Listing Thumbnail

    Vectra AI Platform

     Info
    Sold by: Vectra AI 
    Deployed on AWS
    For security leaders, builders, and operators, who are tasked with protecting a complex, ever-changing environment from attack, Vectra AI protects modern networks from modern attacks. When modern attackers beat customers' existing controls - and they will, Vectra AI sees their every move, connects the dots, prioritizes and stops the attack in real-time. Our customers say we are the cybersecurity AI that stops attacks others can't.

    Overview

    Play video

    Vectra AI Platform capabilities:

    • Coverage: AI Detections that expose attackers' every move across network, identity, cloud - reducing attack exposure by 52%. The Vectra AI Platform covers data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, Microsoft 365, and Microsoft Copilot for 365.
    • Clarity: AI Agents that automatically triage, stitch, and prioritize attacks in real time - removing 99% of alert noise, and up to 50% of time spent on manual tasks.
    • Control: Respond UX to discover, hunt, detect, investigate, stop and report improving security team efficiency and effectiveness by 40%.
      o Discover where attackers can attack across network, identity and cloud to stop attacks before they start.
      o Hunt down attackers by seeing malicious threat activity across network, identity and cloud in one view.
      o Investigate instantly with an aggregated, contextualized view of attack progression in one window.
      o Respond confidently in minutes with automated and manual lockdown of infected hosts and devices.
      o Report on attack exposure, posture, operational efficiency and effectiveness.

    Vectra AI Platform modules:

    • Vectra AI for Network - NDR
    • Vectra AI for Cloud - AWS
    • Vectra AI for Cloud - Azure
    • Vectra AI for Cloud - M365
    • Vectra AI for Identity - Microsoft Active Directory
    • Vectra AI for Identity - Microsoft Entra ID
    • Vectra AI Investigations - Metadata retention 14-day
    • Vectra AI Investigations - Metadata retention 30-day
    • Vectra Managed Detection and Response (MDR)
    • Vectra Managed Extended Detection and Response (MXDR) - includes endpoint management

    Vectra AI Platform packages:

    • Vectra AI Platform Standard: Network, Identity, Cloud
    • Vectra AI Platform Complete: Network, Identity, Cloud, Premium Support, MDR

    Learn more about each Vectra AI Platform module at https://www.vectra.ai/platform 

    For custom pricing, EULA, or a private contract, please contact your Vectra AI sales representative, channel partner, or aws-marketplace@vectra.ai  for a private offer.

    Highlights

    • Attack Coverage: We got you covered with AI Detections that expose modern attackers' every move across network, identity, cloud - reducing attack exposure by 52%.
    • Signal Clarity: We give you clarity with AI Assistants that automatically triage, correlate, and prioritize real attacks in real time - removing up to 50% of time spent on manual tasks.
    • Intelligent Control: We put you in control to discover, hunt, detect, investigate, and stop attacks early - improving security team efficiency and effectiveness by 40%.

    Details

    Delivery method

    Deployed on AWS

    Unlock automation with AI agent solutions

    Fast-track AI initiatives with agents, tools, and solutions from AWS Partners.
    AI Agents

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata. Review certifications and security standards before purchase.

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Vectra AI Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (5)

     Info
    Dimension
    Description
    Cost/month
    Vectra AI Standard
    Vectra AI Platform Standard: Network, Identity, Cloud
    $499.00
    Vectra AI Complete
    Vectra AI Platform Complete: Network, Identity, Cloud, Premium Support, MDR
    $1,299.00
    AWS Brain ( Deprecated )
    Detect for Network - AWS Brain (custom configuration)
    $5,000.00
    Protect for M365 ( Deprecated )
    Vectra Protect for M365
    $2,900.00
    Protect for Azure AD ( Deprecated )
    Vectra Protect for Azure Activity Directory
    $1,160.00

    Additional usage costs (1)

     Info

    The following dimensions are not included in the contract terms, which will be charged based on your usage.

    Dimension
    Cost/unit
    Vectra Threat Detection Contract Overages - One Time Fee
    $1.00

    Vendor refund policy

    All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.

    How can we make this page better?

    We'd like to hear your feedback and ideas on how to improve this page.
    We'd like to hear your feedback and ideas on how to improve this page.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    support@vectra.ai  Contact Vectra Support: https://www.vectra.ai/support  or call us at (408) 326-2022 (US)

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    4
    1 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    100%
    0%
    0%
    0%
    1 AWS reviews
    |
    28 external reviews
    Star ratings include only reviews from verified AWS customers. External reviews can also include a star rating, but star ratings from external reviews are not averaged in with the AWS customer star ratings.
    Nawaf Fawaz

    Automation benefits increase as users create automations with ease

    Reviewed on Apr 24, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Vectra AI  is a tool that I use for detecting and remediating threats through use cases that are default within its system.

    What is most valuable?

    The main feature of Vectra AI  that I find valuable is its focus on the user interface and its approximately two hundred algorithms based on artificial intelligence and machine learning. It allows me to create automations easily. Using this tool for automation has provided more benefits to our processes.

    What needs improvement?

    There are several features found in ExtraHop that are not present in Vectra AI. These include the ability to view graphs of endpoints contacting other endpoints and the bandwidth utilization in the environment. Additionally, ExtraHop's ability to decrypt encrypted data is a feature that Vectra AI lacks. Multiple appliances are required for Vectra AI, making it less convenient compared to competitors.

    For how long have I used the solution?

    I have been using Vectra AI for two years.

    How are customer service and support?

    When I create tickets, the response is fast, and issues are solved promptly. However, more technical queries may take two or three days, or up to a week.

    How would you rate customer service and support?

    Negative

    How was the initial setup?

    Setting up Vectra AI is more complicated compared to other tools like ExtraHop. It requires multiple appliances for different functions, whereas ExtraHop requires only one sensor.

    Which other solutions did I evaluate?

    ExtraHop is another solution that I have evaluated.

    What other advice do I have?

    I would rate Vectra AI eight out of ten. Despite its complexities, I still find it valuable, though ExtraHop seems to be catching up.
    Mohammad Alkurdi

    Innovative detection features enhance monitoring

    Reviewed on Jan 03, 2025
    Review provided by PeerSpot

    What is our primary use case?

    We are using it for our SOC services. We are also using it for our clients. We have our monitoring setup for our SOC staff.

    What is most valuable?

    There are many detection features available. There are extensive out-of-box detection capabilities. I cannot mention just one or two at the moment. There are multiple detection rules, and its integration with ADR and Office 365 AI is very nice, to be honest with you. It is scalable, and they have their own appliance that can handle multiple locations. You can deploy it for enterprises with multiple sites.

    What needs improvement?

    The advantages of the integration are not entirely out-of-the-box. You have to do it manually. When I'm doing tier response, an out-of-the-box solution is not available. You need to have a Linux server, and from the Linux server, you must perform AI tasks, and there is a lot to be handled in the back end. This is a major consideration about them. The recall feature, if it can be placed in some areas instead of the cloud, and charged for, would be better. Recall the storage where you watch all the traffic, and you can recall it and try to analyze it in the back end. It’s cloud-based. If they offer it on-prem, it would be better. I think they have a solution, but I have never tested it, to be honest with you.

    For how long have I used the solution?

    I have been using the solution for years.

    What do I think about the scalability of the solution?

    It is scalable, and they have their own appliance to handle multiple locations. You can deploy it for enterprises with multiple sites.

    How are customer service and support?

    They are supportive. From a support perspective, they are supportive, to be honest with you.

    Which solution did I use previously and why did I switch?

    I am using something else. I am using Vivo, Vixstrap, Vextra AI, Vectra, and Security Onion as open-source. It depends on the clients.

    What's my experience with pricing, setup cost, and licensing?

    It is very acceptable when you compare it with Darktrace, for example.

    What other advice do I have?

    At the end of the day, it's written rules in such a way. The trend in the market is something I did not consider much. The detection rules are written in the back end. There is something happening in such a way to do it again. AI is mentioned too much, and for me, it is only marketing talk. At the end of the day, there is no one hundred percent AI in security. Detection requires manual writing at times. They already handle back-end processes but vendors won't show this. AI is not targeting a specific vendor. AI, for me, is just a trend. It depends on the client. I tailor solutions to client requirements. For visibility and monitoring, I choose the best products. Every application, every NDR solution has its capabilities. It varies by client because I must advise clients on solutions they can use and benefit from. I sometimes advise clients about Vectra as it still serves my clients well. It's fair enough for now. The overall product rating is seven out of ten.

    Which deployment model are you using for this solution?

    On-premises
    reviewer2238027

    Efficient management with minimal manpower and reliable support

    Reviewed on Nov 11, 2024
    Review provided by PeerSpot

    What is our primary use case?

    As an end user, I do not have to commit manpower to manage Vectra since most of their use cases are managed by them. It's a hands-off kind of deployment.

    How has it helped my organization?

    The deployment is hands-off, which means it saves us manpower resources since Vectra manages the use cases.

    What is most valuable?

    Most of their use cases, including deployment, are managed by the tool itself, requiring less manual input from our team.

    What needs improvement?

    Neither Vectra nor Darktrace  have a function like a status health check on my log sources and traffic sources.

    For how long have I used the solution?

    I have been working with Vectra for one or two years.

    What do I think about the stability of the solution?

    It's pretty good with no major issues.

    How are customer service and support?

    The support is quite reliable depending on the service engineer assigned. I would rate them between eight and nine.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We are also working with Darktrace .

    How was the initial setup?

    The setup is generally straightforward.

    What's my experience with pricing, setup cost, and licensing?

    Vectra is cheaper in terms of pricing and features compared to Darktrace.

    Which other solutions did I evaluate?

    Vectra was compared alongside Darktrace.

    What other advice do I have?

    Vectra serves its purpose well and does not require much manpower for updates.

    I'd rate the solution eight out of ten.

    reviewer2403498

    The weekly reports needed more insights and explanation but deployment is straightforward

    Reviewed on May 22, 2024
    Review provided by PeerSpot

    What needs improvement?

    We had another product with Vectra AI and used the MDR solution as an add-on. Initially, it wasn't fully appropriately configured, so we didn't get the expected results. Even once configured correctly, we weren't fully satisfied with its response. The issue was both with their service response and the product's capabilities.

    The solution's weekly reports needed to have more explanations. However, we needed more explanations because the reports provided were mainly statistical. We were looking for more analysis and insights.

    For how long have I used the solution?

    I have been working with the product for less than a year. 

    How was the initial setup?

    The initial setup was pretty straightforward. 

    What's my experience with pricing, setup cost, and licensing?

    The solution's pricing was 50 percent lower than the other vendors shortlisted. 

    What other advice do I have?

    I wouldn't recommend the product to others. We are moving away from it. I rate the overall solution a six out of ten. 

    Naveen Hariharan Vijaya

    Offers real-time threat detection, notices some of the exfiltration techniques and alerts us, and AI uses models to detect abnormal behavior

    Reviewed on May 10, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We use Vectra AI for endpoints where we are unable to install agents, like endpoint agents, EDR agents, or antivirus tools. For example, BYOD devices or routers in our network. We don't have any control over those, but we need monitoring capability. 

    Vectra AI can monitor the traffic from the wireless router to the firewall or any outgoing traffic. It can give us an idea of whether there is any C&C or C2 communication or any botnet activity from those source IPs. Without having any agents in the endpoint, it is a network monitoring tool. We use this tool to detect threats within the environment where the assets are unmanaged. 

    Also, since we tap into certain network points such as firewalls or IDSs, we get more visibility from managed assets as well. So before the endpoint notices the behavior, Vectra notices some of the exfiltration techniques and alerts us.

    How has it helped my organization?

    Overall, it is good and has reduced our time in identifying the system. It is for unmanaged devices. Previously, if we got an alert from the firewall, it was very difficult to find that particular asset. But with the help of this tool, we can simply run a packet capture and immediately get the hostname and know which user is using it. 

    It has greatly reduced our time to remediate the situation. We can identify the user, block their account immediately, and sometimes kick that device off the network completely.

    It has a confidence level of around 60% to detect insider threats of anomalies, but we mostly need to fine-tune the product. We are still in the fine-tuning process. Even though it has been one year since we implemented the product, the first six months were spent integrating various log servers and determining where to tap. 

    For the past three months, we have been actively investigating the alerts. When we investigate some of the insider alerts, most of the time it is a false positive because the domain is allowed. Vectra does not know that those are allowed domains, such as OneDrive and SharePoint, to access our network devices. 

    It considers it malicious because a huge amount of file uploads is seen, according to Vectra. But we know those are known URLs and known behavior. When we slowly started whitelisting, the threat confidence level increased. So right now, for insider threats, it gives around 60% confidence, but around 80% of the incidents were false positives because we are still in the fine-tuning process.

    What is most valuable?

    The packet capturing feature is very useful, and as the name suggests, AI uses models to detect abnormal behavior. Some of the patent-matching algorithms they use are very advanced and detect threats at a very early stage.

    For me, detections from unmanaged networks are one of the greatest values. You can identify threats from BYOD or even mobile devices, which were not handled before.

    What needs improvement?

    The detection algorithms can be improved at the sensor level rather than doing all the things at the brain. For example, if the sensor has some directional algorithm or detects repeating traffic, it can drop those packets at the beginning itself. There is no need to send that traffic to the brain in order to reduce the bandwidth.

    AI is picking up a lot now. There is no manual intervention needed. Whenever a detection happens, it can automatically summarize and give it to you. But Vectra doesn't have those kinds of capabilities. It still needs manual intervention to analyze, and they don't have a summarized kind of output. So that can be improved. But apart from that, the detection models and all the other categories have good support for that.

    In future releases, I would like to see Vectra AI to generate a summary of the instance.

    For how long have I used the solution?

    I have been using it for a year. 

    What do I think about the stability of the solution?


    What do I think about the scalability of the solution?

    I would rate it at eight. The remaining two points I'm not giving because it's a fairly new product. So far, it is good as per our test and it is able to scale as well.

    The only limit is you need to increase the sensors when you have more traffic. For example, the current sensors can handle up to 50 GBPS of traffic per second. If you need more traffic to be utilized, then you need to buy additional sensors to handle the traffic.

    From a technical perspective, there is not much more possible, because there are some hard limits in the hardware. You cannot increase the bandwidth. They have other options to increase with more sensors, but it ultimately ends up being a cost factor.

    If you have more money, you can buy more sensors and do it.

    In our organization, we are an MSSP provider. We use Vectra, and our entire SOC team, which is around 20 people, uses Vectra for our MSSP. We have two customers who are also using this product. Two of the largest telecom industries in Thailand are using this product to understand their behavior as of now. The approximate number of users in those categories will be around ten.

    How are customer service and support?

    The customer service and support are good. So far, we have not faced any issues at all.

    How was the initial setup?

    The setup is a very straightforward process. You need to tap the network traffic at your desired point, and it has two components: a sensor and a brain. The sensor collects the logs and forwards them to the brain, which does the detection and everything. They offer a virtual appliance that you can run in your environment. 

    The setup process is usually very simple. It took only two days to set up. But, initially, deciding the location of the sensor and other factors took more time. The threat team at Vectra AI engaged with us effectively, provided all the support, understood our architecture and advised us on placing the sensors.

    What's my experience with pricing, setup cost, and licensing?

    The licensing is on annual basis. 

    What other advice do I have?

    I would rate it at nine out of ten. The one point I'm reducing is because the model can learn itself. If no one is fine-tuning it, for example, every time we find a huge number of alerts, then only we go and look it up and fine-tune the product. 

    If no one is acknowledging it or it seems like regular traffic, then the product can understand that behavior and have a feedback mechanism to correct it, mark it as a false positive, or whitelist it.

    My recommendation: 

    Understand your network first, and place the sensors in the correct position to receive all kinds of traffic: THC, PDNS, and all those things. If you place the sensors at the egress traffic, you may not receive some of the packets, and you will not have overall visibility. 

    So the placement of sensors is very important; you need to understand your network to place them correctly.

    Which deployment model are you using for this solution?

    Public Cloud
    View all reviews