

Fortinet FortiSandbox and Anomali are leading solutions in the cybersecurity domain. Fortinet FortiSandbox has an upper hand in advanced threat detection due to its comprehensive security ecosystem, while Anomali gains the edge with its enriched threat intelligence and data analysis.
Features: Fortinet FortiSandbox utilizes machine learning for detecting advanced persistent threats, integrates seamlessly with Fortinet's security infrastructure, and offers automated threat response. Anomali aggregates data from diverse sources providing actionable insights, emphasizes context enrichment for proactive threat hunting, and supports extensive threat investigation.
Room for Improvement: Fortinet FortiSandbox could enhance its scalability strategies and augment its user interface to further simplify usability. Additionally, Fortinet's integration with non-Fortinet products can be expanded. Anomali might benefit from reducing initial deployment complexity, improving data processing speed, and broadening data set coverage to enhance its threat intelligence platform.
Ease of Deployment and Customer Service: Fortinet FortiSandbox offers smooth integration with other Fortinet products, requiring minimal setup, and is praised for rapid customer service. Anomali needs more initial setup yet provides comprehensive support to help clients make the most of its intelligence-driven features, offering substantial ongoing assistance.
Pricing and ROI: Fortinet FortiSandbox is valued for its cost-effective setup appealing to budget-conscious enterprises, providing quick ROI through its integrated defense systems. Anomali, although associated with higher initial costs, delivers strong returns through significant security gains over time with its exhaustive threat intelligence capabilities.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
Sometimes the technical engineer is very good and helpful, and sometimes we go through many processes until it gets escalated to a higher level or to another advanced technical engineer.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
Fortinet FortiSandbox works fine, is easy to manage, and functions well.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
I think Fortinet FortiSandbox could introduce more automation tools and AI tools.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
The cost is in the mid-range.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
The smooth integrations between Fortinet FortiSandbox and other Fortinet solutions such as FortiWeb and FortiFirewall and with other Fortinet environments are what I really appreciate.
| Product | Mindshare (%) |
|---|---|
| Fortinet FortiSandbox | 4.8% |
| Anomali | 3.4% |
| Other | 91.8% |

| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 13 |
| Large Enterprise | 9 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
Fortinet FortiSandbox is a robust cybersecurity platform featuring advanced threat detection and dynamic behavior analysis. It integrates seamlessly with Fortinet systems, offering both on-premises and cloud deployment options to enhance protection across networks.
FortiSandbox is a powerful tool for organizations seeking to strengthen their cybersecurity posture. By providing comprehensive protection against threats like ransomware, it ensures that malicious files are effectively scanned and quarantined. It integrates with FortiGate and FortiMail, enhancing email and endpoint protection. The platform facilitates analysis of suspicious activities, safeguarding network data and ensuring efficient handling of zero-day attacks. While offering customization options and AI-driven insights, challenges such as complex deployment, price considerations, and support response times are acknowledged. Improvements in third-party integration, endpoint protection, and email scanning capabilities are areas for growth.
What are the key features of Fortinet FortiSandbox?Industries implementing Fortinet FortiSandbox commonly value its malware detection and network security benefits. It's crucial for companies needing to inspect file threats and analyze suspicious activities, especially in sectors dependent on secure email and data transfer. Its ability to integrate with existing Fortinet solutions makes it an attractive prospect for those aiming to strengthen network integrity and avert potential cyber threats efficiently.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.