Anomali ThreatStream - Review from an MSSP user
Rating: 9 out of 10
IncentivizedUse Cases and Deployment Scope
We are one of the largest MSSPs in the region, and threat intelligence requirements are very critical for us to provide the best-in-class services to our esteemed customers. We are living in an era where the security threat landscape changes each second, and it becomes imperative that we keep up to terms with the latest developing threats. Anomali ThreatStream provides us a platform that we can leverage to stay updated about the latest happenings in Cybersecurity.
Pros
- Provides high confident IOCs that can be used to sweep across logs.
- Provides an excellent platform to research about security content.
- Helps support our internal content development program by providing information about the latest campaigns, threat actors, malware, etc.
Cons
- The user interface, perhaps there is some room for improvement although it is good already.
- Confidence assigning process for IOCs needs to be more robust and transparent.
- While integration with SIEM solutions is a cakewalk, there is definitely added value if SIGMA rule conversion and YARA rule creation are provided from the platform.
Likelihood to Recommend
Anomali ThreatStream is excellent in scenarios where we deliver Managed Security Services to customers. It offers exhaustive volumes of information in the form of threat bulletins, IOCs, Threat Actor profiling, and details related to campaigns in the wild which can be used to a great extent by MSSPs. For an enterprise SOC, I believe it is a little less suited purely because of the pricing aspect as it is slightly towards the expensive side of the spectrum.