Try our new research platform with insights from 80,000+ expert users

Darktrace vs Wazuh comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Darktrace
Ranking in Extended Detection and Response (XDR)
5th
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
77
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), AI-Powered Chatbots (2nd), Cloud Security Posture Management (CSPM) (16th), Cloud-Native Application Protection Platforms (CNAPP) (12th), Attack Surface Management (ASM) (3rd), AI-Powered Cybersecurity Platforms (2nd)
Wazuh
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
7.4
Reviews Sentiment
6.6
Number of Reviews
45
Ranking in other categories
Log Management (2nd), Security Information and Event Management (SIEM) (2nd)
 

Mindshare comparison

As of February 2025, in the Extended Detection and Response (XDR) category, the mindshare of Darktrace is 9.9%, down from 10.7% compared to the previous year. The mindshare of Wazuh is 12.9%, up from 9.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR)
 

Featured Reviews

Peter-Murphy - PeerSpot reviewer
Enables proactive threat detection and immediate response through AI monitoring
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation. Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures. Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
Sandip_Patel - PeerSpot reviewer
Evaluating robust file monitoring with insights for community support improvements
Wazuh's most valuable features include file monitoring and compliance reporting, which do not require excessive costs. These aspects are vital as they provide alerts for changes and facilitate the monitoring of compliance. The platform is also relatively easy to set up and operate. Reports are straightforward to extract and prove useful for compliance requirements.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Darktrace provides better visibility into network risks, allowing you to take preemptive action against risky user behavior."
"The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
"I am impressed with the product's ability to give insights into network traffic."
"One member of staff is enough for deployment and maintenance because Darkforce is AI-driven. It does a lot of things by itself."
"Darktrace is very useful for us because it has a large number of models for detecting threats."
"Provides great network protection."
"We are able to detect a lot of things, actually, and see what is happening in our network."
"Its AI technology supports cybersecurity by learning my environment and accurately responding to threats."
"We found the MITRE framework mapping and the agent enrollment service to be the most valuable features of Wazuh."
"The deployment is easy and they provide very good documentation."
"It's stable."
"It's very easy to integrate Wazuh with other environments, cloud applications, and on-prem applications. So, the advantage is that it's easy to implement and integrate with other solutions."
"I like the features we use, including malware detection, inventory, detection of hidden processes, and activity logs. Inventory is probably the most important feature. It tells us when processes and packages were installed and what they are, which is helpful."
"It is a stable solution."
"It offers built-in modules for file integrity and vulnerability management."
"Good for monitoring, active response, and for vulnerabilities."
 

Cons

"It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not."
"The interface is too mathematical and it should be simplified."
"Darktrace could improve by being more user-friendly."
"There aren't so many third-party vendor platforms natively integrated with the platform."
"The one downside is the pricing, which is quite high."
"It could build in integrations for some complementary products, but it has an assistant plugin so this is not really a big deal."
"The pricing model is a little too high and could be more flexible."
"I would like for the product to work on the endpoints as well. I would like to see enhanced visibility into the endpoints and network but this solution only sits on the network itself."
"It would be better if they had a vulnerability assessment plug-in like the one AlienVault has. In the next release, I would like to have an app with an alerting mechanism."
"Log data analysis could be improved. My IT team has been looking for an alternative because they want better log data for malware detection. We are also doing more container implementation also, so we need better container security, log data analysis, auditing and compliance, malware detection, etc."
"The support channel is not optimal, and extensive research is required on our part to implement Wazuh effectively."
"An issue I noticed is with tag values in certain rules not functioning properly."
"Wazuh currently fails to provide its users with AI and ML."
"The support team could be more responsive and provide quicker replies during our working hours in Indonesia, which would be a significant improvement."
"Integration with Vyara could be better."
"It would be great if there could be customization for the decoder portion."
 

Pricing and Cost Advice

"Darktrace is quite an expensive solution."
"The cost is moderate."
"Prior to negotiating, Darktrace offered their appliance and service for $80,000 per year."
"Darktrace is expensive. You can pay for the license yearly."
"I'm unfamiliar with the exact cost, but we have a yearly license and had to pay for Darktrace's services before the deployment. The product is very expensive, so some organizations can't afford to pay the total amount directly, meaning they often seek a partner or pay in installments, which increases the price more."
"The product is expensive."
"I am using a demo of Darktrace for deployment and testing which is free."
"It's an expensive solution."
"Wazuh is open-source, so I think it's an option for a small organization that cannot go for enterprise-grade solutions like Splunk."
"Wazuh is not an expensive solution."
"The product price is neither too high nor too low."
"The solution's pricing is very competitive."
"The solution's cost is above the average."
"Wazuh is an open-source tool, which means it is freely available for use."
"Wazuh is open-source, therefore it is free. You can purchase support for $1,000 a year."
"Wazuh is a good tool, but the open-source version has scalability limitations."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
838,640 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
Computer Software Company
16%
Comms Service Provider
8%
Government
7%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Wazuh?
Integrates with various open-source and paid products, allowing for flexibility in customization based on use cases.
What needs improvement with Wazuh?
I am investigating more about the community support for Wazuh. I can't provide a definitive answer yet. An issue I noticed is with tag values in certain rules not functioning properly. It's unclear...
What is your primary use case for Wazuh?
I am currently evaluating and using Wazuh for file monitoring and compliance reporting. We are in the process of conducting a POC to understand how the rules work. I lead this effort to explore and...
 

Comparisons

 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Information Not Available
Find out what your peers are saying about Darktrace vs. Wazuh and other solutions. Updated: January 2025.
838,640 professionals have used our research since 2012.