No more typing reviews! Try our Samantha, our new voice AI agent.

Cofense Platform vs Splunk SOAR comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cofense Platform
Average Rating
0.0
Reviews Sentiment
7.1
Number of Reviews
1
Ranking in other categories
Email Security (33rd), Security Incident Response (12th), Threat Intelligence Platforms (TIP) (43rd), Security Awareness Training (11th)
Splunk SOAR
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
76
Ranking in other categories
Security Orchestration Automation and Response (SOAR) (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cofense Platform is designed for Email Security and holds a mindshare of 1.2%, up 0.3% compared to last year.
Splunk SOAR, on the other hand, focuses on Security Orchestration Automation and Response (SOAR), holds 7.0% mindshare, down 7.7% since last year.
Email Security Mindshare Distribution
ProductMindshare (%)
Cofense Platform1.2%
Proofpoint Email Protection5.9%
Microsoft Defender for Office 3655.1%
Other87.8%
Email Security
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Splunk SOAR7.0%
Microsoft Sentinel9.1%
Palo Alto Networks Cortex XSOAR8.8%
Other75.1%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

MohamedShaker - PeerSpot reviewer
Sales Team Leader at ITVikings
Secures the business for customers quickly and accurately
It secures the business for the customers. For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment.
Vikash Kushwaha - PeerSpot reviewer
Full-Stack Software Engineer at mindpathtech
Automated playbooks have transformed incident response and now protect critical services
The biggest advantage I see from my personal experience as an integrator with Splunk SOAR is that it integrates with most of the security features among the Defenders, Microsoft Defender, firewalls, CloudWatch, and AWS security agents, as well as EC2 machines, firewalls, EDR, IAM, email security, and antivirus. It automates the security process over phishing emails and any other brute force attacks. It helps quite a lot because if 100 phishing emails were sent to a domain, a developer can only reach one, two, or five, but for hundreds of others, it actually supports better automated playbooks and provides major security. Splunk SOAR introduced some new and innovative capabilities or approaches that transformed the way my SOC operates. Splunk SOAR provides playbooks for automatic security features, such as for firewalls, phishing mails, and utilizing Defenders or virtual tools. A playbook maintains its algorithms or processes, so if any kind of security issue arises, the playbook automatically runs and handles actions such as IP blocking or resolving brute force attacks, notifying the admin about suspicious users. After implementing Splunk SOAR, the training process for my SOC team to use playbooks takes a long time during the whole integration part, as it retrieves all credentials from us, whether for an EC2 machine or any antivirus. It takes about one to two months for the team to fully sustain and know the processes of the playbooks and security, particularly for three or four individuals in the cyber security or DevOps team. Splunk SOAR significantly reduces the time spent on monotonous security tasks. In banking, insurance, or healthcare, automated services for addressing phishing emails and security threats are common. Having a manual workforce of two or three individuals can only handle five or ten security threats while Splunk SOAR automates the entire process across apps and machines, making it easier and notifying the admin about the threats. If someone tries to breach, Splunk SOAR immediately processes incoming requests, validating them and blocking any unsecured requests, which reduces a lot of time and effort. With the help of the playbook viewer, I assess the visibility provided by Splunk SOAR as very positive, especially for security purposes. If someone is attacked by 100 users, it blocks all the users, while individual developers such as myself can only handle two or three at a time. The automated process of Splunk SOAR handles all the processes concurrently, making it a game-changing solution. It helps reduce mean time to resolve (MTTR). It takes around 10 to 20 minutes to resolve one incident through the whole process and notify the admin of the issue. If there are multiple incidents, calculating the time taken for each, it generally requires around 40 to 50 minutes to resolve five incidents.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"For instance, if any phishing emails come into the environment and employees see it, we direct the email to Triage. The Triage system will investigate it through AI technology to see if it's a phishing email or not. If it is a phishing email, it will quarantine it and erase it from the environment."
"It secures the business for the customers."
"Integration has made our operations significantly easier, and for phishing investigations, IP checks, and endpoint isolations, our response time to incidents has reduced substantially, and false positives are identified much quicker because of Splunk SOAR."
"Splunk SOAR helps my team prioritize and respond to security alerts and incidents very effectively because it automates many of the manual tasks for us."
"The primary benefit relates to the response time of our operations team and our team overall, as certain recurring tasks that used to consume approximately 30 to 45 minutes daily are now automated and completed in around 40 minutes, allowing our limited team to achieve a maximum amount of tasks through automation along with AI."
"It has definitely saved a decent amount of time for our analysts so they can focus on other tasks."
"I have found all the security automation platform features of Splunk SOAR to be good, and the automation playbook development is highly useful."
"Splunk SOAR saves time in threat response, and the time to solve an incident is currently the best in the market."
"Workflow management is most valuable. It is easily customizable"
"Splunk SOAR really automates triaging and investigation, reducing an engineer's one-hour incident investigation to just a few minutes while automatically closing false positive tickets with a high level of granularity."
 

Cons

"If they continue improving and enhancing this solution, it could be even faster and more accurate."
"There are areas in Splunk SOAR that have room for improvement. To make Splunk SOAR a better solution, there could be better built-in debugging tools, smarter playbook suggestions, and enhanced lifecycle management."
"I have found a challenge in my three months with Splunk SOAR in that it is quite a heavy tool to maintain."
"It would be nice if we could put it on other search heads, not just Enterprise Security."
"The UI can be more customizable for the clients."
"The solution is a bit more expensive than other offerings."
"The scalability could be better."
"The technical support for the Splunk SIEM solution was average."
"The dashboard could be improved and some other features. SOAR should integrate network capabilities, allowing us to also monitor the WLAN network. Splunk is also expensive and difficult for beginners to learn. It's hard for a new user to figure out how to visualize old threat data. It took two to three months to learn with hands-on experience how to use the dashboard, visualize events, and analyze threats."
 

Pricing and Cost Advice

Information not available
"The licensing cost is reasonable."
"We renewed it this year. This year was the first time there was a dramatic increase in the price. It was kind of non-negotiable. It was just a high increase. We had internal communications, and it was definitely a surprise to us. In a short time frame, we renewed it this year. Prices are going up everywhere, but they are not always justifiable, at least not to our eyes. The pricing this year was definitely a big shock."
"When we first purchased our Splunk SOAR license, it was based on an event-count model. It was based on the number of events. I had strong opinions at the time that automation should not be stifled by the amount of automation you can accomplish, so the previous structure was not as beneficial for us. Later that year, we got told or saw at a conference that they announced user-based pricing. We are now in a renewal period, so we migrated to a user-based license model, which is more appropriate for us so that we no longer have to worry about stifling our automation based on the quantity."
"I found the price of Splunk SOAR to be good."
"The cost is high and the licensing is on an annual basis."
"Splunk SOAR is moderately priced, neither cheap nor overly expensive."
"Splunk is a fast enterprise tool, but it costs too much. At the same time, it's worth what we pay, in my opinion. We can efficiently perform all the functions and tie together the data. It's the perfect tool for our needs."
"While I can't confirm the exact pricing, some colleagues have mentioned that Splunk SOAR may be on the costlier side."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
914,889 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
19%
Comms Service Provider
11%
Manufacturing Company
9%
Energy/Utilities Company
7%
Financial Services Firm
11%
Manufacturing Company
10%
Outsourcing Company
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise53
 

Questions from the Community

Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Splunk Phantom?
I was not involved with the pricing, setup cost, and licensing.
What needs improvement with Splunk Phantom?
To improve Splunk SOAR, I would suggest making it easier for integration with third-party applications without having to learn custom API commands. If something is not supported out of the box, it ...
What is your primary use case for Splunk Phantom?
My main use case for Splunk SOAR is integration with third-party apps. A quick specific example of how I use Splunk SOAR for integrating with third-party apps is collecting context data to help wit...
 

Also Known As

Cofense Intelligence, PhishMe Intelligence, Intelligence ThreatHQ, Cofense Triage, Cofense LMS
Phantom
 

Overview

 

Sample Customers

Jackson Health System
Recorded Future, Blackstone
Find out what your peers are saying about Proofpoint, Microsoft, Check Point Software Technologies and others in Email Security. Updated: September 2026.
914,889 professionals have used our research since 2012.