Try our new research platform with insights from 80,000+ expert users
Seguridad de la Información at Banco Davivienda (Costa Rica) S.A.
Real User
Allows us to monitor our network 24/7 without a lot of analysts
Pros and Cons
  • "The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7."
  • "I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there."

What is our primary use case?

Darktrace is deployed on our LAN, inside the network. No site, no internet, it's just for monitoring the LAN, local access network. It helps us to find a lot of threats inside the network. We are very happy with the solution. You don't need to have a lot of analysts with Darktrace who are making or following the incident. This solution helps you to send the notification and avoid threats.

What is most valuable?

The main valuable feature is that we don't need a lot of analysts. With few analysts, we have all the network monitored, 24/7.

What needs improvement?

Firstly, the integration should be improved. 

In terms of what additional features I would like included in the next release of Darktrace, I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there.

For how long have I used the solution?

We have been using Darktrace for three years.

Buyer's Guide
Darktrace
February 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.

What do I think about the stability of the solution?

In terms of stability, Darktrace is an excellent product.

What do I think about the scalability of the solution?

Darktrace's scalability is very good. We have about 1,200 users on it currently.

How are customer service and support?

Their technical support is excellent.

Which solution did I use previously and why did I switch?

We have more than an SOC, a security operation center, so we switched to Darktrace because they use artificial intelligence and they are more sophisticated in preventing threats.

How was the initial setup?

The initial setup is straight forward. Deployment took one day.

What about the implementation team?

We implemented with a consultant. It required two people.

What was our ROI?

Our ROI as a result of Darktrace is excellent. The return of the cost of the solution for preventing threats is very good.

What's my experience with pricing, setup cost, and licensing?

Darktrace is expensive, but its results are invaluable.

What other advice do I have?

Because of all it does, Darktrace is a very good solution, and it doesn't take a lot of time to implement and to get results. You can learn the behavior of the network and take actions, not based in signatures. I think this is very, very good.

On a scale of one to ten, I would give Darktrace a nine.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head of Cybersecurity Business Unit at S2E
Real User
Provides a visual representation of attack history, with a nice GUI, but the analysis could be simplified
Pros and Cons
  • "I find it very good in the way that they show the past events, including the attack history."
  • "It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening."

What is our primary use case?

We are a system integrator and we pose solutions, including this one, to our clients.

It is mainly used to reinforce response capabilities with respect to network security.

What is most valuable?

I find it very good in the way that they show the past events, including the attack history. You are able to visualize all of the attack paths and connectivity to see what's happened.

The GUI interface is very good.

They are using the best machine learning and AI at the moment.

What needs improvement?

The need to simplify the analysis from a user perspective. In a few cases, you have to be a specialist in order to understand what's happening. It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening.

For how long have I used the solution?

I was been working with Darktrace for two years.

What do I think about the stability of the solution?

Stability-wise, we have not had any issues and it has been quite good.

What do I think about the scalability of the solution?

We haven't had any trouble with scalability.

How are customer service and technical support?

We have had contact with technical support and help was quite straightforward. Our feedback for them is good.

Which solution did I use previously and why did I switch?

We work with a variety of products in the security space including Darktrace, Splunk, Elastic, and others.

How was the initial setup?

The initial setup is really simple. This product is normally deployed as an on-premises appliance and it normally takes less than one day. It depends on how complex the network is, but it's usually quite simple.

What's my experience with pricing, setup cost, and licensing?

Our customers feel that the price of Darktrace is quite high compared to other solutions. However, I feel that they are one of the top solutions in this space and they want to be paid for that.

What other advice do I have?

They are currently working on improving their interface by including AI to help simplify things, but it does not work on real-time data. Rather, it works on historical events.

This is definitely a product that I can recommend, although I would probably be using it together with a SOC service or somebody else who can manage it properly.

I would rate this solution a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Darktrace
February 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
832,138 professionals have used our research since 2012.
reviewer1248177 - PeerSpot reviewer
Application & Security Specialist at a financial services firm with 1,001-5,000 employees
Real User
Easy to use with an intuitive dashboard, powerful AI, and inbuilt data packet analysis
Pros and Cons
  • "The Dynamic Threat Dashboard is very nice, as it lists all of your threats and rates them, and then you can choose whether to investigate further."
  • "This is quite an expensive product so the pricing is something that can be improved."

What is most valuable?

Once installed, it starts picking up and learning the network very well because it's got a powerful AI integrated into it.

The user interface is very intuitive.

The Dynamic Threat Dashboard is very nice, as it lists all of your threats and rates them, and then you can choose whether to investigate further.

This solution has some good features for customization in terms of how you're tagging your network, which basically makes it easier to identify what is actually happening. You can see where the traffic is going, where it is coming from, and that sort of thing.

Darktrace has quite a few inbuilt features such as its own packet analysis module, which is an offshoot of Wireshark.

This solution has some powerful APIs, although we do not use that functionality at the moment.

What needs improvement?

This is quite an expensive product so the pricing is something that can be improved.

For how long have I used the solution?

I have been using Darktrace for between two and three years.

What do I think about the stability of the solution?

We've seen no major problems between the master and slave devices in our architecture.

What do I think about the scalability of the solution?

Darktrace is definitely scalable. We started off with a single device monitoring a single site and we progressively added more sites with different devices in a master/slave architecture. The more we've added, we've had to re-think a little bit, but overall the scalability is excellent.

We have ten security analysts who are using this solution.

How are customer service and technical support?

The Darktrace technical support is very good.

Which solution did I use previously and why did I switch?

We started off with Darktrace. It was based on a decision from somebody in the business who had previously used it.

Personally, I have used a few other solutions and with respect to the interface, you probably couldn't get more intuitive than Darktrace.

How was the initial setup?

Darktrace is very easy to set up. Even our basic technical people are able to do it. It's almost like plug and play. There is some basic configuration to do, but it's nothing major.

I would say that most technical people can do the majority of the setup.

What about the implementation team?

We were granted access to all of the documentation and information from Darktrace, so we did the implementation ourselves. There may have been one or two areas that we had to go back to Darktrace directly to get clarification on, but there was no third-party partner or reseller involved.

What other advice do I have?

We're very pleased with Darktrace so it is a bit difficult to pinpoint areas for improvement. It covers all of our needs and from what I can see, it does the basics very well. There are many advanced features, also.

This is a solution that I definitely recommend. It offers a proof of value rather than a proof of concept, where they run the tool in your network, let it learn and then catch any vulnerabilities. Then you will actually see the value of the solution, either potentially blocking any exploitive threats or not, but its a really good thing to go through. To do this, I think that you have to go through an actual partner unless you're in a location where Darktrace has a physical office. In any event, I strongly recommend going through the proof of value to see if you like it. If there is a charge then it is definitely worth it.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1762473 - PeerSpot reviewer
ICT Coordinator at a tech services company with 51-200 employees
Real User
A smart, autonomous solution that monitors and identifies threats based on abnormal patterns and proactively blocks them
Pros and Cons
  • "It is autonomous. So, it learns. It uses algorithms and AI to learn the common behavioral patterns on the network, and it is able to identify threats based on abnormal patterns."
  • "It is expensive, but everything else has been great so far."

What is our primary use case?

We have a Darktrace appliance, and we are using it to monitor threats in our network environment. It has the Antigena module installed. So, it does not only monitor but also proactively blocks when there is a physical threat.

It scans the entire network, which includes all IP addresses, subnets, and users. It is very smart for all different segments of the network.

What is most valuable?

It is autonomous. So, it learns. It uses algorithms and AI to learn the common behavioral patterns on the network, and it is able to identify threats based on abnormal patterns.

What needs improvement?

It is expensive, but everything else has been great so far. It is fine for now for what we need it to do.

For how long have I used the solution?

I have been using this solution for about a year and a half.

How are customer service and support?

Their support has been great so far.

How was the initial setup?

It was very easy and straightforward.

What's my experience with pricing, setup cost, and licensing?

It is expensive.

What other advice do I have?

It is good. Recently, they have made it more sensitive for tracking or identifying all the behaviors or patterns. So, you're getting more alerts out of it, which I guess is a good thing.

I would rate it a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1556535 - PeerSpot reviewer
System Architect at a energy/utilities company with 51-200 employees
Real User
Stable with helpful technical support and good network visibility
Pros and Cons
  • "The product offers us a very good user interface and we've found the network visibility to be very good so far."
  • "It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not."

What is most valuable?

Overall, I like the system. The product offers us a very good user interface and we've found the network visibility to be very good so far. The solution has one window and shows all networks.

The solution comes in multiple languages, including English and Arab options.

The solution is stable.

We've found that technical support is helpful and available to assist us if we need them.

What needs improvement?

There are some automation capabilities, however, they could be presented better.

The manual is difficult to follow. While it presents some use cases, it's not very clear. There may also be some language barriers, as it's not available in my language.

Some aspects of the initial setup are complex. 

It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not. 

The cost of the solution is quite high.

I'm very interested in ISO 27001 and these processes. I'd like to better understand how it supports this kind of workflow.

For how long have I used the solution?

I haven't used the solution for very long. It may only be about 20 hours or so. It's very, very new. 

What do I think about the stability of the solution?

The solution is mostly stable. I found that, during the POC, sometimes my rights would do off and I would have to reinstate them, however, other than that, it was very stable. The performance was good. 

What do I think about the scalability of the solution?

I've only used the solution for a short amount of time. I can't really speak to the scalability. There were different models that I tried, however, I can't speak about how different models affect the scalability. I've only used it for a very short amount of time.

There are maybe three or four people on the solution, now that we've tested it. 

How are customer service and technical support?

I haven't really interacted so much with technical support, however, there is a person available to us that could help us troubleshoot or answer our questions if we need assistance. 

How was the initial setup?

There are aspects of the initial setup that are not very straightforward. there is some complexity. I needed to keep going back to the manual to check things at certain points. 

What's my experience with pricing, setup cost, and licensing?

We are still currently in the test period. Within the year, we will have to invest in the cost of licensing. We have not done that yet.

The solution itself is quite expensive. 

Which other solutions did I evaluate?

We did look at other solutions, however, I can't speak to which solutions we actually looked at.

What other advice do I have?

We are a partner.

I'm not sure which version of the solution we're using. My understanding is that it is version 5.

I would recommend the solution to others. However, it's important to ensure you use the solution in order to set up your processes correctly and to the benefit of the organization.

So far, I would rate the solution at an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Head of Strategic Business Development at Grove
Reseller
Simple to set up with a useful antigena and threat visualizer
Pros and Cons
  • "It's a very stable product."
  • "In the next version, I'd like to see penetration testing."

What is our primary use case?

We primarily use this solution as part of our security.

What is most valuable?

The cyber AI analyst, antigena, and threat visualizer are the most valuable aspects of the solution.

The setup is very simple. 

It's a very stable product.

Users can expand it as needed. 

What needs improvement?

I don't have any thoughts on where there might be a need for improvement. 

In the next version, I'd like to see penetration testing. They already have that coming up, so it'll be good to see that.

For how long have I used the solution?

I've been dealing with the solution for three to four years. 

What do I think about the stability of the solution?

The product is extremely stable and mature. There are no bugs or glitches. It doesn't crash or freeze.

What do I think about the scalability of the solution?

The product is very scalable across all vectors of the digital estate.

How was the initial setup?

The initial implementation process is extremely easy. It's extremely seamless and very easy to set up. It's up and running in less than an hour.

What other advice do I have?

I'm a partner and reseller.

We are using the latest version of the solution. 

It's deployed on-premise, in the cloud, in email, via SaaS, and on the endpoint.

I'd advise potential new users to  use antigena. It's a handy tool to stop cyber attacks.

I'd rate the solution ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
reviewer1468230 - PeerSpot reviewer
Founder and CEO at a tech services company with 51-200 employees
Reseller
Detects and blocks attacks automatically, and has excellent support
Pros and Cons
  • "The most valuable feature of this solution is that it does not require human intervention to eliminate a threat."
  • "The user interface and the configuration are a bit complex and should be improved or simplified."

What is our primary use case?

We are using this solution for both the detection and elimination of attacks.

What is most valuable?

The most valuable feature of this solution is that it does not require human intervention to eliminate a threat. It blocks everything automatically.

What needs improvement?

The user interface and the configuration are a bit complex and should be improved or simplified. 

It's user-friendly, but it could be easier.

The pricing could be better and the scalability should be simplified for the customers.

The integration could be better, as it's not that interactive. They could make it more interactive for the customer's daily use.

For how long have I used the solution?

I have been using Darktrace for three years.

What do I think about the stability of the solution?

It's a very stable solution. We are very satisfied with stability.

What do I think about the scalability of the solution?

It's a scalable solution, but it's not very easy to scale. When using a detection environment, it's not very easy for the customer.

How are customer service and technical support?

Technical support is very good. They are excellent.

Which solution did I use previously and why did I switch?

Previously, we had completed some trials with IronNet.

How was the initial setup?

The initial setup is straightforward.

What's my experience with pricing, setup cost, and licensing?

It could be cheaper.

When it comes to large installations, it can be expensive, but for small accounts it's fine.

What other advice do I have?

We are resellers and integrators of Darktrace.

I would rate Darktrace a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
PeerSpot user
Philippe Panardie - PeerSpot reviewer
Philippe PanardieRSSI at SDIS49
Top 10Real User

A real interesting solution, with tremendous efficiency, especially for special accounts and VIP. The cost is quite a bit expensive.

it_user1051182 - PeerSpot reviewer
Product Owner - Cyber Security at a healthcare company with 10,001+ employees
Real User
Helps us to find a few anomalies but I would like to see supervised machines in the next version
Pros and Cons
  • "Darktrace is extremely stable."
  • "Darktrace does not have any capabilities to configure."

What is our primary use case?

Our primary use case of this solution is to monitor lateral traffic.

How has it helped my organization?

The solution helped us to find a few anomalies.

What needs improvement?

Darktrace does not have any capabilities to configure. So I would like to see supervised machines and capabilities in the next version.

For how long have I used the solution?

I have been using the latest version of Darktrace for about three months.

What do I think about the stability of the solution?

Darktrace is extremely stable.

What do I think about the scalability of the solution?

We are only four users on Darktrace currently, and I believe it is scalable.

How are customer service and technical support?

I am satisfied with the technical support we received. 

How was the initial setup?

The initial setup was very straightforward because, in fact, there was nothing to configure. You just plug in the box and search for kickbacks. Deployment took about a day and it was done by one of Darktrace's consultants.

Which other solutions did I evaluate?

I worked on another solution before but we decided to test out Darktrace so that we could compare them.

What other advice do I have?

Darktrace is a good product and it can be implemented on premises. Someone who wants to take care of the lateral movement and configure it, will love what it offers. I rate this solution a seven out of ten. I would like to see supervised machine running in the future.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.