No more typing reviews! Try our Samantha, our new voice AI agent.

Anomali vs ZeroFOX comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 18, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Anomali
Ranking in Threat Intelligence Platforms (TIP)
4th
Average Rating
8.0
Reviews Sentiment
5.9
Number of Reviews
11
Ranking in other categories
Security Information and Event Management (SIEM) (21st), User Entity Behavior Analytics (UEBA) (9th), Advanced Threat Protection (ATP) (17th), Extended Detection and Response (XDR) (14th)
ZeroFOX
Ranking in Threat Intelligence Platforms (TIP)
8th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
3
Ranking in other categories
Digital Risk Protection (2nd)
 

Mindshare comparison

As of June 2026, in the Threat Intelligence Platforms (TIP) category, the mindshare of Anomali is 3.7%, down from 4.7% compared to the previous year. The mindshare of ZeroFOX is 2.5%, down from 4.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Anomali3.7%
ZeroFOX2.5%
Other93.8%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

TarunKumar11 - PeerSpot reviewer
Member Of Leadership Advisory Council at a tech company with 10,001+ employees
Strategic threat intelligence has improved detection speed and consistently reduces analyst workload
Anomali can be improved in various aspects. Its AI-driven automation can further advance, and AI-powered investigation summaries can improve. User experience could be enhanced through simplification of workflows. Better board-level cyber risk dashboards could provide easier visualization. Additionally, Anomali could work on simplifying the pricing structure. Although it excels in threat intelligence aggregation and operationalization, stronger GenAI capability, improved executive reporting, and a more intuitive workflow for analysts would further increase SOC efficiency and add more business value. Regarding Anomali's AI capabilities, governance and security are quite good. Anomali has incorporated AI and machine learning primarily to improve correlation and prioritization. These capabilities are valuable but could be more mature. The platform could achieve better threat correlation, prioritization, more anomaly detection, and allow AI to accelerate intelligence analysis while further improving quality and relevance. The accuracy and reliability of Anomali's AI output are fairly reasonable and good. The AI engine works well, but this capability could be improved. Better threat correlation with threat actors, certain indicators of compromise, malware, and campaigns is possible. Threat prioritization could increase, and alert noise could be reduced through further de-duplication. While reasonable, this is not the best available, and other products possibly have more AI maturity, such as Recorded Future and CrowdStrike Falcon.
AS
Senior Consultant at LTI - Larsen & Toubro Infotech
Efficiently identify and address online threats with timely alerts and thorough takedown capabilities
The most valuable features are its threat intel platform, which provides the latest trends and indicators of compromise (IOCs) that I can act on. I quickly obtain data, such as leaked email IDs and passwords, from the ZeroFOX portal or the threat intel portal when required. The platform's GUI-based features stand out and provide thorough takedown capabilities for domains, social media accounts, and phishing numbers.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR, or threat intelligence platform—operates in multiple shifts."
"Anomali has positively impacted my organization and my clients by helping them improve threat visibility, accelerate incident response, and make better use of their resources."
"Anomali positively impacts our organization, notably improving our vulnerability management program under reducing attack surface management."
"I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
"We now have a very robust collection of threat intelligence based on the capabilities that Anomali provides."
"With Anomali, we benefit by obtaining threat information prior to incidents, making our threat hunts proactive and having incident response plans ready, which saves almost 40% of the time from the traditional model."
"The feature I have found most valuable is credential monitoring. This feature is easy and quick."
"The most valuable aspect of Anomali is the threat modeling capability."
"ZeroFOX has no language limitations. It can detect many languages."
"I rate ZeroFOX a ten overall."
"ZeroFOX is valuable because it enables the detection of chatter on social media without depending on keywords and has no language limitations, as it can detect many languages."
"The best thing about the tool is that its backend team is pretty good and has a strong engineering team."
 

Cons

"I believe Anomali could be improved by making the user interface more user-friendly."
"Less code in integration would be nice when building blocks."
"An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsistent, as any company can use any tags for their reporting."
"A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
"My experience with Anomali's customer support has not gone so well for us."
"Anomali Enterprise could improve by combining all the other tools' features into one solution."
"I can mention one point regarding improvements for Anomali, which is more enhanced reporting flexibility."
"Support in the past has been top-notch, but recent trends indicate that it has taken a back seat, as we often don't get answers for days."
"Social media takedowns are a major issue. The takedowns should not take more than two to three hours, but they take more than that."
"ZeroFOX is not configured to grab the information automatically, including the news."
"ZeroFOX needs improvement in handling duplicate alerts. If an alert on a domain, such as abcd.com, has not been addressed or is still in progress, similar new alerts are not combined into a single incident."
 

Pricing and Cost Advice

"When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price."
Information not available
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Manufacturing Company
10%
Construction Company
7%
Computer Software Company
6%
Financial Services Firm
15%
Manufacturing Company
10%
Computer Software Company
7%
Outsourcing Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise14
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Anomali Enterprise?
My experience with pricing involved a yearly, two-year contract; I can't specify the setup cost, but it was aligned with our budget, so I consider it good.
What needs improvement with Anomali ThreatStream?
I think that Anomali could be improved by addressing a major weakness, which is the issue of its integrators. The capacity they have when publishing a large number of indicators is quite limited. T...
What is your primary use case for Anomali ThreatStream?
My main use case for Anomali in my organization is threat intelligence. We use threat intelligence with Anomali in my day-to-day work to query feeds.What we do is query those feeds looking for all ...
What is your experience regarding pricing and costs for ZeroFOX?
Based on my observations, ZeroFOX is moderately priced. It's neither highly expensive nor very cheap. The pricing depends on the licensed services, such as takedowns or dark data services, chosen.
What needs improvement with ZeroFOX?
ZeroFOX needs improvement in handling duplicate alerts. If an alert on a domain, such as abcd.com, has not been addressed or is still in progress, similar new alerts are not combined into a single ...
What is your primary use case for ZeroFOX?
I am working as a consultant for a manufacturing company, where I use ZeroFOX ( /products/zerofox-reviews ) to monitor social media accounts, brand domains, dark web data, and other online assets. ...
 

Also Known As

Match, Lens, ThreatStream, STAXX, Anomali Security Analytics
LookingGlass Manage Intelligence, VigilanteATI
 

Overview

 

Sample Customers

Bank of England, First Energy, UBISOFT, Bank of Hope, Blackhawk Network
Royal Farms, Hootsuite, BAE Systems, True Citrus
Find out what your peers are saying about Anomali vs. ZeroFOX and other solutions. Updated: June 2026.
900,747 professionals have used our research since 2012.