For security leaders, builders, and operators, who are tasked with protecting a complex, ever-changing environment from attack, Vectra AI protects modern networks from modern attacks. When modern attackers beat customers' existing controls - and they will, Vectra AI sees their every move, connects the dots, prioritizes and stops the attack in real-time. Our customers say we are the cybersecurity AI that stops attacks others can't.
Coverage: AI Detections that expose attackers' every move across network, identity, cloud - reducing attack exposure by 52%. The Vectra AI Platform covers data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, Microsoft 365, and Microsoft Copilot for 365.
Clarity: AI Agents that automatically triage, stitch, and prioritize attacks in real time - removing 99% of alert noise, and up to 50% of time spent on manual tasks.
Control: Respond UX to discover, hunt, detect, investigate, stop and report improving security team efficiency and effectiveness by 40%.
o Discover where attackers can attack across network, identity and cloud to stop attacks before they start.
o Hunt down attackers by seeing malicious threat activity across network, identity and cloud in one view.
o Investigate instantly with an aggregated, contextualized view of attack progression in one window.
o Respond confidently in minutes with automated and manual lockdown of infected hosts and devices.
o Report on attack exposure, posture, operational efficiency and effectiveness.
Vectra AI Platform modules:
Vectra AI for Network - NDR
Vectra AI for Cloud - AWS
Vectra AI for Cloud - Azure
Vectra AI for Cloud - M365
Vectra AI for Identity - Microsoft Active Directory
Vectra AI for Identity - Microsoft Entra ID
Vectra AI Investigations - Metadata retention 14-day
Vectra AI Investigations - Metadata retention 30-day
Vectra Fusion - Metadata retention 45-day
Vectra Fusion - Metadata retention 90-day
Vectra Managed Detection and Response (MDR)
Vectra Managed Extended Detection and Response (MXDR) - includes endpoint management
Vectra AI Platform packages:
Vectra AI Platform Standard: Network, Identity, Cloud
Vectra AI Platform Complete: Network, Identity, Cloud, Premium Support, MDR
For custom pricing, EULA, or a private contract, please contact your Vectra AI sales representative, channel partner, or aws-marketplace@vectra.ai for a private offer.
Highlights
Attack Coverage: We got you covered with AI Detections that expose modern attackers' every move across network, identity, cloud - reducing attack exposure by 52%.
Signal Clarity: We give you clarity with AI Assistants that automatically triage, correlate, and prioritize real attacks in real time - removing up to 50% of time spent on manual tasks.
Intelligent Control: We put you in control to discover, hunt, detect, investigate, and stop attacks early - improving security team efficiency and effectiveness by 40%.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor, and additional usage. You pay upfront or in installments according to your contract terms with the vendor. This entitles you to a specified quantity of use for the contract duration. Usage-based pricing is in effect for overages or additional usage not covered in the contract. These charges are applied on top of the contract price. If you choose not to renew or replace your contract before the contract end date, access to your entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy this platform on a contract basis, choosing one of two current packages. Vectra AI Standard covers threat detection across network, identity, and cloud. Vectra AI Complete adds premium support and managed detection and response (MDR) to the same coverage. A one-time overage fee applies if your usage exceeds your Threat Detection contract terms. Three older options — AWS Brain for network detection, Protect for M365, and Protect for Azure Activity Directory — are deprecated and no longer active choices for new buyers. Pricing scales by the package and coverage level you select.
Top-of-mind questions for buyers
What does the difference between Vectra AI Standard and Vectra AI Complete mean for what I receive?
Both packages cover threat detection across network, identity, and cloud. Vectra AI Complete adds premium support and managed detection and response (MDR). With MDR, Vectra analysts monitor, investigate, and respond to threats on your behalf around the clock. Standard covers the detection platform without those managed services.
When does the Vectra Threat Detection Contract Overage fee apply?
The overage is a one-time fee charged when your usage exceeds the terms of your Threat Detection contract. It applies on top of your Standard or Complete package. Network detection can monitor as many as 300,000 IPs at a time, so scale beyond your contracted coverage can trigger this charge.
Should I still consider the deprecated AWS Brain, Protect for M365, or Protect for Azure options?
No. These three options are deprecated and no longer active choices for new buyers. AWS Brain covered network detection with custom configuration, while the two Protect options covered specific identity and M365 workloads. New buyers select the Standard or Complete package instead, which covers network, identity, and cloud together.
www.vectra.ai+2
Helpful?
Vendor refund policy
All Orders are non-cancellable and all fees and other amounts you pay under this Agreement are non-refundable.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
AI-powered detections that expose attacker activity across network, identity, and cloud environments including data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, and Microsoft 365.
Automated Alert Triage and Correlation
AI agents that automatically triage, stitch, and prioritize attacks in real time, removing up to 99% of alert noise and reducing manual task time by up to 50%.
Unified Investigation and Response Interface
Centralized response user experience that enables discovery, hunting, detection, investigation, and automated response capabilities with aggregated and contextualized views of attack progression across network, identity, and cloud.
Network Detection and Response
Dedicated network detection and response (NDR) module for monitoring and detecting malicious activity across network infrastructure.
Multi-Cloud and Identity Platform Coverage
Modular architecture supporting AWS, Microsoft Azure, Microsoft 365, Microsoft Active Directory, and Microsoft Entra ID with configurable metadata retention periods ranging from 14 to 90 days.
Agentless Detection Architecture
Agentless approach for security detection and response without requiring agent installation across cloud infrastructure.
Real-time Configuration Monitoring
Continuous tracking of behavior and configuration changes to provide an updated model of the environment with instant analysis of security and compliance implications.
Threat Detection Framework
Threat detection across Network and IAM using MITRE ATT&CK framework driven by machine learning analysis.
Attack Chain Visualization
Dynamic visual attack storyline that connects workloads, network data, cloud identities, and audit logs for root cause analysis.
CloudTwin Technology
CloudTwin technology designed to provide a precise and constantly updated model of the cloud environment for rapid response capabilities.
Advanced Threat Detection
Combines multiple AI, machine learning, and correlation engines to detect advanced threats and lateral movements across network traffic
Behavioral Analysis
Automatically identifies suspicious network behavior and anomalies using advanced analytics to detect threats that elude traditional signature and policy-based security
Network Forensics and Investigation
Provides lossless data capture and retrieval with centralized analysis and visualization to determine scope and impact of threats
Intrusion Prevention
Next-generation IPS that uses advanced detection and emulation techniques to detect and block sophisticated malware threats across the network
GenAI-Powered Automation
Integrates with Trellix Helix to leverage GenAI for reducing alert fatigue, automating deep investigations mapped to MITRE ATT&CK framework, and accelerating response actions
Advanced threat analytics have improved alert fidelity and support timely incident response
Reviewed on May 06, 2026
Review provided by PeerSpot
What is our primary use case?
I primarily use Vectra AI for customers, and I only provide Vectra AI.
What is most valuable?
The most valuable features I find are the threat signal intelligence and the ability to build high-fidelity alerting for customers, which is one of the biggest value adds.
Cognito Detect is quite useful, but it has only been used in a few companies that have required deeper insights into their network analytics, so not all customers have it. However, the ones that do have found a lot of value in it.
Vectra AI helps in identifying malicious network activities by enabling threat hunting and providing security enriched network analytics, giving considerable visibility over that aspect.
I am evaluating Cognito Recall's impact on my customers' threat investigation processes by noting that the ones using it are quite intensive. They can use Cognito Recall to look back further in time on events raised from a SIEM perspective.
What needs improvement?
I think one area that could be improved about Vectra AI is their marketing. One of the aspects that Darktrace excels at is their marketing, and I do not feel Vectra AI is on that level yet, leading to a lack of visibility over the solution.
For how long have I used the solution?
I have been working with Vectra AI for about three years.
How are customer service and support?
I would rate their technical support a 10, as we have local support in South Africa and the ability to reach out to the teams quickly and effectively when they are in similar time zones, leading to great support globally.
What's my experience with pricing, setup cost, and licensing?
I find the pricing of Vectra AI to be one of the best we have seen as feedback from customers and partners indicates it is very competitive for an EDR solution.
What other advice do I have?
The intuitive dashboards are incredibly useful, with both the Quadrant UX and the Respond UX, so whether looking from a management point of view or an analyst point of view, both dashboards are very intuitive.
The biggest metric I use to demonstrate the dashboard's effectiveness is the ability to respond to an alert effectively, particularly within the SLA timeframe. Many of our customers have an SLA with our partners, and if they keep to that SLA, it means the tool performs effectively. We have not had instances of it not working among our partners.
I assess the benefits of integrating Cognito Stream with existing SIEM systems by noting that Cognito Stream is very similar to Cognito Recall and provides enriched details around the network side in real-time. However, it is not for investigation purposes but rather for visibility purposes over the network.
My overall rating for Vectra AI is 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Manufacturing
Vectra AI: Fast, Insightful Threat Detection with Strong M365 and Azure AD Integration
Reviewed on Apr 02, 2026
Review provided by G2
What do you like best about the product?
Vectra AI was a valuable addition to our cybersecurity tools. It helps us protect our assets and the company network from modern attacks.
Our security analysts use Vectra AI to go through detections of anomalies in our environment. Easily integrated with M365 and Azure AD.
We were able to quickly identify and prevent data leakage by investigating a suspicious M365 mail forwarding detection by Vectra AI. Other M365 detections we observed included risky Exchange Operations, Phishing simulation configuration change, Suspect eDiscovery Usage, Malicious links sent by external Teams user, and many more.
Detections that helped our SOC team prevent a major cyber incident was Azure AD Admin account creation, Login attempts from a disabled account, Azure AD TOR activity, Azure AD Suspicious device registration, among others.
A great feature is the AI intelligence as well as the Vectra AI Post-Quantum Cryptography Readiness dashboard. Quantum computing threatens today's public-key cryptography, putting SSH and TLS key exchanges at risk of future decryption. This Vectra AI dashboard highlights hosts and daily SSH connections still relying on non-PQC key exchange, helping us identify exposure and prioritize migration to quantum-resistant algorithms.
The interface loads fast and offers clear visualization allowing our SOC analysts to explore our environment to uncover emerging threats.
When assistance was needed, we received fast and professional support from the vendor.
Cost may be a limitation for some, however, for us being a large company with permissive budget, it was a good investment for the value it brought.
What do you dislike about the product?
Initial setup required some reading and calls to support. Cost may be a limitation for some.
What problems is the product solving and how is that benefiting you?
Vectra AI helps us protect our assets and the company network from modern attacks. It is a very powerful solution that offers large amount of data neatly presented through very intuitive and modern interface.
Higher Education
Easy to Learn, Clear, and Truly Helpfulclear use of product
Reviewed on Feb 19, 2026
Review provided by G2
What do you like best about the product?
easy to work with and clear method of learning to use
What do you dislike about the product?
i have zero problems with it and find it quite helpful
What problems is the product solving and how is that benefiting you?
it is helping us to do better threat hunting and know things before they become problems
reviewer2783214
AI‑driven threat detection has transformed alert fatigue and now enables faster response and leaner soc operations
Reviewed on Nov 28, 2025
Review from a verified AWS customer
What is our primary use case?
Vectra AI is being used as an NDR solution to sell to customers as a managed service. The product has been productized to sell to customers as an NDR solution. The network is scanned for any anomalies or threats that are detected and fed to the customer's SIEMs and SOARs.
In one financial sector scenario, a customer was complaining about reduced alert fatigue and detecting an attack missed by traditional tools. They wanted an AI solution that could detect anomalies with the best MTTD and MTTR response times to reduce overhead over the SOC teams.
Vectra AI has been used for identity management, which was integrated with Microsoft Entra ID and Active Directory to monitor account activity. A customer wanted in-depth analysis on their identity management solution. Another scenario involved integrating with the customer's cloud solutions, where they wanted a solution that provided cloud detection and response through AWS and Microsoft 365 environments.
What is most valuable?
The best features of Vectra AI are related to AI. For the NDR part, Attack Signal Intelligence features were mainly responsible for behavior AI, high-fidelity signaling, and prioritization. These features were great for anomaly detection and behavioral-based detection, able to catch zero-day attacks and living-off-the-land attacks. For high-fidelity signaling, it automatically triaged, filtered, and correlated signals, which dramatically reduced alert fatigue noise on the customer side by approximately 80% and eliminated alert fatigue on the SOC teams. Regarding the identity detection and response IDR solution, it monitored Active Directory and Entra ID for any attacks, allowing the SOC to detect any compromised credentials.
Alert noise was dramatically reduced by nearly 80%, allowing SOC analysts to focus more on true threats, which made them more productive and resulted in higher operational efficiency. Attack Signal Intelligence helped reduce irrelevant alerts by 80% to 90%, with metrics showing a 100-plus reduction in investigation workloads and roughly saving about 55,000 hours of investigation time. Investigation time has decreased significantly, empowering analysts with detection and advanced unknown threats that Vectra AI provided. Its knowledge base and database are very up to date, allowing for spotting zero-day attacks with full visibility and helping to stop attacks in minutes.
Vectra AI has reduced the MTTD and MTTR, increasing operational and process efficiency, and has helped reduce the number of SOC analysts that needed to be hired. Thanks to the AI features, the number of employees and SOC analysts hired has been reduced.
What needs improvement?
Pricing could be improved, as many customers have complained about the pricing model and pricing complexity.
Regarding the product itself, extending direct control and simplifying workflows would be beneficial. More granular built-in responses and cloud remediations could be improved. A native CMDB-like feature and risk scoring would be a big advantage. Improved compatibility with the SASE ecosystem expansion would also be valuable.
For how long have I used the solution?
Vectra AI has been in use since 2018.
What do I think about the stability of the solution?
Vectra AI is considered a stable solution.
What do I think about the scalability of the solution?
Vectra AI is scalable because it can work through different kinds of solutions and is compatible with all kinds of cloud solutions. The appliance capacity is very good, whether virtual or physical, providing significant scalability.
How are customer service and support?
Customer support receives a rating of nine out of ten due to being very supportive and responding quite efficiently.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
A different solution was not previously used.
What was our ROI?
A good return on investment has been seen. For cost savings over a period of three years, it could be about 350%. The payback period is roughly six months. Productivity savings could be about 800,000, with SOC efficiency increasing nearly 40%. Workload reduction on the SOC side is now 100% lighter than previously.
Which other solutions did I evaluate?
Other options were not evaluated, as at that time, Vectra AI was the only NDR solution that had AI features. They began with the AI concept that was being sought.
What other advice do I have?
Vectra AI should be considered if looking for an NDR solution and not just an EDR solution only. It provides great value and quality, provided that customers can pay for the licenses, which are quite expensive. Vectra AI is represented as a partner and reseller in business with this vendor. This review has been given a rating of eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
RahulReddy
Threat detection has improved and malicious emails are now identified quickly
Reviewed on Nov 15, 2025
Review provided by PeerSpot
What is our primary use case?
Vectra AI is my main cybersecurity tool, and we use the AI data in our company. For example, when we discovered a malicious email, Vectra AI helped us identify that it was not a legitimate email, and we successfully stopped the threats.
What is most valuable?
Vectra AI offers artificial intelligence capabilities with visibility that can be integrated into our day-to-day operations and other tools, including malware detection tools and cyber threat tools.
Vectra AI has positively impacted my organization. Last year while using it, we received many malicious email threats and virus incidents, including a trojan virus that had reportedly been deployed by someone. Our company used Vectra AI to detect the malicious threats and viruses before they could cause more damage, and we successfully stopped the threats.
Using Vectra AI, I notice that server downtime has decreased significantly. We now experience only two to three hours of downtime, whereas without Vectra AI and other tools, our downtime would exceed 48 to 72 hours.
What needs improvement?
Vectra AI could be improved by focusing on all threat types, not only malicious threats or virus threats. All threats, including hacking attempts, should be comprehensively addressed.
The user interface of Vectra AI is good, so there are no improvements needed in that area. However, reporting and integration with other tools should be enhanced.