

ThreatConnect and Anomali both compete in the threat intelligence platform category, each offering unique strengths. ThreatConnect tends to have the upper hand in integration and customization, while Anomali excels in data analytics capabilities.
Features: ThreatConnect offers robust integration capabilities, allowing seamless connection with various security tools. Its advanced customization options enable users to tailor workflows to specific needs, and it provides a centralized threat intelligence library for streamlined data management. Anomali, noted for its exceptional data analytics, efficiently handles large data sets and offers advanced threat modeling capabilities, adaptable APIs for automation, and threat intelligence prioritization features.
Room for Improvement: ThreatConnect could enhance its data processing capabilities to better compete with analytics-focused platforms like Anomali. Users may also benefit from more intuitive initial setup guides. Furthermore, expanding its automation capabilities could further streamline workflows. Anomali could improve its user interface for greater ease of use, especially for less technical users. It might also consider offering more customization options to match ThreatConnect’s flexibility. Additionally, reducing the complexity of its analytics features could make them more accessible.
Ease of Deployment and Customer Service: ThreatConnect provides a straightforward deployment process with strong customer support, making it suitable for organizations looking to start quickly. Its ease of customization aids in a faster rollout. Anomali also offers a smooth deployment experience and robust customer service, yet its extensive data analytics capabilities require a more comprehensive initial setup, demanding more time before full implementation.
Pricing and ROI: ThreatConnect generally presents a more favorable setup cost and is recognized for its strong ROI, especially due to its versatile platform features. Anomali demands a higher initial investment, but its comprehensive data processing and advanced analytics often justify the costs for data-intensive operations, delivering substantial long-term value.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
We have reduced manual analyst effort by thirty to forty percent.
This trust has led to an increase in sales because customers are confident we can protect their data.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
They have been responsive, knowledgeable, and helpful.
I just like their customer support because, within a short period of contacting them, they are able to help navigate issues.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
ThreatConnect supports scalability by allowing us to identify threats and share information within our team networks.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
Sometimes, when using the solution, it slows down, affecting our ability to mitigate threats.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
The pricing is high for smaller organizations, so it would be beneficial to have tiered pricing.
ThreatConnect Threat Intelligence Platform (TIP) could be improved by simplifying the user interface to better fit day-to-day analyst workflow.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
The pricing seems a bit high for smaller companies.
Generally, the pricing and setup cost are on the higher side.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
The features are simple to use, and the interface is user-friendly, making it easy to navigate and apply the solutions.
The API-first architecture that enables us to perform custom integration with other products and real-time distribution.
| Product | Mindshare (%) |
|---|---|
| Anomali | 3.7% |
| ThreatConnect Threat Intelligence Platform (TIP) | 3.7% |
| Other | 92.6% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 23 |
| Large Enterprise | 4 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
ThreatConnect Threat Intelligence Platform provides a comprehensive solution for operational threat intelligence. It effectively ingests and enriches data, aligning with intelligence requirements for seamless application across security operations.
ThreatConnect TIP stands out by integrating threat intelligence with orchestration for streamlined threat management. It simplifies the user experience with a customizable interface assisting security teams in operationalizing insights across multiple teams without disruption. The platform automates threat scoring and optimizes threat correlation and response, ensuring timely threat detection and protection. Collaboration with Polarity and Risk Quantifier accelerates actionable intelligence, while support and patch management enhance overall user experience. Although improvements in integration processes and training accessibility are necessary, the platform aggregates threat data for efficient threat mitigation.
What are the key features of ThreatConnect TIP?In industries focusing on security, ThreatConnect TIP supports teams in identifying and mitigating security threats through automation. Integrated with cybersecurity networks, it assists in endpoint protection, SOC management, and vulnerability management, being pivotal in threat investigation and intelligence dissemination.
We monitor all Threat Intelligence Platforms (TIP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.