Sign in Agent Mode
Categories
Your Saved List Become a Channel Partner Sell in AWS Marketplace Amazon Web Services Home Help

Vectra AI Platform

Vectra AI

Reviews from AWS customer

3 AWS reviews
  • 5 star
    0
  • 3
  • 3 star
    0
  • 2 star
    0
  • 1 star
    0

External reviews

30 reviews
from and

External reviews are not included in the AWS star rating for the product.


4-star reviews ( Show all reviews )

    reviewer2783214

AI‑driven threat detection has transformed alert fatigue and now enables faster response and leaner soc operations

  • November 28, 2025
  • Review from a verified AWS customer

What is our primary use case?

Vectra AI is being used as an NDR solution to sell to customers as a managed service. The product has been productized to sell to customers as an NDR solution. The network is scanned for any anomalies or threats that are detected and fed to the customer's SIEMs and SOARs.

In one financial sector scenario, a customer was complaining about reduced alert fatigue and detecting an attack missed by traditional tools. They wanted an AI solution that could detect anomalies with the best MTTD and MTTR response times to reduce overhead over the SOC teams.

Vectra AI has been used for identity management, which was integrated with Microsoft Entra ID and Active Directory to monitor account activity. A customer wanted in-depth analysis on their identity management solution. Another scenario involved integrating with the customer's cloud solutions, where they wanted a solution that provided cloud detection and response through AWS and Microsoft 365 environments.

What is most valuable?

The best features of Vectra AI are related to AI. For the NDR part, Attack Signal Intelligence features were mainly responsible for behavior AI, high-fidelity signaling, and prioritization. These features were great for anomaly detection and behavioral-based detection, able to catch zero-day attacks and living-off-the-land attacks. For high-fidelity signaling, it automatically triaged, filtered, and correlated signals, which dramatically reduced alert fatigue noise on the customer side by approximately 80% and eliminated alert fatigue on the SOC teams. Regarding the identity detection and response IDR solution, it monitored Active Directory and Entra ID for any attacks, allowing the SOC to detect any compromised credentials.

Alert noise was dramatically reduced by nearly 80%, allowing SOC analysts to focus more on true threats, which made them more productive and resulted in higher operational efficiency. Attack Signal Intelligence helped reduce irrelevant alerts by 80% to 90%, with metrics showing a 100-plus reduction in investigation workloads and roughly saving about 55,000 hours of investigation time. Investigation time has decreased significantly, empowering analysts with detection and advanced unknown threats that Vectra AI provided. Its knowledge base and database are very up to date, allowing for spotting zero-day attacks with full visibility and helping to stop attacks in minutes.

Vectra AI has reduced the MTTD and MTTR, increasing operational and process efficiency, and has helped reduce the number of SOC analysts that needed to be hired. Thanks to the AI features, the number of employees and SOC analysts hired has been reduced.

What needs improvement?

Pricing could be improved, as many customers have complained about the pricing model and pricing complexity.

Regarding the product itself, extending direct control and simplifying workflows would be beneficial. More granular built-in responses and cloud remediations could be improved. A native CMDB-like feature and risk scoring would be a big advantage. Improved compatibility with the SASE ecosystem expansion would also be valuable.

For how long have I used the solution?

Vectra AI has been in use since 2018.

What do I think about the stability of the solution?

Vectra AI is considered a stable solution.

What do I think about the scalability of the solution?

Vectra AI is scalable because it can work through different kinds of solutions and is compatible with all kinds of cloud solutions. The appliance capacity is very good, whether virtual or physical, providing significant scalability.

How are customer service and support?

Customer support receives a rating of nine out of ten due to being very supportive and responding quite efficiently.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

A different solution was not previously used.

What was our ROI?

A good return on investment has been seen. For cost savings over a period of three years, it could be about 350%. The payback period is roughly six months. Productivity savings could be about 800,000, with SOC efficiency increasing nearly 40%. Workload reduction on the SOC side is now 100% lighter than previously.

Which other solutions did I evaluate?

Other options were not evaluated, as at that time, Vectra AI was the only NDR solution that had AI features. They began with the AI concept that was being sought.

What other advice do I have?

Vectra AI should be considered if looking for an NDR solution and not just an EDR solution only. It provides great value and quality, provided that customers can pay for the licenses, which are quite expensive. Vectra AI is represented as a partner and reseller in business with this vendor. This review has been given a rating of eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)


    Atakan Oztuna

Provides managed detections and responses, enhancing companies' network detection capabilities

  • August 04, 2023
  • Review from a verified AWS customer

What is our primary use case?

Our primary focus lies in identifying weaknesses to address customer concerns regarding visibility into network operations. This is especially crucial due to the presence of various managed devices within the network. Detecting and managing these devices and enhancing visibility is done by Vectra AI. It also has the capability to detect potential threats and correlate diverse events that occur on the network. Hackers often target systems from different domains, requiring cross-domain correlation. Net NDR solutions, particularly Vectra, excel in fulfilling these needs using AI-driven algorithms. Over time, these algorithms learn from the data, aiding in automatic post-event analysis.

What is most valuable?

Within Vectra, multiple models exist, including an AI model which is very important. Vectra is very compatible with various cloud providers, such as Amazon and Azure AD. This is helpful as customers often migrate their network infrastructure to the cloud.

Additionally, Vectra provides managed detections and responses, enhancing a company's network detection capabilities. The platform also has attack signal intelligence to identify attackers based on their tactics and techniques, preventing them from compromising critical network devices. So it acts as a detection platform, essential for halting potential threats, including clouds like Amazon and Microsoft 365.

What needs improvement?

We offer two solutions, Vectra and ExtraHop in the Qatar market. However, ExtraHop has better features that seem more advantageous when compared to Vectra. During demos, I encountered challenges with Vectra when demonstrating its capabilities, such as dealing with expired SSL certificates. Vectra AI is capable but ExtraHop is able to provide comprehensive insights and easier data querying. It excels in data query capabilities which is helpful for customers to access and manipulate their data effortlessly. This is where Vectra needs to enhance its capabilities. Customer support and handling high network traffic are additional areas that it needs to work on. There should be more flexible options to handle customers’ needs. Also, customers desire performance enhancements and integration capabilities with a single solution and cyber security.

For how long have I used the solution?

I have been using Vectra AI for two years.

What do I think about the stability of the solution?

I would rate the stability an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability an eight out of ten.

How are customer service and support?

We have a strong local presence and support in this market, and our company's origins in Turkey also contribute to robust local assistance. While comprehensive support is provided during major incidents and upgrades, we excel in offering immediate assistance for failover situations and downtime prevention. The team is highly specialized in cyber security and SOC technologies. We are quite strong and are able to help ourselves in the field of technical support.

How was the initial setup?

The initial setup is straightforward. I would rate the setup an eight out of ten.

In the case of deployment, 70% of the public prefers the public cloud while the rest prefer private. These are the only two forms of deployment.

The initial deployment should ideally be completed within two weeks. However, due to the need for fine-tuning, false positive elimination, and deriving enhanced value, an extended period of around two months is necessary. This allows users to cover all the potential threats and risks, ensuring comprehensive coverage

What's my experience with pricing, setup cost, and licensing?

The solution is low-cost and affordable.

What other advice do I have?

Vectra faces robust competition, but it substantiates its abilities. Depending on client needs, it can easily work with other IT solutions. Yet, for pure network detection and response, Vectra excels, particularly for enterprises demanding very good solutions. It offers superior detection coverage for heightened security. It has an encryption-based approach, enabling threat detection without decrypting any data. Moreover, Vectra stands out with its broad integration capabilities with third-party tools and I personally find it a successful feature.

Overall, I would rate Vectra AI an eight out of ten.


showing 1 - 2