Overview
Product Information on ThreatBook TDP NDR
What is ThreatBook TDP NDR?
ThreatBook TDP NDR Pricing
Overall experience with ThreatBook TDP NDR
“Incident response improved significantly though regional threat customization still lags”
About Company
Company Description
ThreatBook is a provider of cyber threat detection and response services. We developed new approaches to deliver high-fidelity, efficient, and actionable security intelligence. We integrated these capabilities with a full life cycle threat detection system and incident response mechanisms to enhance protection across cloud, network, and endpoints. This helps enterprises respond to threats efficiently, reduce complexity, and improve security operations.
Company Details
Do You Manage Peer Insights at ThreatBook?
Access Vendor Portal to update and manage your profile.
Key Insights
A Snapshot of What Matters - Based on Validated User Reviews
Top ThreatBook TDP NDR Alternatives
Peer Discussions
ThreatBook TDP NDR Reviews and Ratings
- Manager, IT Security and Risk Management50M-1B USDMiscellaneousReview Source
Incident response improved significantly though regional threat customization still lags
We deployed ThreatBook TDP about eleven months ago to address a long-standing visibility. gap across our global supply chainnetwork. As a consumer electronics. holding company withoperations spanning hardware design, manufacturing, and distribution across Africa and South Asia, we manage a complex network environment with roughly. 4,000 endpoints spreadacross. multipl. sites. BeforeTDP,our security. team relie. almostentirely onfirewall logs. and endpoint alerts,with essentially no east-west traffic. visibility inside oursegmented production and R&D subnets. TDP's out-of-band. mirror deploymen. was critical for us --w. couldn't afford tointroduce an. appliance into the pathof production traffic, and the passive tapapproach meant. we were up and running wit. meaningful coverage within a we. k without . ny change managementoverhead. The immediatevalue was discovering 60+ undocumentedassets acrossour Shenzhen and overseas manufacturing. sites -- servers and embedded devices that nobody had tracked in our CMDB fo. years. The AI-driv. n alertcorrelation engi. e has also been a genu. ne . ime saver: our team of . hree SOC analys. snow reviews roug. ly 35 to45 high-fi. elity. alerts perday down from. a peak of over1,800raw events, which has dramaticallychanged how we allocateinvestiga. ion time.Over the past year, TDPhas beenthe first-touch detection toolin five confirmed incident investigations, including two cases involving suspected supply-chain-motivated lateral movement targeting our R&Dfile servers. - Manager, IT Security and Risk Management50M-1B USDTelecommunicationReview Source
Full-packet capture boosts threat detection but lacks VRF awareness
We deployed ThreatBook TDP across our international POPs to gain carrier-grade traffic visibility. As a telecom operator handling multi-terabit backbone traffic, we needed deeper. inspection thanNetFlow sampling could provide. TDP's passive full-packet capture architecture integrated smoothly. at6 major POPs — Hong Kong, Singapore, Frankfurt, London, Tokyo, and Los Angeles — within a 3-week rollout window. The AI-driven detection engine reduced our daily alert volume from approximately 5,000 NetFlow-based anomalies to roughly 80 actionable incidents requiring SOC investigation. A notable win was catching a multi-hop C2 relay traversing our SingaporeaFrankfurt backbone that NetFlow had completely missed for 11 days. The API-driven closed-loop blocking with our edge routers via BGP Flowspec cut mean-time-to-block from 45 minutes to under 3 minutes. TDP fits well into our existing NOC workflow and has meaningfully improved our backbone threat visibility without adding operational overhead. - IT Associate<50M USDManufacturingReview Source
Comprehensive Security Coverage and Efficient Response Noted With TDP Platform
I think the TDP platform is overall very practical and easy to use,with no major shortcomings.It serves as an all-in-one security operations platform that covers the entire security workflow,including asset attack surface management,monitoring and detection,automated analysis,and response and remediation capabilities.In daily operations,I regularly verify and remediate exposed attack surfaces identified by TDP. Its detection capability is also quite strong. TDP has helped me identify emerging threats such as Sliver Fox malware and worm viruses,and by integrating with the firewall for automated blocking,it has greatly improved the speed of incident response and made further investigation and troubleshooting much more efficient. - IT Associate50M-1B USDConsumer GoodsReview Source
An Integrated One-Stop Security Operations Platform
TDP is a network traffic monitoring platform that provides capabilities such as asset attack surface identification, helping organizations better understand and manage their internal attack surfaces.It also includes threat monitoring features that help detect internal security incidents in a timely manner.For incident response and closed-loop security operations, TDP can integrate with other security devices to automatically block malicious activities.Overall, it serves as a one-stop security operations platform that combines visibility,threat detection,investigation,and automated response capabilities to improve daily security operations efficiency and reduce manual workload for security teams. - Manager, IT Security and Risk Management<50M USDIT ServicesReview Source
Stable threat detection with powerful log collection, but complex deployment process
we have used this security product for years in our daily operation. it delivers stable threat detection capabilities and comprehensive log collection, helping us reduce false alerts effectively. howecer, the initial deployment is complex,user operation is relatively complicated, and functional updates are released too frequently ,bringing extra adaptation costs to our team.



