Skip to main content
TrustRadius
EclecticIQ Platform

EclecticIQ Platform

Overview

What is EclecticIQ Platform?

EclecticIQ Platform is an analyst-centric Threat Intelligence Platform (TIP). The vendor says it is optimized for the collection of intelligence data from open sources, commercial suppliers and industry partnerships into a single collaborative analyst workbench. EclecticIQ Platform aims to eliminate…

Read more
Recent Reviews
Read all reviews

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

EclecticIQ Platform on-premise

$0.00

On Premise

EclecticIQ Platform hybrid

$0.00

On Premise

EclecticIQ Platform hosted

$0.00

Cloud

Entry-level set up fee?

  • Setup fee optional

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Details

What is EclecticIQ Platform?

EclecticIQ Platform is an analyst-centric Threat Intelligence Platform (TIP). The vendor says it is optimized for the collection of intelligence data from open sources, commercial suppliers and industry partnerships into a single collaborative analyst workbench. EclecticIQ Platform aims to eliminate the manual and repetitive work involved with processing multiple intelligence feeds. According to the vendor, this means analysts can focus on identifying the most critical threats, take timely action, advise the organization on how to respond and collaborate with industry peers.

Some of the benefits touted by the vendor include:

Collect and correlate

  • Intelligence data from multiple sources
  • Structured STIX-compatible and unstructured entities
  • Large diversity of supported data formats: csv, pdf, proprietary and STIX


Analyze and collaborate

  • Automated qualification, triage and discovery processes
  • Collaborative workspaces with intuitive graphs, search, pivoting tools and tasking
  • CTI clipboard to capture data from websites and feed it directly into TIP


Produce and disseminate

  • Reports for dissemination to both human and machine consumers
  • Daily digests and full intelligence reports
  • Only TIP to support sending human-readable reports via email

EclecticIQ Platform Features

  • Supported: Collect and correlate intelligence
  • Supported: Analyze and collaborate
  • Supported: Produce and disseminate

EclecticIQ Platform Technical Details

Deployment TypesOn-premise, Software as a Service (SaaS), Cloud, or Web-Based
Operating SystemsRHEL, CentOS and Ubuntu
Mobile ApplicationNo
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(1)

Reviews

(1-1 of 1)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The current environment that I am working in has multiple OSINT and premium Threat Intels subscribed. EclecticIQ, in addition to its own superb intel, is integrated with the rest of the intel via API calling and serves as a common ingestion point for all the Intelligence. This feed from the EIQ is then consumed by SIEM and SOAR.
  • Effective correlation of IOCs
  • Averaging out the Confidence Score based on different intel sources.
  • Serves as an excellent liaison points between the Intels and SIEM/SOAR stack.
  • Misses on a global search bar which can directly gives out the result like VirusTotal.
  • The GUI could be more friendlier. Too many filters and graphs may overwhlem the user sometimes.
  • The ElasticSearch(searching for IOC in the in-house EIQ database) is a little slow compared to its counterparts.
ElecticIQ has an architecture where it usually needs decent computing power within the organisation. The central console along with the ELK servers and PostgreSQL sever needs their own space in a distributed setup. This could be a little too expensive for small-scale organisations. But for the organizations having mid to large-scale networks. EIQ is a decent solution to serve the purpose.
  • Integration with SIEM and SOAR for feed ingestion.
  • Correlation of different Intel data and setting the priority based on Confidence Score.
  • Having a DB to store the IOC for historical reference purpose.
  • Positive: Effective usage of all the premium Intels in a uniform fashion. No need to log in to each tool time and again.
  • Positive: SOC Analysts spends lesser time on the internet and the analysis for the IOCs with graphical format is fulfilled by EclecticIQ.
  • Negative: Higher costs over the resource utilization in the initial setup.
The most important feature of EclecticIQ which gives it an edge compared to other TIPs is that it performs segregation of IOCs based on the relevance of it and the links that IOCs might have which other adversaries. The graphical format mapping where the user can easily figure out how the IOCs have connections to different binaries is another advantage. One can set the half-life time for an IOC which will reduce the confidence score as per one's need.
Rapid7 InsightVM (Nexpose), Recorded Future, FortiAnalyzer
Return to navigation