Try our new research platform with insights from 80,000+ expert users

Share your experience using Tryvium Desk

The easiest route - we'll conduct a 15 minute phone interview and write up the review for you.

Use our online form to submit your review. It's quick and you can post anonymously.

Your review helps others learn about this solution
The PeerSpot community is built upon trust and sharing with peers.
It's good for your career
In today's digital world, your review shows you have valuable expertise.
You can influence the market
Vendors read their reviews and make improvements based on your feedback.
Examples of the 96,000+ reviews on PeerSpot:

Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consultant
Top 20
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
Pros and Cons
  • "I can rate Darktrace's technical support as one of the best products in the world."
  • "Pricing bothers me and this is one of the major factors when choosing a solution."

What is our primary use case?

The typical use case for Darktrace is for threat vector scanning, detecting any unusual activity, and anomaly detection. Apart from that, it is very helpful in incident response.

What is most valuable?

The features I find most effective in Darktrace include anomaly detection. The machine learning model provides accurate alerts after the learning period of 1 or 2 weeks, especially for network anomalies or something that the user is trying to access, which can include trying to visit unknown sites or botnets, and those things get detected and represented in a very good dashboard.

Darktrace positively impacts my organization by enhancing threat hunting, particularly in east-west traffic within the same subnet. Previously, we only used traditional firewalls that cannot catch this lateral traffic. After deploying Darktrace, we gain insights into machine-to-machine communication, which adds more value to the organization and is especially beneficial for the SOC team.

What needs improvement?

In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.

For how long have I used the solution?

I have been familiar with Darktrace for the last 5 to 6 years.

What was my experience with deployment of the solution?

In terms of the speed and effectiveness of Darktrace's automatic response, it gives clear alerts whenever anomalies happen on the network, enabling us to catch them on the fly. However, some of the rules generate false positives, especially with system calls, which get incorrectly marked as anomalies. These are actually system call integrations that need fine-tuning based on our environment integrations.

Regarding Darktrace's capability to adapt and recognize abnormal activities through machine learning and AI, sometimes a password expiration prompts the user to connect to different sources to get the new password changed. During that time, it picks this up as abnormal activity when connecting to LDAP during off-business hours. This is an example of how it detects what it considers an anomaly, since user authentication typically happens during business hours.

What do I think about the stability of the solution?

Regarding overall stability, Darktrace is a stable product, and I have no complaints from customers wherever it is deployed.

What do I think about the scalability of the solution?

While considering if Darktrace is scalable, I note that there are storage limitations, where the planned capacity can sometimes be overutilized. There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.

How are customer service and support?

I can rate Darktrace's technical support as one of the best products in the world. We have seen satisfaction reflected on our customers' faces after deployment when they start seeing the data and the dashboard, and they often express surprise at the network traffic visibility that Darktrace provides.

I would rate the technical support of Darktrace between 6 to 8, as the support is good and we receive timely assistance whenever we raise an issue.

Which solution did I use previously and why did I switch?

Before working with Darktrace, I did not use any similar solution in the same category. Earlier, I was using something called decepters, and my organization may have explored different products, but I learned about network detection and response through Darktrace about 5 to 6 years ago.

How was the initial setup?

Deploying Darktrace is quite easy and plug and play, wherein all we need is to put it in a data center, rack up, and do some switch configuration. The learning would take a week time, and once the data gets populated, we get a very good dashboard.

What about the implementation team?

For deploying Darktrace, I would require 3 to 4 people. We would require a data center person to assist in racking and mounting this, and some network engineers would make this configuration to spend the data ports.

What was our ROI?

When considering return on investment for organizations using Darktrace, the disadvantage lies in having to use a physical appliance. Running a quick POC is not possible since the hardware has to be shipped from the UK or elsewhere, but other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.

What's my experience with pricing, setup cost, and licensing?

In terms of setup and licensing costs, Darktrace is on the pricier side compared to similar solutions in the NDR market. Other NDR solutions are also on the higher side, but Darktrace stands out as a bit higher. Competitive pricing would certainly help me as a system integrator to convince customers.

Which other solutions did I evaluate?

I did not evaluate other options when looking into Darktrace, but some customer preferences led us to consider other NDR solutions, such as 40 NDR. Our customers had a Fortinet setup with various products, and they preferred the 40 NDR for proprietary visibility when collecting logs from Fortinet devices.

What other advice do I have?

We are using the latest version of Darktrace. I have not used Darktrace's Enterprise Immune System. Antigone is the feature of Darktrace that we have recently experienced. At the moment, I have not encountered a situation where Darktrace's self-learning capabilities reduced the risk of data breaches, but it performs very effectively overall. It requires some time to adapt; initially, when we deploy, it takes weeks. On a scale of 1-10, I rate Darktrace a 9.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Flag as inappropriate
Waleed Omar - PeerSpot reviewer
Information Security Specialist at Arab Open University
Real User
Top 5Leaderboard
Provides effective email protection but support could improve
Pros and Cons
  • "The most beneficial feature in Darktrace is identifying phishing emails with the help of the AI engine and machine learning."
  • "I feel that Darktrace could be improved, particularly in the support aspect which is currently very poor. We need to chase Darktrace instead of them being proactive with us."

What is our primary use case?

I am using Darktrace for email security purposes.

What is most valuable?

The most beneficial feature in Darktrace is identifying phishing emails with the help of the AI engine and machine learning. In case it does not identify something, we can automatically make Darktrace learn from selections and other functionalities.

Regarding the ROI, we have experienced a significant reduction in phishing emails and have utilized our time efficiently, resulting in approximately 70% ROI.

What needs improvement?

I feel that Darktrace could be improved, particularly in the support aspect which is currently very poor. We need to chase Darktrace instead of them being proactive with us.

The support is the main problem, though there are some other issues as.

For how long have I used the solution?

I have been dealing with Darktrace for eight to nine months.

What was my experience with deployment of the solution?

We have faced some integration issues when integrating with CrowdStrike, and we are still facing these issues because the support is very poor. Similarly, we need to integrate with our SIEM solution, which is experiencing issues. We cannot proceed significantly because the support is not very active and sometimes gets delayed, so we need their engineering support and other assistance.

What do I think about the scalability of the solution?

Regarding scalability, it is very stable, and it is 100% scalable similar to CrowdStrike.

How are customer service and support?

If I were to rate support from 1 to 10, where one is bad and 10 is good, I would give them four points.

How would you rate customer service and support?

Neutral

How was the initial setup?

The installation is quite plug and play.

What about the implementation team?

Everything is totally handled by Darktrace, and I do not have to do anything for maintenance.

What's my experience with pricing, setup cost, and licensing?

The pricing is affordable and not very expensive. If we rate it on a scale where one is cheap and 10 is expensive, it would be three points.

What other advice do I have?

The Autonomous Response capability in Darktrace handles real cyber threats quite efficiently. The Autonomous Response is excellent at identifying phishing emails and suspicious emails accurately, and it automatically sends a response to users that certain emails were blocked by Darktrace, helping users identify whether it was done correctly or incorrectly. If it was done incorrectly, the user can submit a request, and we can perform human analysis and then add it to a whitelist or blacklist.

In terms of AI functionality, I have seen some AI integrations overall. Darktrace is completely designed based on AI and machine learning, making it very efficient in identifying suspicious behavior and suspicious emails.

We are using the Securonix SIEM solution, and from ManageEngine, I use Help Desk and the Patch Manager.

On a scale from 1 to 10, I would rate Darktrace as six points.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Flag as inappropriate