our threat hunting and incident response.
ThreatBook helps with our threat hunting and incident response by providing very high accurate threat intelligence, aggregating all the alerts from attacker perspectives, and showing me all the attack paths, which helps us easily to do the attribution and threat investigation.
One more thing is that ThreatBook has very low false positives, which allows us to focus on the real threats and reduces a lot of work on noise reduction.
During incident response scenarios, ThreatBook saves us over 80% of time for each incident, reducing the usual time taken from one or two days for attribution to just one or two hours, thanks to their AI techniques that allow me to ask in natural language to explain the meaning and the target of the attacker.
The most useful features ThreatBook offers are compromise detection, because it directly shows me the number of compromised hosts on the dashboard, so we can quickly identify which devices have been compromised, and another valuable feature is called intelligent aggregation.
The intelligent aggregation feature works by aggregating all the alerts into incidents, showing the attack paths and attack timeline from threat actor perspectives, providing a clear picture of the attack, how it attacks, which is really helpful for our threat hunting.
ThreatBook has positively impacted our organization by enabling us to detect all threats with contextual intelligence, which makes it easy to understand the attack context, and the visible alerts displayed on the dashboard helped us significantly.
It would be great if ThreatBook could integrate with our ITSM system to streamline the tasks and incident management, and I hope this feature will be provided in the future.
Everything is perfect, but I mentioned before that it would be better if ThreatBook integrated with our ITSM system.
I have been using ThreatBook TDP for nearly three years.
ThreatBook is totally stable.
Their customer success team is excellent, and the engineers understand both the product and our network environment and operational requirements.
I would rate the customer support absolutely as ten.
We didn't use any dedicated NDR solution before ThreatBook, but we did a lot of research and compared several NDR vendors before purchasing.
We evaluated some NDR solutions such as ExtraHop, Darktrace, and Cyber Command.
The initial setup with ThreatBook is very easy, with no issues at all.
Deploying ThreatBook in my environment is very easy, as it is plug and play, and the deployment process is smooth and quick.
After the first setup, there's nearly nothing that needs to be configured, as the ThreatBook implementation team helped us fine-tune the detection rules based on our environment, so nearly nothing is done from our side.
I didn't see a return on investment.
The procurement process is easy because ThreatBook is a subscription model, and when I need it, I just pay for it.
The billing experience is clear with no extra fees; all the costs are clearly shown on the bills.
The pricing is a little bit high for the NDR market, but it is absolutely worth it given the high-quality capabilities, and the licensing is flexible, allowing you to pay based on your requirements.
If you have never used an NDR solution, it's very important to choose a low false positive and high accuracy NDR solution, and I want to say that ThreatBook is the best choice for you, and you can trust it.
ThreatBook integrates well with other AWS services we use.
I rate ThreatBook 9 to 9.5 out of 10.
We use ThreatBook to have overview visibility of all our assets including if there are any compromised hosts or if there are any incoming attacks from external threats.
When we first deployed ThreatBook in our environment, it gave us a very immediate quick overview of our asset categories and quickly detected compromised hosts, including suspected crypto mining on one of our assets. We were able to attribute quite quickly to the compromised hosts what IP it was and if there were any affected other IPs around our network environment.
We check our ThreatBook dashboard every two to three days to see if there are any new compromised hosts or if there are any brute force attacks on any of our assets.
The visibility from ThreatBook was actually very fast, quite immediate, allowing us to take immediate action to block the incoming compromise or traffic, and from there we can do in-depth checks on the asset itself.
ThreatBook gives me a very quick overview of all our assets, and it actually tells me which attacks are successful so that I can attend to the attacks first instead of wasting time, helping me save a lot of time especially to crack down all the successful attacks in my network.
I remember an incident where we suffered a ransomware attack before the implementation of ThreatBook, which took us two days to find out which asset was being hit, but with ThreatBook it was almost immediate when the host was compromised; it reflects onto the dashboard immediately.
The best part about ThreatBook is that it gives me an immediate overview of the attacking, meaning I know which host has had a successful attack by the attackers, allowing me to quickly go to the respective host to check for any lateral movement from that host and block out the harmful traffic from my network immediately.
From using ThreatBook, our staff uses less time to understand our network situation, security posture, and reaction time.
We have not suffered from any attack for the past few months, which has relatively improved our network security.
I hope that ThreatBook can integrate a feature where if I detect any internal compromised hosts, I can block or isolate those compromised hosts within my internal network; that would be good.
I would want the isolation feature to work either automatically or manually; both work fine for me, but as long as I can isolate the internal compromised assets out of the network, it will be good.
I have been using ThreatBook for more than a year.
ThreatBook is very stable.
ThreatBook's scalability is very good, as they can offer either cascade or cluster for more powerful scaling.
The customer support for ThreatBook is excellent; if there's any need for support, I can easily get hold of them and the feedback is quite fast.
I rate ThreatBook's customer support as a nine.
Positive
We did not use any other solution before ThreatBook.
The setup for ThreatBook was very easy; it is almost a plug and play situation, where I just plug the device onto our network switch and it just works from there.
The initial setup with ThreatBook is very straightforward.
Before choosing ThreatBook, we did take a look at Mandiant.
If customers are looking for a solution that has a quick and easy setup to get immediate network visibility and to understand the immediate security posture, I would recommend ThreatBook to them; it's an easy-to-use solution.
My company does not have a business relationship with this vendor other than being a customer.
I was not offered a gift card or incentive for this review.
I do not have any additional thoughts about ThreatBook before we wrap up.
I rate ThreatBook a nine out of ten.