What is our primary use case?
I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly.
My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard.
The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution.
I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown.
For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.
What is most valuable?
The best features of SOCRadar Extended Threat Intelligence are the Takedown feature and the dark market feature, and also the leaked password monitoring where I can see what passwords in the organization have been leaked. These are really the best features I see value in from SOCRadar's solution.
The Takedown solution in SOCRadar Extended Threat Intelligence is amazing because it feels like they support me by giving all information regarding the takedown process. I can see in the solution all the steps they are taking to ensure the takedown and if there is any problem along the way. Additionally, SOCRadar support is responsive and gives all information when asked about a specific takedown. In the end, if a takedown is possible, I feel it will go through without any problem with their support. If the takedown is not possible, I have all the information explaining why the takedown was not possible, so I can proceed forward and know how to handle such cases.
SOCRadar Extended Threat Intelligence has really impacted my view of the organization, especially what is being discussed on the Dark Web. Regarding the outcome, I feel I now have a better view of what is happening with the organization, the attack surface, supply chain vulnerabilities, and what is coming up with the supply chain. SOCRadar Extended Threat Intelligence has greatly improved the security posture regarding all of this. We feel more secure and more alerted about what is happening with the brand and company.
What needs improvement?
The dashboard and alerting, especially the dashboard, needs some fine-tuning at first. At first, there was a lot of noise in the dashboard, with some things that were already taken care of reappearing in the dashboard. Once I fine-tuned it and selected what I wanted to see, the dashboard became really the best thing in the solution. Once everything is fine-tuned, I need only to look at the dashboard.
Regarding improvement, SOCRadar Extended Threat Intelligence is already advanced and well-mature. Perhaps they could improve the dashboard slightly, though the navigating system is quite efficient and the dashboard is efficient. There is an AI assistant with everything I need, so I do not know of any improvement to suggest to make it better.
Regarding improvement, I do not really have anything to say. They shared their roadmap with me a few times ago, so I will let them provide new metrics and new information to make it better. I do not have anything to add regarding improvement. The solution is quite mature right now, so I have nothing to add.
For how long have I used the solution?
I have started with SOCRadar Extended Threat Intelligence for more than a year.
How are customer service and support?
The customer support is actually really great and really helpful. I have had no problem with the support. I would even say that the customer support is one of the best selling points regarding the solution.
Which solution did I use previously and why did I switch?
SOCRadar Extended Threat Intelligence's solution is the first one I used, but before going with SOCRadar Extended Threat Intelligence, I explored the solutions provided in the region. I checked with Recorded Future, Group-IB, and Kaspersky Threat Intelligence, but I did not find what I needed and the pricing was very high for Group-IB and Recorded Future, so in the end I settled with SOCRadar Extended Threat Intelligence.
What was our ROI?
Regarding return on investment, I really utilized the takedown services and that really helped me get better control on brand images. Regarding metrics, I do not know if I have any metrics to give. I can say that the solution is very helpful and can be used by only one or two employees, which is great. This reduced the employee's workload, which is really helpful. However, I do not know if I can say anything more about the return on investment.
What's my experience with pricing, setup cost, and licensing?
I think the pricing is really one of the best I can find in the region regarding a solid, mature CTI solution, meaning an extended threat intelligence solution. When compared to the competition such as Group-IB or Recorded Future where they gave me a very high price, SOCRadar Extended Threat Intelligence pricing is really much better for a very good set of features. These are mature features, so it is really good. Regarding setup cost, the setup is actually part of the licensing. During the first purchase, the SOCRadar Extended Threat Intelligence customer success team will help me put the platform in place, which is really great and helpful. The licensing is set in different bundles and it can really be optimized if I know exactly what I need, and that is really great.
Which other solutions did I evaluate?
I checked with Group-IB, Recorded Future, and Kaspersky Threat Intelligence solution.
What other advice do I have?
For brand protection, I had my partner, or more of a client who had someone publishing on the internet, especially on LinkedIn, about their vulnerabilities or their scan results about their attack surface vulnerabilities. I quickly got in touch with SOCRadar Extended Threat Intelligence so they could take down those posts because they directly impacted my client's image. The response from SOCRadar Extended Threat Intelligence was amazing. They supported me throughout this process and the post was quickly taken down, I think it was taken down in about a day, something between 24 to 48 hours. It was a very good experience.
SOCRadar Extended Threat Intelligence has really impacted my view of the organization, especially what is being discussed on the Dark Web. Regarding the outcome, I feel I now have a better view of what is happening with the organization, the attack surface, supply chain vulnerabilities, and what is coming up with the supply chain. SOCRadar Extended Threat Intelligence has greatly improved the security posture regarding all of this. I feel more secure and more alerted about what is happening with the brand and company.
For numbers, I do not have any numbers to give, but the most specific metrics I can discuss is the faster response time because I am alerted in real time and I have the information in real time. I can respond more effectively and with the support of the SOCRadar Extended Threat Intelligence team, I can take action very fast. I can really resolve the issue before it becomes a bigger problem, especially with the takedown, with leaked passwords, or with anything similar. That is the biggest metric and the biggest improvement regarding the implementation of SOCRadar's solution.
SOCRadar Extended Threat Intelligence has an AI assistant that is a really simple assistant that explains attacks or things happening in the reports or in the alerts, which is great and really helpful.
I think if anyone is interested in SOCRadar Extended Threat Intelligence, I think calling or booking a POC with them would really give the opportunity to check the solution, to get in touch with the SOCRadar Extended Threat Intelligence team, and see the value they provide. That would be enough for anyone to actively consider the solution.
The solution is very mature. The customer support is really great. I think they will be better and better in the upcoming years and maybe they will be a leader in the industry, which I hope for them because the team is great.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner