The typical use case for Darktrace is for threat vector scanning, detecting any unusual activity, and anomaly detection. Apart from that, it is very helpful in incident response.

Reviews from AWS customer
-
5 star0
-
4 star0
-
3 star0
-
2 star0
-
1 star0
External reviews
External reviews are not included in the AWS star rating for the product.
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
What is our primary use case?
What is most valuable?
The features I find most effective in Darktrace include anomaly detection. The machine learning model provides accurate alerts after the learning period of 1 or 2 weeks, especially for network anomalies or something that the user is trying to access, which can include trying to visit unknown sites or botnets, and those things get detected and represented in a very good dashboard.
Darktrace positively impacts my organization by enhancing threat hunting, particularly in east-west traffic within the same subnet. Previously, we only used traditional firewalls that cannot catch this lateral traffic. After deploying Darktrace, we gain insights into machine-to-machine communication, which adds more value to the organization and is especially beneficial for the SOC team.
What needs improvement?
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
For how long have I used the solution?
I have been familiar with Darktrace for the last 5 to 6 years.
What was my experience with deployment of the solution?
In terms of the speed and effectiveness of Darktrace's automatic response, it gives clear alerts whenever anomalies happen on the network, enabling us to catch them on the fly. However, some of the rules generate false positives, especially with system calls, which get incorrectly marked as anomalies. These are actually system call integrations that need fine-tuning based on our environment integrations.
Regarding Darktrace's capability to adapt and recognize abnormal activities through machine learning and AI, sometimes a password expiration prompts the user to connect to different sources to get the new password changed. During that time, it picks this up as abnormal activity when connecting to LDAP during off-business hours. This is an example of how it detects what it considers an anomaly, since user authentication typically happens during business hours.
What do I think about the stability of the solution?
Regarding overall stability, Darktrace is a stable product, and I have no complaints from customers wherever it is deployed.
What do I think about the scalability of the solution?
While considering if Darktrace is scalable, I note that there are storage limitations, where the planned capacity can sometimes be overutilized. There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
How are customer service and support?
I can rate Darktrace's technical support as one of the best products in the world. We have seen satisfaction reflected on our customers' faces after deployment when they start seeing the data and the dashboard, and they often express surprise at the network traffic visibility that Darktrace provides.
I would rate the technical support of Darktrace between 6 to 8, as the support is good and we receive timely assistance whenever we raise an issue.
Which solution did I use previously and why did I switch?
Before working with Darktrace, I did not use any similar solution in the same category. Earlier, I was using something called decepters, and my organization may have explored different products, but I learned about network detection and response through Darktrace about 5 to 6 years ago.
How was the initial setup?
Deploying Darktrace is quite easy and plug and play, wherein all we need is to put it in a data center, rack up, and do some switch configuration. The learning would take a week time, and once the data gets populated, we get a very good dashboard.
What about the implementation team?
For deploying Darktrace, I would require 3 to 4 people. We would require a data center person to assist in racking and mounting this, and some network engineers would make this configuration to spend the data ports.
What was our ROI?
When considering return on investment for organizations using Darktrace, the disadvantage lies in having to use a physical appliance. Running a quick POC is not possible since the hardware has to be shipped from the UK or elsewhere, but other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
What's my experience with pricing, setup cost, and licensing?
In terms of setup and licensing costs, Darktrace is on the pricier side compared to similar solutions in the NDR market. Other NDR solutions are also on the higher side, but Darktrace stands out as a bit higher. Competitive pricing would certainly help me as a system integrator to convince customers.
Which other solutions did I evaluate?
I did not evaluate other options when looking into Darktrace, but some customer preferences led us to consider other NDR solutions, such as 40 NDR. Our customers had a Fortinet setup with various products, and they preferred the 40 NDR for proprietary visibility when collecting logs from Fortinet devices.
What other advice do I have?
We are using the latest version of Darktrace. I have not used Darktrace's Enterprise Immune System. Antigone is the feature of Darktrace that we have recently experienced. At the moment, I have not encountered a situation where Darktrace's self-learning capabilities reduced the risk of data breaches, but it performs very effectively overall. It requires some time to adapt; initially, when we deploy, it takes weeks. On a scale of 1-10, I rate Darktrace a 9.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Provides effective email protection but support could improve
What is our primary use case?
What is most valuable?
Regarding the ROI, we have experienced a significant reduction in phishing emails and have utilized our time efficiently, resulting in approximately 70% ROI.
What needs improvement?
The support is the main problem, though there are some other issues as.
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Neutral
How was the initial setup?
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
In terms of AI functionality, I have seen some AI integrations overall. Darktrace is completely designed based on AI and machine learning, making it very efficient in identifying suspicious behavior and suspicious emails.
We are using the Securonix SIEM solution, and from ManageEngine, I use Help Desk and the Patch Manager.
On a scale from 1 to 10, I would rate Darktrace as six points.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
How was the initial setup?
Which other solutions did I evaluate?
What other advice do I have?
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
AI-driven incident response streamlines threat management and saves time
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
Which deployment model are you using for this solution?
Autonomous mode effectively responds to anomalies and mitigates data exfiltration risks
What is our primary use case?
What is most valuable?
What needs improvement?
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
How was the initial setup?
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
Which deployment model are you using for this solution?
Has good detection and response analytics
What is our primary use case?
I use the solution as a network detection and response platform for security purposes.
What is most valuable?
The features that are most valuable to me include detection, response with analytics, and network detection. These features are particularly effective because they provide comprehensive security analytics. Additionally, the analytics aspect is highly appreciated for its effectiveness.
I do not use the automation response since I have another product handling automation. Furthermore, I believe that the reporting needs enhancement for better performance.
What needs improvement?
The presence of sales representatives in my country needs improvement. There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
For how long have I used the solution?
I have been using the solution for almost two years.
What do I think about the stability of the solution?
I rate the stability as nine out of ten, indicating it is very stable.
What do I think about the scalability of the solution?
I rate the scalability as nine out of ten, demonstrating its capacity to expand effectively.
How are customer service and support?
The technical support is good. The response time and quality are satisfactory, and I am satisfied with the support provided.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is very simple and was executed in-house by our team without requiring consultants or integrators.
What about the implementation team?
The implementation was done with our own team.
What's my experience with pricing, setup cost, and licensing?
The product is considered expensive compared to others.
Which other solutions did I evaluate?
Vectra and Nextcloud are the main competitors. Among these, I prefer Darktrace due to its stability, security, and excellent analytics.
What other advice do I have?
I highly recommend the overall solution to other users and rate it as nine out of ten.
Which deployment model are you using for this solution?
Enables proactive threat detection and immediate response through AI monitoring
What is our primary use case?
The primary use case for Darktrace includes network monitoring, endpoint monitoring, and email scanning. I integrate it into our cybersecurity strategy and use it to monitor everything happening on the network.
How has it helped my organization?
The organizational value of Darktrace is primarily in protecting the business. It ensures that we are prepared against attacks, providing significant security value.
What is most valuable?
The most valuable feature of Darktrace is its ability to detect and counter threats before they occur. The autonomous response capability is always enabled, blocking threats immediately without hesitation.
Additionally, the Darktrace email platform is a significant asset since it addresses incoming threats before they reach the network, enhancing our security measures.
Protecting the business is essential, and ensuring security through 24/7 AI monitoring is invaluable.
What needs improvement?
Even before I think about any improvements, Darktrace is proactive by bringing out updates and new features every quarter.
However, the one downside is the pricing, which is quite high.
For how long have I used the solution?
I have been working with Darktrace for four years.
What do I think about the stability of the solution?
The stability of Darktrace is excellent, rated ten out of ten. I have never experienced downtime with the system. Even if it goes down, we have other systems in place, although those will not be as fast.
What do I think about the scalability of the solution?
The scalability of Darktrace is rated eight out of ten. It monitors everything as long as endpoints are licensed. Since it's cloud-based, it expands easily.
How are customer service and support?
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected. I would rate their customer service at nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not use any other solutions before Darktrace.
How was the initial setup?
The initial setup can be rated as seven out of ten. The main challenge was time as the system takes about three to six months to learn the network before it becomes fully effective.
What about the implementation team?
The deployment process heavily relied on Darktrace's team, as they did most of the heavy lifting. Only two team members are currently needed for ongoing monitoring.
What was our ROI?
The organizational value gained from Darktrace is securing the business against potential threats. A tangible return on investment is only noticeable if facing an actual cyber attack.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite high, estimated at around $350,000 per year. I rate the pricing component at eight out of ten.
Which other solutions did I evaluate?
There was no alternative when we chose Darktrace; it was the only viable option available in the market at that time.
What other advice do I have?
For new users of Darktrace, it is important to be patient and set up the system properly. Follow Darktrace's advice throughout the setup process, which is crucial for effectiveness. Overall, I rate Darktrace at eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Gain comprehensive network visibility with detailed packet capture
What is our primary use case?
The primary use case for Darktrace is to gain full visibility into the network traffic. Darktrace provides complete packet capture and metadata analysis, unlike other solutions that offer only specific metadata. This comprehensive view allows for better assessment and monitoring of the network environment.
What is most valuable?
Darktrace is valuable since it offers full packet capture and detailed metadata. This feature sets it apart from competitors, which often provide limited metadata visibility.
Additionally, the interaction with the technical team is seamless, and communication with the account manager is flexible and easy.
What needs improvement?
The management dashboards and the meter dashboards should be more user-friendly and simple to use for easy management.
For how long have I used the solution?
I have been using Darktrace for three months.
What do I think about the stability of the solution?
Darktrace is very stable, and I would rate its stability a ten out of ten.
What do I think about the scalability of the solution?
Darktrace has high scalability, and I would rate it a nine out of ten.
How are customer service and support?
The technical support from Darktrace is of high quality, and I would rate it a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously checked with different solutions.I decided to go with Darktrace. However, it offers complete packet capture and metadata, unlike other vendors.
How was the initial setup?
The initial setup was straightforward, however, there were some connection issues when deploying the VM on the cloud. Overall, the setup process was easy.
What about the implementation team?
The deployment and implementation were carried out in-house by our technical team.
What's my experience with pricing, setup cost, and licensing?
Darktrace initially had a high price. After negotiation, we received discounts. Despite the discounts, it is still considered expensive.
What other advice do I have?
I would recommend Darktrace to others as it provides detailed metadata and full visibility of the network environment.
I rate Darktrace a nine out of ten overall.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Enhanced security with automated response but needs refinement in alert management
What is our primary use case?
I am a distributor for several vendors and act as a trusted adviser. Although I do not have an official relationship with Darktrace, I know the product and vendor from working with some organizations in the Netherlands. My clients vary from two hundred fifty seats to fifteen hundred.
How has it helped my organization?
The product features automated response capabilities that clients find beneficial as they look for solutions that feel secure and require less labor. The customers appreciate that the tooling does its work automatically, contributing to a more secure environment.
What is most valuable?
The most valuable feature is the endpoint protection. The autonomous response capabilities are also highly regarded by the market.
What needs improvement?
One area for improvement is the alerting system, which generates too many alerts and becomes labor-intensive for organizations not equipped with enough personnel in their SOC. Aside from that, I am quite fond of Darktrace.
For how long have I used the solution?
I have been working with Darktrace for two years now.
What do I think about the stability of the solution?
Darktrace is perfectly stable.
What do I think about the scalability of the solution?
Darktrace is perfectly scalable, and I would rate it an eight or nine out of ten in terms of scalability.
Which solution did I use previously and why did I switch?
I have experience with other solutions such as Morphisec Endpoint Protection, DeepInStink, Darktrace, Check Point, Defender, Veronis, ForcePoints, Odyxx, and SALT API security.
How was the initial setup?
The initial setup is straightforward. It is easy to install, and it does what it needs to do.
What's my experience with pricing, setup cost, and licensing?
The pricing of Darktrace is perfectly fine and competitive.
What other advice do I have?
I would recommend Darktrace to organizations that have an efficient SOC in place, as the alerting can be a disadvantage for those who are not adequately staffed.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
AI-driven tools enhance security and reduces spam
What is our primary use case?
I am using it for network and email security. I am a systems administrator overseeing cybersecurity at Alpha International Company Limited. We have been using it for about two years, focusing on the latest version.
How has it helped my organization?
Implementing this solution has given us confidence that we are secure. It has improved our network security and email filtering, significantly reducing spam. Overall, it has had a positive impact on our organization's IT operations, providing a comfortable and secure environment.
What is most valuable?
The most valuable features are the AI and advanced learning tools that distinguish it from other products.
What needs improvement?
There are still some issues with the network capturing or blocking traffic even after implementing exceptions. It requires more learning in this area.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
I would rate the stability as a nine out of ten. It is very stable.
What do I think about the scalability of the solution?
The product is scalable, and I would rate it as a nine out of ten for scalability.
How are customer service and support?
The customer support is good and they are responsive. I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I used Barracuda before switching to this solution.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
I led the implementation within my company, with support from them. There was no third-party service involved for training or support.
What was our ROI?
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings. The percentage of budget savings can range from 30% to 40% for online businesses and five to ten percent for in-house processes.
What's my experience with pricing, setup cost, and licensing?
The price is competitively good, although it is a bit on the higher side. I would rate the price a seven out of ten.
Which other solutions did I evaluate?
We evaluated a couple of other products, however, this one suited our pricing and network flexibility.
What other advice do I have?
I would recommend this product to online businesses and infrastructures with more than 250 users.
I'd rate the solution eight out of ten.