No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2845602 - PeerSpot reviewer
Security Analyst L2 at a financial services firm with 10,001+ employees
Real User
Top 20
May 31, 2026
Threat intelligence has strengthened detection and response for malicious URLs and attacks
Pros and Cons
  • "Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR, or threat intelligence platform—operates in multiple shifts."

    What is our primary use case?

    My main use case for Anomali is for threat intelligence. We have a threat stream and threat practice on that. We are checking overall and verifying malicious websites, malicious hashes, and malicious URLs that are coming to the internal organization.

    I can give a quick specific example of how I use Anomali in my workflow. I have used Anomali to check which malicious URLs and websites are attacking our internal organization. We check the threat intelligence portal like VirusTotal and other sources, and if the reputation of that URL is malicious, we block it in Anomali.

    What is most valuable?

    The best features Anomali offers are that it shows all the information on the particular dashboard, whether something is malicious or not and what the reputation status is.

    Anomali has impacted my organization positively because our SOC team, which is actively monitoring all the tools—either SIM, SOAR, or threat intelligence platform—operates in multiple shifts. It has impacted our organization in a positive way by showing whether malicious activities or APTs are present. Whatever attackers are there, it shows on the dashboard and we can perform our analysis and execute remediation effectively.

    Anomali has improved our MTTR and MTDD.

    What needs improvement?

    We can enhance the dashboard and create metrics and improve the themes for incident response in particular. We could implement it through SOAR and gather more data on SOAR.

    For how long have I used the solution?

    I have been using Anomali for about three months.

    Buyer's Guide
    Anomali
    August 2026
    Learn what your peers think about Anomali. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    908,402 professionals have used our research since 2012.

    What do I think about the stability of the solution?

    Anomali is stable.

    Which solution did I use previously and why did I switch?

    I previously used a different solution.

    What's my experience with pricing, setup cost, and licensing?

    I do not know much about the pricing, setup cost, and licensing. These aspects are taken care of by seniors and associate directors.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing Anomali.

    What other advice do I have?

    I have used Anomali for the past four months in my previous organization.

    There is nothing else I would like to add about the features.

    On a scale of one to ten, I would rate Anomali an eight to nine. I would give Anomali that score because we see Anomali as a threat intelligence platform and we can work with it and improve the MTTR. I rate this product eight out of ten overall.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: May 31, 2026
    Flag as inappropriate
    PeerSpot user
    Managing Member at a tech vendor with self employed
    Real User
    Mar 17, 2023
    Easy and quick credential monitoring; tech support could be improved
    Pros and Cons
    • "The feature I have found most valuable is credential monitoring. This feature is easy and quick."
    • "Less code in integration would be nice when building blocks."

    What is our primary use case?

    Our primary use case for this solution is as a threat intelligence platform. We stream various threat feeds into this platform. We also make correlations between the feeds to duplicate the data, aggregate it and then present it to our security solutions for advanced security.

    How has it helped my organization?

    The way that this solution has helped our organization is by utilizing the domain squatting and domain type monitoring feature.

    What is most valuable?

    The feature I have found most valuable is credential monitoring. This feature is easy and quick. The data set is limited when compared to other solutions but it's still the greatest value.

    What needs improvement?

    I think that this solution should improve its integrations. This part of the solution could be bigger and moved into the no-code direction. Less code in integration would be nice when building blocks.

    For how long have I used the solution?

    I have been using this solution for about four months.

    What do I think about the stability of the solution?

    I have yet to encounter any issues with the stability of this solution.

    How are customer service and support?

    Regarding the technical support, we have contacted them for the automation part that we are running through compatibility problems and they were slow to solve our problems.

    Which solution did I use previously and why did I switch?

    Currently, we are not using any other solution for this use case, but previously we used MISP, which is an open-source project that requires a lot of effort to make work. That way, it required a lot of attention from our system administrator, and we had to sanitize the data very frequently because the peers we had. Sometimes they flooded our systems with chunk data and that needs to be handled and we decided to go with a paid solution instead.

    How was the initial setup?

    I would describe the initial setup process of this solution as similar to the regular features of boarding. At first, the second part of onboarding was to integrate the systems that need to be treated by an anomaly and that require a bit of technical knowledge and architectural knowledge and that lasts long and is an ongoing process. There are 10 people involved in the deployment of this solution. The vendor is tasked with the maintenance of this solution.

    What other advice do I have?

    When it comes to other people trying to use this solution, I'd say, first of all, if they are planning to go with Anomali, the very first step they need to go through is to standardize the threat inter-ingestion processes they have. Without that, they can't use anomaly. This is because it builds on the processes you have. If you don't have these processes, you can't use that solution at all.

    Overall, I would rate this solution a seven, on a scale from one to 10, with one being the worst and 10 being the best.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Anomali
    August 2026
    Learn what your peers think about Anomali. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    908,402 professionals have used our research since 2012.
    reviewer914664 - PeerSpot reviewer
    IT Cyber Security Senior Analyst at a consultancy with 10,001+ employees
    Real User
    Oct 28, 2021
    Scalable, easy to use, but more features needed
    Pros and Cons
    • "I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
    • "A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
    • "Anomali Enterprise could improve by combining all the other tools' features into one solution."

    What is our primary use case?

    Anomali Enterprise is a continuous threat detection solution.

    What is most valuable?

    I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use.

    What needs improvement?

    A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution.

    For how long have I used the solution?

    I have been using Anomali Enterprise for approximately two years.

    What do I think about the stability of the solution?

    There have not been any stability issues with Anomali Enterprise.

    What do I think about the scalability of the solution?

    Anomali Enterprise is scalable.

    We have approximately 15 people using the solution in my company.

    Which solution did I use previously and why did I switch?

    I have used many security solutions previously, such as ThreatConnect, Command, and Recorded Future. What I find is they all have different features, even though they work in a similar domain.

    How was the initial setup?

    I did not find the installation difficult.

    What about the implementation team?

    The implementation of the solution was done by our engineers.

    What's my experience with pricing, setup cost, and licensing?

    When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price.

    What other advice do I have?

    Overall the solution is straightforward to use.

    I rate Anomali Enterprise a seven out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Anomali Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Anomali Report and get advice and tips from experienced pros sharing their opinions.