ExtraHop RevealX Threat Detection and Response logo

    ExtraHop RevealX Threat Detection and Response

    Sold by
    Quickly identify, investigate, and respond to threats with SaaS-based RevealX, an agentless network detection and response (NDR) solution for cloud and hybrid security.

    Ratings and reviews

    4.6
    75 ratings
    3 star
    1 star
    78%
    19%
    0%
    3%
    0%
    0 AWS reviews
    |
    75 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (75)
    Insurance

    Complete visibility on network activity

    Reviewed on Jul 31, 2025
    Review provided by G2
    What do you like best about the product?
    What I like most about ExtraHop is the ability to monitor and analyze all traffic passing through the network. Generally, companies have strong endpoint controls through tools like EDR; however, network is often limited to firewalls with intrusion detection and intrusion prevention rules. Where I find ExtraHop excels is through complete network visibility by mapping assets, learning network traffic and spotting anomalies, and giving Security Operations teams visibility into what is occurring on their network.

    ExtraHop is easy to deploy through either and appliance on physical networks our through a virtual appliance in the cloud. The Customer Success teams are deeply knowledgable and provide great support to customers.
    What do you dislike about the product?
    Not a dislike but a feature I would like to see is ExtraHop move towards prevention. Currently, the product is good at identifying and detecting suspicious or malicious activity. Prevention can be achieved through integration with tools but it would be nice to have these native to ExtraHop.
    What problems is the product solving and how is that benefiting you?
    Whenever we perform penetration tests, ExtraHop is always the first tool to detect the activity. Often times, the penetration testers will start their campaigns performing reconnaissance and trying to remain stealthy. Because they are not attempting to exploit vulnerabilities at this stage and may be using legitimate system tools, these actions would usually go unnoticed. By inspecting all network traffic, ExtraHop is quick to determine unusual activity on the network host even if it is not a managed device. The network traffic can be inspected by SOC teams and actions can be taken to contain the suspicious device.
    Henri Heuvel

    Cloud-based administration streamlines network security management

    Reviewed on Jul 11, 2025
    Review provided by PeerSpot

    What is our primary use case?

    The typical use case for ExtraHop Reveal(x) that we use is from a security perspective, specifically Network Detect and Response. The ExtraHop solution has both the network analytics and the security side of it, and a typical use case is the security side of the entire solution.

    We position it in a network to do security-based analytics, detections, and threat and anomaly detection. That's what we position it for and use it for.

    What is most valuable?

    The best features of ExtraHop Reveal(x) include the cloud-based Reveal(x) 360, which is an absolute plus. You've got one point of administration where you can attach multiple vendors or solutions or sensors, and that's good.

    The plus is the capacity of the different sensors that the ExtraHop solution has; it's quite big compared to the price it costs, and the detailed dashboarding is a big plus to get proper insights on both traffic and asset visibility within the network.

    The machine learning-driven behavioral analysis feature is quite useful. I do quite a lot of POVs with customers for a period of four weeks, and I always tell them that in the first week, week and a half, the machine needs to learn the network. Customers appreciate it, so that's good.

    On the other side, it gives you clear insights into what the normal baseline would be and what the actual deviation is after machine learning has understood how the network functions. It's very useful.

    What needs improvement?

    ExtraHop Reveal(x) can improve regarding integration capabilities. For instance, the market is getting really flooded with Microsoft Sentinel, and I know there is an integration possible, but the tools on the market right now indicate that integration should not be a skill from an integrator point of view. It should be quite easy for customers to integrate that solution into SOCs, SIEMs, or any other integration with other tools.

    There are various integrations from which there's a manual on how to do it, but specifically, the Microsoft portfolio, particularly Sentinel, integration is not yet there. If you score them on a scale of one to ten, ExtraHop scores around a 7.5 to an 8 on an integration basis, but there's actually room for improvement on that side.

    In the older days, ExtraHop had a license model where you could do all you can eat, so if you had a sensor with 10 gig of capacity, you could use all the entire 10 gig of throughput. They changed that to an asset-based license model, and that's an absolute downside of the solution, where it is harder for smaller companies to acquire the solution itself.

    That has given us quite some problems in positioning the solution properly within the network, so the licensing model is an absolute downside where they need to improve.

    For how long have I used the solution?

    With ExtraHop specifically, I have about three and a half years of experience.

    What do I think about the stability of the solution?

    I think it is a stable solution.

    What do I think about the scalability of the solution?

    ExtraHop Reveal(x) is absolutely a scalable solution.

    How are customer service and support?

    I would rate the technical support from ExtraHop a solid eight. It's not exceptional, but it's definitely not bad. There are a lot more worse examples in the market, so it's good and we are happy.

    What was our ROI?

    My clients do see an ROI from ExtraHop Reveal(x); they see the value of the solution within the network, and it gives them solid confidence that they actually do see everything that's going across it.

    Looking at the Dutch market, where I am based, and looking at the positioning and the customer base, for instance, educational customers with 20,000 clients find the price has a high impact on positioning it properly within educational environments.

    In contrast, if you look at healthcare, where there are quite a lot of devices in the network or people that come and go, the amount of devices can become quite high, impacting the licensing model of ExtraHop and therefore the cost. The cost and return on investment are relative; if you have an enterprise customer with a static environment, it's quite easy to accept the cost and therefore see the return on investment. However, with other verticals, it's a lot harder to position the solution successfully.

    What's my experience with pricing, setup cost, and licensing?

    We manage the setup cost ourselves, so I am quite happy with that. I also had engagement with professional services from ExtraHop, and it wasn't bad, but I was not impressed; it's not academic work. Pricing-wise, they are not cheap, but they also offer quite a lot of features. Pricing is subjective to different customers.

    What other advice do I have?

    My advice to others considering ExtraHop Reveal(x) is don't doubt, just get it and make sure you have the money because the return on investment will prove itself, and you only need to have one problem for the solution to prove its value. On a scale of one to ten, I rate ExtraHop Reveal(x) an eight.

    reviewer1375044

    Delivers insightful network monitoring with detailed connection visualization

    Reviewed on May 29, 2025
    Review provided by PeerSpot

    What is our primary use case?

    Being in a financial institution, we have certain regulations such as PCI DSS, so we want to ensure any connection from a non-PCA segment is not being connected to a core segment; vice versa connection should not happen. We have something called a server segment and a workstation segment, so apart from the whitelisted internet connection, no connection should be established from the server segment. These are the monitoring use cases we have implemented in ExtraHop Reveal(x) so far.

    What is most valuable?

    The best features of ExtraHop Reveal(x) for me are the depth it provides, especially the picturization where the connection is established; it's absolutely remarkable. If I want to know a specific IP and which server it has been connected to, it's easy to gather those kinds of trees from the NDR.

    ExtraHop is very customizable, it's easy to access, and I can understand the flow where an IP address or email address has reached which level of security system; it's very easy to follow that flow.

    What needs improvement?

    I would like to see improvements in areas where events are getting dropped; we're not able to view complete insights. For example, if I'm sending communication from one place to another while passing multiple security controls, it's not giving a complete flow easily. It shows one communication from the firewall, then one from the firewall to the proxy, and one from the proxy to the user endpoint as separate communications. There's no way to uniquely correlate that this is the same communication happening throughout that packet flow.

    For how long have I used the solution?

    I have been working with ExtraHop Reveal(x) for two to four months. It is a new product.

    What was my experience with deployment of the solution?

    The integration with other security and IT operation tools has been implemented through an agent on the network level, and we are not facing any issues while deploying the agents. We've done integration only with the SIM solutions, specifically QRadar, and we don't find any issues there. The only consideration is that its rules are very noisy, and we need to fine-tune extensively; custom fine-tuning is completely required when bringing NDR into the picture.

    Which other solutions did I evaluate?

    At the moment, we are using different endpoint solutions, including EDR, and we have extra NDR solutions.

    XDR is from Microsoft, and MDR is not from Microsoft; it's ExtraHop.

    What other advice do I have?

    ExtraHop Reveal(x) is a new solution for me, from an NDR SIM perspective, that's a monitoring solution we have just implemented. We are not sure how efficient an NDR is to detect network-level threats; it needs to be explored.

    At the moment, we don't use the machine learning driven behavioral analysis feature; we're not sure where the data will be hosted and where it will be sent, so we don't want to do any kind of AI-based and machine learning-based decision making.

    We don't want to decrypt any of the information; it's supposed to be captured based on the network flow of the packets without opening or reading them, considering the sensitive information stored under the packets.

    I have not put any statistics or metrics to evaluate the effectiveness of ExtraHop Reveal(x) at the moment; it's still on the roadmap. This is an experience from SIM, and many stakeholders also need to be given feedback on the effectiveness, especially to validate with the business if it's blocking any genuine operations which cause an impact or not.

    So far, I am using only EDR, the Microsoft EDR, for containment and related activities; there is no automation at the NDR level at the moment, but it is in the roadmap for future use.

    If you have proper network segmentation, then I would recommend going for this kind of NDR monitoring with ExtraHop Reveal(x) as it provides more insights about what is happening in the networks. If you don't have network segmentation and only small subnets of IPs, I suggest not to go for NDR solutions because they won't add any value, even if you have many solutions on your network.

    I would rate ExtraHop Reveal(x) eight to nine out of ten.

    reviewer2590266

    Improved user experience with intuitive interface and crucial update notifications

    Reviewed on Oct 31, 2024
    Review provided by PeerSpot

    What is our primary use case?

    We have IoT devices, network traffic, and all these traffic. ICT and non-ICT, all.

    How has it helped my organization?

    I am not sure about the specifics of how ExtraHop Reveal(x) has changed our approach. The cybersecurity team could elaborate more on this topic.

    What is most valuable?

    The solution offers a friendly GUI for security features.

    What needs improvement?

    We expect regular firmware patches for upgrades and maintenance. Currently, we have to check manually as we do not receive any notifications about new patches, maintenance, or firmware releases. It would be beneficial if they could send us notifications for new releases and maintenance trials.

    For how long have I used the solution?

    I have been working with Reveal(x) for two years.

    How are customer service and support?

    The technical support is good, very good. I would rate their technical support nine out of ten.

    Which solution did I use previously and why did I switch?

    We used NETSCOUT previously.

    How was the initial setup?

    The initial setup was straightforward. We had 20 credit hours and completed it on time within ten days.

    What about the implementation team?

    The implementation was done with the help of a reseller. We requested two individuals for implementation.

    What's my experience with pricing, setup cost, and licensing?

    I do not know the prices and therefore cannot provide any comments on pricing or setup costs.

    Which other solutions did I evaluate?

    We used NETSCOUT before using ExtraHop Reveal(x).

    What other advice do I have?

    ExtraHop Reveal(x) is highly recommended and very good. It is operationally easy to use.

    I'd rate the solution nine out of ten.

    Telecommunications

    RevealX from a daily user perspective

    Reviewed on Feb 28, 2024
    Review provided by G2
    What do you like best about the product?
    Overall, RevealX is easy to use and provides great visibility into the network. ExtraHop has very thorough documentation and if you can't find what you're looking for the support and training teams are always willing to help. I've experienced a quick turnaround for questions around the product. The training team is excellent at maintain user engagement in a virtual setting. The product is also super customizable which is great for unique use and abuse cases.
    I use RevealX almost daily, my top three pros from a technical perspective are the increased visibility of the network, customizing doesn't mean learning a new language, and low barrier to entry for analysts who are new to networking and security.
    What do you dislike about the product?
    My top three cons for the product are that when adjusting baseline metrics, the baseline completely resets and there is a 3-4 week period before the baseline is calculated. Going off the above, it does not perform "lookback" searches for detections, meaning I can't craft a detection today and then see if the logic matches any stored data in the tool. Some of the customization areas need a bit of work so that they tie into the other features of the product.
    What problems is the product solving and how is that benefiting you?
    ExtraHop enables us to have better visibility. This has resulted in us making configuration changes on hardware and network devices to decrease our attack surface.
    Higher Education

    ExtraHOP provides visibility to quickly resolve performance and security issues

    Reviewed on Feb 21, 2024
    Review provided by G2
    What do you like best about the product?
    ExtraHOP provides great visibility for performance and security issues in our environment. Many of the detections, dashboards, and device groups provide easy starting points for learning to use extraHOP. Then, building custom dashboards and detections is very simple. We use extraHOP every day to assist us resolving problemes. The customer support and partnership we have with extraHOP has been key to our success.
    What do you dislike about the product?
    You need to really understand your environment from the network layer to the application layers. extraHOP provides many options, but you need to determine what works best for your environment. It does take some time for planning the implementation properly but the planning and design time is worth it.
    What problems is the product solving and how is that benefiting you?
    extraHOP has helped us solve authentication issues, storage issues, server issues, network performance issues, security problems and other application problems. We had many blind spots and extraHOP has helped us gain visibility to many of our services.
    reviewer2346030

    Great for analyzing specific attacks and victim logs

    Reviewed on Feb 15, 2024
    Review provided by PeerSpot

    What is our primary use case?

    It can detect new attacks or expired certificates. It's especially effective in identifying Netria attacks or any other online threats that may occur.

    What is most valuable?

    With ExtraHop Reveal(x), it gives me more visibility into the packets. It doesn't provide the entire packet capture, but it offers more information on how connections are made at the network layer. This can be helpful for detecting network attacks. Additionally, I really like the customizable dashboards and reports. The incident dashboard and alerts provide a good summary initially, and diving deeper into them gives more detailed information. It's also great for analyzing specific attacks and victim logs. The feature that tracks the full attack chain makes it easier to monitor the progress of attacks. Plus, it's connected to the Netria.com app, which I find useful for certain tasks.

    What needs improvement?

    I think the tuning capabilities could be improved. We're working on minimizing false positives. Apart from that, everything seems fine to me.

    For how long have I used the solution?

    I have been using ExtraHop Reveal(x) for sometime.

    What do I think about the stability of the solution?

    I would rate it 9 out of 10 as it is very stable.

    What do I think about the scalability of the solution?

    I would rate it 10 out of 10 as it is very high.

    Which solution did I use previously and why did I switch?

    So, in my experience with ExtraHop Reveal(x), I've found it to be a reliable tool. I haven't come across anything that compares directly to what Reveal(x) offers.

    What other advice do I have?

    As for advice or recommendations for someone considering implementing ExtraHop Reveal(x), I'd say it's a good investment, especially considering its price point. It's a great product, particularly for enhancing security measures. Before installing this solution, it's important to consider its compatibility with your existing security infrastructure. While Managed Detection and Response (MDR) solutions are commonly used for comprehensive security, Reveal(x) stands out for its specific strengths in network security.

    I would rate it 8 out of 10.

    Internet

    you get what you pay for

    Reviewed on Feb 14, 2024
    Review provided by G2
    What do you like best about the product?
    We've tested the product using reputable 3rd party pentesters manual and automated. And we've compared it with other products. The difference between seeing that you are being compromised and not seeing it is huge. How do you choose a competitive product that is cheaper if it doesn't see that you are being compromised? Or how do you rest at night knowing that you've done everything you can to safeguard your network? Extrahop's visibility is far above the rest.
    What do you dislike about the product?
    It is pricey. So if you are Misinformed and think that backups, firewalls, and anti-virus solutions are going to save you then you aren't going to understand the price of this product.
    What problems is the product solving and how is that benefiting you?
    Mainly keeping our company from experiencing a ransomware event. We have staff dedicated to keeping their eye on the product and chasing down alerts 24/7/365.
    Jeff H.

    One stop shop for network detections and notifications Easy to use and easy to understand.

    Reviewed on Feb 05, 2024
    Review provided by G2
    What do you like best about the product?
    I like that ExtraHop identifies the alert in a mannert that is easy to follow. It gives the risk level of the alert, shows the metrics, breaks down the records for the incident, shows the packets involved, and even includes a pcap of the packets that can be used in WireShark to analyze further. It also gives the Mitre techniques as well as mitigation options to mitigate the attack.
    What do you dislike about the product?
    I haven't found to many things I dislike about ExtraHop. It is not an automated system that will block an attack as it is happening, but it does e-mail out alerts so that I have the ability to begin investigating the incident as soon as possible leading to a faster mitigation scenario.
    What problems is the product solving and how is that benefiting you?
    As an ISP our network security is very important. ExtraHop is a tool to help ensure we are seeing any attack in realtime, giving us the ability to troubleshoot and mitigate the issue in a speedy manner. We have the abilty to isolate traffic quickly when an issue arises.
    Khaja Ahmed M.

    Overall good product but needs more flexibility.

    Reviewed on Jan 30, 2024
    Review provided by G2
    What do you like best about the product?
    1. Seamless monitoring.
    2. Simple and straightforward rule tuning.
    3. Dashboard capabilities
    What do you dislike about the product?
    1. Lot of false positives.
    2. Machine learning model is not flexible to the requirements.
    3. Sometimes performance issues.
    What problems is the product solving and how is that benefiting you?
    Its providing detections that are required to ensure all the permiters are covered.