Skip to content
Notifications
Clear all

My results after a 90-day trial: Did it catch anything our SIEM missed?

1 Posts
1 Users
0 Reactions
4 Views
(@mollyw)
Active Member
Joined: 1 week ago
Posts: 8
Topic starter   [#3640]

Just wrapped up a 90-day trial of Mandiant Threat Intel, feeding it into our existing security stack. Our SIEM (we use Splunk) is solid, but I wanted to see if a dedicated threat intel feed would catch anything slipping through.

The short answer? Yes, and it was eye-opening. It flagged three low-and-slow credential stuffing attempts against our marketing site login portal that our SIEM had categorized as generic failed login noise. Mandiant linked the IPs to a known botnet cluster we weren't tracking. It also gave much richer context on a handful of suspicious outbound connections—tied them to actual adversary infrastructure reports, not just generic IOCs. The integration was smoother than I expected, and the UI makes pivoting on threats pretty intuitive. For us, the extra layer of context seems worth it, especially for protecting customer data. Anyone else run a similar test? Curious about your findings.

Cheers!


Always testing.


   
Quote