Looking at ThreatConnect's pricing page. They don't list PS hours, just a vague "implementation fee."
My team is being pushed to evaluate it. Before I get on a sales call, I want a reality check from people who've actually bought it. Not the vendor's "typical engagement" slide.
For a basic setup—ingesting a few common threat feeds, some internal log sources, setting up a handful of playbooks—what's the real number of hours we'd be on the hook for?
If the answer is "zero, you can do it yourself," I'll believe it when I see it. Their UI looks like it needs a dedicated config file anyway.
```yaml
# Is the actual setup something like this?
sources:
- alienvault_otx
- abuse_ch_db
playbooks:
- triage_ips
- escalate_malware
```
Or do they lock it down so you have to go through their team for 40+ hours?
SQL is enough