No more typing reviews! Try our Samantha, our new voice AI agent.

Anomali vs ThreatConnect Threat Intelligence Platform (TIP) vs USM Anywhere comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Anomali3.9%
Recorded Future7.6%
CrowdStrike Falcon4.7%
Other83.8%
Threat Intelligence Platforms (TIP)
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
ThreatConnect Threat Intelligence Platform (TIP)3.7%
Recorded Future7.6%
CrowdStrike Falcon4.7%
Other84.0%
Threat Intelligence Platforms (TIP)
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
USM Anywhere1.0%
Splunk Enterprise Security7.2%
Wazuh5.8%
Other86.0%
Security Information and Event Management (SIEM)
 

Featured Reviews

CC
Enterprise Security Architect V at FirstEnergy
Enables automated threat intelligence sorting and enhances proactive threat hunting capabilities
You have to have at least a threat intelligence background or a SOC analyst background to use it, as that's the information you'll dig around with in there. If you don't have that kind of knowledge, it probably can be a little hard to use, but they do provide training. They offer training not only for how to use the platform but also some basic threat intelligence training to explain what these things are and what these terms mean. My company is a customer of Anomali. I would recommend it to other people. I would advise making sure you don't pick it without testing other products and have your use cases well thought out and documented before testing, so you know it will solve the problems you're trying to address. Keep an open mind with it and realize that whatever you can dream of, you can probably do with the platform. Overall, I would rate Anomali an eight out of ten.
Nikhil Jethwa - PeerSpot reviewer
Technical Consultant at ProTechmanize Solutions (P) Ltd.
Centralized threat intelligence has streamlined IOC workflows and now improves response time
ThreatConnect Threat Intelligence Platform (TIP) has positively impacted our organization by significantly reducing response times and improving detection accuracy by ensuring only high-confidence, context-rich indicators are pushed to security controls. From an operational standpoint, ThreatConnect Threat Intelligence Platform (TIP) has helped us reduce IOC handling and response time from hours to minutes by automating injection, enrichment, and distribution workflows.
Kris Nawani - PeerSpot reviewer
Co-Founder/Director at Bangkok MSP Company Limited
Offers complete coverage without the need to install additional software
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence and various other investigation tools The solution offers complete coverage without the need to install additional software, as it is maintained by the vendor. It helps in saving…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
"We now have a very robust collection of threat intelligence based on the capabilities that Anomali provides."
"I have found Cyber threat intelligence (CTI) very useful and concise. The solution is easy to use."
"The feature I have found most valuable is credential monitoring. This feature is easy and quick."
"The most valuable aspect of Anomali is the threat modeling capability."
"We have been able to see a return on investment as our clients believe in us more."
"I like their customer support."
"The most valuable features are ease of use and the ability to customize it."
"ThreatConnect has a highly user-friendly interface; I loved it, and it's really great and easy to configure."
"The tool's installation, integration, and playbooks are very straightforward."
"The product automatically generated a threat score based on the maliciousness of an IP."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"It's a solid platform and is stable enough. It is not complicated and is easy to use."
"The pricing for this solution with the 3 major components: SIEM, FIM, and vulnerability scanning, can’t be beat."
"It has streamlined log aggregation and analysis to meet organizational and regulatory needs."
"Its powerful correlation engine helps reduce time in manually correlating events."
"The most valuable feature is vulnerability management because it gives you insight into your environment to know what systems need to be updated or patched."
"Beyond provided us with an IDS as was our initial need, but AlienVault gave us more useful resources, as SIEM, and as a vulnerability scanner (the last, one of my favourite resources)."
"Once we placed AlienVault in the product we have now, the time it takes to find and respond to real anomalies has dropped from hours to minutes, it has so much potential to be an amazing product despite its many issues."
"The low cost of entry SIEM functionality has increased due to network views and network traffic."
"It has tremendous benefits, and it brings everything into one single pane that includes your vulnerability management, asset management, IDS, logs, and correlation."
 

Cons

"A lot of tools can give you many features, such as CTI intelligence and a tax service reduction. However, many people are combining different tools together to have more capabilities. It is up to the consumer whether they want to have multiple tools or have one tool that serves the purpose. Anomali Enterprise could improve by combining all the other tools' features into one solution."
"Less code in integration would be nice when building blocks."
"An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsistent, as any company can use any tags for their reporting."
"Support in the past has been top-notch, but recent trends indicate that it has taken a back seat, as we often don't get answers for days."
"Anomali Enterprise could improve by combining all the other tools' features into one solution."
"Support is an area with which nobody is ever fully satisfied, so it can be improved."
"ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow and reducing the complexity of configuring playbook and score logic."
"They should make it a little bit easier to generate events and share them with the community."
"I couldn’t get any training videos online when I was working with the tool."
"Integration is an area that could use some improvement."
"Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats."
"It would be good to have more feeds and more integrated sources for enrichment."
"Integration is an area that could use some improvement."
"The search capabilities are not optimal and are going to be optimized in the next versions."
"I feel that some areas of improvement would be vulnerability scanning. We use a separate product that seems to do a much better job."
"One area that has room for improvement is storage. AllienVault is a good place to put logs, but sometimes it's a tough place to go get logs... The logger can only hold so much data. If they improved that, that would help."
"The reporting could do with some improvements for example the vulnerability report only tells you what vulnerabilities are open and lists them but there is no indication of how old they are at a glance and what vulnerabilities have been closed since the previous scans."
"It would be nice to see some machine learning and monitoring of the configuration in network devices."
"Taking into account that server access credentials are controlled by the tool, some more management-focused actions could be performed from AlienVault."
"We would like more plugins. This being the main point of improvement which would benefit the users."
"There were deployment issues. At the time, it was right after USM Anywhere had been released, and not all of the documentation was posted."
 

Pricing and Cost Advice

"When comparing the price of Anomali Enterprise to other solutions it is in the medium to high range. However, I am satisfied with the price."
"I rate the product price as six on a scale of one to ten, where one is extremely expensive, and ten means it is cheap."
"The tool is expensive."
"The price of this product is in the mid-range, not too expensive, nor inexpensive."
"The price could be better."
"AlienVault is flexible on their pricing for unlimited licenses."
"It is affordable, and it also has many features that the premium products such as ArcSight and QRadar have. It is a very good platform for a SIEM solution. Everything is included in the price."
"​The price point is good.​"
"It's affordable for most customers."
"It is a product that is priced in a medium range, making it neither a cheap nor a costly product."
"So far, I feel the product's pricing is a good value. The technology is decent. You get what you pay for. I think it's fair."
"I don't know exactly, but I know it is based on the number of logs and the retention duration, such as 30 days or something like that. So, the smallest package is about 500 a month for 30 days of logs. There is a virtual machine. You need resources for it. It is a log collecting VM. They provide the software, and you just have to load a virtual machine. So, you're going to incur some CPU RAM and storage for wherever this log collecting appliance is running, which typically is in our cloud and on our platform for the customer."
"I don't think the product's pricing is a good value because they try to raise the price 50 percent every year... AlienVault needs to understand that not all customers are huge enterprises... Their sales team is way too aggressive. The price they advertise is not always the price you get."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
885,789 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
7%
Manufacturing Company
7%
Computer Software Company
6%
Financial Services Firm
15%
Comms Service Provider
9%
Retailer
6%
Computer Software Company
6%
Construction Company
22%
Computer Software Company
9%
Financial Services Firm
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise5
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise23
Large Enterprise4
By reviewers
Company SizeCount
Small Business64
Midsize Enterprise29
Large Enterprise25
 

Questions from the Community

What needs improvement with Anomali ThreatStream?
An area for improvement is the intelligence sharing within the Anomali community. The tagging system can be inconsist...
What is your primary use case for Anomali ThreatStream?
I use Anomali ( /products/anomali-reviews ) for threat hunting, threat collection, operationalization of intelligence...
What advice do you have for others considering Anomali ThreatStream?
For new users, I recommend taking the training provided by Anomali as it is very well articulated. I advise reading t...
What is your experience regarding pricing and costs for ThreatConnect Threat Intelligence Platform (TIP)?
My experience with ThreatConnect Threat Intelligence Platform (TIP) pricing, setup cost, and licensing indicates that...
What needs improvement with ThreatConnect Threat Intelligence Platform (TIP)?
Based on my experience, ThreatConnect Threat Intelligence Platform (TIP) is already doing a great job in the market b...
What is your primary use case for ThreatConnect Threat Intelligence Platform (TIP)?
Our main use case for ThreatConnect Threat Intelligence Platform (TIP) is to centralize, analyze, and operationalize ...
What needs improvement with AT&T AlienVault USM?
There are scalability issues due to a 60 TB limit, which restricts its use for large customers like banks. It is also...
What is your primary use case for AT&T AlienVault USM?
USM Anywhere is used for threat detection and investigation. It provides a solution with built-in threat intelligence...
 

Also Known As

Match, Lens, ThreatStream, STAXX, Anomali Security Analytics
No data available
AT&T AlienVault USM, AlienVault, AlienVault USM, Alienvault Cybersecurity
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Bank of England, First Energy, UBISOFT, Bank of Hope, Blackhawk Network
Customer Case Studies & Use Cases
Abel & Cole, Bank of Ireland, Bluegrass Cellular, CareerBuilder, Claire's, Hays Medical Center, Hope International, McCurrach, McKinsey & Company, Party Delights, Pepco Holdings, Richland School District, Ricoh, SaveMart, Shake Shack, Steelcase, TaxAct, Taylor Morrison, Vonage and Zoom
Find out what your peers are saying about CrowdStrike, Recorded Future, Check Point Software Technologies and others in Threat Intelligence Platforms (TIP). Updated: March 2026.
885,789 professionals have used our research since 2012.