Overview

Product video
Vectra AI Platform capabilities:
- Coverage: AI Detections that expose attackers' every move across network, identity, cloud - reducing attack exposure by 52%. The Vectra AI Platform covers data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, Microsoft 365, and Microsoft Copilot for 365.
- Clarity: AI Agents that automatically triage, stitch, and prioritize attacks in real time - removing 99% of alert noise, and up to 50% of time spent on manual tasks.
- Control: Respond UX to discover, hunt, detect, investigate, stop and report improving security team efficiency and effectiveness by 40%.
o Discover where attackers can attack across network, identity and cloud to stop attacks before they start.
o Hunt down attackers by seeing malicious threat activity across network, identity and cloud in one view.
o Investigate instantly with an aggregated, contextualized view of attack progression in one window.
o Respond confidently in minutes with automated and manual lockdown of infected hosts and devices.
o Report on attack exposure, posture, operational efficiency and effectiveness.
Vectra AI Platform modules:
- Vectra AI for Network - NDR
- Vectra AI for Cloud - AWS
- Vectra AI for Cloud - Azure
- Vectra AI for Cloud - M365
- Vectra AI for Identity - Microsoft Active Directory
- Vectra AI for Identity - Microsoft Entra ID
- Vectra AI Investigations - Metadata retention 14-day
- Vectra AI Investigations - Metadata retention 30-day
- Vectra Managed Detection and Response (MDR)
- Vectra Managed Extended Detection and Response (MXDR) - includes endpoint management
Vectra AI Platform packages:
- Vectra AI Platform Standard: Network, Identity, Cloud
- Vectra AI Platform Complete: Network, Identity, Cloud, Premium Support, MDR
Learn more about each Vectra AI Platform module at https://www.vectra.ai/platformÂ
For custom pricing, EULA, or a private contract, please contact your Vectra AI sales representative, channel partner, or aws-marketplace@vectra.ai for a private offer.
Highlights
- Attack Coverage: We got you covered with AI Detections that expose modern attackers' every move across network, identity, cloud - reducing attack exposure by 52%.
- Signal Clarity: We give you clarity with AI Assistants that automatically triage, correlate, and prioritize real attacks in real time - removing up to 50% of time spent on manual tasks.
- Intelligent Control: We put you in control to discover, hunt, detect, investigate, and stop attacks early - improving security team efficiency and effectiveness by 40%.
Details
Unlock automation with AI agent solutions

Features and programs
Trust Center
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
---|---|---|
Vectra AI Standard | Vectra AI Platform Standard: Network, Identity, Cloud | $499.00 |
Vectra AI Complete | Vectra AI Platform Complete: Network, Identity, Cloud, Premium Support, MDR | $1,299.00 |
AWS Brain ( Deprecated ) | Detect for Network - AWS Brain (custom configuration) | $5,000.00 |
Protect for M365 ( Deprecated ) | Vectra Protect for M365 | $2,900.00 |
Protect for Azure AD ( Deprecated ) | Vectra Protect for Azure Activity Directory | $1,160.00 |
The following dimensions are not included in the contract terms, which will be charged based on your usage.
Dimension | Cost/unit |
---|---|
Vectra Threat Detection Contract Overages - One Time Fee | $1.00 |
Vendor refund policy
All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
support@vectra.ai Contact Vectra Support: https://www.vectra.ai/support or call us at (408) 326-2022 (US)
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products



Customer reviews
Automation benefits increase as users create automations with ease
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
How are customer service and support?
How would you rate customer service and support?
Negative
How was the initial setup?
Which other solutions did I evaluate?
What other advice do I have?
Innovative detection features enhance monitoring
What is our primary use case?
We are using it for our SOC services. We are also using it for our clients. We have our monitoring setup for our SOC staff.
What is most valuable?
There are many detection features available. There are extensive out-of-box detection capabilities. I cannot mention just one or two at the moment. There are multiple detection rules, and its integration with ADR and Office 365 AI is very nice, to be honest with you. It is scalable, and they have their own appliance that can handle multiple locations. You can deploy it for enterprises with multiple sites.
What needs improvement?
The advantages of the integration are not entirely out-of-the-box. You have to do it manually. When I'm doing tier response, an out-of-the-box solution is not available. You need to have a Linux server, and from the Linux server, you must perform AI tasks, and there is a lot to be handled in the back end. This is a major consideration about them. The recall feature, if it can be placed in some areas instead of the cloud, and charged for, would be better. Recall the storage where you watch all the traffic, and you can recall it and try to analyze it in the back end. It’s cloud-based. If they offer it on-prem, it would be better. I think they have a solution, but I have never tested it, to be honest with you.
For how long have I used the solution?
I have been using the solution for years.
What do I think about the scalability of the solution?
It is scalable, and they have their own appliance to handle multiple locations. You can deploy it for enterprises with multiple sites.
How are customer service and support?
They are supportive. From a support perspective, they are supportive, to be honest with you.
Which solution did I use previously and why did I switch?
I am using something else. I am using Vivo, Vixstrap, Vextra AI, Vectra, and Security Onion as open-source. It depends on the clients.
What's my experience with pricing, setup cost, and licensing?
It is very acceptable when you compare it with Darktrace, for example.
What other advice do I have?
At the end of the day, it's written rules in such a way. The trend in the market is something I did not consider much. The detection rules are written in the back end. There is something happening in such a way to do it again. AI is mentioned too much, and for me, it is only marketing talk. At the end of the day, there is no one hundred percent AI in security. Detection requires manual writing at times. They already handle back-end processes but vendors won't show this. AI is not targeting a specific vendor. AI, for me, is just a trend. It depends on the client. I tailor solutions to client requirements. For visibility and monitoring, I choose the best products. Every application, every NDR solution has its capabilities. It varies by client because I must advise clients on solutions they can use and benefit from. I sometimes advise clients about Vectra as it still serves my clients well. It's fair enough for now. The overall product rating is seven out of ten.
Which deployment model are you using for this solution?
Efficient management with minimal manpower and reliable support
What is our primary use case?
As an end user, I do not have to commit manpower to manage Vectra since most of their use cases are managed by them. It's a hands-off kind of deployment.
How has it helped my organization?
The deployment is hands-off, which means it saves us manpower resources since Vectra manages the use cases.
What is most valuable?
Most of their use cases, including deployment, are managed by the tool itself, requiring less manual input from our team.
What needs improvement?
Neither Vectra nor Darktrace have a function like a status health check on my log sources and traffic sources.
For how long have I used the solution?
I have been working with Vectra for one or two years.
What do I think about the stability of the solution?
It's pretty good with no major issues.
How are customer service and support?
The support is quite reliable depending on the service engineer assigned. I would rate them between eight and nine.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are also working with Darktrace .
How was the initial setup?
The setup is generally straightforward.
What's my experience with pricing, setup cost, and licensing?
Vectra is cheaper in terms of pricing and features compared to Darktrace.
Which other solutions did I evaluate?
Vectra was compared alongside Darktrace.
What other advice do I have?
Vectra serves its purpose well and does not require much manpower for updates.
I'd rate the solution eight out of ten.
The weekly reports needed more insights and explanation but deployment is straightforward
What needs improvement?
We had another product with Vectra AI and used the MDR solution as an add-on. Initially, it wasn't fully appropriately configured, so we didn't get the expected results. Even once configured correctly, we weren't fully satisfied with its response. The issue was both with their service response and the product's capabilities.
The solution's weekly reports needed to have more explanations. However, we needed more explanations because the reports provided were mainly statistical. We were looking for more analysis and insights.
For how long have I used the solution?
I have been working with the product for less than a year.Â
How was the initial setup?
The initial setup was pretty straightforward.Â
What's my experience with pricing, setup cost, and licensing?
The solution's pricing was 50 percent lower than the other vendors shortlisted.Â
What other advice do I have?
I wouldn't recommend the product to others. We are moving away from it. I rate the overall solution a six out of ten.Â
Offers real-time threat detection, notices some of the exfiltration techniques and alerts us, and AI uses models to detect abnormal behavior
What is our primary use case?
We use Vectra AI for endpoints where we are unable to install agents, like endpoint agents, EDR agents, or antivirus tools. For example, BYOD devices or routers in our network. We don't have any control over those, but we need monitoring capability.Â
Vectra AI can monitor the traffic from the wireless router to the firewall or any outgoing traffic. It can give us an idea of whether there is any C&C or C2 communication or any botnet activity from those source IPs. Without having any agents in the endpoint, it is a network monitoring tool. We use this tool to detect threats within the environment where the assets are unmanaged.Â
Also, since we tap into certain network points such as firewalls or IDSs, we get more visibility from managed assets as well. So before the endpoint notices the behavior, Vectra notices some of the exfiltration techniques and alerts us.
How has it helped my organization?
Overall, it is good and has reduced our time in identifying the system. It is for unmanaged devices. Previously, if we got an alert from the firewall, it was very difficult to find that particular asset. But with the help of this tool, we can simply run a packet capture and immediately get the hostname and know which user is using it.Â
It has greatly reduced our time to remediate the situation. We can identify the user, block their account immediately, and sometimes kick that device off the network completely.
It has a confidence level of around 60% to detect insider threats of anomalies, but we mostly need to fine-tune the product. We are still in the fine-tuning process. Even though it has been one year since we implemented the product, the first six months were spent integrating various log servers and determining where to tap.Â
For the past three months, we have been actively investigating the alerts. When we investigate some of the insider alerts, most of the time it is a false positive because the domain is allowed. Vectra does not know that those are allowed domains, such as OneDrive and SharePoint, to access our network devices.Â
It considers it malicious because a huge amount of file uploads is seen, according to Vectra. But we know those are known URLs and known behavior. When we slowly started whitelisting, the threat confidence level increased. So right now, for insider threats, it gives around 60% confidence, but around 80% of the incidents were false positives because we are still in the fine-tuning process.
What is most valuable?
The packet capturing feature is very useful, and as the name suggests, AI uses models to detect abnormal behavior. Some of the patent-matching algorithms they use are very advanced and detect threats at a very early stage.
For me, detections from unmanaged networks are one of the greatest values. You can identify threats from BYOD or even mobile devices, which were not handled before.
What needs improvement?
The detection algorithms can be improved at the sensor level rather than doing all the things at the brain. For example, if the sensor has some directional algorithm or detects repeating traffic, it can drop those packets at the beginning itself. There is no need to send that traffic to the brain in order to reduce the bandwidth.
AI is picking up a lot now. There is no manual intervention needed. Whenever a detection happens, it can automatically summarize and give it to you. But Vectra doesn't have those kinds of capabilities. It still needs manual intervention to analyze, and they don't have a summarized kind of output. So that can be improved. But apart from that, the detection models and all the other categories have good support for that.
In future releases, I would like to see Vectra AI to generate a summary of the instance.
For how long have I used the solution?
I have been using it for a year.Â
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
I would rate it at eight. The remaining two points I'm not giving because it's a fairly new product. So far, it is good as per our test and it is able to scale as well.
The only limit is you need to increase the sensors when you have more traffic. For example, the current sensors can handle up to 50 GBPS of traffic per second. If you need more traffic to be utilized, then you need to buy additional sensors to handle the traffic.
From a technical perspective, there is not much more possible, because there are some hard limits in the hardware. You cannot increase the bandwidth. They have other options to increase with more sensors, but it ultimately ends up being a cost factor.
If you have more money, you can buy more sensors and do it.
In our organization, we are an MSSP provider. We use Vectra, and our entire SOC team, which is around 20 people, uses Vectra for our MSSP. We have two customers who are also using this product. Two of the largest telecom industries in Thailand are using this product to understand their behavior as of now. The approximate number of users in those categories will be around ten.
How are customer service and support?
The customer service and support are good. So far, we have not faced any issues at all.
How was the initial setup?
The setup is a very straightforward process. You need to tap the network traffic at your desired point, and it has two components: a sensor and a brain. The sensor collects the logs and forwards them to the brain, which does the detection and everything. They offer a virtual appliance that you can run in your environment.Â
The setup process is usually very simple. It took only two days to set up. But, initially, deciding the location of the sensor and other factors took more time. The threat team at Vectra AI engaged with us effectively, provided all the support, understood our architecture and advised us on placing the sensors.
What's my experience with pricing, setup cost, and licensing?
The licensing is on annual basis.Â
What other advice do I have?
I would rate it at nine out of ten. The one point I'm reducing is because the model can learn itself. If no one is fine-tuning it, for example, every time we find a huge number of alerts, then only we go and look it up and fine-tune the product.Â
If no one is acknowledging it or it seems like regular traffic, then the product can understand that behavior and have a feedback mechanism to correct it, mark it as a false positive, or whitelist it.
My recommendation:Â
Understand your network first, and place the sensors in the correct position to receive all kinds of traffic: THC, PDNS, and all those things. If you place the sensors at the egress traffic, you may not receive some of the packets, and you will not have overall visibility.Â
So the placement of sensors is very important; you need to understand your network to place them correctly.