Likelihood to Recommend The tool is very helpful in improving Phishing detection capabilities as it streamlines the process of analyzing user reports a lot. Besides it has a built-in mechanism of rating reporters(end-users) based on their historical performance. Downside - tool requires continuous resource investment to deliver best result. Tool is not helping too much in improving user-education, because automated response process is not immediate and is prone to errors
Read full review Our company has very complex and dynamic security operations because of the large number of security tools and systems that we need to manage and coordinate. Moreover, it helps us to meet many regulatory and compliance requirements because it helps us to automate and document our security operations. We also use it to streamline our security operations and improve our response to potential threats.
Read full review Pros Separating links and attachments contained in the email, and checking to see if they are known malicious. Clustering like emails to save time when responding. Providing risks scores with each cluster to give an estimate on which clusters should be addressed first. Read full review Its security orchestration and integration capability that supports multiple tools. Easy coding that automates our security actions. Enables us to easily collaborate and respond to security issues faster. Splunk SOAR is a flexible product that is easy to deploy. Efficient tracking and monitoring capability. Excellent real-time reporting functionality. Read full review Cons There are too many interdependent pieces which you have to acquire separately. I think Cofense has a lot of capabilities and usefulness, but I think it's too a la carte. We own Cofense and PhishMe currently and there are some gaping holes that require additional licensing to close. Read full review A lack of instruction It can be difficult to contact the support staff. Limited experience from current users. It takes some effort to set up and learn new technology at first. More assistance is required from the support staff. The product's price needs to go down. Cost of the larger version. Read full review Likelihood to Renew Cofense is stable and provides easy to use solution to aid the investigation of emails as well as managing simulated phishing campaigns.
Read full review As we already have a lot of clients being catered with Splunk SOAR and because Splunk SOAR is robust and efficient, we are already using it, and we have understood the product to a certain extent, I feel we are personally more enticed to use and scale it to a lot of business.
Read full review Usability The interface is easy and intuitive.
Read full review Not immediate: it always requires a training.
Read full review Reliability and Availability We've experienced zero downtime.
Read full review Performance No slowness seen.
Read full review We are able to automate almost every one of our use cases, even our threat-hunting, and threat intel procedures. We have 20+ playbooks and cover almost everything, even searching logs into Splunk, looking into TIP and external systems, enrichment, and collecting evidence for analysts; it can perform concurrent playbooks running.
Read full review Support Rating Splunk Support is always great! In addition the Community is very efficient and active.
Read full review In-Person Training Training was through, relevant and easy to follow.
Read full review I never followed an in-person training, I gave my evaluation based on the online training
Read full review Online Training I followed training for Phantom admins and it opened a world for me
Read full review Implementation Rating I already said that the main key insight is the knowledge of Phantom, so a detailed training for all the people involeved.
Read full review Alternatives Considered The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did not like the user interface.
Read full review Splunk Phantom integrates well with Splunk ES and has many integrations. One thing that I liked about XSOAR as compared to Phantom is that it has an "app-store" where you can download not only app integrations (similar to Phantom) but Playbooks and dashboards as well.
Read full review Scalability We've experienced zero downtime
Read full review me and the customers I encountered found it flexible and scalable
Read full review Return on Investment Due to the integration potential, large amounts of time are saved on a daily basis. Incident response time has dropped due to the increased information available by having access to phishing emails directly. Staff are able to effectively learn how multiple tools in our environment are used by mastering Triage. This has decreased training time greatly and increased the effectiveness of each associate. Read full review The playbooks are valuable. They are the core component. Being able to implement and build a code process to work through and scale out what we want to do is valuable Before its use, analyzing each email would take at least 15 to 20 minutes, with some complex cases taking up to 30 minutes...With the automation provided by Splunk Phantom, we could significantly reduce the amount of time and human effort required to complete this task Read full review ScreenShots Cofense Triage Screenshots