Anomali ThreatStream is the platform of cyberinvestigation (Threat Intelligence Platform/TIP) which provides collecting of the known indicators of a compromise (Indicator of Compromise/IOC) from more than 130 sources of data on threats (feeds, fid).
The product implements normalization, correlation and enrichment of IOC indicators and also visualization of incidents and joint investigation of incidents. The solution gives a connectivity of any data sources in the unified format and also works with own data of Threat Intelligence (TI).
Anomali ThreatStream maintains ability to integrate with other systems of protection, for example, sending the IOC lists to monitoring systems of SIEM for conducting investigation or to the EDR solution for search of signs of a compromise at workstations of users.