
Overview
The Darktrace ActiveAI Security Platform provides a full lifecycle approach to cyber resilience that can autonomously spot and respond to known and unknown in progress threats within seconds across the entire organization, including cloud, apps, email, endpoint, network, and operational technology (OT). With its groundbreaking Self-Learning AI, Darktrace continuously learns and updates its knowledge of your business data and applies that understanding to help transform security operations and improve cyber resilience.
Highlights
- Darktrace protects over 9,400 organizations globally from known, unknown and novel cyber-threats.
- Darktrace ActiveAI Security Platform delivers a proactive approach to cyber resilience in a single cybersecurity platform, providing preemptive visibility into security posture, real-time detection, and autonomous response to known and unknown threats without disrupting business operations.
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(2)


Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
30-day Trial | Free Proof of Value (POV) | $0.00 |
Legacy Model | Up to 300 Mbps of average bandwidth. 200 Hosts | $30,000.00 |
Legacy Model | Up to 2 Gbps average bandwidth. 1000 Hosts | $60,000.00 |
Legacy Model | Up to 5Gbps average bandwidth. 10,000 hosts | $100,000.00 |
Vendor refund policy
Per Section 7.1 of the Darktrace Master Services Agreement: https://darktrace.com/legal/master-services-agreement
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Customer Portal support tickets and Phone support +44 (0)8081 893465
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Monitoring has improved data loss detection and now spots abnormal internal file transfers quickly
What is our primary use case?
My main use case for Darktrace is to identify remote connections and abnormal connections such as FTP or any kind of RDP happening inside our LAN network or company network, where we want to verify the data transfers and check if any abnormal user is transferring data through the network to the outside, or any kind of suspicious activity.
One specific example of a situation where Darktrace helped me spot something unusual is when one of the employees tried to copy some of his data to the outside. He is a developer trying to implement an application in a cloud environment, and while he was copying his file from inside our network to a cloud network, we got an alert, which we considered significant because he had not done it earlier, as it was an initial step in his developing environment. Because of that alert from Darktrace, when we checked with him, it was actually a legitimate activity.
How has it helped my organization?
Darktrace impacts my organization positively by providing us with a better understanding of abnormal activities detected among users.
The positive impact includes helping us identify a lot of transfers and abnormal activities, as some users try to perform RDPs inside our network, using LAN for different desktops or laptops, making it quite useful to identify users, especially those from a non-technical background.
What is most valuable?
In my understanding, the best feature Darktrace offers is the identification of copying files, which acts as a DLP , and it is a main concern for companies because users sometimes copy data outside without knowing, especially those without a technical background.
When I mention the DLP-like feature and file copying detection, the alerts have been very timely, as we get an alert within a couple of minutes, which is excellent. Even if some developers are working after hours and copying files, our SOC team detects this, and most of the time they call us so we can identify the users. The alerts are quite accurate and proactive.
What needs improvement?
As of now, I feel Darktrace can be improved to better detect end device activities, such as laptops or desktops, to bind it with our network.
For how long have I used the solution?
I have been using Darktrace for around two years.
What do I think about the scalability of the solution?
Regarding scaling, we initially planned for 2,000 to 4,000 devices, but we did not add any additional licenses for more devices after implementing Darktrace.
How are customer service and support?
The customer support from Darktrace is good. We reached out to them a couple of times to check on some features, and they helped us very effectively.
How would you rate customer service and support?
Negative
How was the initial setup?
Integrating Darktrace with our existing security tools was not difficult at all. We simply SPAN our core network port into the Darktrace side, and we did not face any difficulties at that time.
Which other solutions did I evaluate?
In terms of the interface and reporting, I believe Darktrace is good. I have also worked with ExtraHop, and compared to them, I feel Darktrace is way ahead, so I do not have any improvement suggestions for reporting views.
What other advice do I have?
Darktrace is a very good tool, and we introduced it after we had an incident in a previous company, where we faced an attack and that is when we introduced this tool, which helped us identify a lot of abnormal activities, mainly from our developing team. My company is quite large with around 8,000 employees and they are developing a lot of things without our knowledge.
Although I do not have exact numbers, I can say that our security posture has improved a lot since implementing Darktrace, especially as our SOC team monitors the activities and we communicate with users about the need to stop certain activities.
During my time at the company, we did not find any zero-day threats or unusual attacks, but we noticed certain abnormal activities done by users.
My advice for others looking into using Darktrace is that for large-scale companies with huge teams, especially developers working separately from the system teams, it is crucial to implement security measures, as sometimes the most vulnerable positions come from those in technical backgrounds who can create security loopholes. In such environments, having tools Darktrace is essential to improve the organization's security posture without compromising their reputation. I would rate this product a 9 out of 10.
Intelligent threat response has improved incident handling and provides clear attack path visibility
What is most valuable?
Regarding the autonomous response feature, I appreciate how it functions within the platform.
What needs improvement?
Based on my experience, I believe the solution could be improved in some areas, and there are certain drawbacks that I have encountered.
For how long have I used the solution?
I have been working with Darktrace for approximately one to one and a half years or longer.
What do I think about the stability of the solution?
In general, I would say that the interface of Darktrace is intuitive enough, and it aids in understanding threat landscapes and attack paths.
What do I think about the scalability of the solution?
Regarding scalability, I would rate it eight points.
How are customer service and support?
If asked to rate Darktrace support on a scale from zero to ten where ten is the best, I would give them five points.
How would you rate customer service and support?
Neutral
How was the initial setup?
Regarding the installation and initial setup, I found it to be straightforward rather than complex.
What's my experience with pricing, setup cost, and licensing?
Concerning pricing for the product, I would say it is somewhat expensive.
What other advice do I have?
I have rich experience with many tools including Vectra, Cisco firewall, and Check Point.
Great product, protects manufacturing environments
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
What is our primary use case?
The typical use case for Darktrace is for threat vector scanning, detecting any unusual activity, and anomaly detection. Apart from that, it is very helpful in incident response.
What is most valuable?
The features I find most effective in Darktrace include anomaly detection. The machine learning model provides accurate alerts after the learning period of 1 or 2 weeks, especially for network anomalies or something that the user is trying to access, which can include trying to visit unknown sites or botnets, and those things get detected and represented in a very good dashboard.
Darktrace positively impacts my organization by enhancing threat hunting, particularly in east-west traffic within the same subnet. Previously, we only used traditional firewalls that cannot catch this lateral traffic. After deploying Darktrace, we gain insights into machine-to-machine communication, which adds more value to the organization and is especially beneficial for the SOC team.
What needs improvement?
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
For how long have I used the solution?
I have been familiar with Darktrace for the last 5 to 6 years.
What was my experience with deployment of the solution?
In terms of the speed and effectiveness of Darktrace's automatic response, it gives clear alerts whenever anomalies happen on the network, enabling us to catch them on the fly. However, some of the rules generate false positives, especially with system calls, which get incorrectly marked as anomalies. These are actually system call integrations that need fine-tuning based on our environment integrations.
Regarding Darktrace's capability to adapt and recognize abnormal activities through machine learning and AI, sometimes a password expiration prompts the user to connect to different sources to get the new password changed. During that time, it picks this up as abnormal activity when connecting to LDAP during off-business hours. This is an example of how it detects what it considers an anomaly, since user authentication typically happens during business hours.
What do I think about the stability of the solution?
Regarding overall stability, Darktrace is a stable product, and I have no complaints from customers wherever it is deployed.
What do I think about the scalability of the solution?
While considering if Darktrace is scalable, I note that there are storage limitations, where the planned capacity can sometimes be overutilized. There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
How are customer service and support?
I can rate Darktrace's technical support as one of the best products in the world. We have seen satisfaction reflected on our customers' faces after deployment when they start seeing the data and the dashboard, and they often express surprise at the network traffic visibility that Darktrace provides.
I would rate the technical support of Darktrace between 6 to 8, as the support is good and we receive timely assistance whenever we raise an issue.
Which solution did I use previously and why did I switch?
Before working with Darktrace, I did not use any similar solution in the same category. Earlier, I was using something called decepters, and my organization may have explored different products, but I learned about network detection and response through Darktrace about 5 to 6 years ago.
How was the initial setup?
Deploying Darktrace is quite easy and plug and play, wherein all we need is to put it in a data center, rack up, and do some switch configuration. The learning would take a week time, and once the data gets populated, we get a very good dashboard.
What about the implementation team?
For deploying Darktrace, I would require 3 to 4 people. We would require a data center person to assist in racking and mounting this, and some network engineers would make this configuration to spend the data ports.
What was our ROI?
When considering return on investment for organizations using Darktrace, the disadvantage lies in having to use a physical appliance. Running a quick POC is not possible since the hardware has to be shipped from the UK or elsewhere, but other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
What's my experience with pricing, setup cost, and licensing?
In terms of setup and licensing costs, Darktrace is on the pricier side compared to similar solutions in the NDR market. Other NDR solutions are also on the higher side, but Darktrace stands out as a bit higher. Competitive pricing would certainly help me as a system integrator to convince customers.
Which other solutions did I evaluate?
I did not evaluate other options when looking into Darktrace, but some customer preferences led us to consider other NDR solutions, such as 40 NDR. Our customers had a Fortinet setup with various products, and they preferred the 40 NDR for proprietary visibility when collecting logs from Fortinet devices.
What other advice do I have?
We are using the latest version of Darktrace. I have not used Darktrace's Enterprise Immune System. Antigone is the feature of Darktrace that we have recently experienced. At the moment, I have not encountered a situation where Darktrace's self-learning capabilities reduced the risk of data breaches, but it performs very effectively overall. It requires some time to adapt; initially, when we deploy, it takes weeks. On a scale of 1-10, I rate Darktrace a 9.
Provides effective email protection but support could improve
What is our primary use case?
What is most valuable?
Regarding the ROI, we have experienced a significant reduction in phishing emails and have utilized our time efficiently, resulting in approximately 70% ROI.
What needs improvement?
The support is the main problem, though there are some other issues as.
For how long have I used the solution?
What was my experience with deployment of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
How would you rate customer service and support?
Neutral
How was the initial setup?
What about the implementation team?
What's my experience with pricing, setup cost, and licensing?
What other advice do I have?
In terms of AI functionality, I have seen some AI integrations overall. Darktrace is completely designed based on AI and machine learning, making it very efficient in identifying suspicious behavior and suspicious emails.
We are using the Securonix SIEM solution, and from ManageEngine, I use Help Desk and the Patch Manager .
On a scale from 1 to 10, I would rate Darktrace as six points.