Try our new research platform with insights from 80,000+ expert users

Darktrace vs Wazuh comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Darktrace
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.2
Number of Reviews
70
Ranking in other categories
Email Security (11th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), AI-Powered Chatbots (3rd), Cloud Security Posture Management (CSPM) (14th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Attack Surface Management (ASM) (2nd)
Wazuh
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
7.4
Number of Reviews
42
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (3rd)
 

Featured Reviews

ADITYA KAUSHIK - PeerSpot reviewer
Aug 22, 2024
Provides extensive information on data exfiltration but lacks notification capabilities
Darktrace needs significant improvement in its notification capabilities. While it does notify administrators, the old approach of having admins directly police users is outdated. Users now prefer automated, impersonal responses rather than being confronted by IT staff, which can lead to concerns about privacy violations. We've requested Darktrace to develop a feature that notifies users directly when it detects potential data exfiltration. Darktrace doesn't differentiate between personal and work data uploaded to Google Drive or OneDrive. It flags it as exfiltration and expects the IT team to investigate further. Human policing is a thing of the past; what’s needed now are automated responses, user awareness, and behavior warnings, areas where Darktrace falls short. In contrast, Egress, an email security solution, excels in this regard. It intuitively detects potential risks, even flagging first-time email recipients and integrating data classification. We’ve encouraged Darktrace to adopt this level of functionality, transforming it from just identifying exfiltration to a more comprehensive data leak prevention tool. However, as of now, Darktrace is still limited to identifying when a node is transferring data without distinguishing the nature of that data. Darktrace could improve by enabling user heat maps or risk profiles, a feature that many other EDR and cybersecurity products already effectively provide. It would be beneficial for us if they could offer this functionality without requiring the purchase of an additional email security solution. On the plus side, Darktrace integrates with CrowdStrike, allowing it to monitor CrowdStrike agent actions. This integration helps us achieve a unified view of our security landscape since we route Darktrace, CrowdStrike, FortiGate, and other tools through SecureWorks, our centrally managed security platform.
Md Salim Hossain Hossain - PeerSpot reviewer
Jan 31, 2024
An open-source platform to integrate various products
We use Wazuh for the onboarding of both Windows and Linux machines, as well as for firewall and SIM configuration. The IP address is automatically blocked if a server has multiple wrong passwords Wazuh can integrate with various open-source and paid products, allowing for flexibility in…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
"One member of staff is enough for deployment and maintenance because Darkforce is AI-driven. It does a lot of things by itself."
"It has helped the organization to detect any malware affecting the machines...The network monitoring and the email monitoring features are very valuable for us."
"Its AI technology supports cybersecurity by learning my environment and accurately responding to threats."
"Darktrace is very flexible."
"We liked their approach to identifying intrusions or network anomalies using AI."
"The NDR is good in their solution and they have NTG for email."
"It is autonomous. So, it learns. It uses algorithms and AI to learn the common behavioral patterns on the network, and it is able to identify threats based on abnormal patterns."
"The configuration assessment and Pile integrity monitoring features are decent."
"It is a stable solution."
"I find the PCI DSS feature the most valuable, along with the feature that monitors the compliance of Windows and the CIS benchmarks on other devices like Unix or Linux systems."
"Wazuh is free and easy to use. It is also adjustable, and we can use it on the cloud and on-premises."
"The product is easy to customize."
"I like Wazuh because it is a lot like ELK, which I was already comfortable with, so I didn't have to learn from scratch."
"The MITRE ATT&CK correlation is most valuable."
"The main thing I like about it is that it has an EDR."
 

Cons

"I was under impression that Darktrace's automatic blocking would be an out-of-the-box feature, but we had to integrate it with our firewall to get it to block automatically. The salesperson should be upfront and explain that you need to integrate it with your network. I would also like to see more reporting on risk. Banks in my region want to see at a glance the risk level of various assets."
"I would like to see some additional enhancements."
"It would be good if they can include some endpoint protection for remote workers. Nowadays, most people are working remotely. Therefore, they should include some type of sensors that can be installed on the endpoint in order to directly report the main usage and protect remotely. Phone protection will also be a great feature to add to Darktrace."
"We'd like threat hunting, and we'd like to see a global solution that can automate vulnerability scans. I know it is something they are working on."
"It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."
"The cost is a bit on the higher side."
"The solution's user interface and stability could be improved."
"I believe their network monitoring device licensing module could use some improvement."
"Scalability is a constraint in the on-prem version of Wazuh in terms of the volume of logs we can manage."
"They could include flexibility and customization capabilities by modifying for customers based on partner agreements."
"I have yet to find the same capability in Wazuh to get logs from different sources into the system"
"Its user interface for sure can be improved. It is not so comfortable to use if you're looking for specific logs."
"Alerts should be specific rather than repeatedly triggered by integrating multiple factors. This issue needs improvement to create a more efficient alert system."
"It would be great if there could be customization for the decoder portion."
"Scalability is a challenge because it is distributed architecture and it uses Elastic DB. Their Elastic DB doesn't allow open source waste application."
"The only challenge we faced with Wazuh was the lack of direct support."
 

Pricing and Cost Advice

"It is inexpensive considering what it can do and the competition."
"If you consider the features and the cost of market leaders, we are satisfied with the pricing."
"The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution."
"It was $3,600 a month or $2,000 plus or so. I am not sure. Its licensing is pretty simple."
"Darktrace is quite an expensive solution."
"We had an issue with pricing initially and had to cancel some of the features of the projects to fit the budget. I would like to see pricing that is not broken up into parts so that we can buy the whole package once. Darktrace is more expensive than an average solution, but it's functionality won't match that of an average solution."
"They are too expensive compared with other vendors."
"The pricing is expensive. It costs over $100,000 a year."
"Wazuh is a cheaply priced product."
"Wazuh is free and open source."
"There is not a license required for Wazuh."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"Wazuh is an open-source tool."
"Wazuh has a community edition, and I was using that. It's free and open source."
"The product price is neither too high nor too low."
"It is an open-source product."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
802,829 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
8%
Manufacturing Company
7%
Government
7%
Computer Software Company
17%
Manufacturing Company
7%
Educational Organization
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
Wazuh doesn't have native support for some enterprise solutions. It requires an agent installed on the server, whether Windows Server or Linux, to collect logs. While you can gather information via...
What is your primary use case for Wazuh?
My company specializes in providing SIEM as a service. We leverage Wazoo for that. Since Wazoo is open-source, I hosted it on Azure. We provide Wazuh as a service to our customers. Currently, we ha...
 

Comparisons

 

Learn More

 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Information Not Available
Find out what your peers are saying about Darktrace vs. Wazuh and other solutions. Updated: July 2024.
802,829 professionals have used our research since 2012.