I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user.
Consultant at a computer software company with 5,001-10,000 employees
Descriptive GUI, stable, and easy to understand for new users
Pros and Cons
- "I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user."
- "Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better."
What is most valuable?
What needs improvement?
Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better.
For how long have I used the solution?
It has been close to two months, and I am probably using the latest version.
What do I think about the stability of the solution?
It is definitely stable.
Buyer's Guide
Darktrace
May 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
What do I think about the scalability of the solution?
So far, we haven't had any problems. It is definitely scalable.
We don't have more than 12 people who use this solution.
How are customer service and support?
I never had any technical support problems. It is up to the mark.
Which solution did I use previously and why did I switch?
I have worked with Elastic SIEM and QRadar. Elastic SIEM is entirely different, so there is no one-to-one comparison. It is like comparing apples with oranges, but overall, Darktrace is quite interesting. A new user can easily learn it without much help.
How was the initial setup?
I never did any setup. I'm just an end-user.
What other advice do I have?
My advice is to always go for a PoC before implementing Darktrace. That's because Darktrace can get a lot of personally-identified information, which may not be a good thing for some companies. So, before going for this technology, you should do a PoC, and once everything is compliant with the rules and regulations of the company, you can go for it.
I would rate it an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Chief Operations & Information Officer at MineWorkers Provident Fund
Delivers as expected, provides good analytics around the real-time monitoring of our network, and has good reporting and reporting period
Pros and Cons
- "I particularly like Antigena and the analytics around the real-time monitoring of our network. I also like its reporting because it has got a seven-day reporting period within the system. Every time you run the reports, it gives you the data about the previous seven days. I like that because it is in real-time. I enjoy reading those reports and getting a very clear and decisive idea of what's happening on my network on a real-time basis. I like the actual real-time monitoring of spoofing and things like that. I also like the user monitoring as well as the network logging capabilities."
- "One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network."
What is our primary use case?
We have Antigena on the email, and we also use the network monitoring capabilities. We are using the latest version of the Antigena Email and AI analytics platform.
What is most valuable?
I particularly like Antigena and the analytics around the real-time monitoring of our network. I also like its reporting because it has got a seven-day reporting period within the system. Every time you run the reports, it gives you the data about the previous seven days. I like that because it is in real-time. I enjoy reading those reports and getting a very clear and decisive idea of what's happening on my network on a real-time basis. I like the actual real-time monitoring of spoofing and things like that. I also like the user monitoring as well as the network logging capabilities.
What needs improvement?
One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network.
For how long have I used the solution?
We have been using Darktrace for two years.
How are customer service and technical support?
There were a couple of times when we needed some of the expertise, and the guys were not available at the time when we needed them. Subsequently, they've managed to improve.
What other advice do I have?
In terms of our organization, we are a massive IT organization or financial services company. We've got a very small ITP, but we've got a lot of data. We are not sure about Darktrace in terms of its capacity to deal with huge data, but it is probably too early for me to give some sort of indication of what is not big.
At the moment, they are delivering on the set objective in terms of what I want to achieve as a CIO, and I'm quite happy with some of the deliverables that are coming through at the moment. In terms of what our requirements were and what we expect in terms of what we want them to deliver, they have delivered. Within the next two to three years, I would probably be able to provide a different perspective after we've matured within the Darktrace environment. At the moment, they've delivered the actual scope of work. There is nothing really that they're not delivering on as promised. So, at the moment, I'm quite happy with where we are.
I would rate Darktrace a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Darktrace
May 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,604 professionals have used our research since 2012.
Director at Baverianvine
A great solution for threat detection that intelligently and immediately responds to attacks across your enterprise system
Pros and Cons
- "A simple, powerful AI solution that just does all the work for you when you turn it on."
- "It could build in integrations for some complementary products, but it has an assistant plugin so this is not really a big deal."
What is our primary use case?
We use it to deploy to enterprise customers to provide them with a complete, reliable and intelligent threat detection and response system.
How has it helped my organization?
It helps us to reliably serve our customers with quick deployment of a durable, effective and intelligent product.
What is most valuable?
The most valuable part of the product is the whole package. The features included in the Enterprise Immune System are complete and effective. Its detection engine is ridiculously good.
What needs improvement?
It is hard to really address what needs to be improved in the respect that it does everything I would expect of a superior solution. It is simple enough to use because the interface is quite simple, the setup is quick and painless — in only an hour the product is installed. Users can train on the system in less than three hours. When the configuration is complete they will already know what to do and they can just go on and use the product.
I think that the price is quite good compared to other, similar products. They already have a plugin that you can use to set up integration with virtually any other product.
Maybe it could come with a few more built-in integrations, such as adding ServiceNow. They already have built-in integration with Antigena Cyber AI Response Modules for the clouds and for the network (AWS & Azure), and they did Office 365 (email), and SaaS applications as well.
I guess a few more options and opportunities like this built-in would be nice. It is not a big thing.
For how long have I used the solution?
We have been deploying this solution for clients since 2017
What do I think about the stability of the solution?
The stability of the product is really very good. Clients who have had us do the implementations say it is fantastic after they've tried it.
What do I think about the scalability of the solution?
The product is definitely scalable and can grow with your enterprise business.
How are customer service and technical support?
In terms of customer support, it is really rare that you need them to do anything because the product is really good. You turn it on and it just works. Really anyone can run it. So a level ten tech, a level five tech or a level one tech can use it. It makes everyone competent. It's like driving an automatic car because the gears shift for you. You still have to be a good driver and take the wheel and press the gas. But you can switch it back to manual if you want a different level of control. It's up to you. But everybody with different skill levels and different purposes for the deployment can use it.
When we have contacted the technical support they have been very good.
How was the initial setup?
It's simple enough to install and it does exactly as the product says: "installed in about an hour." With only an hour to install initially and with being able to train people to use it in just a few hours, it is very quick to do the initial setup. Very straightforward. It's a jog in the park.
Normally, once you deploy, for a normal site it's about two weeks time to set up configurations for the network, but then it is optimized and processing even faster. It's faster with fewer features and, usually, I use is about half of what it is capable of doing based on the client need. And once you do that configuration, you're ready to go. All that in less than two weeks and you can start getting threat intelligence reports from the network with intelligent tools. It's fantastic.
What about the implementation team?
We are the ones who do the implementations and we have done many, so we are very good at it.
What was our ROI?
Our return on investment is as a reseller and consultant because we make returns on servicing the customers.
What's my experience with pricing, setup cost, and licensing?
I think that the price is quite fair and very good for this type of product and the features that the product provides.
What other advice do I have?
My advice to people and organizations considering this as a solution is: go buy it. They shouldn't waste their time fussing and looking around at other solutions. It works. I've done administrating for several years, and this is the one solution that works. It complements what you have, whatever that is. It is like a plug-and-play component. There is no solution that does what it does. You even have some excellent systems like Cisco's Stealthwatch — these are just the three packet analysis technologies. Darktrace is actually DPI (Deep Packet Inspection), which in my markets is now called the threat level buttons. It is really an advanced product and everything just works ridiculously well.
If I had to rate the product on a scale of one to ten (ten is the best) I'd give it an actual ten. It is the only product I use that I would give a full ten. It's hard to achieve a ten as you have to be better than everything and everyone else. It does deliver on what it says it can do.
Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller.
Chief Information Security Officer at a consultancy with 201-500 employees
The solution's reports are intuitive and informative
Pros and Cons
- "The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
- "The level of tracking within the network from the transmission level up to the machine level can use improvement."
What is most valuable?
The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff.
What needs improvement?
The level of tracking within the network from the transmission level up to the machine level can use improvement.
The solution works similarly to an intrusion prevention system at the network level. It would be a nice improvement to have an add-on that can act at the post level.
The cost of the solution can be reduced to make it more appealing to customers.
For how long have I used the solution?
I have been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable but costly to do.
How are customer service and support?
The customer support team is responsive and tries to resolve the issue proactively.
How was the initial setup?
The setup is straightforward and easy to integrate.
What's my experience with pricing, setup cost, and licensing?
The setup cost for the entry-level is pricy.
What other advice do I have?
I rate the solution a nine out of ten.
It takes a team of five to maintain the solution.
This solution can reduce the resources required to run a security operation center by two-thirds.
The solution's reports are intuitive and informative.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Information Technology Support Engineer at CCTZ
Secure, beneficial unusual email detection, and high availability
Pros and Cons
- "The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
- "Darktrace could improve its features, such as monitoring and detecting ransomware."
What is our primary use case?
Darktrace is used for network security.
How has it helped my organization?
Darktrace has helped our organization be secure from network spam and attacks.
What is most valuable?
The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network.
What needs improvement?
Darktrace could improve its features, such as monitoring and detecting ransomware.
For how long have I used the solution?
I have been using Darktrace for approximately three months.
What do I think about the stability of the solution?
Darktrace is a stable solution.
What do I think about the scalability of the solution?
The scalability of Darktrace is good.
We have four companies that are using this solution.
How are customer service and support?
I have not used the support from Darktrace.
How was the initial setup?
The initial setup of Darktrace was simple. The deployment of Darktrace took approximately two weeks.
What's my experience with pricing, setup cost, and licensing?
I am using a demo of Darktrace for deployment and testing which is free.
Which other solutions did I evaluate?
My company chose Darktrace because it helped other companies that needed some help with metrics monitoring and spam monitoring.
What other advice do I have?
I would recommend this solution to others.
I rate Darktrace a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Chief ICT Officer at Barbados Public Workers Cooperative Credit Union Ltd
Helps us with network traffic visibility
Pros and Cons
- "I am impressed with the product's ability to give insights into network traffic."
- "I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint."
What is our primary use case?
The tool offers us visibility into network traffic.
How has it helped my organization?
The tool gives us alerts whenever an admin is trying to connect.
What is most valuable?
I am impressed with the product's ability to give insights into network traffic.
What needs improvement?
I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint.
For how long have I used the solution?
I am using the product since September.
What do I think about the stability of the solution?
The solution is stable.
How was the initial setup?
The tool's deployment is easy.
What's my experience with pricing, setup cost, and licensing?
The tool's pricing is costly.
What other advice do I have?
I would rate the tool a nine out of ten. You need to use the tool on a trial basis so that you can get comfortable with it.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CEO at VERINET
Provides great network protection, is innovative and flexible
Pros and Cons
- "Provides great network protection."
- "Needs to improve its collaboration with local partners."
What is our primary use case?
We are a consulting company and sell Darktrace to our customers. Our company is in West Africa. I'm the company CEO.
What is most valuable?
Darktrace can observe networks and respond to those observations. It provides great network protection, is innovative and flexible.
What needs improvement?
I think Darktrace needs to improve its collaboration with local partners. That would include training and improving the technical skills of vendors. Desktop and mobile device protection could also be improved.
For how long have I used the solution?
We've been selling this solution for two years.
What do I think about the stability of the solution?
The solution is stable.
How are customer service and support?
Our customers report that the technical support is very good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is reasonably straightforward although the process requires some preparation beforehand. The size of deployment varies greatly, we've deployed in companies ranging in size from 200 up to 5,000 users.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are expensive, although I think the high cost is partly a currency issue because we're based in West Africa.
What other advice do I have?
I rate this solution eight out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Customer Solution Manager at a tech services company with 51-200 employees
Beneficial artificial intelligence module, high quality support, and powerful
Pros and Cons
- "The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network."
- "The module can improve so that every time it's more intelligent."
What is our primary use case?
Darktrace just scans the entire network and documentation. We then automatically evaluate which behaviors are normal and which are not normal. You can determine what possible risks are in the network.
What is most valuable?
The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network.
You don't need a human operator to be involved. The tool can operate by itself... By itself. That's the best and the most important feature because that reduces the amount of time that a person needs to spend on the tool.
The solution is powerful and very useful, it has the ability to avert many attacks.
The tool does almost 95 percent of the work and you only need to run some features to obtain reports.
What needs improvement?
The module can improve so that every time it's more intelligent.
For how long have I used the solution?
I have been using Darktrace for approximately three years.
What do I think about the stability of the solution?
The stability of Darktrace is good.
What do I think about the scalability of the solution?
Darktrace is a scalable solution.
How are customer service and support?
The support from Darktrace is very good, it is perfect.
How was the initial setup?
Darktrace is installed in an appliance and that appliance is installed in the network.
What about the implementation team?
We have one engineer that does the maintenance of Darktrace. They do the implementation and scanning of the network.
The solution does not require a lot of maintenance, it does most of the operations automatically.
We provide technical services.
What's my experience with pricing, setup cost, and licensing?
The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution.
The license is by device, if you have 1,000 devices, then the cost is going to be high.
What other advice do I have?
My advice to others is for them to try to determine what are their costs in security. Then they can determine the benefit of Darktrace. They need to first acknowledge what their costs are and then they can start pricing what solution would be best.
I rate Darktrace a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Extended Detection and Response (XDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Network Detection and Response (NDR) AI-Powered Chatbots Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity PlatformsPopular Comparisons
Cloudflare
CrowdStrike Falcon
Wazuh
Microsoft Defender for Office 365
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Proofpoint Email Protection
Tenable Security Center
Cloudflare One
Trend Vision One
Microsoft Exchange Online Protection (EOP)
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?