Regarding the autonomous response feature, I appreciate how it functions within the platform.
Darktrace ActiveAI Security Platform
DarktraceExternal reviews
External reviews are not included in the AWS star rating for the product.
Intelligent threat response has improved incident handling and provides clear attack path visibility
What is most valuable?
What needs improvement?
Based on my experience, I believe the solution could be improved in some areas, and there are certain drawbacks that I have encountered.
For how long have I used the solution?
I have been working with Darktrace for approximately one to one and a half years or longer.
What do I think about the stability of the solution?
In general, I would say that the interface of Darktrace is intuitive enough, and it aids in understanding threat landscapes and attack paths.
What do I think about the scalability of the solution?
Regarding scalability, I would rate it eight points.
How are customer service and support?
If asked to rate Darktrace support on a scale from zero to ten where ten is the best, I would give them five points.
How would you rate customer service and support?
Neutral
How was the initial setup?
Regarding the installation and initial setup, I found it to be straightforward rather than complex.
What's my experience with pricing, setup cost, and licensing?
Concerning pricing for the product, I would say it is somewhat expensive.
What other advice do I have?
I have rich experience with many tools including Vectra, Cisco firewall, and Check Point.
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
What is our primary use case?
The typical use case for Darktrace is for threat vector scanning, detecting any unusual activity, and anomaly detection. Apart from that, it is very helpful in incident response.
What is most valuable?
The features I find most effective in Darktrace include anomaly detection. The machine learning model provides accurate alerts after the learning period of 1 or 2 weeks, especially for network anomalies or something that the user is trying to access, which can include trying to visit unknown sites or botnets, and those things get detected and represented in a very good dashboard.
Darktrace positively impacts my organization by enhancing threat hunting, particularly in east-west traffic within the same subnet. Previously, we only used traditional firewalls that cannot catch this lateral traffic. After deploying Darktrace, we gain insights into machine-to-machine communication, which adds more value to the organization and is especially beneficial for the SOC team.
What needs improvement?
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
For how long have I used the solution?
I have been familiar with Darktrace for the last 5 to 6 years.
What was my experience with deployment of the solution?
In terms of the speed and effectiveness of Darktrace's automatic response, it gives clear alerts whenever anomalies happen on the network, enabling us to catch them on the fly. However, some of the rules generate false positives, especially with system calls, which get incorrectly marked as anomalies. These are actually system call integrations that need fine-tuning based on our environment integrations.
Regarding Darktrace's capability to adapt and recognize abnormal activities through machine learning and AI, sometimes a password expiration prompts the user to connect to different sources to get the new password changed. During that time, it picks this up as abnormal activity when connecting to LDAP during off-business hours. This is an example of how it detects what it considers an anomaly, since user authentication typically happens during business hours.
What do I think about the stability of the solution?
Regarding overall stability, Darktrace is a stable product, and I have no complaints from customers wherever it is deployed.
What do I think about the scalability of the solution?
While considering if Darktrace is scalable, I note that there are storage limitations, where the planned capacity can sometimes be overutilized. There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
How are customer service and support?
I can rate Darktrace's technical support as one of the best products in the world. We have seen satisfaction reflected on our customers' faces after deployment when they start seeing the data and the dashboard, and they often express surprise at the network traffic visibility that Darktrace provides.
I would rate the technical support of Darktrace between 6 to 8, as the support is good and we receive timely assistance whenever we raise an issue.
Which solution did I use previously and why did I switch?
Before working with Darktrace, I did not use any similar solution in the same category. Earlier, I was using something called decepters, and my organization may have explored different products, but I learned about network detection and response through Darktrace about 5 to 6 years ago.
How was the initial setup?
Deploying Darktrace is quite easy and plug and play, wherein all we need is to put it in a data center, rack up, and do some switch configuration. The learning would take a week time, and once the data gets populated, we get a very good dashboard.
What about the implementation team?
For deploying Darktrace, I would require 3 to 4 people. We would require a data center person to assist in racking and mounting this, and some network engineers would make this configuration to spend the data ports.
What was our ROI?
When considering return on investment for organizations using Darktrace, the disadvantage lies in having to use a physical appliance. Running a quick POC is not possible since the hardware has to be shipped from the UK or elsewhere, but other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
What's my experience with pricing, setup cost, and licensing?
In terms of setup and licensing costs, Darktrace is on the pricier side compared to similar solutions in the NDR market. Other NDR solutions are also on the higher side, but Darktrace stands out as a bit higher. Competitive pricing would certainly help me as a system integrator to convince customers.
Which other solutions did I evaluate?
I did not evaluate other options when looking into Darktrace, but some customer preferences led us to consider other NDR solutions, such as 40 NDR. Our customers had a Fortinet setup with various products, and they preferred the 40 NDR for proprietary visibility when collecting logs from Fortinet devices.
What other advice do I have?
We are using the latest version of Darktrace. I have not used Darktrace's Enterprise Immune System. Antigone is the feature of Darktrace that we have recently experienced. At the moment, I have not encountered a situation where Darktrace's self-learning capabilities reduced the risk of data breaches, but it performs very effectively overall. It requires some time to adapt; initially, when we deploy, it takes weeks. On a scale of 1-10, I rate Darktrace a 9.
Gain comprehensive network visibility with detailed packet capture
What is our primary use case?
The primary use case for Darktrace is to gain full visibility into the network traffic. Darktrace provides complete packet capture and metadata analysis, unlike other solutions that offer only specific metadata. This comprehensive view allows for better assessment and monitoring of the network environment.
What is most valuable?
Darktrace is valuable since it offers full packet capture and detailed metadata. This feature sets it apart from competitors, which often provide limited metadata visibility.
Additionally, the interaction with the technical team is seamless, and communication with the account manager is flexible and easy.
What needs improvement?
The management dashboards and the meter dashboards should be more user-friendly and simple to use for easy management.
For how long have I used the solution?
I have been using Darktrace for three months.
What do I think about the stability of the solution?
Darktrace is very stable, and I would rate its stability a ten out of ten.
What do I think about the scalability of the solution?
Darktrace has high scalability, and I would rate it a nine out of ten.
How are customer service and support?
The technical support from Darktrace is of high quality, and I would rate it a nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously checked with different solutions.I decided to go with Darktrace. However, it offers complete packet capture and metadata, unlike other vendors.
How was the initial setup?
The initial setup was straightforward, however, there were some connection issues when deploying the VM on the cloud. Overall, the setup process was easy.
What about the implementation team?
The deployment and implementation were carried out in-house by our technical team.
What's my experience with pricing, setup cost, and licensing?
Darktrace initially had a high price. After negotiation, we received discounts. Despite the discounts, it is still considered expensive.
What other advice do I have?
I would recommend Darktrace to others as it provides detailed metadata and full visibility of the network environment.
I rate Darktrace a nine out of ten overall.
Enhanced security with automation offers proactive threat mitigation
What is our primary use case?
Normally, when we have a setup, and I log in with any guest, Darktrace blocks us from remotely logging in from within the office network. It ensures that we cannot remote log in anywhere. It is a security system that identifies hacking attempts. Darktrace also integrates with VirusTotal for verification. Additionally, we use the email protection feature.
How has it helped my organization?
Darktrace ensures that we do not have breaches on our systems, and it helps improve our security status before breaches can even reach our system.
What is most valuable?
The investigative part of Darktrace is valuable, especially the automation features. It allows setting up checks and provides guidance on mitigating situations, which is very useful. There are different modules that you can add to the console for protection.
What needs improvement?
The Darktrace Mobile app needs improvement as it's currently limited in functionality, and the learning AI takes a while to adapt to new devices, flagging new users as threats for up to a month before recognizing them as regular network users.
For how long have I used the solution?
I have been using Darktrace for almost a year now.
What do I think about the stability of the solution?
Darktrace is very stable. I can reliably check logs and track what is happening within the system.
What do I think about the scalability of the solution?
The scalability isn't a high priority for us as it mostly deals with system security. It provides necessary features for security enhancement whenever needed.
How are customer service and support?
The support provided by Darktrace is very good. We had issues with Darktrace Mobile, and they assisted us with a solution, even allowing us to test new features.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I joined the current company after Darktrace was already in use, so I do not have information on previous solutions.
How was the initial setup?
The initial setup can be rated as a seven out of ten because it involves going into the console and ensuring that the network settings are correctly configured.
What about the implementation team?
Two people are enough for deployment, provided they know the network settings and configurations.
What was our ROI?
By using Darktrace alongside Mimecast, it has helped improve our security posture by preventing breaches before they reach our system.
What's my experience with pricing, setup cost, and licensing?
I do not have any experience regarding the pricing or setup costs as it was managed by the company administration.
Which other solutions did I evaluate?
I did not have any information on other solutions evaluated prior to Darktrace as they were in use before I joined the company.
What other advice do I have?
Darktrace is a good product to invest in if you can afford it. It provides excellent security features.
I'd rate the solution eight out of ten.