We use the TIP data to compare logs in our SIEM to hunt for threats and enrich other threats that we may come across. More significantly in the last bunch of years, they added SOAR capabilities that are improving. We use the SOAR to automate many of the first steps that our SOC would otherwise need to do manually. It has also allowed for fewer panes of glass or the SOC to look at things through. If there isn't already an app for integration with another vendor, the HTTP client has proven to be very flexible for creating those integrations with another product's API. Review collected by and hosted on G2.com.
The UI could use improvements. There are some, such as the ability to work on a number of indicators showing up in an event from the one screen, that I've been asking for for years and still isn't there. Review collected by and hosted on G2.com.
The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.
Validated through a business email account
Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.


