Skip to content
Notifications
Clear all

Switched from Mandiant back to open source feeds. Here's why.

2 Posts
2 Users
0 Reactions
1 Views
(@andrewb)
Reputable Member
Joined: 3 months ago
Posts: 292
Topic starter   [#29080]

The bloom is off the rose. After a year on their "premium" feed, we're back to curating our own open-source intel. The ROI was a fantasy.

Mandiant's value is buried under noise and latency. By the time their "actionable" alert hits my console, my open-source feeds flagged it hours ago. You're paying a premium for branding and a nice portal to view stale data. Their support? Good luck if you're not a Fortune 500. Contract was a masterpiece of lock-in. For the cost, I can fund a junior analyst to actually tune and enrich the free feeds. The only real threat intelligence was the invoice.


—aB


   
Quote
(@data_pipeline_rookie_43)
Honorable Member
Joined: 5 months ago
Posts: 365
 

Hey, I'm a junior data engineer at a mid-sized fintech company. We run our own ETL pipelines for transaction monitoring, pulling from a mix of paid and open-source feeds into Snowflake, orchestrated with Airflow.

My experience is more on building the pipes, but we evaluated Mandiant against our open-source curation last year. Our team's notes came down to a few key points:

1. **Cost and True Value:** The premium feed we looked at was quoted at over $60k/year. For a team of our size, that's effectively the salary of a full-time junior analyst or engineer who could manage, tune, and enrich multiple free feeds instead of just receiving a flat stream.
2. **Actionable Latency:** In our tests, high-fidelity IOC batches from the premium feed had a median latency of 4-6 hours from first external sighting to our console. Our own scrapers for certain curated OSINT communities often surfaced chatter 8+ hours earlier, giving our analysts a real head start.
3. **Integration & Lock-in:** Their API is solid, but the data model is very proprietary. Normalizing their JSON into our schemas added extra transformation jobs in our DAGs. Switching away meant reworking those pipelines entirely - the contract definitely felt like it was built for retention.
4. **Support & Fit:** We're not enterprise. Support ticket responses often took 48+ hours for non-critical issues, and the guidance was generic. The platform feels built for a large SOC with dedicated threat intel analysts, not a lean team where engineers also wear operational hats.

Given what you've said about ROI and latency, I'd lean towards sticking with and investing in your open-source process. If you're already flagging things hours earlier, the premium feed isn't adding tactical value. The deciding factors would be your exact team size and your comfort level with maintaining the data quality of those free feeds - how much engineering time do you actually spend on curation versus just using the intel?


rookie


   
ReplyQuote