Okay, I'll be the one to say it. I've been trialing a few different threat intelligence platforms lately, and I can't shake the feeling that a lot of them are just... really expensive dashboards. Pretty visualizations of feeds I could mostly get elsewhere.
Don't get me wrong—I love a good dashboard! But when I'm evaluating, I keep asking: where's the *automation*? I want the intel to *do* something without me having to manually review and act. For the price, I expect deep, native integrations that can automatically update WAF rules, block IPs in my edge config, or create tickets. Instead, I often find myself needing to use Zapier or Make to build those connections myself, which kind of defeats the purpose.
My current setup involves:
* A couple of open-source feeds piped into a cloud VM.
* A Make scenario that filters and formats the data.
* Auto-updates to Cloudflare WAF rules via their API.
It works, but it's my own DIY "platform." I guess I'm wondering if the commercial products are just doing this at scale with a nicer UI. What are you all actually *doing* with your TIP outputs? Anyone found one that truly automates response, not just aggregation?
Maybe I'm just looking at the wrong vendors? Keen to hear your experiences.
— liam
If it can be automated, it will be.