Eclectic IQ. The Intelligent tool for all your desired Intel!
Rating: 9 out of 10
IncentivizedUse Cases and Deployment Scope
The current environment that I am working in has multiple OSINT and premium Threat Intels subscribed. EclecticIQ, in addition to its own superb intel, is integrated with the rest of the intel via API calling and serves as a common ingestion point for all the Intelligence. This feed from the EIQ is then consumed by SIEM and SOAR.
Pros
- Effective correlation of IOCs
- Averaging out the Confidence Score based on different intel sources.
- Serves as an excellent liaison points between the Intels and SIEM/SOAR stack.
Cons
- Misses on a global search bar which can directly gives out the result like VirusTotal.
- The GUI could be more friendlier. Too many filters and graphs may overwhlem the user sometimes.
- The ElasticSearch(searching for IOC in the in-house EIQ database) is a little slow compared to its counterparts.
Likelihood to Recommend
ElecticIQ has an architecture where it usually needs decent computing power within the organisation. The central console along with the ELK servers and PostgreSQL sever needs their own space in a distributed setup. This could be a little too expensive for small-scale organisations. But for the organizations having mid to large-scale networks. EIQ is a decent solution to serve the purpose.