--- title: SOCRadar Extended Threat Intelligence Reviews meta_title: 'SOCRadar Extended Threat Intelligence Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 122 reviews by the users' company size, role or industry to find out how SOCRadar Extended Threat Intelligence works for a business like yours. aggregate_rating: rating_value: 4.7 review_count: 122 scale: '5' date_modified: '2026-10-06' parent_category: name: System Security url: https://www.g2.com/categories/system-security ---

SOCRadar Extended Threat Intelligence Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users appreciate the ease of use of SOCRadar, enjoying its intuitive dashboards and centralized threat data management. (25 mentions)
Users value the comprehensive Threat Intelligence features of SOCRadar, enabling effective risk awareness and proactive security measures. (24 mentions)
Users value the comprehensive and actionable alert notifications from SOCRadar, enhancing their security monitoring and response efforts. (19 mentions)
Users appreciate the exceptional visibility into external threats, benefiting from a centralized and proactive intelligence platform. (18 mentions)
Users value the exceptional visibility SOCRadar provides into external threats, enhancing proactive security measures significantly. (18 mentions)
Users are frustrated by the inefficient alerts, leading to noise and fatigue from duplicate notifications and false positives. (10 mentions)
Users report that the inefficient alert system leads to alert fatigue and necessitates extensive tuning for effectiveness. (10 mentions)
Users struggle with false positives and duplicate notifications, leading to alert fatigue and a need for extensive tuning. (8 mentions)
Users note the limited features in SOCRadar Extended Threat Intelligence, hindering deeper analysis without upgrading. (7 mentions)
Users find the insufficient information from SOCRadar Extended Threat Intelligence to hinder effective decision-making. (6 mentions)

5 Pros or Advantages of SOCRadar Extended Threat Intelligence

5 Cons or Disadvantages of SOCRadar Extended Threat Intelligence

YB
Yazid B.
Sr. Cybersecurity Consultant
Mid-Market (51-1000 emp.)
"Amazing system which provide all our needs"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

There isn’t one specific thing I’d call the best, but I’d say all of the features are great overall. for example the Vulnerability Intelligence helped us keep up to date on our systems. checking IoC enrichment helped us investigate malicious IoC. News and trend news gave us the opportunity to prepare for possible threats. Primum feeds keep us monitor the malicious IoCs which reached to our environment and give us the chance to act and block them. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

I’m running into a few issues when trying to integrate best practices for the Primum feeds. I was hoping there would be a package or built-in option where I could enter the threat actors I’m monitoring and have it return the related IoCs for those actors. Review collected by and hosted on G2.com.

Kamil M.
KM
Kamil M.
Senior Specialist
Enterprise (> 1000 emp.)
"Catches Threats Before They Become Incidents"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What I like best about SOCRadar Extended Threat Intelligence is the dark web monitoring and digital risk protection features. They've helped us catch leaked credentials and phishing domains targeting our brand early, before they became real incidents. The SIEM integration was also easy to set up, and alert prioritization helps our small team focus on what matters instead of chasing noise. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

What I dislike about SOCRadar Extended Threat Intelligence is the volume of false positives in some alert categories, which requires manual tuning to reduce noise. The dashboard can also feel a bit overwhelming for new users, and generating custom reports isn't always as intuitive as I'd like. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"SOCRadar Delivers Actionable AI-Driven Threat Intelligence with a Clean, Intuitive UI"
4/5
What do you like best about SOCRadar Extended Threat Intelligence?

The platform has a user-friendly UI and integrates with many applications that support API integration. The web interface is relatively fast, and adding assets to monitor is straightforward. It also uses AI agents to help with tasks such as IOC enrichment, alarm management, and identity management. Overall, the platform has saved us time when investigating leaked credentials associated with our organization.

SOCRadar also provides weekly support training on how to use the platform effectively. The tool was relatively easy to set up because it was already deployed in the cloud. All it took was providing our main domain; it discovered the subdomains on its own, and we only needed to approve the correct ones. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

The biggest limitation for me is the credit restriction. Because of it, I sometimes have to prioritize which credentials or data to retrieve based on what feels most important at the time. That can be frustrating when I need broader visibility, since I’d rather have access to all relevant credentials without having to choose between them.

Another issue is repetitive alerts. On a few occasions, the platform has sent alerts about detected credentials that were already identified in the past, but they come through again as new alerts. It seems like the system can categorize a repeat detection as “new,” which creates unnecessary noise and makes it harder to focus on what actually changed. Review collected by and hosted on G2.com.

Angel Osiris R.
AR
Angel Osiris R.
Analista de Monitoreo y Respuesta a Incidentes
Enterprise (> 1000 emp.)
"Easy to use, great visibility, and excellent integrations with outstanding support"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What I like most is the ease of finding everything related to the entity's environment, such as compromised client credentials and credit cards mentioned on the Dark Web, as well as the integrations with other applications we have in the entity, in addition to the good support they provide when we have any questions about the tool. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

So far, I haven't found any problems with the platform. Review collected by and hosted on G2.com.

Moises M.
MM
Moises M.
CyberSecurity Architec
Enterprise (> 1000 emp.)
"Pleasant and comprehensive experience"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

The large number of sources available for finding information about our company anywhere. We just switched from another tool we were using, and we never imagined we would have so much visibility compared to the tool we were using before.

Above all, it is very easy to use and we can manage the platform well.

The support they provide is extremely fast. Compared to other vendors, they respond very quickly. Sometimes I create a case and by the time I refresh the page, I already have a response. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

I think they should improve the alarms only, because sometimes I would like to close the incident directly from the alarm, but I have to go to the incident to close it, and that's a bit difficult. Review collected by and hosted on G2.com.

Nagy F.
NF
Nagy F.
Information Security Senior Manager
Enterprise (> 1000 emp.)
"Elegant Interface and Seamless Navigation That Saves Time"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

The interface is elegant, with visual indicators, tags, and hyperlinks that save a lot of effort. The modules are integrated in a seamless manner, with easy-to-use navigation. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

I found it difficult to conduct a thorough analysis of the raised tickets. There was no clear or efficient way to filter out the noise and focus on the real underlying issues, which made the investigation process more time-consuming. Review collected by and hosted on G2.com.

RN
Robert N.
Lead, Security Operations
Mid-Market (51-1000 emp.)
"Broad, Cost-Effective Threat Intelligence with Smooth Onboarding and Easy Integrations"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

The SOCRadar platform has detailed threat intelligence and broad coverage. I work in a region where most platforms provide very scanty intel on so SOCRadar has plugged that gap well, while being cost effective at the same time. The platform is intuitive and easy to use in SOCs of all maturity levels and the usecases supported match client requirements. I use the Digital Risk Protection, Attack Surface Management, and the CTI modules in my everyday tasks and have integrated to most of the security controls (SIEM, XDR, ITSM). The platform supports Agentic AI workflows that automation quite simple. The onboarding process was quite smooth as a TAM is assigned to support in knowledge transfer, building of usecases, and platform tuning to minimise false positives. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

It may be a bit technical for some users at first but once the platform modules are understood, it becomes easier to trace where a specific functionality lies Review collected by and hosted on G2.com.

Aldo Alan G.
AG
Aldo Alan G.
Engineer N1
Small-Business (50 or fewer emp.)
"Great Scope of Information, Improvement in Takedown"
4.5/5
What do you like best about SOCRadar Extended Threat Intelligence?

I like the range of information offered by SOCRadar Extended Threat Intelligence. I also highly value the data obtained and how it facilitates validation in dark web forums using certain keywords. Additionally, the speed for performing takedowns is another feature I appreciate. The initial setup was also easier than I expected. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

I find that the validation of client assets is manual and not automatic. Furthermore, when finding more related assets such as IPs or domains, it does not add them without consulting them first, and this prevents the increase of assets allowed by SOCRadar. Review collected by and hosted on G2.com.

Marcio B.
MB
Marcio B.
Analista de Segurança da Informação Senior
Enterprise (> 1000 emp.)
"AI-Powered Alerts That Save Time and Boost Quality"
4/5
What do you like best about SOCRadar Extended Threat Intelligence?

new version improved with AI for alerts is the most important feature for me, saving time and gain quality. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

In the alerts, we have all the devices listed as if they were a single company, but we have different countries around the world, and the alerts arrive "mixing" all of this into a single alert. Because of this, we cannot process the alert for a discovered device individually, for example. Review collected by and hosted on G2.com.

Verified User in Automotive
AA
Verified User in Automotive
Enterprise (> 1000 emp.)
"Unified and proactive vision of external threats, with contextualized alerts"
5/5
What do you like best about SOCRadar Extended Threat Intelligence?

What is most appreciated about SOCRadar Extended Threat Intelligence is its ability to offer a unified, proactive, and actionable view of external threats from a single platform: it combines threat intelligence, dark web monitoring, brand protection, data leak detection, and external attack surface management, while providing contextualized and prioritized alerts rather than just raw IOCs. This allows SOC and security teams to reduce blind spots, anticipate attacks (phishing, impersonation, asset exposure), decrease operational load through automation, and easily integrate intelligence into existing tools (SIEM, SOAR), thereby improving overall security posture and rapid response capability. Also, the support is very responsive, available, and competent. Review collected by and hosted on G2.com.

What do you dislike about SOCRadar Extended Threat Intelligence?

the alert system can generate too much noise (repeated alerts or false positives) which can lead to information overload and require significant tuning effort to obtain only what is relevant Review collected by and hosted on G2.com.