Our primary use case for this solution is as a threat intelligence platform. We stream various threat feeds into this platform. We also make correlations between the feeds to duplicate the data, aggregate it and then present it to our security solutions for advanced security.
Managing Member at a tech vendor with self employed
Easy and quick credential monitoring; tech support could be improved
Pros and Cons
- "The feature I have found most valuable is credential monitoring. This feature is easy and quick."
- "Less code in integration would be nice when building blocks."
What is our primary use case?
How has it helped my organization?
The way that this solution has helped our organization is by utilizing the domain squatting and domain type monitoring feature.
What is most valuable?
The feature I have found most valuable is credential monitoring. This feature is easy and quick. The data set is limited when compared to other solutions but it's still the greatest value.
What needs improvement?
I think that this solution should improve its integrations. This part of the solution could be bigger and moved into the no-code direction. Less code in integration would be nice when building blocks.
Buyer's Guide
Anomali
June 2026
Learn what your peers think about Anomali. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
899,258 professionals have used our research since 2012.
For how long have I used the solution?
I have been using this solution for about four months.
What do I think about the stability of the solution?
I have yet to encounter any issues with the stability of this solution.
How are customer service and support?
Regarding the technical support, we have contacted them for the automation part that we are running through compatibility problems and they were slow to solve our problems.
Which solution did I use previously and why did I switch?
Currently, we are not using any other solution for this use case, but previously we used MISP, which is an open-source project that requires a lot of effort to make work. That way, it required a lot of attention from our system administrator, and we had to sanitize the data very frequently because the peers we had. Sometimes they flooded our systems with chunk data and that needs to be handled and we decided to go with a paid solution instead.
How was the initial setup?
I would describe the initial setup process of this solution as similar to the regular features of boarding. At first, the second part of onboarding was to integrate the systems that need to be treated by an anomaly and that require a bit of technical knowledge and architectural knowledge and that lasts long and is an ongoing process. There are 10 people involved in the deployment of this solution. The vendor is tasked with the maintenance of this solution.
What other advice do I have?
When it comes to other people trying to use this solution, I'd say, first of all, if they are planning to go with Anomali, the very first step they need to go through is to standardize the threat inter-ingestion processes they have. Without that, they can't use anomaly. This is because it builds on the processes you have. If you don't have these processes, you can't use that solution at all.
Overall, I would rate this solution a seven, on a scale from one to 10, with one being the worst and 10 being the best.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Cyber Security Senior Analyst at a consultancy with 10,001+ employees
Scalable, easy to use, but more features needed
Pros and Cons
- "I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
- "A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
- "Anomali Enterprise could improve by combining all the other tools' features into one solution."
What is our primary use case?
Anomali Enterprise is a continuous threat detection solution.
What is most valuable?
I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use.
What needs improvement?
A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution.
For how long have I used the solution?
I have been using Anomali Enterprise for approximately two years.
What do I think about the stability of the solution?
There have not been any stability issues with Anomali Enterprise.
What do I think about the scalability of the solution?
Anomali Enterprise is scalable.
We have approximately 15 people using the solution in my company.
Which solution did I use previously and why did I switch?
I have used many security solutions previously, such as ThreatConnect, Command, and Recorded Future. What I find is they all have different features, even though they work in a similar domain.
How was the initial setup?
I did not find the installation difficult.
What about the implementation team?
The implementation of the solution was done by our engineers.
What's my experience with pricing, setup cost, and licensing?
When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price.
What other advice do I have?
Overall the solution is straightforward to use.
I rate Anomali Enterprise a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Anomali Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Threat Intelligence Platforms (TIP) Security Information and Event Management (SIEM) User Entity Behavior Analytics (UEBA) Advanced Threat Protection (ATP) Extended Detection and Response (XDR)Popular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
Wazuh
Splunk Enterprise Security
SentinelOne Singularity Endpoint
Darktrace
IBM Security QRadar
Microsoft Defender for Office 365
Microsoft Sentinel
Elastic Security
TrendAI Vision One
Proofpoint Email Protection
TrendAI Vision One – Cloud Security
Rapid7 InsightIDR
Buyer's Guide
Download our free Anomali Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
- How inadvisable is it to use a single vulnerability analysis tool?
- Threat intelligence tools for large organization
- What is your recommended cost-effective solution to detect and prevent APT attacks?
- Compromise Assessment vs Threat Hunting
- When evaluating Threat Intelligence Platforms (TIP), what aspect do you think is the most important to look for?
- What are some of the biggest mistakes that businesses make when it comes to monitoring cyber threats?
- What is the difference between internal and external threat intelligence?
- Which enterprise threat modeling tool do you recommend?
- Can someone provide any independent comparison of threat modeling solutions?













