No more typing reviews! Try our Samantha, our new voice AI agent.

Palo Alto Networks AutoFocus vs SOCRadar Extended Threat Intelligence comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Palo Alto Networks AutoFocus
Ranking in Threat Intelligence Platforms (TIP)
21st
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
7
Ranking in other categories
No ranking in other categories
SOCRadar Extended Threat In...
Ranking in Threat Intelligence Platforms (TIP)
3rd
Average Rating
8.6
Reviews Sentiment
6.2
Number of Reviews
21
Ranking in other categories
Digital Risk Protection (4th), Attack Surface Management (ASM) (6th)
 

Mindshare comparison

As of August 2026, in the Threat Intelligence Platforms (TIP) category, the mindshare of Palo Alto Networks AutoFocus is 1.3%, up from 1.1% compared to the previous year. The mindshare of SOCRadar Extended Threat Intelligence is 2.2%, down from 3.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
SOCRadar Extended Threat Intelligence2.2%
Palo Alto Networks AutoFocus1.3%
Other96.5%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

Tejas Jain - PeerSpot reviewer
Principle Cloud Architect at a tech services company with 11-50 employees
Seamless integration into existing ecosystem empowers effective threat detection
The most valuable feature of Palo Alto Networks AutoFocus is its seamless integration into the Palo Alto Networks ecosystem, allowing the threat intelligence feeds to be automatically consumed without manual effort. It uses the STIX format, which is automatically understood by the firewalls. AutoFocus also excels in behavioral analytics and reputation scoring, providing thorough threat analysis.
yozkul - PeerSpot reviewer
Cyber Security Engineer at Cevizsoft Teknoloji AŞ
Centralized threat intelligence has improved our visibility and accelerated incident response
You can find out new threats and security incidents with SOCRadar Extended Threat Intelligence. You can see the new vulnerabilities when you are using your products. This is very useful. SOCRadar Extended Threat Intelligence has improved security in my organization, but there are some problems. Sometimes there are too many alarms, which can become quite tiring. We have a lot of information infrastructures, and SOCRadar Extended Threat Intelligence has improved our security, but we do experience some alert fatigue. There are a lot of web servers. We also integrated SOCRadar Extended Threat Intelligence with the SIEM. We can see together, and we can see all of the threats and new threats, especially. If you integrate all internal sources, IP addresses, and services to SOCRadar Extended Threat Intelligence, you can view all of the sources together in a single monitor and area. You can also view all the tickets and vulnerabilities and threats. This is very useful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature that I like best is the dashboard."
"It is very easy to install and set up AutoFocus."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"Palo Alto Networks AutoFocus has had a positive impact on my company as we can reduce the cost for the SOC investment, and we can also get good feedback on how to strengthen our network from the expertise people available."
"The logs play a crucial role as they contribute to blocking unwanted Internet traffic."
"The most valuable feature is alerting."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"Thanks to SOCRadar, we have saved more than $500,000 for our customers by protecting them from cyber attacks."
"There is all positive experience with SOCRadar Extended Threat Intelligence."
"SOCRadar Extended Threat Intelligence has positively impacted my organization because it provides tools that alert us if there is credential leakage or vulnerabilities on our public-facing assets, and I can also read news about the dark web."
"SOCRadar Extended Threat Intelligence has really helped us to move from a reactive to a more proactive security approach by providing timely intelligence of vulnerabilities, threat actors, and other activities of the attackers."
"We proactively blocked the IOCs provided by SOCRadar Extended Threat Intelligence before breaches occurred in other banks and financial industries."
"SOCRadar Extended Threat Intelligence offers relevant information about organizations, along with threat intelligence tailored to specific industries."
"Basically, the results that it gives me as an outcome after I integrate with my domain are impressive."
"SOCRadar Extended Threat Intelligence has positively impacted my organization by reducing the risk score."
 

Cons

"It would be helpful to have better documentation for configuring and installing the solution."
"There were one or two instances where firewalls were not getting the threat intelligence feeds."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"It must be on-premises as well; it must have a server on-premises. It is a completely cloud-based product at present."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"Palo Alto Networks AutoFocus is not affordable."
"Regarding the noise minimization capabilities within the Agentic Phishing workflow, I understand that it lacks an organization-level baseline, and I need the analysis provided from Agentic responses to include a severity level."
"SOCRadar Extended Threat Intelligence could improve regarding the licensing scheme, which is credit-based, especially for specific activities, as it would be beneficial to have some flexibility in how these credits are consumed."
"In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set."
"Pricing is a problem as I see it. The credit-based model is extremely expensive."
"I have noticed exposures of credentials that do not show the correct password, as I receive alerts repeatedly for my credentials."
"Everything is good about SOCRadar Extended Threat Intelligence, but it produces too much noise that needs to be reduced."
"I think SOCRadar Extended Threat Intelligence can be improved by adding good keywords, as keywords are critical."
"SOCRadar Extended Threat Intelligence could be improved by implementing an autonomous threat hunting option."
 

Pricing and Cost Advice

"It is expensive."
"The solution is reasonably priced."
Information not available
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Performing Arts
14%
Outsourcing Company
10%
Manufacturing Company
10%
Energy/Utilities Company
6%
Financial Services Firm
14%
Outsourcing Company
12%
Comms Service Provider
10%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Large Enterprise4
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise3
Large Enterprise7
 

Questions from the Community

What needs improvement with Palo Alto Networks AutoFocus?
I feel that Palo Alto Networks AutoFocus can improve, especially since most of the OEMs are implementing MDR, Managed Service feature, which is still not available with Palo Alto. The MDR feature i...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus for threat monitoring, and it is provided by the OEM itself. I use the threat data correlation feature, which correlates with Cortex. We can use it for data corre...
What advice do you have for others considering Palo Alto Networks AutoFocus?
As a partner with Palo Alto Networks, my email is Sarvajit at bsrgroup.in. My job title is Technical Manager. I confirm that we will publish these reviews on peerspot.com in written or audio format...
What needs improvement with SOCRadar Extended Threat Intelligence?
SOCRadar Extended Threat Intelligence could be improved by implementing an autonomous threat hunting option. I am not certain if this is currently implemented, but I would appreciate seeing that fe...
What is your primary use case for SOCRadar Extended Threat Intelligence?
My main use case for SOCRadar Extended Threat Intelligence is Digital Risk Protection, brand risk monitoring, threat intelligence, supply chain attacks, supply chain monitoring, VIP monitoring, ide...
What advice do you have for others considering SOCRadar Extended Threat Intelligence?
SOCRadar Extended Threat Intelligence earns a rating of ten on a scale of one to ten. I rate it a ten because of the quality of information that is always delivered when needed, and the support fro...
 

Also Known As

Palo Alto Threat Intelligence Management
No data available
 

Overview

 

Sample Customers

Telkom Indonesia
Information Not Available
Find out what your peers are saying about Palo Alto Networks AutoFocus vs. SOCRadar Extended Threat Intelligence and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.