The primary use case for Darktrace is for tracking intruders and alerting for network threats.
CTO at CyberSecur, Lda
Get a comprehensive view of your network and whatever is happening inside it in real-time
Pros and Cons
- "It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
- "It is a stable solution without downtime."
- "The pricing model is a little too high and could be more flexible."
- "The interface and dashboards could be improved for ease-of-use."
What is our primary use case?
What is most valuable?
The most valuable feature in Darktrace is that it gives me a comprehensive, detailed view of my network and whatever is happening inside it. It is a very good tool for me that helps me to remain aware of security vulnerabilities. I know what is happening on my network in real-time and it responds quickly. It is really very useful.
What needs improvement?
I am just a manager and I do not really have a technical viewpoint. The tool really suits me perfectly for now for all my basic security needs and what I expect it to do. It does not need any major changes right now to do what I need it to do. It is not missing anything.
If I am thinking about improvement, everything can be improved somewhat. Maybe the interface and dashboards could be better. I would be glad if they could make these easier from the point of view of management. It could save some time.
The price is also a little high and could be more enticing.
For how long have I used the solution?
We have been using Darktrace for about two years.
Buyer's Guide
Darktrace
January 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
What do I think about the stability of the solution?
Darktrace is very stable. It provides 99.9% of our security needs and it does not have downtime. It is a very good, stable solution.
What do I think about the scalability of the solution?
We did not have the opportunity to test the scalability because our organization has not grown much over the period of time that we have been using the product. I think that scalability is built into the product, but for now, we have not experienced how scaling the product works firsthand.
What's my experience with pricing, setup cost, and licensing?
I am not so satisfied with the pricing model for Darktrace. The price is a little bit high compared to other solutions. The pricing model should be more flexible.
What other advice do I have?
On a scale from one to ten where one is the worst and ten is the best, I would rate Darktrace as an eight-out-of-ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Team Lead - Cyber Security & Compliance at Al Tuwairqi Group
Easy to deploy, stable, and scalable
Pros and Cons
- "The AI-based pattern is the most valuable feature."
- "There is a high ratio of false positive information."
What is our primary use case?
The solution is used as an anti-phishing tool.
What is most valuable?
The AI-based pattern is the most valuable feature. The AI monitors users' patterns in how they draft and send emails, so if there is a change in the pattern the email is flagged.
What needs improvement?
There is a high ratio of false positive information. For example, AI capabilities can sometimes make it difficult to distinguish between a legitimate email and a phishing email. This is one of the features that need to be manually sorted out and aligned. We need to improve this feature by putting DNS into the micro.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support team is good and they provide support on a priority level.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The cost is moderate.
What other advice do I have?
I give the solution an eight out of ten.
Our organization chose Darktrace because of its phishing capabilities.
Darktrace is the best way to secure a gateway and I recommend the solution to others.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Darktrace
January 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Cyber Security Engineer at Natica IT Consulting at Natica IT Consulting
A user-friendly cyber defense solution with useful dashboards
Pros and Cons
- "I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good."
- "It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
What is our primary use case?
Our customers use Darktrace to monitor network traffic.
What is most valuable?
I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good.
What needs improvement?
It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper.
What do I think about the stability of the solution?
Darktrace is relatively stable.
What do I think about the scalability of the solution?
Darktrace is scalable. It's very good. We have two big banks in Turkey using this solution.
How was the initial setup?
The initial setup is straightforward. It takes me about half an hour to deploy this solution.
What about the implementation team?
We implement this solution.
What's my experience with pricing, setup cost, and licensing?
Darktrace is expensive. You can pay for the license yearly.
What other advice do I have?
I would recommend this solution to potential users. But the cloud solution is challenging to use in Turkey.
On a scale from one to ten, I would give Darktrace an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Customer Solution Manager at a tech services company with 51-200 employees
Beneficial artificial intelligence module, high quality support, and powerful
Pros and Cons
- "The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network."
- "The module can improve so that every time it's more intelligent."
What is our primary use case?
Darktrace just scans the entire network and documentation. We then automatically evaluate which behaviors are normal and which are not normal. You can determine what possible risks are in the network.
What is most valuable?
The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network.
You don't need a human operator to be involved. The tool can operate by itself... By itself. That's the best and the most important feature because that reduces the amount of time that a person needs to spend on the tool.
The solution is powerful and very useful, it has the ability to avert many attacks.
The tool does almost 95 percent of the work and you only need to run some features to obtain reports.
What needs improvement?
The module can improve so that every time it's more intelligent.
For how long have I used the solution?
I have been using Darktrace for approximately three years.
What do I think about the stability of the solution?
The stability of Darktrace is good.
What do I think about the scalability of the solution?
Darktrace is a scalable solution.
How are customer service and support?
The support from Darktrace is very good, it is perfect.
How was the initial setup?
Darktrace is installed in an appliance and that appliance is installed in the network.
What about the implementation team?
We have one engineer that does the maintenance of Darktrace. They do the implementation and scanning of the network.
The solution does not require a lot of maintenance, it does most of the operations automatically.
We provide technical services.
What's my experience with pricing, setup cost, and licensing?
The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution.
The license is by device, if you have 1,000 devices, then the cost is going to be high.
What other advice do I have?
My advice to others is for them to try to determine what are their costs in security. Then they can determine the benefit of Darktrace. They need to first acknowledge what their costs are and then they can start pricing what solution would be best.
I rate Darktrace a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Team Lead Manager with 501-1,000 employees
Gives us visibility of rogue network traffic, prevents data exfiltration, good technical support
Pros and Cons
- "The most valuable feature is that it gives us visibility of rogue traffic that is on the network."
- "This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."
What is our primary use case?
We use Darktrace for security, and to give us better visibility.
How has it helped my organization?
If a user is exfiltrating data, normally we don't have the tools to detect it. With Darktrace, it detects this data. Also, if there is any command-and-control then this solution will highlight that.
What is most valuable?
The most valuable feature is that it gives us visibility of rogue traffic that is on the network.
The detection capabilities are good.
What needs improvement?
This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.
Integration with SOAR systems may be helpful, depending on the SOAR.
What do I think about the stability of the solution?
Stability-wise, Darktrace is very good. It runs in the background 24/7.
What do I think about the scalability of the solution?
The scalability is good because it covers our whole network.
We have 1,000 business and IT users and for our environment, the scalability is very good.
How are customer service and support?
The technical support is good. I would rate them an eight out of ten.
Which solution did I use previously and why did I switch?
We did not use another similar solution prior to Darktrace.
How was the initial setup?
The initial setup was very straightforward. It took approximately two months to complete the implementation and deployment.
What about the implementation team?
We used a consultant to assist us with the implementation.
One person is enough for the deployment and maintenance.
Which other solutions did I evaluate?
There may have been others that we looked at but this is the main one we evaluated.
What other advice do I have?
My advice for anybody who is looking into implementing Darktrace is to do a proof of concept first. Try to out because it's quite useful for providing visibility in the network.
Overall, this is a good product that seems to be working well.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Engineer at a real estate/law firm with 1,001-5,000 employees
Provides a higher level of threat detection, detects any type of attack, and very useful for an autonomous response
Pros and Cons
- "The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
- "They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there."
What is our primary use case?
We use it to protect IoT devices. Darktrace does network traffic analysis. So, by analyzing all traffic patterns in your environment, you can detect any type of anomalous activity, as far as the network is concerned.
I have been using its latest version. Its deployment depends on the environment. It can do sensors in the cloud, and it can also do on-prem.
How has it helped my organization?
It provided a higher level of threat detection.
What is most valuable?
The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response.
What needs improvement?
They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there.
For how long have I used the solution?
I used it for about a year.
What do I think about the stability of the solution?
It is a very stable product. We didn't have any issues.
What do I think about the scalability of the solution?
It has sensors that you can install. So, it can scale on-prem and off-prem in the cloud.
It is being used extensively. We have 2,000 employees. We use it to protect IoT devices. We also use it to protect Windows servers, desktops, and laptops. Its usage would increase if the net grows, but it's probably not going to grow too much bigger than 2,000 employees.
How are customer service and technical support?
The support from Darktrace is very helpful.
Which solution did I use previously and why did I switch?
We didn't use any other solution previously.
How was the initial setup?
It was pretty straightforward. You just monitor everything from your core switch. It monitors everything in and out.
We got it up in half an hour, but it still has to learn. You still have to give it some time to learn about the environment, and that's usually going to be at least two weeks.
What about the implementation team?
We brought in their guy to the site. In terms of maintenance, it is automatically set up to reach out to their website and pull down updates and stuff. We don't have to worry about that too much.
What's my experience with pricing, setup cost, and licensing?
It was $3,600 a month or $2,000 plus or so. I am not sure.
Its licensing is pretty simple.
Which other solutions did I evaluate?
We were thinking about getting another solution called Vector, but we didn't. We brought Darktrace in.
What other advice do I have?
Darktrace is a pretty good company. The only thing that they need to really work on is just being able to get rid of some of those false positives. Once the solution is tuned up, it pretty much just runs.
I would advise making sure that you do a really good PoC of the product so that you can be sure that it makes sense in your environment.
I would rate it a nine out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Group IT Manager at a manufacturing company with 1,001-5,000 employees
Advanced Cybersecurity Artificial Intelligence, plenty of features, and impressive threat detection
Pros and Cons
- "I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network."
- "In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from."
What is our primary use case?
Darktrace is used for cybersecurity, you can buy it as a physical appliance or solution as a service on the cloud. I tried the on-premises solution to detect any threat over our network.
How has it helped my organization?
Darktrace played an important role in the security detection strategy by reducing the time lost in detecting, analyzing, and incident resolving. This is due to its friendly user interface that shows you in simple graphs and analytics the output for any log over your network whether it is computer, device, switch, access point, etc...
What is most valuable?
I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network.
There is an included library of threat detections, not only locally, but threats being experienced all around the world. It is similar to a database of all the threats and what is done by cybersecurity administrators across the internet. By collecting events and information all around the world makes Darktrace more proactive in dealing with threat notifications and cybersecurity detection. The service is very comprehensive and can cover all security areas.
It has simple tracking capabilities and a graphical interface that can assist you with coding, you do not need to be a guru. The dashboards are user-friendly and you do not need an application to access your work, it is all done through any browser. Additionally, there is a mobile application that is one of the best features because you can see any threats from your phone. There is a playbook that can give you instructions. For example, if you see your network servers are being injected by ransomware you can stop the session and be notified of which person on what computer triggered the threat.
The solution is very professional. Everybody would like to have an application on their phone to be more proactive about security anywhere and this solution delivers.
What needs improvement?
In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from. Since it is collecting all scenarios that might happen from any threat, new playbooks may be discovered and customers will have the privilege to use them in their environment. Other than that, Darktrace is leading in every aspect.
For how long have I used the solution?
I have been using this solution for one month.
What do I think about the stability of the solution?
Very Stable
What do I think about the scalability of the solution?
We have a number of employees using the solution in my organization which includes administrators and management.
How are customer service and technical support?
Technical support is excellent. You can communicate with them by sending an email, WhatsApp messages, or other types of communication. They have their support in many places around the world so what ever your time zone is, they are available.
The support you do receive is excellent.
Which solution did I use previously and why did I switch?
I have used other solutions previously but non had this intelligence,
How was the initial setup?
The installation is very easy. I was shocked by the simplicity of the management, implementation, and dashboards.
What about the implementation team?
I have implemented it using Darktrace Team who were very professional.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is not cheap. It is not a one-time purchase, there is a subscription that needs to be paid every one to five years depending on your choice. It is expensive but you can reduce the price by only using the services that you want. There is some flexibility, for example, if you only want to have email inspections, network inspections, endpoint inspections, or brief analytics of the reports and controls over your infrastructure, can reduce the prices accordingly. Not choosing all the features can reduce the price. When comparing this solution to competitors in the market it is expensive. However, you are paying for a valuable solution with plenty of features. Their artificial and cyber intelligence is working extremely well. I am a consultant and work with a variety of solutions by myself, attend training, and understand people who are working with these solutions.
I need to know the advantage, disadvantages, weaknesses, and what makes the solution better than the others. Darktrace proves at some point that the value of money you are paying for the solution is reasonable for the advanced technology you are receiving as it covers many solutions that can cost much much more than darktrace where as i you bought Darktrace you reducing all the complexity to one simple solution.
Which other solutions did I evaluate?
I have evaluated many other solutions.
What other advice do I have?
My advice to those wanting to implement this solution is if they want to experience artificial intelligence, advanced cybersecurity, and high-level detection, this solution is the one.
I rate Darktrace a nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief ICT Officer at Barbados Public Workers Cooperative Credit Union Ltd
Helps us with network traffic visibility
Pros and Cons
- "I am impressed with the product's ability to give insights into network traffic."
- "I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint."
What is our primary use case?
The tool offers us visibility into network traffic.
How has it helped my organization?
The tool gives us alerts whenever an admin is trying to connect.
What is most valuable?
I am impressed with the product's ability to give insights into network traffic.
What needs improvement?
I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint.
For how long have I used the solution?
I am using the product since September.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The tool's deployment is easy.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is costly.
What other advice do I have?
I would rate the tool a nine out of ten. You need to use the tool on a trial basis so that you can get comfortable with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Extended Detection and Response (XDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Network Detection and Response (NDR) AI-Powered Chatbots Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Wazuh
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Vectra AI
Trend Vision One
Cynet
Rapid7 InsightIDR
Stellar Cyber Open XDR
NetWitness NDR
Adlumin Cybersecurity
Fidelis Elevate
LogRhythm UEBA
Secureworks Taegis XDR
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?