What is our primary use case?
In my current role, I am using SOCRadar Extended Threat Intelligence as a threat intelligence platform to monitor emerging cyber threats and assess their impact on our clients. Every day, I review newly disclosed CVEs, ransomware campaigns, threat actor activities, phishing campaigns, exploited vulnerabilities, and malware trends. I identify whether any of these threats are relevant to our clients by checking the affected technologies, software versions, or exposed assets. If a critical vulnerability or active exploitation is observed, I prepare an advisory containing the CVSS score, affected products, exploitation status, business impact, and recommended mitigation steps. I also enrich indicators such as malicious IPs, domain URLs, and file hashes before sharing them with the SOC team for detection and monitoring. SOCRadar Extended Threat Intelligence is also useful for tracking ransomware groups, threat actor profiles, attack trends, and industry-specific threats, allowing us to proactively inform clients before they become victims.
My primary usage of SOCRadar Extended Threat Intelligence includes threat intelligence to monitor the latest cyber threats, malware campaigns, ransomware attacks, and threat actors, then tracking attacker TTPs using the MITRE ATT&CK framework, then identifying IOCs such as malicious IPs, domain URLs, and file hashes. For example, SOCRadar Extended Threat Intelligence really helps us when a new ransomware group starts targeting the financial sector. Through SOCRadar Extended Threat Intelligence, we can provide intelligence about the group's behavior, IOCs, and then mitigate the issue effectively. The other use case is related to vulnerabilities. We are using SOCRadar Extended Threat Intelligence to track newly disclosed CVEs, then check whether these vulnerabilities are being actively exploited or not in the environment and whether they are affecting the sector of our clients or not. This is very helpful in that case. The third case associated with SOCRadar Extended Threat Intelligence is attack surface management. It helps us to discover internet-facing assets such as websites, servers, IP addresses, and subdomains, then to identify exposed services, misconfigurations, or forgotten assets that attackers could exploit. For example, we have worked on multiple such cases where SOCRadar Extended Threat Intelligence helped us to identify an exposed RDP service on a public IP that should not be accessible from the internet. This helped us to provide effective security posture and improve the security posture of the client successfully. The last use case is Digital Risk Protection. We are using SOCRadar Extended Threat Intelligence to monitor for brand protection or brand impersonation, then detecting phishing websites using the company name or logo, identifying fake mobile applications or fraudulent domains that are targeting our clients or organization.
One example where SOCRadar Extended Threat Intelligence was really very helpful was during the Fortinet SSL VPN vulnerability, which is also known as FortiBleed or FortiOS critical vulnerability. When the advisory was published, SOCRadar Extended Threat Intelligence generated intelligence about the vulnerability, including the affected FortiOS versions, the CVSS score, exploitation status, technical details, and mitigation recommendations. My first step was to review the advisory and understand the impact. I then identified which of our clients were using Fortinet firewalls and checked whether their FortiOS versions were vulnerable or not. Since the vulnerability was being actively exploited, we classified it as high priority. Then I prepared a client advisory that included a summary of the vulnerability, affected FortiOS versions, whether public exploits were available or not, the business impact, and the vendor mitigation and patching recommendations. Along with that, we informed the SOC team to closely monitor FortiGate VPN logs for indicators of compromise, such as unusual SSL VPN logins, then unexpected administrator account creation. Through this, we helped the clients, and we also ensured the clients were advised to patch immediately and review the logs for any signs of compromise.
What is most valuable?
The features of SOCRadar Extended Threat Intelligence that stand out the most for me are Vulnerability Intelligence, Dark Web Monitoring, Threat Actor Intelligence, IOC Intelligence, and Attack Surface Management because they help us proactively identify and mitigate risk before they become security incidents. Vulnerability Intelligence helps us to track newly disclosed CVEs, understand their severity, determine whether they are being actively exploited or not, and prioritize the patching. Dark Web Monitoring allows us to detect leaked employee credentials, stolen data, ransomware leak posts, and company mentions on underground forums, enabling early response. Threat Actor Intelligence provides insights into attacker groups, their tactics, techniques, and procedures, and recent campaigns, which helps us to understand potential threats targeting our clients. IOC Intelligence enables us to enrich malicious IPs, then domains, URLs, and file hashes and correlate them with known campaigns during investigations. Finally, Attack Surface Management helps us to identify internet-facing assets, exposed services, and misconfigurations so organizations can reduce their attack surface before attackers exploit them. These features are valuable because they allow us to move from a reactive approach to a proactive security posture. Instead of waiting for an alert, we can identify emerging threats, assess them, and assess which clients are affected, issue security advisories, and implement mitigation measures before an incident occurs.
SOCRadar Extended Threat Intelligence has a significant impact on our organization because my organization is providing security as a service to a lot of financial clients, primarily the banking sector. It is really important to us to provide security in both proactive and reactive ways. While working in the SOC particularly, you are entirely based on the reactive approach, where something will trigger, an alert will be there in the SIEM, and then your team will respond. But proactively, the SOC is not that helpful. For the proactive approach, we implemented SOCRadar Extended Threat Intelligence in our organization and started giving dark web monitoring as a service to a lot of our clients. As I mentioned before, many of our clients are based in the banking sector. It is really important to us that we also provide a proactive approach to security and in that way, SOCRadar Extended Threat Intelligence helped us to provide them proactive security. Basically, we monitor if any employee credentials are leaked in the darknet or dark webs and if any confidential data is leaked over the dark web and also monitor if the company name is discussed in the dark web forums and if any confidential data is leaked. In all of that, SOCRadar Extended Threat Intelligence has played a vital role for us. Hence, we continue using SOCRadar Extended Threat Intelligence as our DWM tool.
SOCRadar Extended Threat Intelligence has been a stable platform. During my day-to-day work, it has been consistently available for monitoring vulnerabilities, threat actors, ransomware campaigns, and dark web intelligence. I have not experienced any major stability issues that significantly impacted our operations. The platform delivers timely threat intelligence updates and performs reliably for daily analyst activities. Like any cloud-based platform, there may occasionally be scheduled maintenance or brief service interruptions, but I have not seen these have a significant impact on our workflow.
What needs improvement?
Overall, SOCRadar Extended Threat Intelligence is a strong platform, but there are a few areas where it could be enhanced. For example, deeper SIEM and EDR integrations to automatically enrich alerts with threat intelligence and reduce manual investigation would be beneficial. The second area for improvement would be more customizable dashboards and reporting so analysts can create reports tailored to different clients and management teams. The third area I think SOCRadar Extended Threat Intelligence can improve is IOC confidence scoring to help analysts quickly prioritize the most credible indicators and reduce false positives.
For how long have I used the solution?
It has been around 1.6 years that I have been working in cybersecurity and threat hunting and threat intelligence specifically. I started as a SOC analyst in my current organization and then got promoted to the intelligence and hunting side of the security team.
What do I think about the scalability of the solution?
In my experience, SOCRadar Extended Threat Intelligence has been highly scalable. Since it is a cloud-based SaaS platform, it can support organizations of different sizes without requiring any infrastructure management. As our organization monitors multiple clients in an MSSP environment, the platform was able to handle intelligence for different industries and environments simultaneously. We could monitor multiple organizations, then track vulnerabilities, threat actors, ransomware campaigns, and internet-facing assets from a centralized dashboard. Another aspect of its scalability is that it continuously updates threat intelligence feeds and can easily accommodate new clients or assets without major changes to the platform. This makes it suitable for both growing enterprises and MSSPs that need to manage security for multiple customers.
How are customer service and support?
Regarding customer support for SOCRadar Extended Threat Intelligence, it is really active. We have attended multiple meetings with the SOCRadar Extended Threat Intelligence original team, and they were really supportive when we were facing some issues with the integrations of SOCRadar Extended Threat Intelligence feeds in our SIEM tool. At that time, we had a meeting with the support staff. The technical team really helped us in that situation, and we were successfully able to integrate SOCRadar Extended Threat Intelligence with our SIEM tool. I think it is a very good aspect of SOCRadar Extended Threat Intelligence that their customer support is really active over time when we needed them. I rate them highly.
Which solution did I use previously and why did I switch?
As I mentioned earlier, we were not providing dark web monitoring service. This is the first time we are providing the dark web monitoring service to our clients. SOCRadar Extended Threat Intelligence is our first solution for this service.
What was our ROI?
Regarding return on investment, SOCRadar Extended Threat Intelligence has really helped us in a positive way. Earlier, our whole team was doing reactive monitoring work, basically in the SOC. After setting up SOCRadar Extended Threat Intelligence as a dark web service, half of the team is working entirely into the dark web operations. This has improved the client's security posture a lot compared to when they were only taking the SOC service. Through SOCRadar Extended Threat Intelligence, we are enabled and we got a chance to provide proactive security to the clients. In that case, SOCRadar Extended Threat Intelligence has really helped us and really helped organizations to make planned decisions about their security posture.
Which other solutions did I evaluate?
I was not directly involved in the product selection process, so I did not personally evaluate or compare multiple threat platforms before SOCRadar Extended Threat Intelligence was adopted. However, as far as I know, per the information I received from the upper management, we did consider multiple platforms such as Recorded Future, CrowdStrike Falcon Intelligence, Microsoft Defender Threat Intelligence, and Mandiant Threat Intelligence. SOCRadar Extended Threat Intelligence stood out because it offered a combination of threat intelligence, Digital Risk Protection, ASM, and dark web monitoring in one platform, along with an intuitive interface and actionable intelligence that suited our operational requirements.
What other advice do I have?
My advice for others would be positive about SOCRadar Extended Threat Intelligence because as a fresher, I used SOCRadar Extended Threat Intelligence as my first tool in the threat intelligence and dark web monitoring part. It is really easy to use and easy to understand. The features are very good for everyone to understand how dark web monitoring works, how analysts see, and what they are doing regarding the alerts that are generated by SOCRadar Extended Threat Intelligence. It is really easy to understand. The dashboard is very easy to navigate. The options are very familiar, and it really helps anyone to understand what is actually going on the platform. Compared to the other solutions, I would prefer SOCRadar Extended Threat Intelligence as a fresher.
Overall, my final thought about SOCRadar Extended Threat Intelligence is that I had a positive experience with it. It has helped us to move from a reactive to a more proactive security approach by providing timely intelligence of vulnerabilities, threat actors, and other activities of the attackers. I particularly value having threat intelligence and dark web monitoring integrated into a single platform, which streamlines investigations and improves analyst efficiency. While there is always room for improvement, particularly around deeper automation or SIEM or SOAR integrations, I believe SOCRadar Extended Threat Intelligence is a mature and reliable platform that delivers actionable intelligence and helps organizations strengthen their overall security posture. I would rate SOCRadar Extended Threat Intelligence a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other