Senior Threat Researcher at a tech vendor with 5,001-10,000 employees
MSP
Top 20
Jul 23, 2026
My main use case for SOCRadar Extended Threat Intelligence is Digital Risk Protection, brand risk monitoring, threat intelligence, supply chain attacks, supply chain monitoring, VIP monitoring, identity intelligence, and geopolitical intelligence. I can provide a specific example of how I have used SOCRadar Extended Threat Intelligence for one of those use cases. We obtained information regarding a particular threat actor for our customer, and that threat actor was targeting other brands and companies in that particular sector. We notified our customer that this threat actor might pose a risk to them, we recommended they safeguard their defenses, and we started monitoring for that customer. The effort was successful, and we successfully thwarted that cyber threat attack against our customer, saving a significant amount of money that would have been lost as a victim. I have additional information about my main use case and how I use SOCRadar Extended Threat Intelligence. SOCRadar provides high fidelity, suspicious, and malicious IOCs that we can straightaway input into our security tools and directly block, which is valuable. Instead of scouring the internet or social media platforms for malicious IOCs for weeks or months, which consumes considerable time, I have used SOCRadar Threat Hunting platform. In conducting proactive threat hunts, I use the information about threat actors and their TTPs provided by SOCRadar to perform proactive threat hunts on my customers' environments. We use the information provided by SOCRadar to develop detection mechanisms, which is extremely useful and has proven to be a great success story for our organization.
Cibersecurity Pre Sales Enginer at a tech vendor with 11-50 employees
Real User
Top 20
Jul 20, 2026
Investigating indicators of compromise, searching for threat actor reports and threat activity, and performing threat hunting activities are the main use cases I have for SOCRadar Extended Threat Intelligence in my day-to-day work. I primarily use SOCRadar Extended Threat Intelligence for detecting an alert during monitoring or something that has been reported on the network, in searching for malicious indicators of some type, including IP addresses or some URLs. Another interesting case with SOCRadar Extended Threat Intelligence is searching for credential compromises on the Dark Web, which is something that was commonly used and continues to be used.
Cyber Security Engineer at a tech consulting company with 11-50 employees
Real User
Top 20
Jul 20, 2026
I primarily use SOCRadar Extended Threat Intelligence for monitoring data credential leaks and password leaks, handling exposures, and managing GitHub public repository, SSL expiry, and attack surface along with public repositories exposures and cyber threat intelligence, as well as feeding threat intel feeds to my other tools such as LogRhythm and EDR, XDR. For instance, I created a use case involving my company's domain name and email ID where if any user with my company's email ID gets exposed on the dark web and deep web, I receive an alert so I can validate whether the credential is currently active or not and take necessary actions. Regarding public repository exposure, if any of our company employees push their data to public platforms such as GitHub, we get alerts based on critical keywords which allows me to analyze how critical the exposure is to our organization. For SSL expiry, I validate certificates on domains and subdomains based on their expiry, ensuring they are either self-signed or public SSL, which helps us reach out to the domain users and owners for renewal.
Product Engineer at a tech services company with 11-50 employees
Real User
Top 20
Jul 20, 2026
My main use case for SOCRadar Extended Threat Intelligence is to monitor the attack surface and then to monitor credential leakage and Digital Risk Protection like impersonation domain and impersonation web, and data breach. I also use SOCRadar Extended Threat Intelligence to integrate IOCs to SIEM, to firewall, and to EDR. One specific example of how I use SOCRadar Extended Threat Intelligence for credential leakage or digital protection is when I receive an alert about password leakage, and from there I can see whose password is leaked and sold on the dark web, and then I can tell the user and ask them to change the password. I can add that another example is about SOCRadar Extended Threat Intelligence having Attack Surface Management where I can monitor vulnerabilities on our public-facing assets, and SOCRadar Extended Threat Intelligence will scan our assets regularly and report to us if there are vulnerabilities. I can check the vulnerabilities and then fix and patch them as recommended by SOCRadar Extended Threat Intelligence. Regarding SOCRadar Extended Threat Intelligence's AI capabilities, I believe it has good governance and security since SOCRadar Extended Threat Intelligence has an NDA in place, meaning I trust them to handle our sensitive data. I have utilized SOCRadar Extended Threat Intelligence's unique dark web sources, which include IOCs such as malicious IPs and domains, and I can integrate these sources into our security tools like SIEM and firewall to identify potential threats early and block them. I have utilized the managed takedown services provided by SOCRadar Extended Threat Intelligence when there are impersonation cases involving domains, websites, or social media accounts, allowing us to take down malicious accounts or sites.
Dark L2 Web Analyst at a tech services company with 11-50 employees
Real User
Top 5
Jul 17, 2026
My main use case for SOCRadar Extended Threat Intelligence is to monitor my clients, check if any suspicious activities are observed over the internet or on the black market, and I also use it for brand monitoring. It is a helpful tool for us. A specific example of how I have used SOCRadar Extended Threat Intelligence for brand monitoring or catching suspicious activities is that we get alerts from SOCRadar Extended Threat Intelligence itself, such as for the Facebook impersonating accounts. We do not see these things normally, but when we get alerts, we know someone has created a channel regarding our brand and it is a misuse. For black market purposes, we receive alerts, obtain them, and check the credentials, and this way we work. I use SOCRadar Extended Threat Intelligence not just for threat intelligence but also for my own research on threat hunting, which is a good specific feature in SOCRadar Extended Threat Intelligence where I can check any domain, any IP, or any username to see if any data is available over the domain.
Lead Engineer - Network & Security at Connex Information Technologies
Real User
Top 10
Jun 29, 2026
I prefer SOCRadar Extended Threat Intelligence for multiple use cases, starting from brand protection to assessing the external attack surface of the organizations I provide security solutions for, mainly the public open IP addresses, the ports, and the certificates that have been opened publicly. When I try to do proof of concepts for my customers, I normally add the domain to SOCRadar Extended Threat Intelligence. Once I add the domain, it normally scans the domain and discovers all the external IP addresses and ports that have been opened. Then it scans from a brand protection perspective such as the bad names that circulate around that particular domain, or any threats targeted towards the open public IP address. I have covered all the use cases that I get out of SOCRadar Extended Threat Intelligence. Basically, the results that it gives me as an outcome after I integrate with my domain are impressive. Based on the results, I could also identify the threats that are targeted towards my domain and the bad reputations it has created based on the domain I have added. I also consider social media monitoring, which detects any fake news or bad reputations that have been created.
Learn what your peers think about SOCRadar Extended Threat Intelligence. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
Principal Cybersecurity Engineer at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Jun 29, 2026
I primarily use SOCRadar Extended Threat Intelligence for threat intelligence. Secondary uses include dark web news monitoring, threat hunting, and alerts regarding the dark web such as data breaches, VIP monitoring, and brand protection. These are the activities we use regularly. Regarding the IGENTIC phishing workflow, we do not directly use it because this tool is not utilized for phishing purposes. We have not used that module and workflow. However, we have observed that it is able to detect phishing alerts, though not directly. The alerts are mostly related to similar domains being registered and hosting similar pages. Our engineers resolve these alerts, but we have not implemented IGENTIC or automation for this.
Cybersecurity Consultant at a tech services company with 11-50 employees
Real User
Top 10
Jun 27, 2026
I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly. My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard. The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution. I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown. For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.
I primarily use SOCRadar Extended Threat Intelligence for incident response and threat detection. Apart from threat monitoring and incident response support, SOCRadar Extended Threat Intelligence also helps track threat actor activity, leak credentials, and brand impersonation risk, which are some key features that definitely help the organization to secure everything. Among the features of advanced dark web monitoring, external attack surface management, and brand protection, I rely the most on advanced dark web monitoring, as it helps to identify leaked credentials, sensitive data exposure, and discussions by threat actors related to our organization. This is very useful because it provides early warning about potential security incidents and allows us to take proactive actions such as resetting compromised accounts and strengthening security controls before any attack happens.
Senior Cyber Security Expert at a computer software company with 201-500 employees
Real User
Top 10
Feb 24, 2026
I use SOCRadar Extended Threat Intelligence for VIP monitoring, CM tool monitoring, and CTI, specifically for early detection systems for our customers. If there is any leakage of customer accounts, we know about it. If there is any information about them on the dark web, we are immediately informed. Overall, I use it for intelligence purposes.
SOCRadar Extended Threat Intelligence enables users to identify and mitigate cybersecurity risks through comprehensive threat visibility and real-time monitoring.
Organizations utilize SOCRadar Extended Threat Intelligence for early detection and proactive defense against potential cyber attacks. With its robust features, users gain enhanced security posture and informed strategic decision-making. Detailed analytics and actionable insights contribute to improved threat response and...
My main use case for SOCRadar Extended Threat Intelligence is Digital Risk Protection, brand risk monitoring, threat intelligence, supply chain attacks, supply chain monitoring, VIP monitoring, identity intelligence, and geopolitical intelligence. I can provide a specific example of how I have used SOCRadar Extended Threat Intelligence for one of those use cases. We obtained information regarding a particular threat actor for our customer, and that threat actor was targeting other brands and companies in that particular sector. We notified our customer that this threat actor might pose a risk to them, we recommended they safeguard their defenses, and we started monitoring for that customer. The effort was successful, and we successfully thwarted that cyber threat attack against our customer, saving a significant amount of money that would have been lost as a victim. I have additional information about my main use case and how I use SOCRadar Extended Threat Intelligence. SOCRadar provides high fidelity, suspicious, and malicious IOCs that we can straightaway input into our security tools and directly block, which is valuable. Instead of scouring the internet or social media platforms for malicious IOCs for weeks or months, which consumes considerable time, I have used SOCRadar Threat Hunting platform. In conducting proactive threat hunts, I use the information about threat actors and their TTPs provided by SOCRadar to perform proactive threat hunts on my customers' environments. We use the information provided by SOCRadar to develop detection mechanisms, which is extremely useful and has proven to be a great success story for our organization.
Investigating indicators of compromise, searching for threat actor reports and threat activity, and performing threat hunting activities are the main use cases I have for SOCRadar Extended Threat Intelligence in my day-to-day work. I primarily use SOCRadar Extended Threat Intelligence for detecting an alert during monitoring or something that has been reported on the network, in searching for malicious indicators of some type, including IP addresses or some URLs. Another interesting case with SOCRadar Extended Threat Intelligence is searching for credential compromises on the Dark Web, which is something that was commonly used and continues to be used.
I primarily use SOCRadar Extended Threat Intelligence for monitoring data credential leaks and password leaks, handling exposures, and managing GitHub public repository, SSL expiry, and attack surface along with public repositories exposures and cyber threat intelligence, as well as feeding threat intel feeds to my other tools such as LogRhythm and EDR, XDR. For instance, I created a use case involving my company's domain name and email ID where if any user with my company's email ID gets exposed on the dark web and deep web, I receive an alert so I can validate whether the credential is currently active or not and take necessary actions. Regarding public repository exposure, if any of our company employees push their data to public platforms such as GitHub, we get alerts based on critical keywords which allows me to analyze how critical the exposure is to our organization. For SSL expiry, I validate certificates on domains and subdomains based on their expiry, ensuring they are either self-signed or public SSL, which helps us reach out to the domain users and owners for renewal.
My main use case for SOCRadar Extended Threat Intelligence is to monitor the attack surface and then to monitor credential leakage and Digital Risk Protection like impersonation domain and impersonation web, and data breach. I also use SOCRadar Extended Threat Intelligence to integrate IOCs to SIEM, to firewall, and to EDR. One specific example of how I use SOCRadar Extended Threat Intelligence for credential leakage or digital protection is when I receive an alert about password leakage, and from there I can see whose password is leaked and sold on the dark web, and then I can tell the user and ask them to change the password. I can add that another example is about SOCRadar Extended Threat Intelligence having Attack Surface Management where I can monitor vulnerabilities on our public-facing assets, and SOCRadar Extended Threat Intelligence will scan our assets regularly and report to us if there are vulnerabilities. I can check the vulnerabilities and then fix and patch them as recommended by SOCRadar Extended Threat Intelligence. Regarding SOCRadar Extended Threat Intelligence's AI capabilities, I believe it has good governance and security since SOCRadar Extended Threat Intelligence has an NDA in place, meaning I trust them to handle our sensitive data. I have utilized SOCRadar Extended Threat Intelligence's unique dark web sources, which include IOCs such as malicious IPs and domains, and I can integrate these sources into our security tools like SIEM and firewall to identify potential threats early and block them. I have utilized the managed takedown services provided by SOCRadar Extended Threat Intelligence when there are impersonation cases involving domains, websites, or social media accounts, allowing us to take down malicious accounts or sites.
My main use case for SOCRadar Extended Threat Intelligence is to monitor my clients, check if any suspicious activities are observed over the internet or on the black market, and I also use it for brand monitoring. It is a helpful tool for us. A specific example of how I have used SOCRadar Extended Threat Intelligence for brand monitoring or catching suspicious activities is that we get alerts from SOCRadar Extended Threat Intelligence itself, such as for the Facebook impersonating accounts. We do not see these things normally, but when we get alerts, we know someone has created a channel regarding our brand and it is a misuse. For black market purposes, we receive alerts, obtain them, and check the credentials, and this way we work. I use SOCRadar Extended Threat Intelligence not just for threat intelligence but also for my own research on threat hunting, which is a good specific feature in SOCRadar Extended Threat Intelligence where I can check any domain, any IP, or any username to see if any data is available over the domain.
I prefer SOCRadar Extended Threat Intelligence for multiple use cases, starting from brand protection to assessing the external attack surface of the organizations I provide security solutions for, mainly the public open IP addresses, the ports, and the certificates that have been opened publicly. When I try to do proof of concepts for my customers, I normally add the domain to SOCRadar Extended Threat Intelligence. Once I add the domain, it normally scans the domain and discovers all the external IP addresses and ports that have been opened. Then it scans from a brand protection perspective such as the bad names that circulate around that particular domain, or any threats targeted towards the open public IP address. I have covered all the use cases that I get out of SOCRadar Extended Threat Intelligence. Basically, the results that it gives me as an outcome after I integrate with my domain are impressive. Based on the results, I could also identify the threats that are targeted towards my domain and the bad reputations it has created based on the domain I have added. I also consider social media monitoring, which detects any fake news or bad reputations that have been created.
I primarily use SOCRadar Extended Threat Intelligence for threat intelligence. Secondary uses include dark web news monitoring, threat hunting, and alerts regarding the dark web such as data breaches, VIP monitoring, and brand protection. These are the activities we use regularly. Regarding the IGENTIC phishing workflow, we do not directly use it because this tool is not utilized for phishing purposes. We have not used that module and workflow. However, we have observed that it is able to detect phishing alerts, though not directly. The alerts are mostly related to similar domains being registered and hosting similar pages. Our engineers resolve these alerts, but we have not implemented IGENTIC or automation for this.
I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly. My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard. The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution. I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown. For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.
I primarily use SOCRadar Extended Threat Intelligence for incident response and threat detection. Apart from threat monitoring and incident response support, SOCRadar Extended Threat Intelligence also helps track threat actor activity, leak credentials, and brand impersonation risk, which are some key features that definitely help the organization to secure everything. Among the features of advanced dark web monitoring, external attack surface management, and brand protection, I rely the most on advanced dark web monitoring, as it helps to identify leaked credentials, sensitive data exposure, and discussions by threat actors related to our organization. This is very useful because it provides early warning about potential security incidents and allows us to take proactive actions such as resetting compromised accounts and strengthening security controls before any attack happens.
I use SOCRadar Extended Threat Intelligence for VIP monitoring, CM tool monitoring, and CTI, specifically for early detection systems for our customers. If there is any leakage of customer accounts, we know about it. If there is any information about them on the dark web, we are immediately informed. Overall, I use it for intelligence purposes.