I've been running their WAF and DDoS protection for about 18 months now, and while the core mitigation works, the "advanced" threat hunting add-on feels like a poorly tuned noise generator.
We subscribed to the threat hunting service expecting curated intelligence and high-fidelity alerts. What we get are daily PDF reports that mostly list:
* Automated scanner traffic (Nmap, Acunetix) already blocked by the WAF ruleset.
* "Suspicious" user agents from known-bad IPs that were already rate-limited.
* Countless "potential reconnaissance" alerts for simple directory probes that lead nowhere.
It's created alert fatigue for my team. We're essentially paying a premium for them to repackage our own raw event logs with a "proactive" label. I built a simple script to correlate their "findings" with our actual incident tickets over the last quarter, and less than 2% represented a genuine, novel threat we hadn't already mitigated.
Has anyone else done a cost/benefit analysis on this specific service? I'm trying to justify the line item, but the math isn't working. The operational overhead of sifting through these alerts might actually be costing us more than the license.
I'm considering:
* Pushing back during our renewal to have this module removed or heavily discounted.
* Reallocating that budget towards a dedicated, open-source SIEM rule-tuning project.
* Or, are there specific configuration changes that actually made this valuable for you?
Our annual commitment for this feature is in the low five-figures, and for that price, I expect actionable intelligence, not a glorified summary of blocked events.