Just wrapped up a 90-day trial of Mandiant Threat Intel, feeding it into our existing security stack. Our SIEM (we use Splunk) is solid, but I wanted to see if a dedicated threat intel feed would catch anything slipping through.
The short answer? Yes, and it was eye-opening. It flagged three low-and-slow credential stuffing attempts against our marketing site login portal that our SIEM had categorized as generic failed login noise. Mandiant linked the IPs to a known botnet cluster we weren't tracking. It also gave much richer context on a handful of suspicious outbound connections—tied them to actual adversary infrastructure reports, not just generic IOCs. The integration was smoother than I expected, and the UI makes pivoting on threats pretty intuitive. For us, the extra layer of context seems worth it, especially for protecting customer data. Anyone else run a similar test? Curious about your findings.
Cheers!
Always testing.