Try our new research platform with insights from 80,000+ expert users

Corelight vs Darktrace comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Nov 24, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Corelight
Ranking in Network Traffic Analysis (NTA)
7th
Ranking in Network Detection and Response (NDR)
14th
Average Rating
9.0
Reviews Sentiment
7.6
Number of Reviews
5
Ranking in other categories
No ranking in other categories
Darktrace
Ranking in Network Traffic Analysis (NTA)
1st
Ranking in Network Detection and Response (NDR)
1st
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
77
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (1st), Extended Detection and Response (XDR) (5th), AI-Powered Chatbots (2nd), Cloud Security Posture Management (CSPM) (16th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Attack Surface Management (ASM) (3rd), AI-Powered Cybersecurity Platforms (2nd)
 

Mindshare comparison

As of February 2025, in the Network Traffic Analysis (NTA) category, the mindshare of Corelight is 10.8%, up from 10.4% compared to the previous year. The mindshare of Darktrace is 27.0%, up from 26.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Traffic Analysis (NTA)
 

Featured Reviews

HamadaElewa - PeerSpot reviewer
An expensive solution to monitor internet traffic with multiple dashboards
The huge library especially the open source link, makes it the main engine for Corelight with some enhancements in the commercial version. It has a very powerful level, such as signature-based attacks or behavioral attacks, with enhancements in the design. It is very flexible for intelligent implementations like IPs, especially between big companies and banks. Corelight is easy to understand and monitor what is going on behind the team. The solution is already integrated with other systems like Suricata, Elastic, and Microsoft tools. It's very easy to integrate signature-based or behavior-based engines. You can use Elastic for the dashboards to get it from Corelight, along with all the benefits and expandability.
Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Corelight is easy to use."
"It's an easy way for us to get visibility in a client's environment."
"It's easy to create additional dashboards specific to supporting specific tasks."
"The most valuable feature is the embedded IDS from Suricata."
"It is easy to deploy and easy to handle."
"The product offers us a very good user interface and we've found the network visibility to be very good so far."
"Technical support is helpful and responsive."
"The most valuable features are the AI and advanced learning tools that distinguish it from other products."
"I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it."
"It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
"The initial setup is simple."
"What I like about Darktrace, is that you can quickly identify threats."
"The active threat dashboard is the most valuable feature of this solution."
 

Cons

"The solution’s architecture is complex and difficult to understand. There are multiple machines and VMs."
"They can enhance the interface of the product. They can make it more interactive and also easier to use for feature access."
"In the next release, building a graphical user interface would be helpful."
"Corelight hasn’t added features in a long time."
"Machine learning could be a good improvement, but it's very costly."
"The main portal needs improvement as it is difficult to use."
"The pricing model is a little too high and could be more flexible."
"I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint."
"It's a very complex platform."
"The solution's user interface and stability could be improved."
"Darktrace does not have any capabilities to configure."
"Getting logs from different sources can be a challenge."
"The solution could be easier to use."
 

Pricing and Cost Advice

"It's a yearly fee and depends on what you are looking for."
"It is expensive."
"The product is expensive."
"The pricing is very flexible for Darktrace. Sometimes, a customer does not have the appropriate budget, but Darktrace can handle that. They offer monthly payments, so the customer can acquire the solution very easily."
"The pricing is subscription-based and it is high."
"This solution is expensive."
"The cost of the solution can be reduced to make it more appealing to customers."
"I am using a demo of Darktrace for deployment and testing which is free."
"It is pretty expensive, but it is worth it. Its licensing is yearly."
report
Use our free recommendation engine to learn which Network Traffic Analysis (NTA) solutions are best for your needs.
838,640 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Government
13%
Computer Software Company
11%
Manufacturing Company
7%
Computer Software Company
15%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What is the biggest difference between Corelight and Vectra AI?
The two platforms take a fundamentally different approach to NDR. Corelight is limited to use cases that require the eventual forwarding of events and parsed data logs to a security team’s SIEM or ...
What do you like most about Corelight?
It's easy to create additional dashboards specific to supporting specific tasks.
What is your experience regarding pricing and costs for Corelight?
The solution is too expensive compared to others. If you have the technical knowledge, it's good. Corelight is a very big gap between you and others if you’re new.
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
 

Overview

 

Sample Customers

Education First
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Find out what your peers are saying about Corelight vs. Darktrace and other solutions. Updated: January 2025.
838,640 professionals have used our research since 2012.