

Recorded Future and Anomali compete in the threat intelligence market. Recorded Future appears to have an edge due to its robust threat intelligence feed and real-time data enrichment capabilities.
Features: Recorded Future stands out with its threat intelligence feed, browser plug-in for seamless comparisons, and dark web activity detection. Detailed vulnerability reports are also a strong suit. Anomali excels with substantial threat modeling capabilities, a versatile Threat Intelligence Platform, and powerful data correlation tools that streamline operations.
Room for Improvement: Recorded Future can improve by reducing reliance on deep and dark web analysis that can lead to inaccuracies, addressing high cost barriers for smaller firms, and enhancing email threat intelligence. Anomali could expand its integrator capacity, improve handling of large indicator volumes, and refine user interface management for better usability.
Ease of Deployment and Customer Service: Both Recorded Future and Anomali primarily deploy on public clouds, with Recorded Future offering private cloud support. Recorded Future's technical support receives mixed feedback, whereas Anomali's support is satisfactory. Both products allow ease of integration with external systems but suggest enhancements for out-of-the-box solutions.
Pricing and ROI: Recorded Future's pricing is high, targeted for large enterprises but offers substantial ROI for experienced users. Anomali's pricing is medium to high, maintaining customer satisfaction despite complex feed costs. Both platforms offer potential savings through threat management, although Recorded Future's initial costs might limit ROI for newer users.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
We have seen a return on investment as we have been able to identify leaked credentials and close those accounts off easily, thereby improving our security.
I have seen a return on investment as I explained earlier, it reduces the investigation time from days to minutes, and that is the biggest ROI;
A metric indicating a 30 to 40 percent reduction in time and effort from the SOC team, which reflects our return on investment.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
Recorded Future's customer support is excellent.
Whenever there are false positives, issues during upgrades, or alert enrichment, I reach out regarding these use cases, and they help us solve these issues promptly.
The customer support is frustrating and not efficient.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
This product significantly assists us on the scalability side, as we have not faced any roadblocks or downtime while using it.
Recorded Future can handle a large volume of data accurately without issues, accommodating our needs effectively.
Being a SaaS, Recorded Future generally does a good job in terms of scalability.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
Recorded Future is very stable, with a rating of nine.
Recorded Future is stable, and I have not experienced any downtime or reliability issues.
For reliability and stability, we are in a small security team, but the data Recorded Future provides and the stability of this product are very effective.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
The Insikt Group covers a narrow range of areas, which doesn't reflect my needs.
A possible improvement for Recorded Future would be better filtering options, particularly when dealing with large datasets.
It requires tuning to avoid alert fatigue, especially in high-threat environments like energy, where many threats seem relevant.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
Recorded Future is expensive, with a personal rating of eight for cost.
The price of Recorded Future is a bit high, especially for smaller teams working on a tight budget, but it is very effective and relatively competitive for large organizations.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
Having a layer of intelligence within my SIEM that reflects in Recorded Future, and being able to enrich the data at my SIEM, offers various angles that I wouldn't be able to see without it.
The tool helps our SOC team save 30 to 40 percent of effort due to the reduction of manual threat detection and false positives.
The platform uses machine learning to analyze the threat actor behavior, identify emerging vulnerabilities, and leaked credentials of any user account.
| Product | Mindshare (%) |
|---|---|
| Recorded Future | 6.7% |
| Anomali | 3.7% |
| Other | 89.6% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 3 |
| Large Enterprise | 14 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
Recorded Future offers a comprehensive platform for threat intelligence and brand monitoring, supporting real-time alerts and data mining to protect against cyber threats and enhance security insights.
Recorded Future integrates advanced threat intelligence, allowing for seamless data comparison, comprehensive monitoring of cyber threats, and the detection of dark web activities. Users receive real-time alerts, access to an expansive database, and customizable dashboards for enhanced SIEM insights. The platform's capabilities extend to leveraging social media investigations and providing personalized user experiences. Key competitors such as Mandiant and CrowdStrike create a competitive landscape. Areas for improvement include reducing false positives, refining pricing strategies for smaller markets, and enhancing email threat intelligence.
What are the key features?Recorded Future is a reliable tool for industries focusing on threat detection and risk management. It is employed for threat intelligence, brand monitoring, and cyber risk assessments. Clients use its cloud-based capabilities for activities such as threat hunting, forensic investigations, and continuous monitoring of cyber activities and data feeds. Industries benefit from its ability to alert on security threats and vulnerabilities, offering protection and maintaining brand reputation in an increasingly digital landscape.
We monitor all Threat Intelligence Platforms (TIP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.