


NetWitness NDR and AWS Security Hub compete in network threat detection and security management. NetWitness NDR appears to have the upper hand due to its advanced threat detection capabilities.
Features: NetWitness NDR offers advanced behavioral analysis, packet capture capabilities, and superior threat detection. AWS Security Hub provides centralized security management, effective integration into AWS services, and compliance checks.
Room for Improvement: NetWitness NDR requires enhancement in integration flexibility, ease of use, and reducing deployment complexity. AWS Security Hub could improve in user interface simplicity, broader applicability beyond AWS environments, and cost-effectiveness for smaller organizations.
Ease of Deployment and Customer Service: NetWitness NDR supports adaptive deployment across diverse environments with proactive customer service. AWS Security Hub offers seamless integration within AWS infrastructures, though its usability is limited outside the AWS ecosystem and might be perceived as less flexible.
Pricing and ROI: NetWitness NDR has substantial initial costs but promises significant ROI through comprehensive security enhancements. AWS Security Hub presents a lower initial investment and cost efficiency by leveraging existing AWS services.
| Product | Market Share (%) |
|---|---|
| AWS Security Hub | 6.8% |
| Torq | 4.9% |
| NetWitness NDR | 1.2% |
| Other | 87.1% |


| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 5 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
AWS Security Hub is a comprehensive security service that provides a centralized view of security alerts and compliance status across an AWS environment. It collects data from various AWS services, partner solutions, and AWS Marketplace products to provide a holistic view of security posture. With Security Hub, users can quickly identify and prioritize security issues, automate compliance checks, and streamline remediation efforts.
The service offers a range of features including continuous monitoring, threat intelligence integration, and customizable dashboards. It also provides automated insights and recommendations to help users improve their security posture. Security Hub integrates with other AWS services like Amazon GuardDuty, AWS Config, and AWS Macie to provide a unified security experience. Additionally, it supports integration with third-party security tools through its API, allowing users to leverage their existing security investments.
With its user-friendly interface and powerful capabilities, AWS Security Hub is a valuable tool for organizations looking to enhance their security and compliance posture in the cloud.
Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness NDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.