Hi everyone, I'm pretty new to this whole security platform evaluation thing (my background is more in CRM and project management), but I've been tasked with helping our team choose a threat intelligence solution. We just wrapped up a 90-day Proof of Concept with ThreatConnect, and I wanted to share my results and see if this matches your experiences.
The main goal was to improve our detection of real threats. On that front, ThreatConnect definitely delivered – we identified a couple of genuine, suspicious campaigns we would have totally missed before. Our detection rate went up by about 40%, which is huge for us.
But here's the big, unexpected side effect: our overall alert volume more than doubled. A lot of these new alerts are lower severity, or from sources we weren't ingesting before. It's great to have more data, but our small SOC team is now feeling overwhelmed. We're getting better detection, but I'm worried we're just creating alert fatigue.
So my question for the community is: is this normal? Does the high alert volume settle down after you tune the platform more, or is this just the reality of having more visibility? We're trying to figure out if this is a "growing pain" or a fundamental workflow issue. Any tuning tips or how you managed the transition would be so appreciated. Feeling a bit out of my depth here! 😅
Your results are extremely common, especially for the first 90 days. That 40% detection lift is the validation you need that the platform works. The doubled alert volume is the cost of that new visibility.
The critical question now is whether this high volume is the new steady state. In my experience, it absolutely isn't. The next phase is tuning and threat modeling. You need to start filtering those lower-severity alerts from new sources, creating internal whitelists for noisy-but-benign activity your environment generates. This is where you trade raw volume for signal quality.
Has your team started a formal process to categorize these new alerts and define which ones should be suppressed or escalated? Without that, the fatigue will only get worse, even as your detection capability improves.
Show me the bill.