Threat intelligence has never been more valuable. Threat intelligence products gather information on internal and external threats to deliver a general picture of vulnerabilities and highlight risks of varying severity so analysts can concentrate their efforts on the most critical and vulnerable assets. Actionable threat intelligence can unburden security teams while giving them the tools to proactively fortify their defenses instead of relying exclusively on reactive practices like responses and mitigations.We live in a connected world that’s constantly expanding. Every connection presents another potential risk. These products embrace this inter-connectedness and have built-in collaboration tools to facilitate internal communication and intelligence sharing as well as external, community forums where security pros may share or research public-facing intelligence to stay aware and ahead of new and re-emerging threats.These products are designed to aggregate intelligence from multiple sources and present it in a way that makes it as easily digestible and actionable as possible. We probably saw the most improvement in the third-party integration capabilities. These solutions are now designed for the logical integration with other products such as SIEM, SOAR and firewall solutions. We saw both pre-built integrations and API integrations, maximizing the value of these products so security teams can leverage them for both consumption and production needs.Security teams have to strike a careful balance between having enough information, but not so much information that they become overwhelmed. The industrywide skills gaps and lack of resources make this exceptionally tricky. However, the robust automation capabilities of these products are minimizing the impact of any imbalance and effectively optimizing existing resources. We consider these staple products for any security toolset. They will empower security teams with the targeted threat intelligence necessary to effectively make decisions and prioritize according to most critical needs.Pick of the Litter ReversingLabs Titanium Platform maps threats to the MITRE ATT&CK Framework to accelerate investigation and response activities, while its massive known-malware repository ensures organizations keep pace with the ever-growing threat landscape. Titanium always issues descriptions in plain language so that even analysts with less experience can actively and effectively engage in threat hunting and response. This exceptional threat intelligence platform delivers valuable information while maximizing actionability. Such ease-of-use, transparency, and scalability make Titanium an attractive option for organizations of all sizes. It’s also one of the less expensive options we looked at this month, making this product an SC Labs Best Buy.Recorded Future Security Intelligence Platform has become a strong player in the threat intelligence market, especially considering its robust integration catalogue and fully documented API. It offers analysts transparency, explaining the reasons behind the threat ratings it issues and supports these explanations with evidence and details. While many platforms with a multitude of options become heavy and difficult to navigate, Recorded Future remains easy-to-use for even novices. The ease-of-use balanced with advanced capabilities to optimize analyst efficiency and reduce response times make this our SC Labs Recommended product for this month’s round of testing.November ReviewsAnalyst1 v1.9Anomali AT&T Alien Labs Open Threat Exchange (OTX)BanduraDarkOwl VisionDomain Tools Iris Investigation Platform v.3.0EclecticIQ Platform v2.4IntSights External Threat Protection SuiteLookingGlass Cyber Solutions, Inc. scoutPRIME 2020.2.K.25.66ManageEngine Log360Recorded Future Security Intelligence Platform v2020ReversingLabs Titanium PlatformThreatConnect v6.0
