Primarily we use the solution to spot problems that cannot be found by other solutions.
RSSI at SDIS49
A clever solution that spots problems that cannot be found by other solutions but it would benefit from having automation
Pros and Cons
- "The solution is stable. We've never had any problems with it."
- "The solution would benefit from automation. Currently, you have to know what you are searching for."
What is our primary use case?
How has it helped my organization?
Darktrace has improved our knowledge of abnormal phenomenen which could have potentially be hazardous for the organization.You have to be vigilant with GDPR compliance rules in Europe
What is most valuable?
The most valuable aspect of the solution is that you can see all the process mistakes. You can see all the different types of unusualcsituations that you usually don't see in a traffic solution.
What needs improvement?
The solution would benefit from automation. Currently, you have to know what you are searching for.
Buyer's Guide
Darktrace
February 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
For how long have I used the solution?
I've been using the solution for one month.
What do I think about the stability of the solution?
The solution is stable. We've never had any problems with it.
What do I think about the scalability of the solution?
The solution is scalable. So far, we have 12 networks done. We have about 500 users on it currently.
How are customer service and support?
I haven't had too much interaction with technical support. Technical support was in France but the experts were in England. It's good generally, but we haven't used the solution for too long.
Which solution did I use previously and why did I switch?
We didn't previously use a different solution.
How was the initial setup?
When you have an expert, the initial setup is easy, but if you do it on your own, it could be complex. Deployment takes at least a month.
Which other solutions did I evaluate?
We didn't evaluate another solution. We met the solution's team in Cannes for an IT meeting and decided to pursue discussions with implementation.
What other advice do I have?
We use the on-premises deployment model.
It's a quite clever solution. It has a lot of potential, but I'd advise those considering to hold off implementing the solution until after a newer version is released.
I'd rate the solution seven out of ten. If they added automation and included it in the price, I'd rate it higher.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Information Security Analyst at INFRATEL CORPORATION ZAMBIA LIMITED
Efficient behaviour analytics features and offers high stability
Pros and Cons
- "One thing I appreciate is Antigena Email, which is for email protection."
- "One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent."
What is our primary use case?
Our primary use case is incident response.
How has it helped my organization?
One thing I appreciate is Antigena Email, which is for email protection.
What is most valuable?
One of the most valuable features is Behavior analytics.
What needs improvement?
One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent.
For example, if a user is sent an unauthorized file via SMB, Darktrace would only flag that SMB traffic occurred between the two users. It wouldn't be able to tell us which file was sent, so we would have to manually investigate the incident to determine what happened.
It would be helpful if Darktrace could flag the specific file that was being transferred in SMB traffic incidents. This would make it much easier to investigate these incidents and take appropriate action.
In future releases, I would like to see more playbooks.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
I would rate the stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. There are five end users in our analyst team.
How are customer service and support?
The customer service and support are really good. That's one of the things that I've come to appreciate about Darktrace.
Any concern that you give to them, they come on board and arrange a meeting where you could possibly do some practical work with them. They would take on the incident, and they would say, "Okay. Let's set this incident together."
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used Sophos. We chose Darktrace because of its reliability. Unlike other solutions that rely heavily on signature-based logins, Darktrace operates by learning the behavior of individual users. This means that what may seem normal to me could be considered abnormal for someone else, and Darktrace can effectively block such anomalies. This feature has proven to be immensely helpful.
How was the initial setup?
The initial setup is very easy. I would rate my experience with the initial setup a ten out of ten, where one is difficult and ten is easy to set up.
It took around an hour to set up.
What about the implementation team?
The deployment process is pretty self-sufficient. It handles network closure and device discovery.
One person is sufficient for the deployment process.
What's my experience with pricing, setup cost, and licensing?
The solution is quite expensive. I would rate the licensing model an eight out of ten.
What other advice do I have?
I would recommend it based on its excellent behavior analytics and AI implementation.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Darktrace
February 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
Manager, Information Security at a manufacturing company with 1,001-5,000 employees
A hybrid quality solution for email, network and cloud security
What is our primary use case?
We use the solution for email, network and cloud security.
What is most valuable?
The network security and AR response are the main things.
What needs improvement?
The product is expensive, but it is a very good product. The user interface is also good.
For how long have I used the solution?
I have been using Darktrace for two years.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
The solution’s scalability is pretty straightforward. We’ve around 3500 users using this solution.
I rate the solution’s scalability an eight out of ten.
How are customer service and support?
I contact technical support on occasion and ask questions, and they are responsive. I can get them on call or email. I’m very happy with the support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was quick and painless.
What's my experience with pricing, setup cost, and licensing?
The product is very expensive.
What other advice do I have?
The product is expensive, but it is a quality product. If you look apart from the cost, it's a good product followed by very good support. If you're willing to spend the money, it is worth consideration.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at VERINET
Provides great network protection, is innovative and flexible
Pros and Cons
- "Provides great network protection."
- "Needs to improve its collaboration with local partners."
What is our primary use case?
We are a consulting company and sell Darktrace to our customers. Our company is in West Africa. I'm the company CEO.
What is most valuable?
Darktrace can observe networks and respond to those observations. It provides great network protection, is innovative and flexible.
What needs improvement?
I think Darktrace needs to improve its collaboration with local partners. That would include training and improving the technical skills of vendors. Desktop and mobile device protection could also be improved.
For how long have I used the solution?
We've been selling this solution for two years.
What do I think about the stability of the solution?
The solution is stable.
How are customer service and support?
Our customers report that the technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is reasonably straightforward although the process requires some preparation beforehand. The size of deployment varies greatly, we've deployed in companies ranging in size from 200 up to 5,000 users.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are expensive, although I think the high cost is partly a currency issue because we're based in West Africa.
What other advice do I have?
I rate this solution eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Information Technology Support Engineer at CCTZ
Secure, beneficial unusual email detection, and high availability
Pros and Cons
- "The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
- "Darktrace could improve its features, such as monitoring and detecting ransomware."
What is our primary use case?
Darktrace is used for network security.
How has it helped my organization?
Darktrace has helped our organization be secure from network spam and attacks.
What is most valuable?
The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network.
What needs improvement?
Darktrace could improve its features, such as monitoring and detecting ransomware.
For how long have I used the solution?
I have been using Darktrace for approximately three months.
What do I think about the stability of the solution?
Darktrace is a stable solution.
What do I think about the scalability of the solution?
The scalability of Darktrace is good.
We have four companies that are using this solution.
How are customer service and support?
I have not used the support from Darktrace.
How was the initial setup?
The initial setup of Darktrace was simple. The deployment of Darktrace took approximately two weeks.
What's my experience with pricing, setup cost, and licensing?
I am using a demo of Darktrace for deployment and testing which is free.
Which other solutions did I evaluate?
My company chose Darktrace because it helped other companies that needed some help with metrics monitoring and spam monitoring.
What other advice do I have?
I would recommend this solution to others.
I rate Darktrace a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Network Security Engineer at Social Security Commission
Antigena feature offers immediate and helpful response
Pros and Cons
- "I like the Antigena feature in Darktrace, as it offers immediate response and is helpful."
- "The interface is too mathematical and it should be simplified."
What is our primary use case?
Darktrace makes up part of our security solution and it is able to operate without intervention from IT staff. Antigena feature for automatic response is awesome.
How has it helped my organization?
You can have a one-person IT team and with Darktrace, you can get notification of potential threats that are incoming or are already happening on the network.
What is most valuable?
I like the Antigena feature in Darktrace, as it offers immediate response and is helpful.
This product collects more data than your traditional type of software, which is useful for us.
Darktrace picks up anomalies as soon as they arise.
What needs improvement?
The interface is too mathematical and it should be simplified. If you are a seasoned user then you would know where to go, but you have to learn it first. The terminologies being used are mostly numbers. In general, it could be more user-friendly. The GUI can be more simplified and the sections on the interface can be better organised. Usability and visibility of features can improve the skills of administrators and the product will be a preferred solution and ratings will increase.
For how long have I used the solution?
My experience with Darktrace is short because we are just implementing it now.
What do I think about the stability of the solution?
The stability of Darktrace is fine.
What do I think about the scalability of the solution?
We do not intend to scale. Scalability is more of a contract issue that comes into play if you want to add nodes to the system. We are opting for a specific number of nodes or endpoints, which we would be able to keep for quite a number of years. I don't expect that we will expand that much, so scalability should not be an issue.
How are customer service and support?
We have been in contact with technical support using different platforms. We have dealt with them using Microsoft Teams, Zoom, WhatsApp and via email.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
No
How was the initial setup?
The initial setup was quite simple and straightforward, taking about an hour to complete. After that, the port modeling took perhaps an hour or two.
What about the implementation team?
Vendor Team
What's my experience with pricing, setup cost, and licensing?
If you consider the features and the cost of market leaders, we are satisfied with the pricing.
Which other solutions did I evaluate?
Snode
What other advice do I have?
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Security at DFCC
Stable security solution that offers behavioral analytics for the monitoring of traffic
Pros and Cons
- "The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic."
- "The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
What is our primary use case?
We are a financial Institute and make use of the IDS solution. We have the SIM called QRadar. We analyze all the traffic clouds with Darktrace and SIM.
What is most valuable?
The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic.
What needs improvement?
Sometimes the solution gives some false positives which could be improved. The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
The technical support is very good but we would like to get some information from APAC because we are in APAC region.
Which solution did I use previously and why did I switch?
We considered McAfee and other solutions but based on budget and features, we decided to go with Darktrace.
How was the initial setup?
The initial setup is straightforward and so is the maintenance.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Operations & Information Officer at MineWorkers Provident Fund
Delivers as expected, provides good analytics around the real-time monitoring of our network, and has good reporting and reporting period
Pros and Cons
- "I particularly like Antigena and the analytics around the real-time monitoring of our network. I also like its reporting because it has got a seven-day reporting period within the system. Every time you run the reports, it gives you the data about the previous seven days. I like that because it is in real-time. I enjoy reading those reports and getting a very clear and decisive idea of what's happening on my network on a real-time basis. I like the actual real-time monitoring of spoofing and things like that. I also like the user monitoring as well as the network logging capabilities."
- "One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network."
What is our primary use case?
We have Antigena on the email, and we also use the network monitoring capabilities. We are using the latest version of the Antigena Email and AI analytics platform.
What is most valuable?
I particularly like Antigena and the analytics around the real-time monitoring of our network. I also like its reporting because it has got a seven-day reporting period within the system. Every time you run the reports, it gives you the data about the previous seven days. I like that because it is in real-time. I enjoy reading those reports and getting a very clear and decisive idea of what's happening on my network on a real-time basis. I like the actual real-time monitoring of spoofing and things like that. I also like the user monitoring as well as the network logging capabilities.
What needs improvement?
One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network.
For how long have I used the solution?
We have been using Darktrace for two years.
How are customer service and technical support?
There were a couple of times when we needed some of the expertise, and the guys were not available at the time when we needed them. Subsequently, they've managed to improve.
What other advice do I have?
In terms of our organization, we are a massive IT organization or financial services company. We've got a very small ITP, but we've got a lot of data. We are not sure about Darktrace in terms of its capacity to deal with huge data, but it is probably too early for me to give some sort of indication of what is not big.
At the moment, they are delivering on the set objective in terms of what I want to achieve as a CIO, and I'm quite happy with some of the deliverables that are coming through at the moment. In terms of what our requirements were and what we expect in terms of what we want them to deliver, they have delivered. Within the next two to three years, I would probably be able to provide a different perspective after we've matured within the Darktrace environment. At the moment, they've delivered the actual scope of work. There is nothing really that they're not delivering on as promised. So, at the moment, I'm quite happy with where we are.
I would rate Darktrace a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Product Categories
Extended Detection and Response (XDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Network Detection and Response (NDR) AI-Powered Chatbots Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity PlatformsPopular Comparisons
CrowdStrike Falcon
Wazuh
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Trend Vision One
Vectra AI
Cynet
Rapid7 InsightIDR
Stellar Cyber Open XDR
NetWitness NDR
Adlumin Cybersecurity
Fidelis Elevate
LogRhythm UEBA
Secureworks Taegis XDR
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?