

Anomali and IRONSCALES are products in the cybersecurity space, each with unique strengths. Anomali excels in threat intelligence, ideal for identifying and analyzing threats, whereas IRONSCALES is notable for email phishing defense.
Features: Anomali's strengths include advanced threat detection, comprehensive threat intelligence capabilities, and API automation for extensive scalability. IRONSCALES provides efficient email threat detection, automated response capabilities, and a greatly effective phishing prevention mechanism.
Room for Improvement: Anomali can improve its ease of deployment, reduce integration complexity, and enhance email security functions. IRONSCALES may benefit from expanding training resources, lowering false positives, and increasing user customizability in email threat detection settings.
Ease of Deployment and Customer Service: Anomali typically involves complex integration suited for large-scale operations with reliable customer support. In contrast, IRONSCALES provides easy deployment and strong customer support, making it suitable for fast-paced environments.
Pricing and ROI: Anomali often has a higher setup cost but delivers substantial ROI for organizations focusing on threat intelligence. IRONSCALES features competitive pricing with faster ROI due to its focus on reducing phishing incidents, offering cost-effectiveness compared to Anomali's broader approach.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
Customer support for IRONSCALES is outstanding.
I would rate their technical support as very good, as they respond promptly when my team opens a ticket.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
If there were clickable drill downs on specific users or specific correspondence to relate them to certain types of mails, that would be beneficial.
Having a more user-friendly UI would make it easier to identify features and options when using the tool.
Though this isn't problematic for our users, the content could be updated more frequently.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with Anomali's pricing is that it is higher compared to other open-source alternatives.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
While I don't specifically oversee the pricing details, I understand that IRONSCALES is in the range of similar solutions while offering better results.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
IRONSCALES has positively impacted my organization by making email security simple in terms of controlling mails, understanding where the threats are, and protecting the organization itself.
The best features of IRONSCALES are that most alerts are validated through AI, which reduces the fatigue of alerts that need to be worked on by the team handling the alerts investigation part.
IRONSCALES excels at analyzing the intention, not just the content itself, but the sender's attempt to gain user attention.
| Product | Mindshare (%) |
|---|---|
| Anomali | 3.5% |
| IRONSCALES | 2.9% |
| Other | 93.6% |

| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 4 |
| Large Enterprise | 4 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
IRONSCALES delivers cutting-edge AI-driven email phishing detection and prevention, seamlessly integrating with Microsoft 365 for enhanced security.
IRONSCALES, with its advanced AI capabilities, focuses on email security by detecting phishing threats, mitigating business email compromises, and preventing impersonation. Its integration with Microsoft 365 strengthens spam filters, automatically responding to suspicious emails. The platform is used globally for threat inspection, quarantine, and end-user incident reporting. Staff training is enhanced through simulated phishing campaigns, offering an extra layer of protection beyond Microsoft's spam filters. Areas for improvement include better Google Suite integration, pricing adjustments, and enhanced reporting features.
What features make IRONSCALES stand out?In finance, IRONSCALES plays an essential role in safeguarding sensitive data from phishing attacks, ensuring compliance with industry standards. Educational institutions use IRONSCALES for training faculty and students on recognizing phishing attempts, thereby enhancing overall cybersecurity awareness. IT sectors leverage its capabilities for managing complex threat landscapes.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.