


NetWitness NDR and Tines are leading products in network detection and response and automation respectively. Tines is preferred due to higher user satisfaction with its feature adaptability and user-friendly deployment, despite NetWitness NDR's strong threat detection.
Features: NetWitness NDR offers advanced threat detection, detailed analytics, and seamless integration with existing security setups. Tines provides customizable workflows, efficient automation capabilities, and streamlined incident management.
Room for Improvement: NetWitness NDR has a steep learning curve, needs better documentation, and enhanced user support. Tines can improve its integration with certain third-party tools, refine its user interface, and expand its automation templates.
Ease of Deployment and Customer Service: NetWitness NDR's deployment process is complex and often requires extensive support. Tines has an intuitive deployment process with quick setup and responsive customer support.
Pricing and ROI: NetWitness NDR has higher initial setup costs but offers strong ROI through robust security features. Tines has a flexible pricing model, providing value through automation efficiencies and reduced manual effort.
| Product | Market Share (%) |
|---|---|
| Torq | 4.9% |
| Tines | 6.2% |
| NetWitness NDR | 1.2% |
| Other | 87.7% |


| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness NDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.
Tines offers no-code and low-code automation for users to automate tasks without coding expertise, integrating seamlessly with APIs to enhance incident management and security operations.
Known for a vendor-neutral approach, Tines provides detailed documentation and live chat support, allowing for effective integration with other tools, scheduling capabilities, and streamlined processes that save time and effort. Users find it intuitive for efficient task handling, making manual intervention unnecessary. Challenges include the need for more comprehensive documentation and instructional videos, as well as improvements in AI integration and reporting aesthetics. Pricing is also noted as higher compared to alternatives.
What are the most important features of Tines?Tines primarily serves organizations in the security sector, automating security operations such as alert detection and managed detection and response. It's utilized extensively in security operation centers for tasks like phishing email processing, ticket creation, IOC investigations, and ticket assignments within enterprise security frameworks, with multiple teams delivering Tines services to enhance task handling efficiency.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.