SOCRadar Extended Threat Intelligence unifies Cyber Threat Intelligence, Digital Risk Protection, and External Attack Surface Management in a single AI-powered platform. Continuously monitor the surface, deep, and dark web for threats to your brand, assets, and credentials.
SOCRadar XTI is an AI-powered Extended Threat Intelligence platform that gives security teams a unified view of external risk. It combines three capabilities that are usually sold separately: Cyber Threat Intelligence (CTI), Digital Risk Protection Services (DRPS), and External Attack Surface Management (EASM).
The platform continuously collects and analyzes data across the surface, deep, and dark web (forums, marketplaces, paste sites, Telegram channels, and leaked databases), then enriches and prioritizes it with cross-source confidence scoring so analysts focus on what matters. Core modules include Dark & Deep Web Monitoring, Brand Protection, Attack Surface Management, Vulnerability Intelligence, Supply Chain Intelligence, and VIP/Fraud Protection, alongside takedown services and IOC enrichment APIs.
SOCRadar integrates with leading SIEM and SOAR platforms, enabling automated enrichment and response workflows. The result is reduced alert noise, faster investigations, and proactive defense against external threats without adding operational overhead.
Highlights
Extended Threat Intelligence in one platform: Cyber Threat Intelligence, Digital Risk Protection, and External Attack Surface Management, with AI-driven prioritization and cross-source confidence scoring.
Surface, deep, and dark web monitoring for leaked credentials, brand abuse, fraud, and supply-chain risk, backed by takedown services and threat-actor context.
Custom scope, module bundles, volume and multi-year enterprise pricing are available through AWS Marketplace Private Offers. Contact sales@socradar.io to request a tailored private offer for your organization.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Annual access to the SOCRadar Extended Threat Intelligence Platform, with a flexible scope defined through a customer-specific agreement with Private Offer for the selected contract term. Customers can license one or more modules, including Cyber Threat Intelligence, Dark & Deep Web Monitoring, Brand Protection, and External Attack Surface Management, or opt for API-only access, such as IOC Enrichment and Reputation APIs. Customers can license exactly what they need.
$100,000.00
Advanced Brand Protection - Business
SOCRadar Brand Protection monitors social media, third-party apps, and the dark web to protect digital assets and brand reputation. Detects phishing domains, impersonation, and exposed credentials with real-time alerts and takedown management. Business tier: 50 IPs, 10 VIP accounts, 3 domains, 10 brand keywords, 5 mobile apps, 5 social accounts, 1 user.
$28,750.00
Advanced Dark Web Monitoring - Business
Advanced Dark Web Monitoring continuously scans dark web marketplaces and forums for leaked credentials and sensitive data, with early warnings and customizable alerts. Business tier: 1 domain, 1 seat; blackmarket, employee data breach, stealer/botnet tracking, hacker discussions, Telegram & Discord, ransomware activity, and VIP monitoring.
$9,100.00
Cyber Threat Intelligence - Essential
SOCRadar Cyber Threat Intelligence (CTI) gathers, analyzes, and acts on data from open sources, social media, and the dark web - threat hunting, threat-actor tracking, real-time alerts, and SIEM/SOAR integration. Essential tier: 1 seat, 50+ feed sources, 100 threat-hunting rules, 6000+ combolists, 1000 threat-search credits/yr, 100 malware-analysis credits/yr.
$14,750.00
External Attack Surface Management - Business Edition
SOCRadar External Attack Surface Management (EASM) discovers and monitors internet-facing assets (websites, cloud, APIs) with automated discovery, risk scoring, and real-time alerts to reduce exposure. Business Edition: 100 assets, 1 user.
You license this platform on an annual contract, and you can buy in two ways. The XTI Platform option gives you a flexible, custom scope through a Private Offer. You choose one or more modules, or opt for API-only access, licensing exactly what you need. Alternatively, you can buy four fixed single-module tiers: Advanced Brand Protection Business, Advanced Dark Web Monitoring Business, Cyber Threat Intelligence Essential, and External Attack Surface Management Business Edition. Each fixed tier sets defined limits, such as assets, domains, seats, and credits. All options bill per unit over the annual term.
Top-of-mind questions for buyers
How do the four fixed single-module tiers combine if I license more than one on Marketplace?
Each fixed tier bills independently as its own unit with its own defined limits. Buying Brand Protection Business and Dark Web Monitoring Business, for example, adds each tier's price separately. To combine modules under one flexible custom scope instead, use the XTI Platform option through a Private Offer.
What counts as an "asset" or "IP" in the fixed tiers' quantity limits?
Limits map to distinct monitored items. Attack Surface Management Business Edition covers 100 internet-facing assets such as websites, cloud services, and APIs. Brand Protection Business counts 50 IPs, 3 domains, 5 mobile apps, and 5 social accounts. Each item consumes one unit against its category cap.
What happens if I reach a fixed tier's seat, credit, or asset limit during the year?
Fixed tiers set hard limits, such as 1 seat, 1 domain, or defined threat-search and malware-analysis credits per year. The description does not specify automatic overage billing. To raise limits or add flexible scope, move to the XTI Platform option via a Private Offer. Contact the vendor to confirm expansion mechanics.
socradar.io
Helpful?
Vendor refund policy
All sales of the SOCRadar XTI Platform are final and non-refundable, except where required by applicable law. For billing questions, contact support@socradar.io.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
SOCRadar provides 24/7 support to all customers. Email: support@socradar.io. Support portal: https://help.socradar.io.
Subscriptions include onboarding assistance, a dedicated customer success contact. Standard response targets: critical issues within hours, standard requests within one business day.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Threater is the only active defense solution that blocks every threat from every path in your network at any scale in real time. Your security stack is better with Threater.
Recorded Future arms security teams with the only complete threat intelligence solution powered by patented machine learning to lower risk. Recorded Future can help you find threats 10 times faster, identify 22 percent more threats before impact, and resolve threats 63 percent quicker.
The AI-native CrowdStrike Falcon Platform provides comprehensive protection across all areas of enterprise risk - devices, identities, data, endpoints and cloud. Powered by a single agent, crowdsourced data, expert threat intelligence, and advanced AI, the Falcon Platform simplifies security operations and stops breaches.
For security leaders, builders, and operators, who are tasked with protecting a complex, ever-changing environment from attack, Vectra AI protects modern networks from modern attacks. When modern attackers beat customers' existing controls - and they will, Vectra AI sees their every move, connects the dots, prioritizes and stops the attack in real-time. Our customers say we are the cybersecurity AI that stops attacks others can't.
What problems is the product solving and how is that benefiting you?
It's give me a full visibility of my org digital reputation
Yazid B.
Amazing system which provide all our needs
Reviewed on Aug 25, 2026
Review provided by G2
What do you like best about the product?
There isn’t one specific thing I’d call the best, but I’d say all of the features are great overall. for example the Vulnerability Intelligence helped us keep up to date on our systems. checking IoC enrichment helped us investigate malicious IoC. News and trend news gave us the opportunity to prepare for possible threats. Primum feeds keep us monitor the malicious IoCs which reached to our environment and give us the chance to act and block them.
What do you dislike about the product?
I’m running into a few issues when trying to integrate best practices for the Primum feeds. I was hoping there would be a package or built-in option where I could enter the threat actors I’m monitoring and have it return the related IoCs for those actors.
What problems is the product solving and how is that benefiting you?
I’m benefiting from the new news, feeds, and investigations I work on as part of my daily tasks.
Nagy F.
Elegant Interface and Seamless Navigation That Saves Time
Reviewed on Aug 12, 2026
Review provided by G2
What do you like best about the product?
The interface is elegant, with visual indicators, tags, and hyperlinks that save a lot of effort. The modules are integrated in a seamless manner, with easy-to-use navigation.
What do you dislike about the product?
I found it difficult to conduct a thorough analysis of the raised tickets. There was no clear or efficient way to filter out the noise and focus on the real underlying issues, which made the investigation process more time-consuming.
What problems is the product solving and how is that benefiting you?
One of the main problems is the high level of noise and repeated tickets. Similar or closely related alerts are often raised separately instead of being clearly flagged as duplicates, similarity matches, or proximity matches, which makes analysis more time-consuming and can distract from the actual underlying issue.
coolhankss .
Proactive Threat Detection with Seamless Setup
Reviewed on Aug 10, 2026
Review provided by G2
What do you like best about the product?
I like how SOCRadar Extended Threat Intelligence helps us improve external attack surface visibility and detects threats proactively. The discovery of exposed devices over the dark web and the identification of IOCs are particularly valuable. It provides IOCs relevant to our environment and compromised employee credentials for appropriate actions, helping us address threats proactively. Plus, the initial setup was very easy.
What do you dislike about the product?
None
What problems is the product solving and how is that benefiting you?
SOCRadar improves our external attack surface visibility, detects threats proactively, and coordinates timely remediation. It provides IOCs relevant to our environment and compromised employee credentials, helping us address threats proactively.
Kamil M.
Catches Threats Before They Become Incidents
Reviewed on Aug 04, 2026
Review provided by G2
What do you like best about the product?
What I like best about SOCRadar Extended Threat Intelligence is the dark web monitoring and digital risk protection features. They've helped us catch leaked credentials and phishing domains targeting our brand early, before they became real incidents. The SIEM integration was also easy to set up, and alert prioritization helps our small team focus on what matters instead of chasing noise.
What do you dislike about the product?
What I dislike about SOCRadar Extended Threat Intelligence is the volume of false positives in some alert categories, which requires manual tuning to reduce noise. The dashboard can also feel a bit overwhelming for new users, and generating custom reports isn't always as intuitive as I'd like.
What problems is the product solving and how is that benefiting you?
Before SOCRadar, we had no visibility into threats outside our own network leaked credentials, fake domains copying our brand, that kind of thing. We usually found out too late. Now we get alerted early enough to actually do something about it. It's saved us from a couple of credential leaks we would've missed, and it's freed up time for our small team since we're not manually digging through forums anymore.