Try our new research platform with insights from 80,000+ expert users

Darktrace vs Tanium comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Darktrace
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
82
Ranking in other categories
Email Security (8th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), Cloud Security Posture Management (CSPM) (14th), Cloud-Native Application Protection Platforms (CNAPP) (10th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (2nd)
Tanium
Average Rating
7.4
Reviews Sentiment
6.8
Number of Reviews
17
Ranking in other categories
Server Monitoring (6th), Vulnerability Management (25th), Endpoint Protection Platform (EPP) (34th), Endpoint Detection and Response (EDR) (31st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Darktrace is designed for Network Detection and Response (NDR) and holds a mindshare of 22.3%, down 25.0% compared to last year.
Tanium, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 2.4% mindshare, up 2.4% since last year.
Network Detection and Response (NDR) Market Share Distribution
ProductMarket Share (%)
Darktrace22.3%
Vectra AI15.6%
ExtraHop Reveal(x)8.2%
Other53.900000000000006%
Network Detection and Response (NDR)
Endpoint Protection Platform (EPP) Market Share Distribution
ProductMarket Share (%)
Tanium2.4%
Microsoft Defender for Endpoint9.9%
CrowdStrike Falcon7.9%
Other79.8%
Endpoint Protection Platform (EPP)
 

Featured Reviews

Malebo Lethoba Group - PeerSpot reviewer
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
The functions I find most valuable in Darktrace are the AI analyst as well as the detection.The autonomous response capabilities of Darktrace are not crucial for me because it doesn't work in a network where there are no core switches. In a modern network, the autonomous response doesn't work, especially when sitting in a shared data center.If I'm running a traditional network where I am not in a shared data center with a layer two dedicated for my resources, then it can work for me. However, if I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
NitinKushwaha - PeerSpot reviewer
Stable product with an ability to build complex roles
We use Tanium as an EDR solution for managing end-user devices and servers The product is granular and can build complex roles compared to other EDR vendors. Tanium's dashboard UI could be similar to CrowdStrike. We have been using Tanium for two and a half years. The product is stable. I rate…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The scalability of Darktrace is very high."
"Darktrace is very stable, and I would rate its stability a ten out of ten."
"A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time."
"The autonomous response is also highly designed in Darktrace."
"The solution is outstanding from a monitoring perspective."
"The most valuable feature is the endpoint protection."
"The initial setup is simple."
"The platform has many modules, and each module examines a different situation in the behavior."
"I like the tool's incident response and security patching."
"The interrogation piece was the most valuable feature because it was very detailed."
"For incident response tasks, all these tasks can get done in minutes with minimal disruption to the end-user."
"I'm not so familiar with the tool but I like the interaction of the console to the picture. Patching is the primary model I have been focusing on for the last couple of weeks. So I have created a proof of concept environment and have been checking the available features."
"Threat hunting is a very good feature on Tanium. We have just started using it and have not used it extensively."
"When I push a quick update, it's done right away, and I can rescan immediately to confirm completion within minutes."
"Tanium is a very good product and I would rate it eight or nine out of ten."
"I would say Tanium is the best tool for vulnerability management."
 

Cons

"There is a high ratio of false positive information."
"One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent."
"The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
"There aren't so many third-party vendor platforms natively integrated with the platform."
"Its threat analyzer could be better. It should also have agents. They should improve this product by installing agents for the machine to get more visibility. Currently, they are monitoring only the network. They should also monitor the agents from inside. It should also have a better pricing plan because it is an expensive product."
"I did not use the AI features because they should make it more user-friendly which would be a benefit. Additionally, the solution could integrate with more SIEM or SOAR tools."
"The pricing is a bit high for the region."
"It can have more integration with orchestration or event management solutions. They can provide more knowledge or research information for analysts for investigating cases and detecting anomalies in networks."
"The solution needs to improve the reporting and tracking capabilities."
"They could improve the UI."
"The performance could improve in future releases. We have had performance issues in specialized web environments, but overall I think the problems are less than 2% of the computer systems being used."
"Tanium's limitations should be improved because although it is a great tool, it is limited to only a few classes during a session."
"When working with Tanium, there are some older devices that haven't been patched for a long time, and certain patches are not included in Tanium. I have to search outside to download patches, create bundles, and then perform the task."
"The most painful thing is the interface. It's a bit unclear sometimes."
"The main issues are the network connection because different customers have issues with their networks. It's difficult implementing this type of solution because the network is the main feature in the architecture for these types of solutions. Tanium could improve by creating some network optimization."
"When working with Tanium, there are some older devices that haven't been patched for a long time, and certain patches are not included in Tanium."
 

Pricing and Cost Advice

"The pricing is subscription-based and it is high."
"We've budgeted about 50,000 Kuwaiti dinars for the solution. That is a yearly operating cost."
"The price of the solution is not cheap. It is not a one-time purchase, there is a subscription that needs to be paid every one to five years depending on your choice. It is expensive but you can reduce the price by only using the services that you want."
"I'm unfamiliar with the exact cost, but we have a yearly license and had to pay for Darktrace's services before the deployment. The product is very expensive, so some organizations can't afford to pay the total amount directly, meaning they often seek a partner or pay in installments, which increases the price more."
"It was $3,600 a month or $2,000 plus or so. I am not sure. Its licensing is pretty simple."
"The solution is about $6,000 per quarter."
"The pricing is reasonable."
"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"It is higher than some competitors in the market."
"The solution is expensive but it's a good investment."
"It's an expensive solution. It would be nice if the cost were lower."
"There is an annual license required to use this solution."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"The solution offers value for money."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
869,785 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Comms Service Provider
7%
Financial Services Firm
16%
Government
12%
Manufacturing Company
9%
Computer Software Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise10
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Tanium?
The product is granular and can build complex roles compared to other EDR vendors.
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the core functions.
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about Darktrace, Vectra AI, Trend Micro and others in Network Detection and Response (NDR). Updated: October 2025.
869,785 professionals have used our research since 2012.