A tool every SOC should have
May 12, 2021

A tool every SOC should have

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Recorded Future Intelligence Cloud

Recorded Future is being utilized by SOC analysts as a threat intel. Since our company offers SOC services among our clients, Recorded Future has been advantageous to us in processing artifacts and identifying possible threats in a short period of time.
  • Gives latest threat reports regarding an artifact (IP, domain or hash).
  • Browser extension provides a real-time information about an artifact.
  • Accurate in identifying malicious domains and IPs.
  • For the Browser extension, since the main purpose is to present information with regards to the IP, I think it's best to give us an idea of where the IP originated/some additional information about the organization it belongs to.
  • Web page display of the IP/domain reputation
  • Queries for pwned domains of our clients
  • Recorded Future crashes my web browser in cases I have to open a web page containing hundreds of IPs. A quick disable feature for a particular tab would be beneficial for someone like me.
To be honest I use Recorded Future together with VirusTotal to fully understand the possible threats on our network. However, Recorded Future has a better threat intelligence feed that I prefer to use as a reference in finalizing my investigations.

Do you think Recorded Future Intelligence Cloud delivers good value for the price?

Yes

Are you happy with Recorded Future Intelligence Cloud's feature set?

Yes

Did Recorded Future Intelligence Cloud live up to sales and marketing promises?

I wasn't involved with the selection/purchase process

Did implementation of Recorded Future Intelligence Cloud go as expected?

I wasn't involved with the implementation phase

Would you buy Recorded Future Intelligence Cloud again?

Yes

Recorded Future is mainly beneficial to the SOC. As part of the Monitoring team, Recorded Future makes the investigation of the alarms a lot easier for me. It can show the reputation of the IP/domain or even hashes which helps me redirect my focus to potentially malicious network activities.