No more typing reviews! Try our Samantha, our new voice AI agent.
Evans Vasavan - PeerSpot reviewer
Security Engineer at GlobeSecure Technologies Pvt Ltd
Real User
Top 5Leaderboard
May 12, 2026
Automation has transformed threat hunting and has reduced false positives in daily investigations
Pros and Cons
  • "Anvilogic has positively impacted my organization by helping with both known and unknown threats already present in the current threat landscape, detecting SIEM tools such as Splunk, Microsoft Sentinel, Snowflake, and Databricks, optimizing those tools, and strengthening my organization in the cybersecurity realm."
  • "I chose a nine because, while Anvilogic is excellent, there is room for improvement in terms of the false-positive reports that have been presented and the AI pattern that can be improved."

What is our primary use case?

Anvilogic serves as my cybersecurity company's platform that provides detection, SIEM support, and SOC investigation, along with the implemented MITRE ATT&CK framework.

A specific example of how I use Anvilogic in my daily work is that it provides threat detection, reports, detailed reports, detection engineering, and threat hunting, which is quite good.

Anvilogic's threat hunting feature has made my work easier because it supports advanced threats and attack scenarios, analyzing across platforms to detect both known and unknown threats, which proves very useful for my organization.

Anvilogic has changed how my team thinks about detection by improving detection engineering, reducing false-positive alerts, and integrating hybrid SIEM and data lake architectures, and so far, it has been beneficial.

What surprised me the most about Anvilogic once I started using it is the automation capability, which automatically detects and investigates threats such as malware and provides us with reports, making the automation aspect very strong in this software.

Since onboarding, my usage has evolved. During the first 90 days, the software wasn't configured properly, and we were just understanding its basics. As use cases increased daily, we altered and modified some policies and rules to reduce false-positive reports.

What is most valuable?

Anvilogic's best features are detection, SIEM support that is logged into the SIEM, AI detection in the SOC workflow, as well as threat detection and correlation of that particular software.

Anvilogic's AI detection in the SOC workflow stands out compared to other solutions I've tried because the accuracy of the AI makes it the best software for my organization. The AI agent assists with detection and threat creation, analyzes behaviors, and triggers alerts if any suspicious behavior occurs, along with investigation and MITRE ATT&CK mapping, which helps me significantly.

Anvilogic has positively impacted my organization by helping with both known and unknown threats already present in the current threat landscape, detecting SIEM tools such as Splunk, Microsoft Sentinel, Snowflake, and Databricks, optimizing those tools, and strengthening my organization in the cybersecurity realm.

I have seen a reduction in response time as a specific outcome. Due to SIEM modernization and SOC automation, it has helped me significantly by reducing false-positive reports and alerts.

What needs improvement?

I chose a nine because, while Anvilogic is excellent, there is room for improvement in terms of the false-positive reports that have been presented and the AI pattern that can be improved.

For how long have I used the solution?

I have been using Anvilogic for three years.

Buyer's Guide
Anvilogic
September 2026
Learn what your peers think about Anvilogic. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,683 professionals have used our research since 2012.

What do I think about the stability of the solution?

Anvilogic is quite stable.

What do I think about the scalability of the solution?

On a scale of one to ten, I would rate Anvilogic's scalability as a nine.

How are customer service and support?

The customer support of Anvilogic is good and quite responsive.

Which solution did I use previously and why did I switch?

We did not previously use any different solution and directly switched to Anvilogic.

How was the initial setup?

Before choosing Anvilogic, we did not evaluate other options and directly purchased it from a vendor who offered it to improve our organization's capabilities. After trying it for two years, it has been working well.

What about the implementation team?

I am from the technical department, so I do not have details about pricing, setup cost, or licensing, as that was handled by my management team.

What was our ROI?

I am not certain about return on investment, but I can say it is meeting what I needed and what is necessary for the organization.

What's my experience with pricing, setup cost, and licensing?

I am from the technical department, so I do not have details about pricing, setup cost, or licensing, as that was handled by my management team.

Which other solutions did I evaluate?

We did not previously use any different solution and directly switched to Anvilogic. Before choosing Anvilogic, we did not evaluate other options and directly purchased it from a vendor who offered it to improve our organization's capabilities. After trying it for two years, it has been working well.

What other advice do I have?

My advice to others looking into using Anvilogic is that they should try it at least once by conducting a proof of concept, and if their use cases are met, they can proceed with confidence.

When other teams ask about Anvilogic, I tell them it has helped significantly and has reduced work in reporting and investigation within my organization since adoption.

I have not considered what would break first if Anvilogic disappeared, but I would say the automation capability and reporting would negatively impact my organization.

Looking 12 months ahead, I see Anvilogic playing a bigger role as features evolve rapidly. Any improvements in false-positive reports or new features would definitely enhance its role in my organization.

The need for something better was triggered by the various threats present in the world, which needed to be improved and detected. For that reason, we chose to purchase this software, and having worked on it for the past two years, it satisfies our organizational use cases.

I rate this review a nine overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: May 12, 2026
Flag as inappropriate
PeerSpot user
reviewer2741304 - PeerSpot reviewer
Director, Cybersecurity at a financial services firm with 10,001+ employees
Real User
Top 10
Jul 18, 2025
Holistic approach and good partnership have improved threat detection and efficiency
Pros and Cons
  • "By using this detection engineering platform, we can manage the entire detection engineering lifecycle, making it simple to show executives our progress, where we started, where we currently are, and what remains to be done."

    What is our primary use case?

    The main use cases for Anvilogic are around detections and detection engineering, trying to accomplish everything from identifying, prioritizing threats, baselining current capabilities, and, based on the threat prioritization, identifying the gaps and recommended use cases that we will have to deploy to bridge those gaps. These are the use cases that we have deployed.

    How has it helped my organization?

    We enjoy a good partnership with the Anvilogic product and engineering teams. We could put many features that were not available in their pipeline, and they are quick to deliver key features for us. Deploying Anvilogic required training our team to adopt it, but during the evaluation, we planned our success criteria, which included training. The Anvilogic team has been with us since the beginning of the evaluation until now, maintaining the same cadence of meetings to review progress and areas for improvement, which is very helpful as a customer because we know they are not just after the next sale.

    We were one of the first customers of Anvilogic, so many of its features were still under development when we began our journey with them. During the first 90 days, our primary focus was on migrating our detection content from the previous platform to Anvilogic. We concentrated on ensuring that this migration was done correctly. As we got more familiar with the platform, we discovered that Anvilogic has a highly robust detection library, with over 3,000 detections available. Their research team plays a crucial role in building these detections. Initially, we only deployed our custom detections that we had migrated, but over time, we began utilizing the detections from the library as well.

    With each new feature that was released, we found our experience improved significantly. For instance, we appreciated the option to automatically deploy recommended detections. The insights capability was particularly impactful for us, as it automatically identified recommendations for tuning our use cases and fixing issues that needed attention. It also helped us discover areas we weren't actively monitoring. These differentiating features made a significant difference in our operations. Although it took us nearly a year to fully adopt Anvilogic, we are now at a point where all key stakeholders on the security operations team love the product and the user experience. Most importantly, we value the level of support we receive from Anvilogic.

    From a maturity perspective, it has been very easy to measure our detection maturity over time. By using this detection engineering platform, we can manage the entire detection engineering lifecycle. Therefore, it’s simple to show executives our progress: where we started, where we currently are, and what remains to be done. We can also demonstrate how our maturity is evolving as new threats are identified and how we respond to them. All of this information is easy to justify thanks to the maturity dashboards available within the platform.

    What is most valuable?

    The features of Anvilogic that I prefer the most include having a holistic approach, from identifying the concept of analyzing maturity, doing it similarly to how we were doing it, looking at data maturity, data timeliness, data availability, and then into our detection maturity, and not only looking at prioritized detections needed for our specific area or domain, which was very important for us. From that point, deploying any recommended content is very simple. 

    Another important feature is the concept of a multistage threat scenario. After we started subscribing to Anvilogic, in future releases, they built out new features around automated threat detections and insights, such as health insights, hunt insights, and tuning insights, which are all neat features that allow my team to be more efficient.

    What needs improvement?

    I believe the future is very exciting, especially regarding the agentic approaches that have gained popularity following the rise of generative AI and large language models. We fully expect that within a year, Anvilogic will incorporate some level of agentic workflow capabilities. We might adopt these features solely within Anvilogic, or we may choose to integrate them with our own homegrown agentic workflows. This is the direction I see for Anvilogic's adoption moving forward.

    Anvilogic can be improved by focusing on the agentic way of doing things, similar to what we saw with Monte Copilot, which still needs work. The team is currently doing that work as seen in the roadmap, including having an agent for search, a detection agent, and a hunt agent, making those concepts come to fruition.

    For how long have I used the solution?

    We started looking at Anvilogic in late 2021, and then we started evaluating them in early 2022. By late 2022, we were already subscribed to Anvilogic.

    What do I think about the stability of the solution?

    Other than scheduled downtimes, I have not experienced any outages.

    What do I think about the scalability of the solution?

    Anvilogic scales effectively with the growing needs of our organization, and we don't have issues when onboarding our primary stakeholders into the platform. They can use it and receive necessary training and coaching, while the most important part is that we can meet with the Anvilogic customer success team almost weekly to review our adoption and share feedback.

    How are customer service and support?

    They are top-notch. They are always available. The customer service team is always available to us. The product management and the product engineering team are available to us if we need to review something with them.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Like many companies in this field, we utilize the MITRE ATT&CK framework to benchmark our current capabilities and build detections. Each year, at the beginning of the year, we download the latest version of the MITRE ATT&CK framework and assess our current detections. We tag and benchmark them, prioritize threats, and identify which use cases require new detection capabilities. Previously, this process took my team about two to three weeks, and we only performed it annually. However, around 2021, MITRE introduced the concept of sub-techniques. Initially, we were analyzing around 300 techniques, but now we have to analyze over 600. This effectively doubled the time that my team needed to complete the analysis. The work became repetitive and monotonous. As a result, I began searching for a solution that could streamline this process.

    When Anvilogic reached out, we discussed our detection processes, and they explained the capabilities of their platform. It felt like a meeting of the minds because what we were doing manually, they could automate. We realized this solution could save us a significant amount of time and make us more agile. By automating the processes of prioritization, identifying gaps, and deploying recommended detections, we could conduct threat prioritization exercises whenever necessary. Given that the threat landscape evolves almost daily, completing these exercises only once a year would put us at a disadvantage. When we recognized Anvilogic’s capabilities, we knew we had to consider their solution.

    In early to mid-2021, Anvilogic was the only one doing it this way. We were doing it manually while they were building it, and now there are many similar companies emerging, but we are happy with the success we have had with Anvilogic, choosing to partner with them and providing feedback and feature requests they can incorporate into subsequent releases.

    How was the initial setup?

    Since Anvilogic was a new concept and product, we needed to invest a lot of time in training our team to adopt it. Fortunately, during the evaluation phase, we established clear success criteria, one of which was training on Anvilogic. The Anvilogic team has been with us from the very beginning of this process and continues to support us today. 

    We have detections in multiple places. Most of our detections are on-prem, but there are some that are in the cloud. We use their integration pipelines to bring all of them together.

    What's my experience with pricing, setup cost, and licensing?

    It was fair. All of us like to deal with vendors who have a certain level of integrity, and the people who run Anvilogic have the highest level of integrity, which makes those sorts of negotiations much easier.

    Which other solutions did I evaluate?

    During our evaluation, we encountered many products making various promises. However, when it came to Anvilogic, they were able to identify key aspects of our processes during the evaluation period, which was impressive. This demonstrated that the Anvilogic product was engineered effectively and was functioning as intended. As a result, we started to trust both the team and the platform more.

    Since then, we have enjoyed a strong partnership with the Anvilogic product and engineering teams. There were times when features we needed were not initially available, but we were able to communicate our requests, and they were quick to prioritize and deliver those key features for us.

    What other advice do I have?

    If Anvilogic were to disappear tomorrow, my heart would break. My advice to Anvilogic is to prioritize my request. 

    I would rate Anvilogic a nine out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Anvilogic
    September 2026
    Learn what your peers think about Anvilogic. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
    913,683 professionals have used our research since 2012.
    reviewer2200662 - PeerSpot reviewer
    Sr. Manager, SOC, NOC, and Corporate Security at a computer software company with 1,001-5,000 employees
    Real User
    Jul 30, 2024
    The solution provides security analytics across multiple data platforms
    Pros and Cons
      • "Anvilogic's prebuilt rules and threat scenarios didn't work the best for us because many of the rules were geared toward a Windows environment, whereas we're more of a Mac environment, so many of them didn't necessarily fit with what we have."

      What is our primary use case?

      Our use cases for Anvilogic primarily revolve around detection engineering. We ingest the logs to figure out our cybersecurity score and improve detection.

      How has it helped my organization?

      Anvilogic provides security analytics across multiple data platforms. We integrate it with Splunk, but it also integrates with Snowflake and other data platforms. Overall, it's been good since many people aim to move away from Splunk to save on overall costs. The fact that it integrates with various data lakes, specifically Snowflake, the most popular, makes sense.

      Using Anvilogic decreases your detection engineering time while helping you build out additional detections and increasing your assurance and protection. It has decreased the engineering time by at least 20 percent. 

      It's been decent in terms of false positives. It doesn't necessarily reduce them, but the new detections have been pretty well-tuned so they aren't producing additional false positives. Anvilogic has increased security coverage by building out some detections, specifically in areas like Active Directory and IAM-type rules. While it hasn't reduced the overall cost, it may have helped the optimization side. 

      What is most valuable?

      We integrate Anvilogic directly with Splunk rather than using the Amplitude platform separately.  That has been helpful because we don't need to bring logs to a third-party source.

      Anvilogic's AI assistant is pretty good. It helps us build out detections within your environment. It has improved our detection logic by a small amount and slightly reduced the time involved in detection writing. Generally, the detection builder is decent.

      The drag-and-drop detection engine portal has been helpful because you don't need any programming experience. One area where the generative AI aspect has been helpful is when we are figuring out the specific threats about something that's triggered or similar campaigns. You can write in the latest from this type of detection that I'm looking at and get information back. 

      What needs improvement?

      We need more around case management. I know that's something on the road map. We would like a way to create a ticket that we can export into a third-party platform like Jira. Anvilogic's prebuilt rules and threat scenarios didn't work the best for us because many of the rules were geared toward a Windows environment, whereas we're more of a Mac environment, so many of them didn't necessarily fit with what we have. I know a few other people who use them, and they've worked out well there.

      For how long have I used the solution?

      I've been a full-time customer of Anvilogic for about two years now, and we did a proof of concept eight months or so before we became a customer.

      What do I think about the stability of the solution?

      We haven't had any issues with stability.

      What do I think about the scalability of the solution?

      Anvilogic is as scalable as the environments you've integrated it with, whether it's Snowflake or Splunk.

      How are customer service and support?

      We have a biweekly standing call with the Anvilogic team to talk through detections and updates, but I can't think of a case where we've had to contact them outside of that call.

      How was the initial setup?

      The initial deployment was easy because we had it set up for our proof of concept, so it just took a little tuning, and we had it set up within a week. We had one person on our side working with somebody on their side. It's a cloud-based solution, but they push out updates on it. We haven't had any issues where it's broken on our systems, where we've had to lean in on the maintenance side.

      What was our ROI?

      We roughly broke even. If we had invested more or tuned our environment a little better, we might have come out on top.

      What's my experience with pricing, setup cost, and licensing?

      Anvilogic's pricing has been highly competitive. 

      Which other solutions did I evaluate?

      We did an extensive proof of concept for Anvilogic, Panther, Devo, Google Chronicle, Splunk, and a few different SIEM/detection engines. We did a breakdown based on our criteria and scoring on various features. Anvilogic outperformed the other tools that we tested.

      The price was right for the organization. They also offered a multiyear deal that kept the price down looking forward. We compared it to something like the Chronicle, which required us to export our data specifically to that. It required multiple areas for ingestion, bringing up operational costs on top of the licensing cost. It wasn't providing better detection support than Anvilogic because it was able to integrate with Splunk and our case. It was able to pull off of data that was already being ingested, when we needed to have it ingest in multiple locations.

      What other advice do I have?

      I rate Anvilogic seven out of 10. To prepare for Anvilogic, I recommend leaning into it. Take advantage of the support team and get some additional training. Use the workshops and commit to using the product. It's a tool that's only as good as the time you put into it. If you bring in the detection engine but don't put any time into creating those detections, then there's not much point. 

      Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
      PeerSpot user
      Buyer's Guide
      Download our free Anvilogic Report and get advice and tips from experienced pros sharing their opinions.
      Updated: September 2026
      Buyer's Guide
      Download our free Anvilogic Report and get advice and tips from experienced pros sharing their opinions.