What is our primary use case?
Investigating indicators of compromise, searching for threat actor reports and threat activity, and performing threat hunting activities are the main use cases I have for SOCRadar Extended Threat Intelligence in my day-to-day work.
I primarily use SOCRadar Extended Threat Intelligence for detecting an alert during monitoring or something that has been reported on the network, in searching for malicious indicators of some type, including IP addresses or some URLs.
Another interesting case with SOCRadar Extended Threat Intelligence is searching for credential compromises on the Dark Web, which is something that was commonly used and continues to be used.
What is most valuable?
The best features offered by SOCRadar Extended Threat Intelligence include the centralized platform, having all the reports at hand, all the functionalities related to CTI-type tools, which are indeed useful for investigations and threat hunting, and the tool is very easy to use.
SOCRadar Extended Threat Intelligence makes my work or my team's work more efficient by reducing the time it takes to do a search based on a specific domain for some client to whom we provide the service, allowing us to search for all the information related to that domain and different types of indicators or valuable information.
SOCRadar Extended Threat Intelligence positively impacts my organization significantly by providing reports and high-level executive reporting that gives interesting visibility to top management or personnel with decision-making capacity, without requiring major additional effort to obtain this information.
What needs improvement?
SOCRadar Extended Threat Intelligence could improve regarding the licensing scheme, which is credit-based, especially for specific activities, as it would be beneficial to have some flexibility in how these credits are consumed.
For how long have I used the solution?
I have been working in the cybersecurity field for more than five years. I have been using SOCRadar Extended Threat Intelligence for about three years, mainly in my previous experience at Grupo Radica, where I worked in the SOC area and we used the tool to deliver the service.
What do I think about the stability of the solution?
I consider SOCRadar Extended Threat Intelligence to be a stable solution.
What do I think about the scalability of the solution?
SOCRadar Extended Threat Intelligence can be adapted to the organization's needs by maintaining a flexible licensing scheme and even with its multi-tenant capabilities to provide a service from a security scheme.
How are customer service and support?
My experience with SOCRadar Extended Threat Intelligence's customer support has been acceptable, as they have met the agreed timelines and scope.
Which solution did I use previously and why did I switch?
I only used OSINT sources and open sources before SOCRadar Extended Threat Intelligence, and we decided to switch basically because of the reach that the solution has.
What was our ROI?
I do not have the exact figure for return on investment with the platform, but there is a significant reduction in the effort of conducting threat hunting and threat investigations manually.
What's my experience with pricing, setup cost, and licensing?
My experience with the price, implementation cost, and licensing of SOCRadar Extended Threat Intelligence has been good.
Which other solutions did I evaluate?
At the time, I evaluated a solution called Polaris and a solution called Vadar before choosing SOCRadar Extended Threat Intelligence.
What other advice do I have?
I would advise other people who are considering using SOCRadar Extended Threat Intelligence to focus on the versatility of the tool, on its entire scope and all the coverage it has in the different types of intelligence it handles, from the executive point of view to the operational one, and to adapt it to their internal processes based on that. I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.