Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Vectra AI Platform

Vectra AI

Reviews from AWS customer

3 AWS reviews
  • 5 star
    0
  • 3
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

29 reviews
from and

External reviews are not included in the AWS star rating for the product.


    Sajid Mukhtar

The solution provides advanced threat detection and operates based on metadata, offering comprehensive information about traffic between source and destination

  • September 11, 2023
  • Review from a verified AWS customer

What is our primary use case?

This tool operates on machine learning principles, utilizing its own AI-based models and rules to detect activity within your environment. Initially, Vectra AI observes and monitors your organization's behavior for a two-week period, identifying legitimate services operating within your environment. Once it completes this monitoring phase and detects all services, it begins to assign certainty and severity levels to the network traffic it observes.

What is most valuable?

Vectra AI offers a range of valuable features. Firstly, it utilizes its own AI-based tools. Secondly, it provides various dashboards that facilitate the identification of connections and can detect data exfiltration, meaning data sent from your environment to another. The tool operates based on metadata, offering comprehensive information about traffic between source and destination. Some key features include the ability to integrate with EDR or EPP solutions, allowing you to secure servers with stability issues or infections. Alternatively, you can use Active Directory to lock down infected hosts if you choose not to incorporate EPP or EDR. These features provide insights into your network, showing connection details, data transfers, VPN connections, and the number of connected EDS event hosts, among other things.

What needs improvement?

One area where there's room for improvement is the absence of a comprehensive TCP recording and replay feature. While there is an alternative method available, it doesn't provide the same functionality in a graphical interface.

For how long have I used the solution?

I have been using Vectra AI for the past 12 months.

What do I think about the stability of the solution?

In terms of stability, I've been using it for the past month, and I haven't encountered any significant issues or downtime. Based on this one-month experience, I would rate its stability as a seven out of ten.

What do I think about the scalability of the solution?

Scalability is excellent and I would rate it a 10 out of 10. Expanding the sensor capacity is relatively straightforward. However, it's crucial to plan for scalability during deployment. If an organization anticipates significant traffic, they should choose a brain that can handle it. Selecting a smaller brain initially and then attempting to expand later may lead to challenges. The scalability largely depends on the organization's needs and Vectra's ability to accommodate them.

How are customer service and support?

From what I've heard, the support team is responsive and helpful. However, I haven't had the opportunity to directly interact with the technical support team.

How would you rate customer service and support?

Positive

How was the initial setup?

The on-prem setup requirement is something easy. However, the cloud's environment setup is a bit tricky and complex. Not only because of the Vectra but also due to the some limitations of the cloud setup. The deployment process varies depending on the organization's size and footprint. It typically takes about one week for data centers with a dispersed network across different regions. For Vectra, on-premises deployment is relatively straightforward, but the cloud deployment can be more complex.

The deployment process involves adhering to ITIL processes, including change management. This entails creating change requests and engaging Smart Hands for physical sensor deployment or allocating VM resources for virtual sensors. Network availability and coordination are essential aspects of the deployment process. In simple terms, it involves a well-defined change management process and various steps to ensure a successful deployment. I would rate it a six out of ten.

What's my experience with pricing, setup cost, and licensing?

It's relatively on the pricier side, but when compared to other solutions. It's not the most budget-friendly option, but it can be considered somewhat more cost-effective in comparison to other alternatives.

I would rate it a seven.

What other advice do I have?

I would advise other organizations using Vectra to ensure they fine-tune their service groups, correctly label their services, and integrate their firewalls and AWS systems. This will help obtain accurate and updated information about DMZ tools, VPN tools, and EC2 tools, allowing Vectra to have better visibility into the services running. This, in turn, can improve the accuracy of the scan feed and provide more precise results, reducing false positives.

Overall, I would rate it seven out of ten.


    Dan Jeske

The solution's marketing is not good, but it has the ability to detect intrusion on the network

  • August 11, 2023
  • Review provided by PeerSpot

What is our primary use case?

We've introduced Vectra AI to our clients and had it in proof of concepts with other technologies like Darktrace for network detection and response.

What is most valuable?

Vectra AI can bring the ability to detect intrusion on the network more so than legacy IDS tools. It goes beyond just doing sample packet capture as Corelight does and provides value to the customer regarding their reporting and what the tool is doing.

What needs improvement?

The solution's marketing is not good. It probably needs to refresh its branding because a lot of it is confusing. People see it as an expensive tool for what it actually does.

For how long have I used the solution?

I have been working with Vectra AI for five years.

What do I think about the scalability of the solution?

With tools like Vectra, the more you want to scale, the more you have to ingest, and the higher your costs are. So scalability can be there, but it also comes with an increased price.

How are customer service and support?

The solution's customer support is fairly strong.

How was the initial setup?

Vectra AI didn't have a SaaS model until recently. Companies don't like deploying something complex that'll turn customers away. From what I understand, Vectra AI is somewhat complex in its deployments.

What other advice do I have?

The technology is strong, but everything around the technology outside of support is weak. Vectra AI needs to find a way to make it more cost-effective for customers to compete with some of the other tools on the marketplace that customers are buying. Vectra AI should do sample packet captures for clients with different use cases. They're trying to forcefully push their tool on the market when the market wants something else.

Overall, I rate Vectra AI a five out of ten.


    Atakan Oztuna

Provides managed detections and responses, enhancing companies' network detection capabilities

  • August 04, 2023
  • Review from a verified AWS customer

What is our primary use case?

Our primary focus lies in identifying weaknesses to address customer concerns regarding visibility into network operations. This is especially crucial due to the presence of various managed devices within the network. Detecting and managing these devices and enhancing visibility is done by Vectra AI. It also has the capability to detect potential threats and correlate diverse events that occur on the network. Hackers often target systems from different domains, requiring cross-domain correlation. Net NDR solutions, particularly Vectra, excel in fulfilling these needs using AI-driven algorithms. Over time, these algorithms learn from the data, aiding in automatic post-event analysis.

What is most valuable?

Within Vectra, multiple models exist, including an AI model which is very important. Vectra is very compatible with various cloud providers, such as Amazon and Azure AD. This is helpful as customers often migrate their network infrastructure to the cloud.

Additionally, Vectra provides managed detections and responses, enhancing a company's network detection capabilities. The platform also has attack signal intelligence to identify attackers based on their tactics and techniques, preventing them from compromising critical network devices. So it acts as a detection platform, essential for halting potential threats, including clouds like Amazon and Microsoft 365.

What needs improvement?

We offer two solutions, Vectra and ExtraHop in the Qatar market. However, ExtraHop has better features that seem more advantageous when compared to Vectra. During demos, I encountered challenges with Vectra when demonstrating its capabilities, such as dealing with expired SSL certificates. Vectra AI is capable but ExtraHop is able to provide comprehensive insights and easier data querying. It excels in data query capabilities which is helpful for customers to access and manipulate their data effortlessly. This is where Vectra needs to enhance its capabilities. Customer support and handling high network traffic are additional areas that it needs to work on. There should be more flexible options to handle customers’ needs. Also, customers desire performance enhancements and integration capabilities with a single solution and cyber security.

For how long have I used the solution?

I have been using Vectra AI for two years.

What do I think about the stability of the solution?

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How are customer service and support?

We have a strong local presence and support in this market, and our company's origins in Turkey also contribute to robust local assistance. While comprehensive support is provided during major incidents and upgrades, we excel in offering immediate assistance for failover situations and downtime prevention. The team is highly specialized in cyber security and SOC technologies. We are quite strong and are able to help ourselves in the field of technical support.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is straightforward. I would rate the setup an eight out of ten.

In the case of deployment, 70% of the public prefers the public cloud while the rest prefer private. These are the only two forms of deployment.

The initial deployment should ideally be completed within two weeks. However, due to the need for fine-tuning, false positive elimination, and deriving enhanced value, an extended period of around two months is necessary. This allows users to cover all the potential threats and risks, ensuring comprehensive coverage

What's my experience with pricing, setup cost, and licensing?

The solution is low-cost and affordable.

What other advice do I have?

Vectra faces robust competition, but it substantiates its abilities. Depending on client needs, it can easily work with other IT solutions. Yet, for pure network detection and response, Vectra excels, particularly for enterprises demanding very good solutions. It offers superior detection coverage for heightened security. It has an encryption-based approach, enabling threat detection without decrypting any data. Moreover, Vectra stands out with its broad integration capabilities with third-party tools and I personally find it a successful feature.

Overall, I would rate Vectra AI an eight out of ten.


    reviewer2197812

Provides real-time visibility of potential threats to the network and prioritizes them to help us react quickly

  • May 29, 2023
  • Review provided by PeerSpot

What is our primary use case?

We use it as our internal network monitoring solution.

How has it helped my organization?

It's interesting to consider how it has helped our organization because it's a security product. But the way it has helped is that nothing has gone wrong. And it has certainly enhanced our internal security capabilities.

Vectra has helped accelerate our threat investigations, providing us with real-time visibility of potential threats to the network that we can act upon or triage accordingly. Prior to the implementation of Vectra, we didn't have that visibility. We had a number of disparate security tools, each with its own alerting functionality. Vectra has significantly helped with a consolidated view of potential threats. And the prioritization of threats allows us to focus specifically on those threats that we believe present the greatest risk and to react to those threats extremely quickly.

Vectra MDR is also very important for us, given the relatively small size of our internal team, and it gives us 24/7 capability that we didn't have before we used Vectra's MDR service.

What is most valuable?

We particularly like the user experience around the dashboard, which we find to be much more straightforward than the dashboard of some of the competitive products. In the grand scheme of things, we're a relatively small organization with approximately 1,000 users and a small internal security team. Compared with some of its competitors, Vectra is a really easy system to understand and use to prioritize where we need to focus our security resources.

We use Microsoft 365 and Vectra extends our ability to track attacker activity, whether that happens on-premises, in a data center, or in a SaaS environment. It provides complete coverage and visibility across our ICT estate. That was a real positive when we were going through the selection process. The simplicity of the dashboard and the categorization of alerts as low, medium, high, or critical, presents us with the potential of a security risk. We can then choose to investigate it, regardless of whether it's an on-premises or cloud-security risk. They are presented in the single-pane-of-glass dashboard, and that allows us to take the appropriate action. The detection and prioritization of attacker behaviors are extremely important.

What needs improvement?

A blind spot that I have is around the ease with which you can automate threat intervention.

For how long have I used the solution?

We've been using Vectra AI for approximately 12 months.

What do I think about the stability of the solution?

It seems to be extremely stable. We've not had any issues in that respect.

What do I think about the scalability of the solution?

Vectra has visibility across our entire ICT network, which is a combination of on-premises and cloud environments. Our cloud solution is Azure, and it extends to about 1,000 users. The vast majority of them are now remote or mobile workers.

It has comfortably managed the needs of our organization and I don't have any concerns if we were to need, at some point in the future, to either scale or switch the current balance between on-prem and cloud.

How are customer service and support?

We are very satisfied with the support. It has been excellent so far. It has been very timely, very personalized, and always quick to find solutions. We've been really pleased with it.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We didn't have a previous solution. We have no internal networking monitoring capability.

How was the initial setup?

We started with a proof of concept and then we committed to the Vectra solution. That's when we began the formal implementation. From the very initial engagement to the proof concept and through the transition to service, it took approximately six months.

The deployment went very well and that was a real positive in terms of the engagement with the onboarding and the customer experience.

Across our ICT team, six individuals were involved in security, infrastructure, project management, and service transition.

There is no maintenance of the solution on our side.

What about the implementation team?

The implementation was supported directly by Vectra UK itself.

What was our ROI?

The return on investment from the product comes from not incurring unplanned costs because of a security incident.

What's my experience with pricing, setup cost, and licensing?

The upfront pricing model that we have would have been more beneficial if it had been a recurring license fee, but that wasn't a massive issue for us. It's fairly priced.

Which other solutions did I evaluate?

We evaluated other options very thoroughly. It became a two-horse race between Vectra and Darktrace. The differentiators for us were the UI experience, the MDR, and we felt that there was better engagement with the Vectra presales team. They better understood our needs and how Vectra would fit as a solution.

What other advice do I have?

The percentage of critical alerts from Vectra that are critical or true positives, to be fair, is relatively small, probably about 10 percent, but that's more a reflection of the fact that we're still a relatively new client and that the system is still learning. What we have noticed though is that the triage process is effective and we don't get multiple false negatives once we've identified an issue.

We bought Vectra AI through our IT partner, which is CDW. They were only involved in the procurement process. We used a partner to ensure that we could demonstrate that we had done so according to compliance.

I would definitely recommend Vectra and to do a proof of concept. We learned quite a lot through that proof-of-concept process. Those lessons certainly helped us when we went into the implementation process and to engage internal ICT team stakeholders and anticipate central issues in the implementation process. A proof of concept would be invaluable for anybody thinking about implementing this or one of the competitive solutions.

At the moment, we're really pleased with the product and it's a really good fit for the size of our organization.


    Paul D.

Team Manager, Enterprise Information Security

  • September 17, 2020
  • Review provided by G2

What do you like best about the product?
Ease of deployment, intuitive UI, and easy to work with sales and support staff.
What do you dislike about the product?
Reporting is lacking, currently only one report available with different timelines, also no ability to export from the console.
What problems is the product solving and how is that benefiting you?
Visibility of network traffic, analysis of network traffic, and baselining.


    Joel V.

Easy to deploy and works great at finding evil.

  • September 11, 2020
  • Review provided by G2

What do you like best about the product?
Vectra finds what other controls miss. It is used to help with network visibility and integrates great with Splunk. We have passed every pen test since Vectra was deployed. The company has really listened to the customers and made big improvements over the last three years.
What do you dislike about the product?
It can get expensive if you have a lot of offices. The appliances are not cheap so if you have a bunch of smaller offices it can start to add up.
What problems is the product solving and how is that benefiting you?
Network visibility in east-west traffic is our primary use. Because we ingest the data in Splunk it is also used to evaluate incidents and help make decisions on incident prioritization.
Recommendations to others considering the product:
Vectra helps IR teams with prioritizing events. It can take some time to get everything reporting correctly so use the Vectra resources to help create the rules and whitelisting events is recommended.


    Information Technology and Services

Unbeaten speed of innovation

  • August 27, 2020
  • Review provided by G2

What do you like best about the product?
Vectra does what it says on the tin, but goes beyond in providing a constant. speed of innovation that means they are constantly releasing new features. and detections, helping us to keep up to speed with any threats on our network
What do you dislike about the product?
As with any security tool, the alerts! But thankfully by monitoring the. quadrant based approach serious issues boil up for quick investigation.
What problems is the product solving and how is that benefiting you?
East-west visibility and identification of dark/unknown IT


    Financial Services

Vectra AI Review

  • July 07, 2019
  • Review provided by G2

What do you like best about the product?
This is a high quality anomaly detection tool, very easy to understand and it helps very nicely to get reports, PCaps, and lets you see in an easy way what is happening in the network, this has top of the line algorithms, I simply love this product.
What do you dislike about the product?
Is very long process to tweak it to the point that it works perfect, but once that is done this is a beast
What problems is the product solving and how is that benefiting you?
Monitoring the network for cyberattacks
Recommendations to others considering the product:
This is an awesome tool for recognizing cyberattacks in real time


    Sandy S.

"A good threat tool"

  • June 29, 2019
  • Review provided by G2

What do you like best about the product?
Generally excellent instrument to identify and stay away from digital assaults utilizing man-made consciousness progressively. Interestingly, the device advances as the strategies of digital assaults advance gratitude to the way that it depends on a man-made brainpower that is found out and improved after some time. It permits to discover digital assaults and dangers in the cloud, server farm and in business situations.
What do you dislike about the product?
Need all around data of the instrument to recognize possible security perils. This puts aside chance to end up acquainted with the product.I severely dislike about this is you need a minium of knowleadge about you see beacuse its overflowing with therms without information
What problems is the product solving and how is that benefiting you?
The eventual fate of security needs to settle on choices for people, however help people settle on choices all the more rapidly. This innovation is genuinely a power multiplier in an industry that is suffocating in information that necessities to drive choices.
Recommendations to others considering the product:
At present I would state that it is the best stage to distinguish, forestall and anticipate cyberattack dangers. My organization is one of the biggest banks on the planet and has depended on this instrument, after a long investigation by the IT specialists of the organization.


    Irene M.

Good protection program

  • April 21, 2019
  • Review provided by G2

What do you like best about the product?
Sweep the different types of utilization and source code for escape clauses. The unauthorized channel demands dependencies of the ordering. Send warnings instantly following a suspicious ongoing movement condition. The screens and user interface are extraordinary in terms of customer experience. Easy to introduce/incorporate. Process programmed for framework and application filtering. Offers numerous setups to configure on the distinctive board. The emotional support network is exceptionally large from the vectra systems.
What do you dislike about the product?
Internal and external information about the instrument is needed to distinguish possible safety hazards. This sets aside the opportunity to get used to the product. I detest this because it requires a minimum of knowledge about its presence, as it is full of data without data.
What problems is the product solving and how is that benefiting you?
Many of our clients worry about this danger, especially nowadays. This allows our clients to feel comfortable. We use this to see the problems in the organization's system.
Recommendations to others considering the product:
A completely solid article for any information-sensitive application. We have achieved incredible results so far. Very good device. This is surely prescribed.