Try our new research platform with insights from 80,000+ expert users

Anomali vs ThreatConnect Threat Intelligence Platform (TIP) vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Threat Intelligence Platforms (TIP) Market Share Distribution
ProductMarket Share (%)
Anomali3.9%
Recorded Future7.9%
CrowdStrike Falcon5.1%
Other83.1%
Threat Intelligence Platforms (TIP)
Threat Intelligence Platforms (TIP) Market Share Distribution
ProductMarket Share (%)
ThreatConnect Threat Intelligence Platform (TIP)3.9%
Recorded Future7.9%
CrowdStrike Falcon5.1%
Other83.1%
Threat Intelligence Platforms (TIP)
Security Information and Event Management (SIEM) Market Share Distribution
ProductMarket Share (%)
USM Anywhere1.0%
Splunk Enterprise Security7.4%
Wazuh7.3%
Other84.3%
Security Information and Event Management (SIEM)
 

Featured Reviews

CC
Enterprise Security Architect V at FirstEnergy
Enables automated threat intelligence sorting and enhances proactive threat hunting capabilities
You have to have at least a threat intelligence background or a SOC analyst background to use it, as that's the information you'll dig around with in there. If you don't have that kind of knowledge, it probably can be a little hard to use, but they do provide training. They offer training not only for how to use the platform but also some basic threat intelligence training to explain what these things are and what these terms mean. My company is a customer of Anomali. I would recommend it to other people. I would advise making sure you don't pick it without testing other products and have your use cases well thought out and documented before testing, so you know it will solve the problems you're trying to address. Keep an open mind with it and realize that whatever you can dream of, you can probably do with the platform. Overall, I would rate Anomali an eight out of ten.
Vyas Shubham - PeerSpot reviewer
Product Analyst at a consultancy with 51-200 employees
Centralized threat insights have streamlined detection and automated phishing response
Based on my experience, ThreatConnect Threat Intelligence Platform (TIP) is already doing a great job in the market by decreasing threats from external sources. A few improvements I would suggest include integration enhancements, as users report that some integrations could be tighter or easier to configure. Additionally, plug and play connectors for popular security tools and threat feeds could streamline operations. There could also be easier event generation and sharing, as some reviewers mentioned that generating and sharing events or intelligence with internal teams or external partners is not as smooth as it could be. Improved pricing or tiered options could make it more accessible, especially for smaller organizations that do not require all enterprise features. Some users find the interface complex, particularly for everyday tasks such as filtering, tagging, or navigating playbooks. A more intuitive UI that aligns with typical analyst workflows would reduce the learning curve and boost productivity. To improve my rating closer to ten, the user interface can be simplified, as it is complex. Enhancing user experience and providing richer enrichment sources would further increase its value. Addressing these areas would make the platform more intuitive, comprehensive, and easier to adopt across all teams.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature I have found most valuable is credential monitoring. This feature is easy and quick."
"We now have a very robust collection of threat intelligence based on the capabilities that Anomali provides."
"I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
"The most valuable aspect of Anomali is the threat modeling capability."
"ThreatConnect has a highly user-friendly interface."
"The product automatically generated a threat score based on the maliciousness of an IP."
"We have been able to see a return on investment as our clients believe in us more."
"ThreatConnect Threat Intelligence Platform (TIP) is a robust platform that helps with advanced AI-driven intelligence, and it assists whenever there is a problem, serving as a single-stop solution."
"The most valuable features are ease of use and the ability to customize it."
"ThreatConnect Threat Intelligence Platform (TIP) has a significant positive impact on our organization by improving our ability to detect, prioritize, and respond to threats quickly through centralized and enriched threat intelligence."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"I like their customer support."
"It has allowed us to see what is happening on our servers."
"OTX is a great module that lets staff maintain and monitor updates regarding events in the infrastructure and takes decision to improve the security perimeter."
"What I find the most valuable about USM Anywhere is its compliance. It shows a list of all the administrators logged on and does it quite well. There are no whistles and bells, it's reliable and simple to use."
"The most valuable feature is threat intelligence."
"The pricing is amazing and really cheap."
"This is a USM, so being able to get all the features under one roof makes it a good product with good new features."
"It brought our logs into one place for review and set up alarms based on changes we were missing due to lack of having one place for everything to go."
"The vulnerability scanning is helpful to identify the areas that need patching or fixes installed."
 

Cons

"Less code in integration would be nice when building blocks."
"An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsistent, as any company can use any tags for their reporting."
"Support in the past has been top-notch, but recent trends indicate that it has taken a back seat, as we often don't get answers for days."
"A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
"Some users find the interface complex, particularly for everyday tasks such as filtering, tagging, or navigating playbooks."
"Support is an area with which nobody is ever fully satisfied, so it can be improved."
"Integration is an area that could use some improvement."
"ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic."
"It would be good to have more feeds and more integrated sources for enrichment."
"I would like to see improvements in the time zone support of their customer service, considering users are from different time zones."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
"They should make it a little bit easier to generate events and share them with the community"
"This solution could be easier to use."
"Maybe logs are the problem, as the database query is too slow. If you want to search something, you need time to find it."
"It was easy on PoC, but when we got to the product it was different story. We had to learn the product again and got feeling that the PoC was a different product."
"One area that has room for improvement is storage. AllienVault is a good place to put logs, but sometimes it's a tough place to go get logs... The logger can only hold so much data. If they improved that, that would help."
"The AT&T AlienVault USM is okay, but the relational database is not very good for large amounts of data. For example, many logs cannot be processed. It has been very slow for the queries and some data which are large, it is not very good in this case."
"There is room for improvement in Log parsing."
"Its reporting tools need improvements. It would be good if they can provide integration with other ticketing systems. Currently, we only have integration with Slack and Jira. It is also a bit slow, and its replication engine can be improved."
"The vulnerability reporting needs to have options to be able to sort or customize the output."
 

Pricing and Cost Advice

"When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price."
"The price could be better."
"The tool is expensive."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"It's very reasonably priced. It was one of the lowest among the ones I looked at. Licensing is pretty flexible. They can do a two-year or a three-year, even a one-year, perhaps."
"It has good pricing."
"​The vulnerability management solution is worse than buying a Nessus Professional license.​"
"The licensing fees are dependent on usage."
"I rate the price of AT&T AlienVault USM a four out of five."
"So far, I feel the product's pricing is a good value. The technology is decent. You get what you pay for. I think it's fair."
"The ROI is quite good."
"Its price is much lower than McAfee ESM."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
880,901 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
7%
Manufacturing Company
7%
Educational Organization
7%
Financial Services Firm
17%
Computer Software Company
6%
Comms Service Provider
6%
Retailer
6%
Computer Software Company
13%
Comms Service Provider
10%
Performing Arts
7%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise1
Large Enterprise5
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise23
Large Enterprise4
By reviewers
Company SizeCount
Small Business64
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What needs improvement with Anomali ThreatStream?
An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsist...
What is your primary use case for Anomali ThreatStream?
I use Anomali ( /products/anomali-reviews ) for threat hunting, threat collection, operationalization of intelligence...
What advice do you have for others considering Anomali ThreatStream?
For new users, I recommend taking the training provided by Anomali as it is very well articulated. I advise reading t...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit da...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
ThreatConnect Threat Intelligence Platform (TIP) serves as the primary platform in our organization for IOC aggregati...
What do you like most about AT&T AlienVault USM?
The most valuable feature of the solution is the ease of deployment that it provides to users. The integrations that ...
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also...
 

Also Known As

Match, Lens, ThreatStream, STAXX, Anomali Security Analytics
No data available
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Bank of England, First Energy, UBISOFT, Bank of Hope, Blackhawk Network
Customer Case Studies & Use Cases
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about CrowdStrike, Recorded Future, VirusTotal and others in Threat Intelligence Platforms (TIP). Updated: December 2025.
880,901 professionals have used our research since 2012.