Lead Engineer - Network & Security at Connex Information Technologies
Real User
Top 10
Jun 29, 2026
I prefer SOCRadar Extended Threat Intelligence for multiple use cases, starting from brand protection to assessing the external attack surface of the organizations I provide security solutions for, mainly the public open IP addresses, the ports, and the certificates that have been opened publicly. When I try to do proof of concepts for my customers, I normally add the domain to SOCRadar Extended Threat Intelligence. Once I add the domain, it normally scans the domain and discovers all the external IP addresses and ports that have been opened. Then it scans from a brand protection perspective such as the bad names that circulate around that particular domain, or any threats targeted towards the open public IP address. I have covered all the use cases that I get out of SOCRadar Extended Threat Intelligence. Basically, the results that it gives me as an outcome after I integrate with my domain are impressive. Based on the results, I could also identify the threats that are targeted towards my domain and the bad reputations it has created based on the domain I have added. I also consider social media monitoring, which detects any fake news or bad reputations that have been created.
Principal Cybersecurity Engineer at a tech vendor with 1,001-5,000 employees
Real User
Top 20
Jun 29, 2026
I primarily use SOCRadar Extended Threat Intelligence for threat intelligence. Secondary uses include dark web news monitoring, threat hunting, and alerts regarding the dark web such as data breaches, VIP monitoring, and brand protection. These are the activities we use regularly. Regarding the IGENTIC phishing workflow, we do not directly use it because this tool is not utilized for phishing purposes. We have not used that module and workflow. However, we have observed that it is able to detect phishing alerts, though not directly. The alerts are mostly related to similar domains being registered and hosting similar pages. Our engineers resolve these alerts, but we have not implemented IGENTIC or automation for this.
Cybersecurity Consultant at a tech services company with 11-50 employees
Real User
Top 10
Jun 27, 2026
I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly. My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard. The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution. I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown. For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.
I primarily use SOCRadar Extended Threat Intelligence for incident response and threat detection. Apart from threat monitoring and incident response support, SOCRadar Extended Threat Intelligence also helps track threat actor activity, leak credentials, and brand impersonation risk, which are some key features that definitely help the organization to secure everything. Among the features of advanced dark web monitoring, external attack surface management, and brand protection, I rely the most on advanced dark web monitoring, as it helps to identify leaked credentials, sensitive data exposure, and discussions by threat actors related to our organization. This is very useful because it provides early warning about potential security incidents and allows us to take proactive actions such as resetting compromised accounts and strengthening security controls before any attack happens.
Senior Cyber Security Expert at a computer software company with 201-500 employees
Real User
Top 10
Feb 24, 2026
I use SOCRadar Extended Threat Intelligence for VIP monitoring, CM tool monitoring, and CTI, specifically for early detection systems for our customers. If there is any leakage of customer accounts, we know about it. If there is any information about them on the dark web, we are immediately informed. Overall, I use it for intelligence purposes.
Learn what your peers think about SOCRadar Extended Threat Intelligence. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
SOCRadar Extended Threat Intelligence enables users to identify and mitigate cybersecurity risks through comprehensive threat visibility and real-time monitoring.
Organizations utilize SOCRadar Extended Threat Intelligence for early detection and proactive defense against potential cyber attacks. With its robust features, users gain enhanced security posture and informed strategic decision-making. Detailed analytics and actionable insights contribute to improved threat response and...
I prefer SOCRadar Extended Threat Intelligence for multiple use cases, starting from brand protection to assessing the external attack surface of the organizations I provide security solutions for, mainly the public open IP addresses, the ports, and the certificates that have been opened publicly. When I try to do proof of concepts for my customers, I normally add the domain to SOCRadar Extended Threat Intelligence. Once I add the domain, it normally scans the domain and discovers all the external IP addresses and ports that have been opened. Then it scans from a brand protection perspective such as the bad names that circulate around that particular domain, or any threats targeted towards the open public IP address. I have covered all the use cases that I get out of SOCRadar Extended Threat Intelligence. Basically, the results that it gives me as an outcome after I integrate with my domain are impressive. Based on the results, I could also identify the threats that are targeted towards my domain and the bad reputations it has created based on the domain I have added. I also consider social media monitoring, which detects any fake news or bad reputations that have been created.
I primarily use SOCRadar Extended Threat Intelligence for threat intelligence. Secondary uses include dark web news monitoring, threat hunting, and alerts regarding the dark web such as data breaches, VIP monitoring, and brand protection. These are the activities we use regularly. Regarding the IGENTIC phishing workflow, we do not directly use it because this tool is not utilized for phishing purposes. We have not used that module and workflow. However, we have observed that it is able to detect phishing alerts, though not directly. The alerts are mostly related to similar domains being registered and hosting similar pages. Our engineers resolve these alerts, but we have not implemented IGENTIC or automation for this.
I use SOCRadar Extended Threat Intelligence for cyber threat intelligence, CTI lookup, for IOCs, and for looking up advisories information, such as APTs group information. I also look up Dark Web intelligence and leaked information, including password leaks. Additionally, I use it for takedown in different social media platforms such as Facebook, Twitter, and LinkedIn for impersonation and brand protection mostly. My main use case is that SOCRadar Extended Threat Intelligence's dashboard offers everything I need and their alerting system, once configured properly, provides everything necessary to monitor all attack surface and monitor all leaked passwords. I also use it for Dark Web monitoring where I query the Dark Web to look up additional information that may not come up in the dashboard. The impact of using Dark Web monitoring and querying the Dark Web is that we can be even more proactive, allowing us to actually search for leaks or things happening in the Dark Web easily from SOCRadar Extended Threat Intelligence solution. I used the managed takedown, and the takedown services are really good and helpful. They provide all the steps SOCRadar Extended Threat Intelligence is taking to ensure the takedown succeeds. If the takedown is successful or fails, they provide the reason why the takedown failed. This is really great, and we rely one hundred percent on SOCRadar to provide the takedown. For the IOCs, I also only use the IOCs provided by SOCRadar Extended Threat Intelligence and I trust their validation. I have had no problems regarding the IOCs. I found them very helpful, so I trust them regarding this.
I primarily use SOCRadar Extended Threat Intelligence for incident response and threat detection. Apart from threat monitoring and incident response support, SOCRadar Extended Threat Intelligence also helps track threat actor activity, leak credentials, and brand impersonation risk, which are some key features that definitely help the organization to secure everything. Among the features of advanced dark web monitoring, external attack surface management, and brand protection, I rely the most on advanced dark web monitoring, as it helps to identify leaked credentials, sensitive data exposure, and discussions by threat actors related to our organization. This is very useful because it provides early warning about potential security incidents and allows us to take proactive actions such as resetting compromised accounts and strengthening security controls before any attack happens.
I use SOCRadar Extended Threat Intelligence for VIP monitoring, CM tool monitoring, and CTI, specifically for early detection systems for our customers. If there is any leakage of customer accounts, we know about it. If there is any information about them on the dark web, we are immediately informed. Overall, I use it for intelligence purposes.