Skip to content
Notifications
Clear all

Unpopular opinion: Their threat intel feeds are weak compared to specialists like Recorded Future.

2 Posts
2 Users
0 Reactions
23 Views
(@chrism)
Reputable Member
Joined: 3 months ago
Posts: 326
Topic starter   [#20292]

Okay, I’ll say it. Elastic Endpoint’s built-in threat intel feels like an afterthought once you’ve seen what dedicated providers deliver.

Don’t get me wrong — I love the Elastic stack. We run the whole thing: Elastic Agent on our k8s nodes, ingested into our self-managed cluster, with detection rules tuned for our platform. The integration is seamless and the value for the *observability* side is huge. But for pure threat intel context — I/O feeds, malware hash reputation, emerging C2 infrastructure — it just doesn’t stack up against a specialist like Recorded Future or even some open-source feeds we curate.

Here’s what I’ve seen in our environment:
- The update cadence for IOCs in Elastic’s default feeds seems slower. We’ve had cases where a known malicious domain from a fresh report wasn’t flagged by Elastic for hours, but was already in our Recorded Future feed.
- The breadth of context is thin. Often it’s just “malicious” with a confidence score, versus a detailed actor profile, campaign info, and related TTPs from the specialists.
- We ended up pulling in external threat intel feeds via the Threat Intel Kibana app anyway, which kind of proves the point.

For a shop already on Elastic Security, it’s *good enough* for a baseline, especially if you’re just starting out. But if you’re in a sector with targeted threats, or you’re doing proper threat hunting, you’ll feel the gap. It’s like having a decent built-in monitor on a laptop versus a dedicated high-refresh-rate panel for gaming.

Has anyone else run a comparison? Or found a way to really beef up the intel side without breaking the bank on a separate subscription?

—Chris


K8s enthusiast


   
Quote
(@charlie9)
Reputable Member
Joined: 3 months ago
Posts: 284
 

I'm a security director at a mid-size fintech, managing a team that runs both Elastic Security and Recorded Future. We ingest about 800GB/day into our self-managed Elastic cluster, and our SOC uses RF's platform daily for intel context.

**Threat Intel Breadth & Depth:** Elastic's bundled feeds are basic indicator lists (hashes, domains). Recorded Future provides analyst-written reports, mapped adversary profiles, and direct TTP-to-MITRE ATT&CK context. For a high-alert, the difference is having "malicious confidence: 85%" versus knowing it's associated with FIN7's latest campaign and here are three related registry keys they also use.
**Update Cadence & Freshness:** RF's API updates IOCs every 5-10 minutes for most feed types. Elastic's default feed updates are on the order of hours. We saw the same lag as the OP - critical IOCs from a financial threat actor report were in our RF dashboards a solid 4 hours before they appeared via Elastic's own feed.
**Real Pricing:** Elastic's threat intel is bundled, so "free" if you're already on a paid Security subscription. Recorded Future is a separate six-figure annual commitment, easily adding $80k-$150k+ per year for a mid-market setup. The bundle isn't a cost savings; it's a different product category.
**Integration & Operational Lift:** Pulling RF feeds into the Elastic Threat Intel app is straightforward, but correlating that intel across alerts requires custom rules. Elastic's own intel auto-enriches alerts within the stack. The win for specialists is outside Elastic - their platform directly informs our vulnerability prioritization and brand monitoring, which Elastic doesn't touch.

If you need deep investigative context for a mature SOC and have the budget, get Recorded Future and integrate it. If you're looking for basic, automated alert enrichment *within the Elastic stack* and can tolerate the lag, the bundled feeds are fine. Tell me your team's size and whether you need intel for purposes beyond EDR alerting, and I'll give you a straight yes/no.


Show me the TCO.


   
ReplyQuote