

Anomali and Cybersixgill operate within the cybersecurity platform category, with Cybersixgill holding an advantage due to its comprehensive threat intelligence capabilities.
Features: Anomali offers high-quality threat detection, robust integration capabilities, and a range of analytical tools, while Cybersixgill provides real-time monitoring, dark web intelligence, and agile threat tracking to stay ahead of emerging threats.
Room for Improvement: Anomali could enhance its integration with additional third-party tools, improve user interface intuitiveness, and expand analytical capabilities. Cybersixgill might benefit from improved open source intelligence gathering, streamlining its complex setup process, and enhancing multilingual support for broader accessibility.
Ease of Deployment and Customer Service: Anomali supports seamless integration through its straightforward deployment process and reliable customer support. Cybersixgill, although more complex to deploy, offers effective customer service to maximize the model's efficacy.
Pricing and ROI: Anomali provides competitive upfront setup costs with steady ROI, while Cybersixgill requires a higher initial investment but offers significant ROI through its advanced threat intelligence capabilities, promising greater long-term value.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
The return of investment was quick and easily seen within the first 90 days, and that is when an actual quarterly meeting, a QBR, would take place to be able to show that return on investment.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
The customer support is top-notch and excellent.
Cybersixgill's customer support replies within an hour or two or within the day.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
As small or as large as I want to be, Cybersixgill is able to accommodate any organization.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
During the onboarding, that is the most crucial part to make sure that the organizations who purchase Cybersixgill ensure that they actually have the right person or persons to go through the onboarding.
I hope that in the future, Cybersixgill can separate the leaked credentials by email and domain.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with Anomali's pricing is that it is higher compared to other open-source alternatives.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
Based on the needs of the customer, there was always a negotiation that could be done to get a slightly lower price.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
The best feature that Cybersixgill offers with respect to dark web intelligence is that they provide very good screenshots of where the particular data has been taken, which allows for better visualization and understanding of the scenario, with the source being indicated through onion links that can be reverse-engineered for further investigation.
What specifically stands out to me about the cyber threat intelligence feature is the speed and the depth from the data lake.
I appreciate that I can search in the dashboard for credentials by entering the domain directly rather than navigating through other sections, making it very easy to check the dashboard.
| Product | Mindshare (%) |
|---|---|
| Anomali | 3.9% |
| Cybersixgill | 2.5% |
| Other | 93.6% |

| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
Cybersixgill offers automated threat intelligence solutions designed to help organizations combat cybercrime through real-time detection and amplified incident response capabilities.
Cybersixgill provides a robust tool equipped with a vast array of features to monitor and analyze deep and dark web activities. Capable of delivering real-time, actionable alerts tailored to specific requirements, it aids security teams in conducting covert investigations swiftly. Its Investigative Portal empowers users with contextual alerts, vast data on threat actors, and detailed analysis of their profiles and history.
What are the most important features of Cybersixgill?Cybersixgill is implemented across industries to enhance cybersecurity by providing extensive monitoring of dark web activities related to malware, illegal sales, and exposed sensitive information. Its API capabilities support data collection and reporting, making it a vital tool for threat trend identification and reducing risks for multiple clients, operating efficiently as a software-as-a-service platform.
We monitor all Threat Intelligence Platforms (TIP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.