

Anomali and SOCRadar Extended Threat Intelligence are competitive products in the threat intelligence platform category. Based on data comparisons, SOCRadar tends to have the upper hand in feature richness due to its comprehensive capabilities, while Anomali excels in customer service satisfaction.
Features: Anomali offers robust analytics, extensive threat data visibility, and integration capacities as its most valuable features. SOCRadar provides a comprehensive threat intelligence feed, automated threat detection, and a strong emphasis on proactive threat management, particularly through automation.
Ease of Deployment and Customer Service: Anomali is known for straightforward deployment and high customer satisfaction in support services. SOCRadar offers a flexible deployment model with a focus on automation, which may require additional setup but is supported by dependable post-deployment services. Anomali users report higher satisfaction with ongoing support.
Pricing and ROI: Anomali's setup costs are regarded as an investment with favorable ROI thanks to its extensive feature set and support. SOCRadar may have a higher initial cost, yet its advanced functionalities and automation capabilities suggest an enhanced ROI over time, reflecting the value of its pricing for those who prioritize cutting-edge automation.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
The platform aggregates intelligence from multiple sources and provides contextual insights, reducing the manual research required for tasks that previously involved manual dark web searches or correlation across different threat intelligence sources.
Through SOCRadar Extended Threat Intelligence, we are enabled and we got a chance to provide proactive security to the clients.
We proactively blocked the IOCs provided by SOCRadar Extended Threat Intelligence before breaches occurred in other banks and financial industries.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
SOCRadar provides IOC-related insights that correlate with recent campaigns and geopolitical tensions, enabling us to understand whether the information suits the financial services or retail sectors.
When you open a ticket, they generally answer immediately.
I can tell you they are super fast, super helpful, and they seem to be quite knowledgeable.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
I rate the scalability of SOCRadar Extended Threat Intelligence at ten out of ten.
Another aspect of its scalability is that it continuously updates threat intelligence feeds and can easily accommodate new clients or assets without major changes to the platform.
It is scalable because you can have multiple sources and multiple customers, with everything going through the API.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
SOCRadar Extended Threat Intelligence is a very stable tool with no lack of performance.
SOCRadar Extended Threat Intelligence is definitely stable and provides much better security compared to any other solution.
SOCRadar Extended Threat Intelligence is good and stable.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
If the pricing were structured as a flat fee of €70,000 or €30,000 with unlimited searches and unlimited credits, I would see much greater value in the solution.
This improvement could focus on customizable reporting and dashboards, along with expanded automation and API integration.
Pricing, interface, customization, AI, and integration could be improved.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with Anomali's pricing is that it is higher compared to other open-source alternatives.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
When compared to the competition such as Group-IB or Recorded Future where they gave me a very high price, SOCRadar Extended Threat Intelligence pricing is really much better for a very good set of features.
My experience with SOCRadar Extended Threat Intelligence concerning pricing, setup cost, and licensing has been generally positive, as the platform offers a flexible pricing model and modular licensing that makes it easier for organizations to scale as their threat intelligence needs grow.
I think the pricing, setup cost, and licensing of SOCRadar Extended Threat Intelligence are good.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
With features such as dark web monitoring and external attack surface visibility, we can identify potential threats such as leaked credentials, which improves our overall response to threats and strengthens our security posture.
The accuracy and reliability of SOCRadar Extended Threat Intelligence is very high based on the artificial intelligence used.
A credential user was stolen by an infostealer, and we detected this through SOCRadar Extended Threat Intelligence before any incident occurred.
| Product | Mindshare (%) |
|---|---|
| SOCRadar Extended Threat Intelligence | 2.2% |
| Anomali | 3.8% |
| Other | 94.0% |


| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 3 |
| Large Enterprise | 7 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
SOCRadar Extended Threat Intelligence enables users to identify and mitigate cybersecurity risks through comprehensive threat visibility and real-time monitoring.
Organizations utilize SOCRadar Extended Threat Intelligence for early detection and proactive defense against potential cyber attacks. With its robust features, users gain enhanced security posture and informed strategic decision-making. Detailed analytics and actionable insights contribute to improved threat response and management, making it a valuable tool in the cybersecurity landscape.
What are the key features of SOCRadar Extended Threat Intelligence?
What are the benefits or ROI that users should look for in reviews?
SOCRadar Extended Threat Intelligence finds application across multiple industries such as finance, healthcare, and retail, where cybersecurity is critical. In finance, it helps secure sensitive financial data. Healthcare organizations use it to protect patient information. In retail, it safeguards against data breaches and fraud, ensuring safe consumer transactions.
We monitor all Threat Intelligence Platforms (TIP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.