

Darktrace and Palo Alto Networks Advanced Threat Prevention are both leaders in the cybersecurity domain. While Darktrace shines with its AI capabilities and user satisfaction, Palo Alto is preferred for its comprehensive ecosystem integration and threat prevention features. Pricing and AI-driven performance give Darktrace an edge.
Features: Darktrace is known for its alert system that offers meaningful, action-oriented notifications and incorporates AI for effective network behavior learning. Its Antigena provides robust autonomous response, and the platform allows in-depth threat visualizations. Meanwhile, Palo Alto Networks is valued for its real-time threat response, application control, and effective sandboxing capabilities. It ensures broad threat coverage with a strong integration option within its security suite.
Room for Improvement: Darktrace users seek reduced false positives and a more straightforward interface, alongside enhanced endpoint visibility for broader scalability. Enhanced automation in responses is also desired. Palo Alto users mention high pricing and the need for better localized support and AI integrations. Reducing false positives and improving endpoint integration are common aspirations for both platforms.
Ease of Deployment and Customer Service: Darktrace supports flexible deployment across on-premises and hybrid environments and is noted for its rapid and effective technical support. Its customer service is recognized for proactive assistance and regular integration checks. Palo Alto aligns well with hybrid and on-premises setups, receiving varied feedback on technical support. Enhancements are suggested for complex scenarios and multi-vendor integrations despite prompt service responsiveness.
Pricing and ROI: Darktrace is seen as pricey, yet its advanced AI and machine learning benefits justify the cost through significant ROI in threat detection and mitigation. Its pricing flexibility and negotiation support add allure to its subscription model. In contrast, Palo Alto's pricing is challenging for smaller organizations, but the comprehensive security features justify the expense for large enterprises focused on extensive infrastructure protection.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
It offers insights into security threats, despite the inability to quantify its impact in numbers.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
I rate technical support from Palo Alto as eight out of ten.
I have proof of this rating - when I escalate a case, I receive a reply from TAC support after two days.
Overall, I find the technical support from Palo Alto Networks quite good, although getting a hold of the TAC can be challenging and sometimes requires long phone calls.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Palo Alto Networks Advanced Threat Prevention is scalable and works well wherever enforcement points exist.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
For stability, I would rate Darktrace an eight out of ten.
Proper sizing of the firewall models ensures that the system does not experience crippling performance issues.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Palo Alto needs to focus on how to bring that technology to end users and how easy it is to use, especially in a hybrid environment where users work from various locations.
The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate firewalls.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
As traditional signature-based mechanisms become less effective due to the evolving nature of attacks, this solution's focus on behavioral analysis is crucial.
We are satisfied with the analytic capabilities of Palo Alto Networks Advanced Threat Prevention, especially the reporting features available in the Palo Alto portal in terms of their application visibility interface, which is very good for us to get visibility on all critical applications and the associated users, as well as the risks associated with every category of traffic.
| Product | Mindshare (%) |
|---|---|
| Darktrace | 10.5% |
| Palo Alto Networks Advanced Threat Prevention | 4.8% |
| Other | 84.7% |

| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 20 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 4 |
| Large Enterprise | 14 |
Darktrace revolutionizes network security with AI-driven alerts, anomaly detection, and robust visibility across networks. It autonomously detects threats, minimizing the need for human oversight, and offers efficient IP identification with minimal false positives.
Darktrace uses advanced AI analytics to enhance network protection. Its powerful real-time threat response capabilities and self-learning enable thorough monitoring and insightful analysis of network activities. While providing scalable and reliable security, users seek improvements in false positive reduction, user-friendly interfaces, and pricing. Enhanced third-party integration, more effective dashboards, and centralized automation features remain top priorities. Users benefit greatly from its Antigena feature, offering automated responses like blocking suspicious connections for robust network defense.
What Are Darktrace's Key Features?In industries employing Darktrace, it is pivotal in securing LAN networks, analyzing behavioral patterns, and detecting internal and external threats. Adoption alongside platforms like F5 and SAP enhances incident response, traffic analysis, and threat identification, utilizing Antigena for proactive security measures.
Palo Alto Networks Advanced Threat Prevention provides comprehensive security with application control, real-time threat detection, and seamless integration with cloud services. Known for its high performance and ease of use, it addresses diverse security challenges for modern organizations.
Palo Alto Networks Advanced Threat Prevention integrates machine learning, behavioral analysis, anti-malware protection, and WildFire sandboxing to deliver proactive defense against threats. Its features include advanced firewall capabilities, comprehensive bandwidth management, and robust reporting. Integration with cloud-based URL filtering enhances organizational security efforts. While the tool offers significant protection, areas like pricing, ease of use, false positive management, and documentation clarity require improvement. Expanding AI capabilities and optimizing support will enhance threat prevention and user experience.
What are the most important features?Palo Alto Networks Advanced Threat Prevention is implemented across industries for server protection and LAN/WAN traffic security, providing solutions for network testing and application control. Organizations benefit from features like GlobalProtect VPN, anti-spyware, and vulnerability protections, ensuring security through efficient deployment both on-premises and in the cloud.
We monitor all Intrusion Detection and Prevention Software (IDPS) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.