It has improved our monitoring capabilities.
Group CISO/CTO at Gulf Based Private Conglermate
Improved our monitoring capabilities and has a good graphical user interface
Pros and Cons
- "The most valuable feature is the alerts. The alerts are meaningful. The event rolls up into meaningful and actionable alerts rather than just being noise."
- "I would like for the product to work on the endpoints as well. I would like to see enhanced visibility into the endpoints and network but this solution only sits on the network itself."
How has it helped my organization?
What is most valuable?
The most valuable feature is the alerts. The alerts are meaningful. The event rolls up into meaningful and actionable alerts rather than just being noise.
What needs improvement?
The products is designed to monitor traffic sent and received via the corporate egress /network points.
I would be interested to see further integration or development of a capability to obtain visibility of mobile devices such as Laptops and Mobiles, which operate outside of the network and may communicate specifically when off the corporate network.
For how long have I used the solution?
We have done pilots with this solution and have used it for around three months.
Buyer's Guide
Darktrace
April 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,253 professionals have used our research since 2012.
What do I think about the stability of the solution?
The stability isn't good but I like the product. It's a good product but we need to look into other similar products that operate in the same zone: user behavior analysis and user detection. We need it to be good in comparison.
What do I think about the scalability of the solution?
We currently have an inner network. We don't have a full-scale deployment. It is on network segment where there are around 5,000 users. The full company would be around 9,000 users if we deployed it across all the subsidiaries.
How are customer service and support?
Their technical support is good.
Which solution did I use previously and why did I switch?
This is the first solution of this type that we've used. During the initial three month trial, we saw a lot of stuff from the product that we were unable to see through the conventional tooling technologies that we had in place.
How was the initial setup?
The setup was straightforward. It was a matter of hours. It took around two to three hours.
What other advice do I have?
My advice to someone considering this solution is to install it, conduct a pilot, and see. You need to see how easy it is to implement and you need to add it to install. You need to see what kinds of results it provides and compare it to your existing tool kit. The product demonstrates its actual capabilities when it's actually working. It's difficult to comprehend what it can actually do but it does give you an added level of visibility.
It has good capabilities. I would rate it an eight out of ten.
Cross-correlation with the endpoint based activities would be useful, like the ability to look at the deep supervised learning engine of the artificial intelligence unit and being able to take input data from the endpoints in order to apply the rules. It works on supervised learning and rules but I would like to be able to do things on different feeds as well.
It has a very good graphical user interface. The ability to get a console on the mobile phone and being able to respond and do basic incident response capabilities remotely is also a good feature.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Co-Founder & Managing Director at a comms service provider with 1-10 employees
Used for detecting network-based threats like ransomware or illicit communications with external endpoints
Pros and Cons
- "A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time."
- "Darktrace could expand into EDR (endpoint detection and response) and combine it with its network detection."
What is our primary use case?
Darktrace is used for detecting network-based threats like ransomware in the early stage or illicit communications with external endpoints.
What is most valuable?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time. Data acquisition is the source rather than tapping the data downstream after some processing.
What needs improvement?
Darktrace could expand into EDR (endpoint detection and response) and combine it with its network detection. They could thereby have a more holistic knowledge of the system through network information or through visibility into the operating system of the endpoints.
For how long have I used the solution?
I have been working with Darktrace for four years.
What do I think about the stability of the solution?
Darktrace is a very stable solution.
What do I think about the scalability of the solution?
Darktrace is a very scalable solution. Our clients for Darktrace are enterprise customers.
How are customer service and support?
The solution’s technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The solution’s initial setup is very straightforward.
What about the implementation team?
The solution's deployment time depends on the complexity of the network. For some huge networks, you need to tap the right resources and measure the system to acquire all the required traffic. The deployment is very straightforward in smaller networks where you have to connect to only one switch.
What's my experience with pricing, setup cost, and licensing?
Darktrace is quite an expensive solution. Users need to pay a yearly licensing fee for the solution.
What other advice do I have?
Darktrace has improved our client's organization's threat detection and response capabilities. Darktrace has helped users intercept and stop ransomware attack attempts in the very early stage, within a couple of minutes of its detection Autonomous response is a very good and useful feature that differentiates Darktrace from other solutions.
One person can easily maintain the solution. Darktrace easily integrates with our client's IT infrastructure solutions, like Microsoft 365, CrowdStrike, and Palo Alto firewalls. Darktrace has impacted our clients' incident response time to be very quick.
Darktrace is an autonomous solution. Users have to ensure they present all the traffic to the tool so it can intercept threats and not have hidden spots in their networks.
Overall, I rate Darktrace a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
Buyer's Guide
Darktrace
April 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
848,253 professionals have used our research since 2012.
Network Security Engineer at Social Security Commission
Can be deployed in half a day and is scalable
Pros and Cons
- "I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it."
- "It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."
What is our primary use case?
We have a layered approach to our cyber security. We have unified threat management and use several solutions such as Kaspersky, FortiGate, and Mimecast. However, we felt that we needed something on top of all of these and decided to go with Darktrace. We only have one in-house IT security person and were looking for a solution like Darktrace that was more automated.
What is most valuable?
I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it.
What needs improvement?
It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time.
For how long have I used the solution?
We did a proof of concept with Darktrace for a year.
What do I think about the scalability of the solution?
It is a scalable solution.
How are customer service and support?
Darktrace's technical support staff were responsive. We did not have to wait long for feedback on anything.
How was the initial setup?
We were able to deploy it in half a day. One person can handle the maintenance of the solution.
What about the implementation team?
We implemented the solution with the help of Darktrace representatives.
What's my experience with pricing, setup cost, and licensing?
We had an issue with pricing initially and had to cancel some of the features of the projects to fit the budget. I would like to see pricing that is not broken up into parts so that we can buy the whole package once.
Darktrace is more expensive than an average solution, but it's functionality won't match that of an average solution.
What other advice do I have?
I would rate Darktrace at nine out of ten. It is a growing product that helps with an ever changing threat landscape. Traditional endpoint antivirus solutions will not be able to keep up.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Infrastructure Sup at Capital Development Services
Provides visibility into our infrastructure and helps in identifying most vulnerable devices
Pros and Cons
- "The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network."
- "They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity."
What is our primary use case?
We use it to understand our network and traffic. We are basically getting visibility into our infrastructure.
We are using its latest version. It has both deployments. There is one cloud, and there is one on-prem.
What is most valuable?
The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network.
With Antigena Email, you know from where most of your spam is coming and which country is spamming you a lot.
What needs improvement?
They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity.
For how long have I used the solution?
I have been using it for three months.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable. Currently, we have just two users of this solution, but it covers all the devices that we have.
How are customer service and support?
The customer success manager has been helpful. Their support is pretty good.
Which solution did I use previously and why did I switch?
We used Microsoft.
How was the initial setup?
It was straightforward. The installation took 30 minutes to an hour. We had training before doing the installation.
What about the implementation team?
We used a consultant. We have just two engineers who are doing the deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It is pretty expensive, but it is worth it. Its licensing is yearly.
What other advice do I have?
I would recommend it, but you just need to make sure that your organization is big enough. It's not worth it when the organization is small. I would recommend it for organizations with more than 5,000 devices on their network.
I would rate it an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
System Administrator at Finlays
Reasonably prices, stable, and straightforward to set up
Pros and Cons
- "The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us."
- "The solution could be easier to use."
What is our primary use case?
We are primarily using the solution for network monitoring as well as cybersecurity.
What is most valuable?
The ability to detect activity on the network is very useful to us. Even if it's not necessarily an illegal activity, if it is abnormal activity, it is able to detect it and notify us.
The solution is stable.
The product scales well within a network.
The initial setup is pretty simple.
The solution isn't too expensive.
What needs improvement?
The solution could be easier to use.
The user interface is a bit too detailed. They should work to pare it down and simplify it. They seemed to have designed it for an expert user and not a layman. If there are some system administrators who are not experts and they just want to just get sensors reports and escalate, it should be easier for them to do so.
For how long have I used the solution?
I've been using the solution for three years at this point.
What do I think about the stability of the solution?
The solution is very stable. As far as we've been using it, we've not had any major issues. It doesn't crash or freeze. There are no bugs or glitches. It's reliable.
What do I think about the scalability of the solution?
The solution is scalable within the network. If a company needs to expand it, it can do so.
For our particular office, we have around 100 users.
I cannot say if we will increase usage. We have many offices and decisions in relation to usage increases would come from our UK office.
How are customer service and technical support?
Technical support is great. They are very responsive and helpful. We are very satisfied with the level of support they provide to us.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. For cybersecurity, this is our first product. We were using the traditional endpoint protection as well, and we still do. For that, we use Sophos.
How was the initial setup?
The installation was straightforward, from what I understand. I didn't actually handle ht process. That was done by a consultant.
The deployment was fast. In less than an hour, everything was up and running.
I handle the maintenance myself.
What about the implementation team?
We had a consultant that assisted us with the implementation. They made the process very easy.
What's my experience with pricing, setup cost, and licensing?
We typically do yearly or three-year licensing, however, I can't speak to the exact costs or arrangements.
It's not too expensive. The price is good for what it offers.
What other advice do I have?
We're just a customer and an end-user.
Overall, I'd rate the solution at an eight out of ten. We've mostly been quite happy with the product.
I'd recommend it to other users and organizations.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CTO at CyberSecur, Lda
Get a comprehensive view of your network and whatever is happening inside it in real-time
Pros and Cons
- "It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
- "It is a stable solution without downtime."
- "The pricing model is a little too high and could be more flexible."
- "The interface and dashboards could be improved for ease-of-use."
What is our primary use case?
The primary use case for Darktrace is for tracking intruders and alerting for network threats.
What is most valuable?
The most valuable feature in Darktrace is that it gives me a comprehensive, detailed view of my network and whatever is happening inside it. It is a very good tool for me that helps me to remain aware of security vulnerabilities. I know what is happening on my network in real-time and it responds quickly. It is really very useful.
What needs improvement?
I am just a manager and I do not really have a technical viewpoint. The tool really suits me perfectly for now for all my basic security needs and what I expect it to do. It does not need any major changes right now to do what I need it to do. It is not missing anything.
If I am thinking about improvement, everything can be improved somewhat. Maybe the interface and dashboards could be better. I would be glad if they could make these easier from the point of view of management. It could save some time.
The price is also a little high and could be more enticing.
For how long have I used the solution?
We have been using Darktrace for about two years.
What do I think about the stability of the solution?
Darktrace is very stable. It provides 99.9% of our security needs and it does not have downtime. It is a very good, stable solution.
What do I think about the scalability of the solution?
We did not have the opportunity to test the scalability because our organization has not grown much over the period of time that we have been using the product. I think that scalability is built into the product, but for now, we have not experienced how scaling the product works firsthand.
What's my experience with pricing, setup cost, and licensing?
I am not so satisfied with the pricing model for Darktrace. The price is a little bit high compared to other solutions. The pricing model should be more flexible.
What other advice do I have?
On a scale from one to ten where one is the worst and ten is the best, I would rate Darktrace as an eight-out-of-ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Network Administrator at a healthcare company with 501-1,000 employees
Detailed interface and good granularity but too expensive
Pros and Cons
- "t was pretty as far as the granularity of what you were getting out of it."
- "The price point for the product was too high for what our possible use case could be."
What is our primary use case?
We're part of our regional hospital group in Northwestern Ontario. One of our group members was using the DarkTrace product suite. It was brought forward that other hospitals within the group may want to try it. A couple of us did a demo, which basically involved getting the appliance installed in our data center and routing all the traffic through it.
We basically had the product running for a company, however, it really didn't pop up or offered anything that we were not already aware of.
What is most valuable?
It has a very detailed interface - almost too detailed. It was pretty as far as the granularity of what you were getting out of it.
The solution is very detailed. It has lots of fancy graphics that don't necessarily lead to a good outcome regarding knowing what's going on.
What needs improvement?
The only problem with these kinds of demos is that unless something actually goes wrong or you have something in the data center already; you don't see any difference. However, no news is good news.
The price point for the product was too high for what our possible use case could be. The demo might have gone more favorably in their direction if something had actually occurred during the demo. However, nothing did, and management decided that it was not worth the very high price.
The interface didn't really give you a whole bunch of insight into actually what was going on.
They did have some AI that they claimed could tell if traffic was malicious or what the intent of the traffic was. We never got to see that actually do anything. They identified some traffic. They said it was malicious. However, it turns out it was a known traffic that we had occurring, and it wasn't malicious. So there were a few missteps that way.
The UI is too dark.
We ultimately didn't find any value in the product.
For how long have I used the solution?
We did a demo for two or three months. We did not use the solution for a very long time.
What do I think about the scalability of the solution?
In terms of scalability, you would need a separate device for every location. For our particular hospital, we actually have three or four main facilities, or what we would consider main facilities. You'd actually need to have a physical box for every deployment in order for traffic to be efficiently detected. They did say that we could route the traffic from the site through the box. However, essentially, that would be doubling the traffic load, which didn't really seem like it was a wise decision. As far as scalability, the box that we had was very capable of handling the traffic load that we were producing. I would say we are probably using maybe ten percent of it at the most at peak levels.
How are customer service and support?
We had some interactions with them during setup and during the demo. They were fine.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup depends on the network. We had a mature infrastructure which made it a bit more challenging.
It took us a few hours to set everything up and make sure it was capturing everything it needed to.
If you had a straightforward Cisco environment where you could easily forward traffic and CDP needed, it would be pretty easy.
What's my experience with pricing, setup cost, and licensing?
I'd rate the pricing two or three out of ten. It is pretty expensive. For us, it just wasn't worth it.
What other advice do I have?
We are customers and end-users.
I'd rate the solution five out of ten. It's an interesting maturing market. They do have potential, however, they do need to work a fair bit on their AI models and their interface.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Engineer at Natica IT Consulting at Natica IT Consulting
A user-friendly cyber defense solution with useful dashboards
Pros and Cons
- "I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good."
- "It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
What is our primary use case?
Our customers use Darktrace to monitor network traffic.
What is most valuable?
I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good.
What needs improvement?
It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper.
What do I think about the stability of the solution?
Darktrace is relatively stable.
What do I think about the scalability of the solution?
Darktrace is scalable. It's very good. We have two big banks in Turkey using this solution.
How was the initial setup?
The initial setup is straightforward. It takes me about half an hour to deploy this solution.
What about the implementation team?
We implement this solution.
What's my experience with pricing, setup cost, and licensing?
Darktrace is expensive. You can pay for the license yearly.
What other advice do I have?
I would recommend this solution to potential users. But the cloud solution is challenging to use in Turkey.
On a scale from one to ten, I would give Darktrace an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Extended Detection and Response (XDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Network Detection and Response (NDR) AI-Powered Chatbots Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Wazuh
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Trend Vision One
Vectra AI
Cynet
Rapid7 InsightIDR
Stellar Cyber Open XDR
Adlumin Cybersecurity
NetWitness NDR
Fidelis Elevate
LogRhythm UEBA
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?