What is our primary use case?
ThreatConnect Threat Intelligence Platform (TIP) serves as the primary platform in our organization for IOC aggregation, normalization, and distribution to downstream security controls like SIEM, EDR, and SOAR in a managed services context.
In our daily operations, we use ThreatConnect Threat Intelligence Platform (TIP) to automatically inject IOCs from multiple sources including commercial feeds, open source intelligence, and client-specific detection, then distribute the highly confidential IOCs to downstream tools such as SIEM and EDR.
We also use ThreatConnect Threat Intelligence Platform (TIP) for continuous threat scoring, deduplication, and lifecycle management of IOCs, ensuring only high confidence, relevant indicators are operationalized and kept in sync across all integrated security tools including SIEM, EDR, and SOAR.
How has it helped my organization?
ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls.
From an operational standpoint, ThreatConnect Threat Intelligence Platform (TIP) has helped us reduce IOC handling and response time from hours to minutes by automating injection, enrichment, and distribution workflows.
What is most valuable?
The best features of ThreatConnect Threat Intelligence Platform (TIP) in my experience are the centralized IOC injection and normalization, the flexible playbook and automation, and the API-first architecture that enables us to perform custom integration with other products and real-time distribution.
What needs improvement?
ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic.
For how long have I used the solution?
I have been working in my current field for five years.
What do I think about the stability of the solution?
In my experience, ThreatConnect Threat Intelligence Platform (TIP) is stable.
What do I think about the scalability of the solution?
ThreatConnect Threat Intelligence Platform (TIP) is highly scalable and handles increasing volumes of IOC effectively.
How are customer service and support?
Our experience with customer support has been positive, as they have been responsive, knowledgeable, and helpful.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Previously, we used a combination of standalone threat feeds and basic SIEM integration for threat intelligence before switching to ThreatConnect Threat Intelligence Platform (TIP).
What was our ROI?
We have seen a measurable return on investment from ThreatConnect Threat Intelligence Platform (TIP), as we have reduced manual analyst effort by thirty to forty percent.
What's my experience with pricing, setup cost, and licensing?
Generally, the pricing and setup cost are on the higher side.
Which other solutions did I evaluate?
Before choosing ThreatConnect Threat Intelligence Platform (TIP), we evaluated other vendors including Recorded Future and MISP.
What other advice do I have?
My advice would be to fully leverage ThreatConnect Threat Intelligence Platform (TIP)'s automation and integration capabilities from the start. The review rating for ThreatConnect Threat Intelligence Platform (TIP) is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?