Try our new research platform with insights from 80,000+ expert users

Darktrace vs Dragos comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Darktrace
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), Cloud Security Posture Management (CSPM) (11th), Cloud-Native Application Protection Platforms (CNAPP) (9th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (4th), AI Observability (9th)
Dragos
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
2
Ranking in other categories
Operational Technology (OT) Security (5th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Darktrace is designed for Network Detection and Response (NDR) and holds a mindshare of 16.8%, down 25.4% compared to last year.
Dragos, on the other hand, focuses on Operational Technology (OT) Security, holds 8.9% mindshare, down 11.2% since last year.
Network Detection and Response (NDR) Market Share Distribution
ProductMarket Share (%)
Darktrace16.8%
Vectra AI12.6%
ExtraHop Reveal(x)6.8%
Other63.800000000000004%
Network Detection and Response (NDR)
Operational Technology (OT) Security Market Share Distribution
ProductMarket Share (%)
Dragos8.9%
Nozomi Networks20.6%
Claroty Platform18.2%
Other52.3%
Operational Technology (OT) Security
 

Featured Reviews

AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
JR
OT Cybersecurity Engineer at Nadar
Offers strong incident response features but requires more asset visibility and flexibility
Dragos' best features are that they are more focused towards Incident Response, so they have a dedicated playbook in their platform, making it easier for anyone investigating any incidents to investigate the alerts. One of the main features of Dragos is that they have a dedicated Incident Response team, so if clients need any help, they are there to help. Dragos does real-time monitoring as well, collecting mirror traffic from the span port of the switch, and as soon as it gets the traffic, it analyzes it in real time and shows what's going on in the networks, which relates to the real-time visibility feature for ICS networks.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The investigative part of Darktrace is valuable, especially the automation features. It allows setting up checks and provides guidance on mitigating situations, which is very useful. There are different modules that you can add to the console for protection."
"Darktrace is extremely stable."
"Darktrace is very stable, and I would rate its stability a ten out of ten."
"Artificial intelligence and machine learning functionalities are valuable."
"The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
"Its most valuable feature is its ability to identify malicious connected IPs from outside and the attacks that get through to the inside."
"The models, triggers, and alerts are customizable."
"The most valuable feature is that it gives us visibility of rogue traffic that is on the network."
"Dragos is more expensive than other vendors, probably about fifteen to twenty percent more, but it is generally worth the investment."
"Dragos' best features are that they are more focused towards Incident Response, so they have a dedicated playbook in their platform, making it easier for anyone investigating any incidents to investigate the alerts."
 

Cons

"The management dashboards and the meter dashboards should be more user-friendly and simple to use for easy management."
"Darktrace could improve its features, such as monitoring and detecting ransomware."
"In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from."
"It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening."
"I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there."
"One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network."
"It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
"The pricing is a bit high for the region."
"Dragos could improve its asset visibility and discovery tools, as the competitor Claroty has better options in this area."
"I think Dragos can offer more flexibility similar to Nozomi and more visibility into the assets, nodes, and links, which would make it more competitive in the future."
 

Pricing and Cost Advice

"Darktrace is pricey, but the price is reasonable for what the solution does, and it's comparable to other products."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"It is pretty expensive, but it is worth it. Its licensing is yearly."
"The cost of the solution can be reduced to make it more appealing to customers."
"The solution is about $6,000 per quarter."
"They are too expensive compared with other vendors."
"Our customers feel that the price of Darktrace is quite high compared to other solutions."
"The tool's pricing is costly."
Information not available
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
881,707 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
Energy/Utilities Company
15%
Manufacturing Company
13%
Construction Company
7%
Comms Service Provider
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
No data available
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What is your experience regarding pricing and costs for Dragos?
Dragos is more expensive than other vendors, probably about fifteen to twenty percent more, but it is generally worth the investment.
What needs improvement with Dragos?
I think Dragos could be improved, as I have worked in Nozomi and compared it to Nozomi. Nozomi offers a lot of flexibility in what I am able to learn and unlearn, and I have more visibility towards...
What is your primary use case for Dragos?
I am an engineer in a service provider company where we help clients choose and implement security solutions, and I'm still looking for a new solution. I am certified in Dragos, but I have not depl...
 

Comparisons

 

Also Known As

No data available
Dragos Platform
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
NaturEner
Find out what your peers are saying about Darktrace, Vectra AI, TrendAI and others in Network Detection and Response (NDR). Updated: January 2026.
881,707 professionals have used our research since 2012.