No more typing reviews! Try our Samantha, our new voice AI agent.
Information Security Management Analyst Support at Tata Consultancy
Real User
Top 20
Jul 15, 2026
Unified threat intelligence has strengthened visibility and prioritizes response to external risks
Pros and Cons
  • "SOCRadar Extended Threat Intelligence has improved our organization's visibility into external cyber threats and helped us identify potential risks early."

    What is our primary use case?

    Our main use case is in Cyber Threat Intelligence, CTI, and we use SOCRadar Extended Threat Intelligence to monitor the surface, deep, and dark web for emerging threats, leaked credentials, brand impersonation, and threat actor activity. For example, we use the platform to identify exposed credentials related to our organization, assess the potential business impact, prioritize the risk, and coordinate remediation with the security team before the information could be exploited.

    I have been using SOCRadar Extended Threat Intelligence since the beginning of our project. I was involved from the initial implementation. I have used the platform throughout the project to support threat intelligence activity, monitor the threat landscape, and strengthen our cybersecurity capabilities.

    What is most valuable?

    One of the biggest advantages of our main use case with SOCRadar Extended Threat Intelligence is having multiple threat intelligence capabilities consolidated in a single platform. It provides continuous visibility and external detections, helping us prioritize risk based on their potential business impact and enable faster, more informed decision-making. It also improves collaboration between threat intelligence, SOC, and incident response teams by providing actionable and contextualized intelligence.

    The features that stand out the most in SOCRadar Extended Threat Intelligence are the External Attack Surface Management, Dark Web Monitoring, Digital Risk Protection, and threat intelligence capability. I also appreciate the platform's ability to provide contextual intelligence, monitor leaked credentials, and brand impersonation, and deliver actionable alerts that help prioritize remediation efforts. Another strength is having these capabilities integrated into a single platform. It makes it easy to investigate threats, assess business impact, and support fast decision-making for security teams.

    SOCRadar Extended Threat Intelligence has improved our organization's visibility into external cyber threats and helped us identify potential risks early. This has enabled us to prioritize remediation efforts based on risk and business impact rather than reacting after an incident occurs. For example, by identifying exposed credentials and monitoring external attack surface changes, we were able to notify the appropriate team, reduce exposure, and strengthen our overall security posture. It has also supported faster investigation and more informed decision-making through actionable threat intelligence.

    What needs improvement?

    Overall, my experience with SOCRadar Extended Threat Intelligence has been positive. One area of improvement would be expanding customizing options for dashboard and reports, allowing organizations to tailor the view more closely to different stakeholders. I also think additional integration with third-party security tools and more flexible automation capabilities would further streamline security operations. As the threat landscape evolves, continuously expanding threat intelligence coverage and enrichment would also add value.

    For how long have I used the solution?

    I have been working in the cybersecurity field for over three years. During this time, I have gained experience in cybersecurity, cyber threat intelligence, security operation, governance, vulnerability management, digital forensics, and supporting security initiatives across the banking and financial service sector.

    Buyer's Guide
    SOCRadar Extended Threat Intelligence
    August 2026
    Learn what your peers think about SOCRadar Extended Threat Intelligence. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
    911,473 professionals have used our research since 2012.

    What's my experience with pricing, setup cost, and licensing?

    I am not directly involved in licensing and the budget planning, so I cannot comment on the price from a personal perspective regarding SOCRadar Extended Threat Intelligence. However, my impression is that having freemium options and flexible licensing can help organizations evaluate the platform before making a large investment. This can reduce adoption risk and make it easy to justify the business value based on real-world use cases and outcomes.

    What other advice do I have?

    In my experience, the AI capabilities of SOCRadar Extended Threat Intelligence have generally been accurate and reliable when used to support threat intelligence and prioritizing. The information has been trustworthy, especially when combined with the contextual threat intelligence and the analysis validation. As with any AI-driven capability, I consider it a decision support tool rather than a replacement for human analysis. But it has helped improve efficiency and accelerate investigations.

    I have utilized SOCRadar Extended Threat Intelligence's unique dark web sources as part of our cyber threat intelligence activity. This source has helped improve our visibility into potential threats, including leaked credentials, exposed data, threat actor discussions, and IOCs, indicators of compromise. The main impact has been the ability to identify potential risks early, validate the exposure, and provide actionable intelligence to security teams, so they can take preventive measures before a threat escalates into a security incident.

    I provided an overall rating of eight for this review.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2865849 - PeerSpot reviewer
    Cybersecurity Consultant at a tech services company with 11-50 employees
    Real User
    Top 10
    Jun 30, 2026
    Proactive threat monitoring has strengthened brand protection and reduced incident response time
    Pros and Cons
    • "SOCRadar Extended Threat Intelligence has greatly improved the security posture regarding all of this and we feel more secure and more alerted about what is happening with the brand and company."

      What is our primary use case?

      I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly.

      My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard.

      The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution.

      I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown.

      For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.

      What is most valuable?

      The best features of SOCRadar Extended Threat Intelligence are the Takedown feature and the dark market feature, and also the leaked password monitoring where I can see what passwords in the organization have been leaked. These are really the best features I see value in from SOCRadar's solution.

      The Takedown solution in SOCRadar Extended Threat Intelligence is amazing because it feels like they support me by giving all information regarding the takedown process. I can see in the solution all the steps they are taking to ensure the takedown and if there is any problem along the way. Additionally, SOCRadar support is responsive and gives all information when asked about a specific takedown. In the end, if a takedown is possible, I feel it will go through without any problem with their support. If the takedown is not possible, I have all the information explaining why the takedown was not possible, so I can proceed forward and know how to handle such cases.

      SOCRadar Extended Threat Intelligence has really impacted my view of the organization, especially what is being discussed on the Dark Web. Regarding the outcome, I feel I now have a better view of what is happening with the organization, the attack surface, supply chain vulnerabilities, and what is coming up with the supply chain. SOCRadar Extended Threat Intelligence has greatly improved the security posture regarding all of this. We feel more secure and more alerted about what is happening with the brand and company.

      What needs improvement?

      The dashboard and alerting, especially the dashboard, needs some fine-tuning at first. At first, there was a lot of noise in the dashboard, with some things that were already taken care of reappearing in the dashboard. Once I fine-tuned it and selected what I wanted to see, the dashboard became really the best thing in the solution. Once everything is fine-tuned, I need only to look at the dashboard.

      Regarding improvement, SOCRadar Extended Threat Intelligence is already advanced and well-mature. Perhaps they could improve the dashboard slightly, though the navigating system is quite efficient and the dashboard is efficient. There is an AI assistant with everything I need, so I do not know of any improvement to suggest to make it better.

      Regarding improvement, I do not really have anything to say. They shared their roadmap with me a few times ago, so I will let them provide new metrics and new information to make it better. I do not have anything to add regarding improvement. The solution is quite mature right now, so I have nothing to add.

      For how long have I used the solution?

      I have started with SOCRadar Extended Threat Intelligence for more than a year.

      How are customer service and support?

      The customer support is actually really great and really helpful. I have had no problem with the support. I would even say that the customer support is one of the best selling points regarding the solution.

      Which solution did I use previously and why did I switch?

      SOCRadar Extended Threat Intelligence's solution is the first one I used, but before going with SOCRadar Extended Threat Intelligence, I explored the solutions provided in the region. I checked with Recorded Future, Group-IB, and Kaspersky Threat Intelligence, but I did not find what I needed and the pricing was very high for Group-IB and Recorded Future, so in the end I settled with SOCRadar Extended Threat Intelligence.

      What was our ROI?

      Regarding return on investment, I really utilized the takedown services and that really helped me get better control on brand images. Regarding metrics, I do not know if I have any metrics to give. I can say that the solution is very helpful and can be used by only one or two employees, which is great. This reduced the employee's workload, which is really helpful. However, I do not know if I can say anything more about the return on investment.

      What's my experience with pricing, setup cost, and licensing?

      I think the pricing is really one of the best I can find in the region regarding a solid, mature CTI solution, meaning an extended threat intelligence solution. When compared to the competition such as Group-IB or Recorded Future where they gave me a very high price, SOCRadar Extended Threat Intelligence pricing is really much better for a very good set of features. These are mature features, so it is really good. Regarding setup cost, the setup is actually part of the licensing. During the first purchase, the SOCRadar Extended Threat Intelligence customer success team will help me put the platform in place, which is really great and helpful. The licensing is set in different bundles and it can really be optimized if I know exactly what I need, and that is really great.

      Which other solutions did I evaluate?

      I checked with Group-IB, Recorded Future, and Kaspersky Threat Intelligence solution.

      What other advice do I have?

      For brand protection, I had my partner, or more of a client who had someone publishing on the internet, especially on LinkedIn, about their vulnerabilities or their scan results about their attack surface vulnerabilities. I quickly got in touch with SOCRadar Extended Threat Intelligence so they could take down those posts because they directly impacted my client's image. The response from SOCRadar Extended Threat Intelligence was amazing. They supported me throughout this process and the post was quickly taken down, I think it was taken down in about a day, something between 24 to 48 hours. It was a very good experience.

      SOCRadar Extended Threat Intelligence has really impacted my view of the organization, especially what is being discussed on the Dark Web. Regarding the outcome, I feel I now have a better view of what is happening with the organization, the attack surface, supply chain vulnerabilities, and what is coming up with the supply chain. SOCRadar Extended Threat Intelligence has greatly improved the security posture regarding all of this. I feel more secure and more alerted about what is happening with the brand and company.

      For numbers, I do not have any numbers to give, but the most specific metrics I can discuss is the faster response time because I am alerted in real time and I have the information in real time. I can respond more effectively and with the support of the SOCRadar Extended Threat Intelligence team, I can take action very fast. I can really resolve the issue before it becomes a bigger problem, especially with the takedown, with leaked passwords, or with anything similar. That is the biggest metric and the biggest improvement regarding the implementation of SOCRadar's solution.

      SOCRadar Extended Threat Intelligence has an AI assistant that is a really simple assistant that explains attacks or things happening in the reports or in the alerts, which is great and really helpful.

      I think if anyone is interested in SOCRadar Extended Threat Intelligence, I think calling or booking a POC with them would really give the opportunity to check the solution, to get in touch with the SOCRadar Extended Threat Intelligence team, and see the value they provide. That would be enough for anyone to actively consider the solution.

      The solution is very mature. The customer support is really great. I think they will be better and better in the upcoming years and maybe they will be a leader in the industry, which I hope for them because the team is great.

      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      Last updated: Jun 30, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      SOCRadar Extended Threat Intelligence
      August 2026
      Learn what your peers think about SOCRadar Extended Threat Intelligence. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
      911,473 professionals have used our research since 2012.
      Principal Cybersecurity Engineer at a tech vendor with 1,001-5,000 employees
      Real User
      Top 20
      Jun 30, 2026
      Threat intelligence has strengthened dark web monitoring and improves breach response decisions
      Pros and Cons
      • "The pricing for SOCRadar Extended Threat Intelligence is within our budget, and the features offered are more comprehensive compared to other solutions available at the same price point."
      • "The support quality is inconsistent."

      What is our primary use case?

      I primarily use SOCRadar Extended Threat Intelligence for threat intelligence. Secondary uses include dark web news monitoring, threat hunting, and alerts regarding the dark web such as data breaches, VIP monitoring, and brand protection. These are the activities we use regularly.

      Regarding the IGENTIC phishing workflow, we do not directly use it because this tool is not utilized for phishing purposes. We have not used that module and workflow. However, we have observed that it is able to detect phishing alerts, though not directly. The alerts are mostly related to similar domains being registered and hosting similar pages. Our engineers resolve these alerts, but we have not implemented IGENTIC or automation for this.

      What is most valuable?

      SOCRadar Extended Threat Intelligence provides access to unique dark web sources where credentials can be purchased. We have credits provided by SOCRadar that allow us to unlock more details. Sometimes general information is provided, such as an email ID found. When we need a hash, password, or further details regarding which server was compromised or which identities were compromised, we purchase this information using these credits. We use these credits to buy from the Russian market or any other dark web sources we deem necessary. SOCRadar Extended Threat Intelligence also offers a malware analysis option that uses some credits. The credits vary depending on different modules, as each module has a different set of credits that renew monthly, which we utilize.

      What needs improvement?

      The support quality is inconsistent. While support is adequate in some scenarios, they fail to assist when we request takedowns of websites that use our company's key information and portray themselves as fake versions of our company. In these situations, they respond that this falls outside their scope. During the proof of concept phase, this was within their scope, but after purchasing, when we ask them to take down websites similar to our company, they refuse by stating it does not come within their scope.

      Recently, SOCRadar Extended Threat Intelligence integrated its own artificial intelligence, but I do not believe it is sufficiently capable. The AI still requires training on its own platform and does not provide accurate results. The platform can deliver good results based on the data it possesses. When asking generic questions, the AI has difficulty, but when we navigate to any particular page and ask for details regarding it, the results improve. However, when directly requesting information from the dashboard, the AI does not work as expected.

      For how long have I used the solution?

      I have used SOCRadar Extended Threat Intelligence for about two years.

      What do I think about the stability of the solution?

      I have not observed significant lagging, crashing, or downtime. On one or two occasions, it failed due to SSO, but this was not a direct failure. Nothing has impacted us because of these issues since it is not a critical tool. As a result, we have not experienced any problems until now.

      What do I think about the scalability of the solution?

      The licenses we purchased for SOCRadar Extended Threat Intelligence are being utilized for nearly all of our needs, but sometimes we must confirm from our end whether something is our asset or not. This is the only challenging task because the tool scans across the entire internet and provides us with many URLs similar to our company. However, some results are not actually similar, as they may contain synonyms or be from other products or companies that are not part of our organization, yet the tool still shows them. This represents a hectic task that we must manage. Apart from this, I do not see much of an issue.

      How are customer service and support?

      We can have three to four connections with the support team every quarter, and they assist us with suggestions on how to fine-tune and obtain better results. We have engaged with them in the past, approximately six months ago.

      SOCRadar Extended Threat Intelligence was easy to deploy because it is a SaaS-based tool that does not require much integration with our other tools. It does not require any personally identifiable information from our company, so the deployment was straightforward. We have completed a few integrations, and these were also simple. The tool does not have direct integration, but it offers open-source integrations such as STIX format and TAXII, which were helpful.

      Which solution did I use previously and why did I switch?

      We conducted proof of concept evaluations for FortiRecon from CrowdStrike, ThreatFox, and another vendor whose name I do not recall exactly. Additionally, CloudSEK was another vendor we evaluated. We ran proof of concept studies with three to four vendors, and SOCRadar emerged as the winner.

      How was the initial setup?

      SOCRadar Extended Threat Intelligence was easy to deploy because it is a SaaS-based tool that does not require much integration with our other tools. It does not require any personally identifiable information from our company, so the deployment was straightforward. We have completed a few integrations, and these were also simple. The tool does not have direct integration, but it offers open-source integrations such as STIX format and TAXII, which were helpful.

      What other advice do I have?

      I expect clear and detailed responses to my inquiries based on the product.

      Since SOCRadar Extended Threat Intelligence is a SaaS platform, maintenance can primarily be handled by the vendor. We only need to fine-tune the alerts for our benefit by determining which alerts are necessary and which are not.

      The pricing for SOCRadar Extended Threat Intelligence is within our budget, and the features offered are more comprehensive compared to other solutions available at the same price point. Overall, I rate this solution at eight out of ten.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jun 30, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2807343 - PeerSpot reviewer
      Soc N1 at a university with 10,001+ employees
      Real User
      Top 20
      Mar 6, 2026
      Credential leak detection on the dark web has improved protection but still needs better growth support
      Pros and Cons
      • "The best feature that SOCRadar Extended Threat Intelligence offers is definitely the detection of leaks in the dark web."
      • "SOCRadar Extended Threat Intelligence does not handle growth well as my needs change."
      • "SOCRadar Extended Threat Intelligence does not handle growth well as my needs change."

      What is our primary use case?

      My primary use case for SOCRadar Extended Threat Intelligence is detecting credential and data leaks for our clients. We use the platform to monitor the dark web for compromised domains and leaked datasets containing our customers' emails and passwords. When we discover an active, leaked account—particularly for high-risk clients like those in the banking sector—we immediately notify them to change their credentials and secure the account before an attacker can exploit it. My experience with the tool is highly focused on this specific area of proactive data leak detection, and it is highly effective for this work.

      What is most valuable?

      The best feature that SOCRadar Extended Threat Intelligence offers is definitely the detection of leaks in the dark web.

      When I mentioned detection clips, I think a lot of our customers don't have security teams, so it is easier to use.

      SOCRadar Extended Threat Intelligence has positively impacted my organization by saving time and giving us an overview of all that we need in our hands.

      We reduce the surface of attack for our customers and give them more recommendations based on what we found in SOCRadar Extended Threat Intelligence.

      For how long have I used the solution?

      I have been using the solution for the past three months.

      What do I think about the stability of the solution?

      SOCRadar Extended Threat Intelligence is stable in my experience.

      What do I think about the scalability of the solution?

      SOCRadar Extended Threat Intelligence does not handle growth well as my needs change.

      What other advice do I have?

      Regarding the utilization of SOCRadar Extended Threat Intelligence's unique dark web sources, I should clarify that I am not the one who pays for SOCRadar Extended Threat Intelligence or provides the licenses. I was using it as a solution.

      I have used SOCRadar Extended Threat Intelligence's dark web sources to find leaked credentials or data about my customers, and it helps. It is very helpful and gives us an advantage in protecting our customers.

      For advice, I think it is easier if you go to read the documentation before using it.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Microsoft Azure
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Mar 6, 2026
      Flag as inappropriate
      PeerSpot user
      Yevheniy Moyko - PeerSpot reviewer
      Cyber Security Engineer at Underdefense
      Real User
      Top 5
      Apr 14, 2026
      Early threat detection has improved through tailored intelligence and dark web monitoring
      Pros and Cons
      • "SOCRadar Extended Threat Intelligence offers relevant information about organizations, along with threat intelligence tailored to specific industries."
      • "However, pricing, interface, customization, AI, and integration could be improved."

      What is our primary use case?

      SOCRadar Extended Threat Intelligence is primarily used for threat intelligence and attack surface management.

      What is most valuable?

      SOCRadar Extended Threat Intelligence offers relevant information about organizations, along with threat intelligence tailored to specific industries. For example, if monitoring the telecom sector, I receive only telecom-related threat intelligence.

      The platform provides valuable insights on various Telegram channels involved in cyber campaigns, particularly relevant given the Russia-Ukraine conflict.

      SOCRadar Extended Threat Intelligence helps me identify potential threats early through monitoring of Telegram channels and dark web sources. I typically receive information about users whose data was leaked from companies we monitor, as well as information regarding APT plans that may involve our clients.

      SOCRadar Extended Threat Intelligence minimizes noise through its noise minimization capabilities and agentic phishing workflow. However, the system sometimes misses phishing emails, requiring me to double-check emails that appear suspicious or may be false positives. Overall, the platform provides significant assistance to our operations.

      The Attack Surface Threat Assessment feature is exceptional. I can understand how attacks are initiated, where they originate, and how to proceed accordingly, making it an excellent feature.

      I utilize the unique dark web sources through SOCRadar Extended Threat Intelligence via dark web monitoring, which is a valuable feature.

      What needs improvement?

      For our use cases, SOCRadar Extended Threat Intelligence performs well overall. However, pricing, interface, customization, AI, and integration could be improved. The AI has not been fully trained yet and requires enhancement. The interface is somewhat complicated with multiple tools that could be more intuitive for users.

      For how long have I used the solution?

      I have been using SOCRadar Extended Threat Intelligence for approximately one year and a half.

      What do I think about the stability of the solution?

      I rate the stability of SOCRadar Extended Threat Intelligence at ten out of ten.

      What do I think about the scalability of the solution?

      I rate the scalability of SOCRadar Extended Threat Intelligence at ten out of ten.

      How are customer service and support?

      I rate the technical support for SOCRadar Extended Threat Intelligence at nine out of ten.

      Which solution did I use previously and why did I switch?

      I have not compared SOCRadar Extended Threat Intelligence with other solutions directly. CrowdStrike is an EDR system, which is somewhat different and has its own threat intelligence capabilities. For our use cases, we utilize CrowdStrike as an EDR system and SOCRadar Extended Threat Intelligence as a threat intelligence and dark web monitoring tool, and both work effectively together.

      How was the initial setup?

      The implementation of SOCRadar Extended Threat Intelligence depends on specific use cases, but in general, it is easy to implement.

      What about the implementation team?

      Our company is an MSSP provider, and the organization using SOCRadar Extended Threat Intelligence is an enterprise. Approximately twenty people from our side use the platform. From the client side, approximately fifteen to twenty people use it, bringing the total to approximately forty users.

      What other advice do I have?

      For organizations considering SOCRadar Extended Threat Intelligence, a proof of concept should be the primary step. Many organizations adopt security tools without involving their people and rely on default configurations. Organizations should first conduct a proof of concept, then educate their teams on proper usage and configuration to take full advantage of the platform rather than relying on default settings. I rate this review at ten out of ten.
      Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
      Last updated: Apr 14, 2026
      Flag as inappropriate
      PeerSpot user
      Cyber Security Specialist at Gambia Revenue Authority
      Real User
      Top 20
      Jul 29, 2026
      Proactive threat intelligence has reduced incident time and improves visibility into external risks
      Pros and Cons
      • "SOCRadar Extended Threat Intelligence has impacted my organization positively by enabling us to monitor and see exactly what our external threat exposures are, a capability we lacked before using SOCRadar Extended Threat Intelligence."
      • "In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set."

      What is our primary use case?

      My main use case for SOCRadar Extended Threat Intelligence is for cyber threat intelligence activities related to our work, as we use it to search for potential threats to our digital infrastructure.

      A specific example of how I use SOCRadar Extended Threat Intelligence for searching potential threats to my digital infrastructure is a recent incident involving a third-party data breach, where one of our staff's email addresses was involved. Through SOCRadar Extended Threat Intelligence, we were able to investigate and discovered that a staff email had been involved in a data breach. Due to that information, the platform proved to be very effective as we followed our incident response procedures, notified the staff to change her password, and investigated further.

      Another way I have used SOCRadar Extended Threat Intelligence is that the platform automatically scans for potential digital targets based on certain preset values we configured in the system, giving us insight into the external threat exposure of our infrastructure. This helps us understand what we are putting out there and how the world sees that as a threat to our systems and how we can protect it.

      What is most valuable?

      The best features SOCRadar Extended Threat Intelligence offers are the threat intelligence feature, which I find very effective, as it allows me to scan for data breach exposures in the dark web, and the Attack Surface Management feature, which helps us know what a potential attack surface is. I also use the Vulnerability Intelligence feature.

      The dark web intelligence feature has helped me in threat hunting, allowing me to research my domain and digital assets, such as IP addresses and cloud buckets involved in potential leaks or data breaches. The Attack Surface Management feature gives us a comprehensive view of our digital footprint and vulnerability monitoring systems.

      SOCRadar Extended Threat Intelligence has impacted my organization positively by enabling us to monitor and see exactly what our external threat exposures are, a capability we lacked before using SOCRadar Extended Threat Intelligence.

      What needs improvement?

      In terms of improvement for SOCRadar Extended Threat Intelligence, I think the asset identification procedures could be better, as we receive a lot of false positives related to the specific flags we set.

      For how long have I used the solution?

      I have been using SOCRadar Extended Threat Intelligence for three years.

      What was our ROI?

      Specific outcomes I have noted include a reduction in the time we spend on incidents because we now have the capability to respond more effectively.

      What other advice do I have?

      I would rate SOCRadar Extended Threat Intelligence an 8.5 out of 10. I advise others looking into using SOCRadar Extended Threat Intelligence to try the product, as it is very effective and a great product that I believe would be very helpful.

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jul 29, 2026
      Flag as inappropriate
      PeerSpot user
      Tanuja Parab - PeerSpot reviewer
      Dark L2 Web Analyst at a tech services company with 11-50 employees
      Real User
      Top 5Leaderboard
      Jul 17, 2026
      Brand monitoring and threat hunting have strengthened our protection across clients and social media
      Pros and Cons
      • "SOCRadar Extended Threat Intelligence has positively impacted our organization by helping us stay in good posture and shows us how many users have been impacted."
      • "I think SOCRadar Extended Threat Intelligence can be improved by adding good keywords, as keywords are critical."

      What is our primary use case?

      My main use case for SOCRadar Extended Threat Intelligence is to monitor my clients, check if any suspicious activities are observed over the internet or on the black market, and I also use it for brand monitoring. It is a helpful tool for us.

      A specific example of how I have used SOCRadar Extended Threat Intelligence for brand monitoring or catching suspicious activities is that we get alerts from SOCRadar Extended Threat Intelligence itself, such as for the Facebook impersonating accounts. We do not see these things normally, but when we get alerts, we know someone has created a channel regarding our brand and it is a misuse. For black market purposes, we receive alerts, obtain them, and check the credentials, and this way we work.

      I use SOCRadar Extended Threat Intelligence not just for threat intelligence but also for my own research on threat hunting, which is a good specific feature in SOCRadar Extended Threat Intelligence where I can check any domain, any IP, or any username to see if any data is available over the domain.

      How has it helped my organization?

      SOCRadar Extended Threat Intelligence has positively impacted our organization by helping us stay in good posture and shows us how many users have been impacted. It helps us make our business strong regarding brand monitoring, PII exposure, black market activities, and checking user data on social media, enabling us to stay protected and ahead. For example, during the FortiBleed event, we checked if it was related to us or our client, we observed this and informed them to check all their users, and we were able to log in, which was crucial. We are not merely waiting for an attack; we can significantly lessen the impact.

      What is most valuable?

      In my opinion, the best features SOCRadar Extended Threat Intelligence offers are brand monitoring, CTI, and currently the executive one.

      Out of those features, I find myself using brand monitoring the most because it depends on the client scenario based on mostly clients focusing on what impact is on their brand, such as Facebook or any social media or any fake accounts. They do not usually go for the CTI, so we often use these tools as advanced brand protection.

      I appreciate the new feature where we can add social media accounts ourselves, allowing us to receive alerts if we do not observe any alert, and we can add accounts manually when we see Facebook or Instagram accounts. We can initiate the takedown, which I observed to be an excellent feature. For the executive feature, you can take down from the forum, which is also good for VIP users.

      The noise minimization capabilities within the agentic phishing workflow are very good; if someone creates a domain, that does not automatically mean we must get an alert. The AI agentic modifies the rule, and it only gets triggered based on impactful events; thus, we avoid most false positives, ensuring we get alerts when necessary.

      What needs improvement?

      I think SOCRadar Extended Threat Intelligence can be improved by adding good keywords, as keywords are critical. Additionally, they need to enhance AI-generated scores for parked or normal domains because sometimes we receive impersonating domains based solely on the AI score. There also need to be time adjustments since I work in India but receive alerts based on UST time, which sometimes causes delays that impact our business.

      The reporting feature is good now, though I would say the timing of the alerts can be improved since sometimes there are delays, and they scan by themselves for a day before we receive alerts.

      For how long have I used the solution?

      I have been using SOCRadar Extended Threat Intelligence for the past three years.

      What do I think about the stability of the solution?

      SOCRadar Extended Threat Intelligence is stable.

      What do I think about the scalability of the solution?

      The scalability of SOCRadar Extended Threat Intelligence is rated at nine.

      How are customer service and support?

      I would rate customer support at ten.

      Which solution did I use previously and why did I switch?

      We previously used CyberArk and Cybel, but the solutions were not satisfactory, so we moved to SOCRadar Extended Threat Intelligence.

      How was the initial setup?

      My experience with pricing, setup cost, and licensing is very good; I can quickly check how many tokens are required for domain utilization and make budget adjustments. It is wonderful and allows for easy minor changes.

      What was our ROI?

      I have seen a return on investment; for example, with user creations, many people create numerous accounts, but not everyone uses SOCRadar Extended Threat Intelligence. We focused on one or two main accounts and made use of the webhook feature to get alerts on Teams for critical updates. This way, our costs regarding users have diminished, and we can monitor significant events.

      Which other solutions did I evaluate?

      We did not evaluate other options before choosing SOCRadar Extended Threat Intelligence; we just appreciated SOCRadar Extended Threat Intelligence's features.

      What other advice do I have?

      My advice to others looking into using SOCRadar Extended Threat Intelligence is to use the demo first, check your keywords, run them, and see how it goes because SOCRadar Extended Threat Intelligence helps us with its ease of use, making it a wonderful and simple tool that is efficiently strong and easy to understand. I would rate this product at nine out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      Last updated: Jul 17, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2868204 - PeerSpot reviewer
      Soc Analyst 11 at a tech services company with 11-50 employees
      Real User
      Top 5Leaderboard
      Jul 6, 2026
      Proactive threat monitoring has strengthened client protection and reduces external attack risks
      Pros and Cons
      • "There is all positive experience with SOCRadar Extended Threat Intelligence."
      • "Everything is good about SOCRadar Extended Threat Intelligence, but it produces too much noise that needs to be reduced."

      What is our primary use case?

      My main use case for SOCRadar Extended Threat Intelligence is tracking threat campaigns on our clients.

      There was a recent Team 313 campaign going on, and on a public Telegram channel, they stated they were targeting a Dubai-based government. That Dubai-based government is integrated with us, so as a provisional measure, we made a case on high severity and told them to use rate limiting or other DDoS prevention techniques. This is how we use SOCRadar Extended Threat Intelligence.

      We also use SOCRadar Extended Threat Intelligence to track the PII exposure of clients. For example, if there is a third-party application, such as a Udemy breach, we check if our client data is leaked or not. If we are logged in because of the credentials of that user, we will raise a high severity alert.

      What is most valuable?

      The best feature that SOCRadar Extended Threat Intelligence offers is its scans. It does passive scanning, and you will know if there is anything suspicious related to the client. In case there is an impersonation domain or any GitHub repository, you will know instantly. That's the best thing about SOCRadar Extended Threat Intelligence.

      The passive scan definitely improves accuracy. If you do the manual work, it may take some time, around three to four business days. However, with SOCRadar Extended Threat Intelligence, you will get notified if there is a new domain formed or if the domain formed is related to the client. That's the best thing.

      There is all positive experience with SOCRadar Extended Threat Intelligence. For example, if an exposed subdomain or leaked credential is detected through passive methods, the organization can take proactive actions, such as restricting access, resetting passwords, or enabling MFA. This reduces the risk of unauthorized access, data breaches, or account compromise.

      Passive scanning improves our organization's security posture in measurable ways. It helps to reduce the external attack surface by identifying and removing exposed assets, such as new subdomains or open services. Our organization can track metrics corresponding to the number of exposed assets discovered versus remediated over time. This lowers the risk of account compromise by detecting leaked credentials.

      What needs improvement?

      Everything is good about SOCRadar Extended Threat Intelligence, but it produces too much noise that needs to be reduced. SOCRadar Extended Threat Intelligence works by keywords, so if there is a particular keyword that you have added, it will trigger an alert. Most of the time, those cases are false positives, so it does take time with the investigation you have done. This is a key improvement area. I would also suggest improving the customization options, such as a tailor-made dashboard, industry-specific intelligence, and more flexible alert rules. With SOCRadar Extended Threat Intelligence, there are no options to create rules; there is a fixed number of rules that will be triggered.

      Regarding SOCRadar Extended Threat Intelligence's AI capabilities, the accuracy and reliability of output are not that accurate.

      For how long have I used the solution?

      I have been using SOCRadar Extended Threat Intelligence for around 1.3 years.

      What do I think about the stability of the solution?

      SOCRadar Extended Threat Intelligence is stable.

      What do I think about the scalability of the solution?

      SOCRadar Extended Threat Intelligence is pretty scalable.

      How are customer service and support?

      The customer support for SOCRadar Extended Threat Intelligence is pretty good. You will get a response within one business day. For example, if there is a takedown request, you will definitely get a faster response.

      Which solution did I use previously and why did I switch?

      We have only relied on SOCRadar Extended Threat Intelligence from the start and have not used any previous solutions.

      Which other solutions did I evaluate?

      We have evaluated other options with DarkOwl services, but SOCRadar Extended Threat Intelligence's services are pretty good. We spoke with different organizations regarding DarkOwl.

      What other advice do I have?

      I would advise others looking into using SOCRadar Extended Threat Intelligence to definitely go ahead, especially if you are a fresher, because the dashboard is pretty user-friendly. If you are new to dark web monitoring, SOCRadar Extended Threat Intelligence team is going to provide you with the guidance.

      Time has definitely been saved. I rate this product an 8 out of 10.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Other
      Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
      Last updated: Jul 6, 2026
      Flag as inappropriate
      PeerSpot user
      reviewer2867601 - PeerSpot reviewer
      SOC Analyst L2 at a computer retailer with 11-50 employees
      Real User
      Top 20
      Jul 6, 2026
      Credential leaks have been detected faster and data sources now need clearer identification
      Pros and Cons
      • "I am using the freemium tier of SOCRadar Extended Threat Intelligence, and it is a very good one."
      • "I think the feature about the data source, such as the Telegram channel or breach forums, should be more clear, containing the Telegram channel name or the breach forum name instead of just the link."

      What is our primary use case?

      My main use case for SOCRadar Extended Threat Intelligence is credential leakage. For example, I deal with leaked credential users, and those credential users are using the credentials to access the environment or something similar, such as a valid account.

      What is most valuable?

      SOCRadar Extended Threat Intelligence offers excellent features, including the differentiation between breaches and infostealers, and the classification of the data and the source from where it is collected.

      When I mention classification of data and differentiating breaches from infostealers, this helps me decide if a situation is affecting the environment scale or a personal account. SOCRadar Extended Threat Intelligence has helped us monitor our environment for leakage or breaches.

      I have noticed a faster response time. For example, a credential user was stolen by an infostealer, and we detected this through SOCRadar Extended Threat Intelligence before any incident occurred.

      What needs improvement?

      I think the feature about the data source, such as the Telegram channel or breach forums, should be more clear, containing the Telegram channel name or the breach forum name instead of just the link.

      For how long have I used the solution?

      I have been using SOCRadar Extended Threat Intelligence for almost six months.

      What do I think about the stability of the solution?

      SOCRadar Extended Threat Intelligence is good and stable.

      What do I think about the scalability of the solution?

      SOCRadar Extended Threat Intelligence has good scalability.

      How are customer service and support?

      My company does not have a business relationship with this vendor other than being a customer.

      Which solution did I use previously and why did I switch?

      I previously used a few different solutions, including Group-IB.

      How was the initial setup?

      I think the pricing, setup cost, and licensing of SOCRadar Extended Threat Intelligence are good.

      What about the implementation team?

      I am using the freemium tier of SOCRadar Extended Threat Intelligence, and it is a very good one. I am not investing more and getting very good value. Since I am using the freemium tier, this reflects in money-saving ways.

      What was our ROI?

      I think the return on investment is good and looking positive regarding the features of SOCRadar Extended Threat Intelligence.

      What's my experience with pricing, setup cost, and licensing?

      I think the pricing, setup cost, and licensing of SOCRadar Extended Threat Intelligence are good.

      Which other solutions did I evaluate?

      I evaluated other options before choosing SOCRadar Extended Threat Intelligence, such as Group-IB.

      What other advice do I have?

      My advice to others looking into using SOCRadar Extended Threat Intelligence is that it is a good solution. SOCRadar Extended Threat Intelligence sits very well with other competitors, and very few companies are better than SOCRadar. SOCRadar Extended Threat Intelligence's AI capabilities are good and accurate. I found this interview good and do not think anything needs to change for the future. I would appreciate a short poem to summarize my review. I gave this product a rating of seven out of ten.

      Which deployment model are you using for this solution?

      Public Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jul 6, 2026
      Flag as inappropriate
      PeerSpot user
      Cyber Security Engineer at a tech consulting company with 11-50 employees
      Real User
      Top 20
      Jul 20, 2026
      Threat intelligence has strengthened dark web monitoring and automated credential exposure response
      Pros and Cons
      • "SOCRadar Extended Threat Intelligence has positively impacted my organization by enabling me to feed higher severity IOCs to other tools, automatically blocking malicious threat actors roaming in the market, while generating reports related to CVEs that we share with our vendors and respective teams for vulnerability validation and remediation."
      • "I have noticed exposures of credentials that do not show the correct password, as I receive alerts repeatedly for my credentials."

      What is our primary use case?

      I primarily use SOCRadar Extended Threat Intelligence for monitoring data credential leaks and password leaks, handling exposures, and managing GitHub public repository, SSL expiry, and attack surface along with public repositories exposures and cyber threat intelligence, as well as feeding threat intel feeds to my other tools such as LogRhythm and EDR, XDR.

      For instance, I created a use case involving my company's domain name and email ID where if any user with my company's email ID gets exposed on the dark web and deep web, I receive an alert so I can validate whether the credential is currently active or not and take necessary actions.

      Regarding public repository exposure, if any of our company employees push their data to public platforms such as GitHub, we get alerts based on critical keywords which allows me to analyze how critical the exposure is to our organization. For SSL expiry, I validate certificates on domains and subdomains based on their expiry, ensuring they are either self-signed or public SSL, which helps us reach out to the domain users and owners for renewal.

      What is most valuable?

      I find all the features of SOCRadar Extended Threat Intelligence, including those related to internal threat actors and ongoing threats, to be impressive as they offer crucial IOCs, allowing me to proactively extract and block any threat actors targeting specific organizations.

      Exporting any IOCs detail from SOCRadar Extended Threat Intelligence is straightforward, as they come in CSV format, allowing me to easily categorize them by IPs, domains, or URLs and quickly integrate them into my other tools for action.

      The dashboard and reporting features are very user-friendly, and I have personalized my dashboard to include daily and weekly alerts related to IPs, top most threat actors, and the most infected users.

      SOCRadar Extended Threat Intelligence has positively impacted my organization by enabling me to feed higher severity IOCs to other tools, automatically blocking malicious threat actors roaming in the market, while generating reports related to CVEs that we share with our vendors and respective teams for vulnerability validation and remediation.

      What needs improvement?

      I have noticed exposures of credentials that do not show the correct password, as I receive alerts repeatedly for my credentials. Since SOCRadar Extended Threat Intelligence crawls the dark web and picks up any data being sold that includes my credentials, I believe there should be an improvement to avoid repeated notifications for already remediated records.

      For how long have I used the solution?

      I have been working in cyber security for more than five years.

      What do I think about the stability of the solution?

      SOCRadar Extended Threat Intelligence is stable.

      What do I think about the scalability of the solution?

      Its scalability is good as it effectively covers broader threats.

      How are customer service and support?

      Customer support for SOCRadar Extended Threat Intelligence is good.

      Which solution did I use previously and why did I switch?

      We previously used other tools, including one named Cybel, but we switched to SOCRadar Extended Threat Intelligence because it covers a broader range of threats and features and is more user-friendly.

      Which other solutions did I evaluate?

      We evaluated Cybel as another option before choosing SOCRadar Extended Threat Intelligence.

      What other advice do I have?

      We have utilized SOCRadar Extended Threat Intelligence's unique dark web sources and have noticed significant impacts in identifying potential threats early.

      I have utilized SOCRadar Extended Threat Intelligence's managed takedown services to initiate the takedown of impersonate domains not owned by us, which is a valuable feature for our organization.

      In the phishing workflow, we have submitted impersonate domains and origin senders, and SOCRadar Extended Threat Intelligence has facilitated their takedown, aiding in our internal threat remediation.

      I would rate this product an eight out of ten.

      Which deployment model are you using for this solution?

      Hybrid Cloud

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      Last updated: Jul 20, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free SOCRadar Extended Threat Intelligence Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2026
      Buyer's Guide
      Download our free SOCRadar Extended Threat Intelligence Report and get advice and tips from experienced pros sharing their opinions.