No more typing reviews! Try our Samantha, our new voice AI agent.

Cofense Platform vs Splunk SOAR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cofense Platform
Average Rating
0.0
Reviews Sentiment
7.1
Number of Reviews
1
Ranking in other categories
Email Security (33rd), Security Incident Response (12th), Threat Intelligence Platforms (TIP) (43rd), Security Awareness Training (11th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
76
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cofense Platform is designed for Email Security and holds a mindshare of 1.2%, up 0.3% compared to last year.
Splunk SOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 6.9% mindshare, down 8.0% since last year.
Email Security Mindshare Distribution
ProductMindshare (%)
Cofense Platform1.2%
Proofpoint Email Protection5.9%
Microsoft Defender for Office 3655.1%
Other87.8%
Email Security
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR6.9%
Microsoft Sentinel9.8%
Palo Alto Networks Cortex XSOAR9.0%
Other74.3%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

MohamedShaker - PeerSpot reviewer
Sales Team Leader at ITVikings
Secures the business for customers quickly and accurately
It secures the business for the customers. For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment."
"It secures the business for the customers."
"Splunk SOAR is very good and very efficient; the UI is very good, and that way we don't have to struggle with a lot of pages because everything is on the dashboard and every detail is just a click away, which saves a lot of time compared to other SOAR solutions whose UIs are quite complex."
"One particular example I can recall is that in enterprise, we get around 100 to 200 notables daily, which consumes approximately 16 to 40 hours per day for an analyst, but since we have Splunk SOAR, it is now just about five to seven minutes or five to 10 minutes per alert."
"The most valuable features of Splunk SOAR are the easy integration with other solutions, including other Splunk solutions. The most important playbooks we need on the market come already on the Frontend. However, nowadays, Splunk changed its name, it's not Frontend anymore, it's Splunk Store. This is a very strong point."
"Splunk SOAR helps in automating a lot of tasks, reduces man-hours, reduces response time since everything is automated, and it requires less human interaction."
"Its ability to integrate with other systems and applications in our environment is pretty easy. Sometimes if we see any complexity we try to involve a consultant to help us. Everything is through the built-in app. Splunk can connect to any assets through the built-in app. It could be in a platform, firewalls, or endpoints. It's easy if it's an app integration."
"The solution’s dashboard is really good and customizable. It also has a good UI."
"The automation part of the product is great."
"The benefits were immediate when we started using Mission Control Splunk SOAR over a year ago; it has made it easier for our analysts to work on alerts using playbooks and forward them."
 

Cons

"If they continue improving and enhancing this solution, it could be even faster and more accurate."
"In the beginning, we couldn't find any specific documents for every function. It wasn't easy to navigate to what we needed."
"I'm not an expert on Splunk SOAR, but I'm sure our team members know what areas could be improved."
"While support is available, the resources around Splunk SOAR are more homegrown by other users, and discovering different troubleshooting methods is harder to do with Splunk SOAR than with Enterprise Security or other Splunk services."
"The application does not work properly and does not pass the log-based configuration. I feel that some kind of review should happen in the application. This review should validate things so that we can get the right information. Splunk does not tell us where the IP address is associated with."
"The UI can be more customizable for the clients."
"Splunk SOAR can improve IoT/OT security-related case studies or your use cases. Their integration with identity and access management (IAM) solutions is a bit shaky. They don't have good integration with a lot of IAM solutions. They do have good capability in terms of user access management internally, but even with privileged user access, they have a good module. However, if they have to integrate with solutions, such as CyberArk or IBM IAM solutions they are lacking, the visibility of user access is not that much."
"Splunk SOAR can be improved by simplifying certain aspects of the Automation Broker. The Automation Broker is utilized to connect to any on-premises security controls, but the primary challenge is that installing it on Linux is quite difficult."
"The technical support for the Splunk SIEM solution was average."
 

Pricing and Cost Advice

Information not available
"In my opinion, the price is high, but if you want good products, you have to be willing to pay for them."
"The cost is high and the licensing is on an annual basis."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
"The licensing cost is reasonable."
"I don't know the exact price, but for my region, it is very expensive."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"It's very overpriced because it is based on the number of users. There is no bulk licensing."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
915,287 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
19%
Comms Service Provider
11%
Manufacturing Company
9%
Energy/Utilities Company
7%
Financial Services Firm
11%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise53
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Splunk Phantom?
I was not involved with the pricing, setup cost, and licensing.
What needs improvement with Splunk Phantom?
To improve Splunk SOAR, I would suggest making it easier for integration with third-party applications without having to learn custom API commands. If something is not supported out of the box, it ...
What is your primary use case for Splunk Phantom?
My main use case for Splunk SOAR is integration with third-party apps. A quick specific example of how I use Splunk SOAR for integrating with third-party apps is collecting context data to help wit...
 

Also Known As

Cofense Intelligence, PhishMe Intelligence, Intelligence ThreatHQ, Cofense Triage, Cofense LMS
Phantom
 

Overview

 

Sample Customers

Jackson Health System
Recorded Future, Blackstone
Find out what your peers are saying about Proofpoint, Microsoft, Check Point Software Technologies and others in Email Security. Updated: September 2026.
915,287 professionals have used our research since 2012.