--- title: SOCRadar Extended Threat Intelligence Reviews meta_title: 'SOCRadar Extended Threat Intelligence Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 122 reviews by the users' company size, role or industry to find out how SOCRadar Extended Threat Intelligence works for a business like yours. aggregate_rating: rating_value: 4.7 review_count: 122 scale: '5' date_modified: '2026-10-06' parent_category: name: System Security url: https://www.g2.com/categories/system-security ---

SOCRadar Extended Threat Intelligence Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users appreciate the ease of use of SOCRadar, enjoying its intuitive dashboards and centralized threat data management. (25 mentions)
Users value the comprehensive Threat Intelligence features of SOCRadar, enabling effective risk awareness and proactive security measures. (24 mentions)
Users value the comprehensive and actionable alert notifications from SOCRadar, enhancing their security monitoring and response efforts. (19 mentions)
Users appreciate the exceptional visibility into external threats, benefiting from a centralized and proactive intelligence platform. (18 mentions)
Users value the exceptional visibility SOCRadar provides into external threats, enhancing proactive security measures significantly. (18 mentions)
Users are frustrated by the inefficient alerts, leading to noise and fatigue from duplicate notifications and false positives. (10 mentions)
Users report that the inefficient alert system leads to alert fatigue and necessitates extensive tuning for effectiveness. (10 mentions)
Users struggle with false positives and duplicate notifications, leading to alert fatigue and a need for extensive tuning. (8 mentions)
Users note the limited features in SOCRadar Extended Threat Intelligence, hindering deeper analysis without upgrading. (7 mentions)
Users find the insufficient information from SOCRadar Extended Threat Intelligence to hinder effective decision-making. (6 mentions)

5 Pros or Advantages of SOCRadar Extended Threat Intelligence

5 Cons or Disadvantages of SOCRadar Extended Threat Intelligence

Noyan A.
NA
Noyan A.
Customer Contact Center Outbound Agent
Mid-Market (51-1000 emp.)
"SOCRadar Threat Intelligence: A Powerful, Time-Saving Security Tool"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

SOCRadar Threat Intelligence is a powerful tool for performing security controls across our assets, and it has been a real time-saver for our day-to-day operations. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

Extended Thread Intelligence has so many sections. If the tabs could be made more compact, it would be more effective and easier to use. Review collected by and hosted on G2.com.

Thariq R.
TR
Thariq R.
Layer 2 Cyber Threat Intelligence Analyst
Mid-Market (51-1000 emp.)
"Excellent Detection and User-Friendly Interface with a Pro Customer Support"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

I aligned this with my client's PIR, and I found the detection to be very good. Additionally, the user interface is quite friendly, and easy to implement, the CS is really fast too. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

The detection of new vulnerabilities in vuln intelligence is not particularly fast. I understand that there are challenges, especially when a new CVE is involved and the product vendor has not yet published mitigation steps or made the CVE public, sometimes sharing details only with their clients. There are also cases where discussions about a vulnerability appear on social media before any official information is released. In such situations, it would be helpful to use an admiralty code to indicate the reliability of the information.

For example, if details about a vulnerability or exploit are posted by a new account on a forum but are being widely discussed by many people and security vendors, the appropriate admiralty code would be F4. Review collected by and hosted on G2.com.

LC
Luis C.
Oficial de Seguridad de la Información
Mid-Market (51-1000 emp.)
"Modern interface and the best dashboard, with great integration to the SIEM and support"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

The modern interface allows you to quickly find reports and incidents, so far it has the best dashboard on the market. We really like the integration it has with our SIEM and the support. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

The reporting regarding app vulnerabilities should improve; currently, a list of the vulnerabilities found cannot be removed. Review collected by and hosted on G2.com.

Alhussain A.
AA
Alhussain A.
Analyst
Small-Business (50 or fewer emp.)
"Love the New AI Agent Integrations"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

the new integrations with the AI agents. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

need to fine-tuning the rules carefully. Review collected by and hosted on G2.com.

omid n.
ON
omid n.
Specialist IT Security
Enterprise (> 1000 emp.)
"Proactive, Risk-Focused Threat Intelligence"
4/5
What do you like best about SOCRadar Extended Threat Intelligence?

External Attack Surface

It continuously monitors exposed assets (domains, IPs, cloud services, credentials)

Actionable Threat Intelligence

Instead of raw IOCs, SOCRadar provides context, severity, and relevance, making it easier to prioritize threats that actually impact your organization.

Dark Web

Strong coverage of dark web forums, marketplaces, and paste sites, Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

Alert Noise & Tuning Effort

Initial configurations can generate a high volume of alerts, requiring time and expertise to fine-tune relevance and reduce noise.

Learning Curve for Advanced Features

While dashboards are intuitive, deeper capabilities (threat actor tracking, attack surface correlation, exploit context) require training to use effectively. Review collected by and hosted on G2.com.

Verified User in Gambling & Casinos
IG
Verified User in Gambling & Casinos
Mid-Market (51-1000 emp.)
"Socradar Threat Intelligence Makes Data Leak Evidence Clear and Actionable"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What I like most about Socradar is its Threat Intelligence section. It allows you to review data leaks linked to corporate accounts, including usernames associated with employees and password information. You can search for username and corp.

On other solutions, when the leak only shows partial passwords or hashes, it’s less effective for employee awareness (people often don’t fully believe they’ve been compromised “without having done anything.”) Having clearer evidence really helps them understand the risk and take action. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

I don’t fully understand the value of the Identity & Access Intelligence module. I find it hard to use and difficult to search, and it doesn’t always let me review the leaks clearly. Overall, it also feels a bit unstable. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Effective Brand protection and Digital Risk Visibility"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

The best part is the visibility it gives us into our domains, IP addresses, and brand—especially what’s happening on the dark web. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

There’s still room for improvement when it comes to false positives, and the search across social media platforms should be expanded. Also, leaked information on WhatsApp needs to be monitored. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
UC
Verified User in Computer & Network Security
Small-Business (50 or fewer emp.)
"SOCRadar: Reliable Dark Web Monitoring Alerts and Leak Lookup That Save Investigation Time"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What I like most about SOCRadar Extended Threat Intelligence is its dark web monitoring and alerting. The platform continuously tracks underground sources and sends timely notifications when company-related data shows up, helping analysts respond quickly rather than discovering incidents too late.

Another feature I find especially useful is the free leak lookup. After registering with an organizational email domain, it provides visibility into exposed credentials and datasets tied to that domain. This makes it easier to confirm whether the exposure is real, understand the scope of a breach, and prioritize remediation accordingly.

Overall, the service is practical for both proactive threat monitoring and incident response readiness. It cuts down on manual searching across underground sources and turns scattered intelligence into actionable alerts, saving security teams a significant amount of investigation time. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

One limitation is that some alerts can be noisy and may require manual verification before they’re truly actionable, especially in large organizations with many exposed assets. The platform delivers valuable intelligence, but analysts still need to triage results and correlate findings with internal logs to confirm the real impact.

In addition, some advanced investigation details and automation capabilities are limited in the free tier, which can hold back deeper analysis unless you upgrade. The interface is generally clear, but working through large datasets or multiple exposures would be easier with stronger filtering and prioritization options.

Overall, the tool is useful, but it performs best when paired with internal monitoring and analyst validation, rather than being treated as a fully standalone detection solution. Review collected by and hosted on G2.com.

DS
Dale S.
Associate SOC Engineer
Enterprise (> 1000 emp.)
"Outstanding Support Sets SOCRadar Apart"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What I appreciate most is the outstanding support we receive. Vidit Parab, our Technical Account Manager, has been exceptionally helpful, and his assistance has consistently been superb. This level of support is rare among other vendors, and it is one of the primary reasons we continue to choose SOCRadar. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

We often find ourselves overwhelmed by the sheer volume of information presented to us at once. It seems that focusing on and addressing only the most important alerts would be much easier if there were less noise. We recognize that our limited experience with the platform may be contributing to this feeling, and we expect that as we become more familiar with it, this should improve. Review collected by and hosted on G2.com.

Christopher M.
CM
Christopher M.
Group Cybersecurity Administrator
Enterprise (> 1000 emp.)
"Actionable Real-Time Threat Monitoring in One Intuitive Dashboard"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

It provides real-time monitoring of the dark web, phishing domains, vulnerabilities, and our external attack surface all in one place. The alerts are actionable, false positives are low, and the interface is intuitive, which makes it easier to prioritize real risks and respond more quickly. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

What I dislike most is the noisy alerting and the fatigue caused by duplicate notifications and false positives, which means it takes a lot of upfront tuning to get things under control. The platform can also feel overwhelming because of the sheer volume of data, and that sometimes makes it hard to prioritize what matters most. Integrations still need some improvement as well, since they can end up flooding the SIEM with alerts if they aren’t configured carefully. On top of that, pricing per asset feels steep when you’re working with a larger scope, and the social network coverage is fairly limited. Review collected by and hosted on G2.com.