No more typing reviews! Try our Samantha, our new voice AI agent.

Corelight Open NDR vs Darktrace comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Corelight Open NDR
Average Rating
8.8
Reviews Sentiment
7.6
Number of Reviews
7
Ranking in other categories
Network Traffic Analysis (NTA) (4th), Network Detection and Response (NDR) (7th)
Darktrace
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Email Security (10th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), Cloud Security Posture Management (CSPM) (11th), Cloud-Native Application Protection Platforms (CNAPP) (10th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (4th), AI Observability (7th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
reviewer2834367 - PeerSpot reviewer
Growth And Strategy Lead at a computer software company with 51-200 employees
Network visibility has transformed how we detect nation state threats and protect critical industry
Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale. However, I think with a lot of the artificial intelligence that they are building in, it is getting a lot easier to query in the platform. I would definitely encourage them to continue down that path where anybody can hop into the platform and start running queries, whether it is a simple instruction like I want this, and an artificial intelligence process can actually build the query and do it. I think that would be super powerful. Cyber skill sets are in high demand, and there is a huge backlog in cyber talent. We cannot fill all the positions we need. The easier we can make these cyber systems for people to pick up and be effective on, I think is really key. Explainability of data is hyper important. In the past few artificial intelligence related updates we have gotten from Corelight, that has been one of the first questions our team has asked every time or that I have asked: show me what the model is doing, show me how it came to this analysis. Within Investigator platform, they are able to walk through and see exactly what data the artificial intelligence pulled from where and why it did what it did as far as making its suggestions. They have definitely built their system with artificial intelligence in mind up front, and having that openness as one of the key features of any of their artificial intelligence and machine learning processes in the platform is important. The issue with black boxes is obviously hallucinations from artificial intelligence and just not being able to trace to ground truth. When we are talking about these cyber incidents and being able to do forensics, you need to be able to pinpoint and tie everything together, and black boxes really obscure that and prevent you from doing so. Corelight has done a really good job of making sure that everything is explainable and everything is mapped when it comes to leveraging any of their artificial intelligence features.
Pasan Jayarathna - PeerSpot reviewer
Network Security Engineer at Cyberwell Solution
Monitoring has improved data loss detection and now spots abnormal internal file transfers quickly
In my understanding, the best feature Darktrace offers is the identification of copying files, which acts as a DLP, and it is a main concern for companies because users sometimes copy data outside without knowing, especially those without a technical background. When I mention the DLP-like feature and file copying detection, the alerts have been very timely, as we get an alert within a couple of minutes, which is excellent. Even if some developers are working after hours and copying files, our SOC team detects this, and most of the time they call us so we can identify the users. The alerts are quite accurate and proactive.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Traps is quite a stable product. Once it was properly deployed and configured, you have nothing to be worried about."
"We can use Cortex XDR to get the entire graph of the incidents from source to destination, and we can take remedial action."
"Since they've done their most recent update, the ease to isolate endpoints is valuable. If we find one where there is a virus on it, we can easily isolate it. We don't even have to contact the user. We don't have to manually take them off the network. We can easily isolate them."
"The main benefit of using Cortex XDR by Palo Alto Networks while employing Palo Alto Firewall at the internet edge is that it improves security on our endpoint devices, integrating seamlessly with Palo Alto Firewalls to deliver comprehensive network, analyst, and security details all in a single dashboard, which allows us to manage everything from our network devices."
"We think that this product will help us grow, as it meets our needs currently and we can grow with it over time."
"The policy configuration is great, the granularity of policies that are available is very helpful, it is straightforward to set up, and it has pretty much everything we need and works well within the Palo Alto ecosystem."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"My advice for anybody who is considering Cortex XDR is that it is a complete solution, and has very good features."
"It's an easy way for us to get visibility in a client's environment."
"It is easy to deploy and easy to handle."
"Technical support seems to be good."
"Corelight makes much easier the remediation of cyber attacks; instead of facing a chaotic amount of logs, Corelight provides correlated metrics that allow pivoting to find, in seconds, all the data related to an alert, detection, or asset."
"It's easy to create additional dashboards specific to supporting specific tasks."
"Our company has seen massive improvements in cybersecurity position for our clients."
"Corelight Open NDR has had a positive impact on my company, providing visibility as the Suricata engine can scan huge volumes of traffic, including north-south and east-west, revealing signatures and exposures I was not expecting and enabling me to catch them with Suricata alerts."
"The most valuable feature is the embedded IDS from Suricata."
"Overall, this is a good product that seems to be working well."
"The Enterprise Immune System, Cyber Artificial Intelligence Analyst, and Antigena technology are all very useful aspects of the product."
"The product offers us a very good user interface and we've found the network visibility to be very good so far."
"The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
"One thing I appreciate is Antigena Email, which is for email protection."
"We have found the product to be stable and issue-free."
"The most valuable feature is the endpoint protection."
"The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network."
 

Cons

"As an improvement, I would like to see enhanced connection speeds."
"This product has not improved my organization - in fact, we are in the process of moving back to another product as a result of Cortex's horrible impact on system performance."
"The MAC agent is not as robust feature-wise as the PC version."
"Additionally, I think the price is very high, and if it can be adjusted, I believe it will be a very good solution."
"It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
"I would like to see them include NDR (Network Detection Response). Then it would work well with SIEM Response."
"The solution should offer more dashboards and they should be better customized."
"Cortex XDR could improve its sales support team, including better commission structures and referral programs."
"Before Corelight recently started pushing some of the agentic features, querying at times could be a little difficult, depending on your mastery of log scale."
"Corelight hasn’t added features in a long time."
"The solution’s architecture is complex and difficult to understand. There are multiple machines and VMs."
"They can enhance the interface of the product. They can make it more interactive and also easier to use for feature access."
"Machine learning could be a good improvement, but it's very costly."
"It's an expensive solution and the price could be reduced."
"In the next release, building a graphical user interface would be helpful."
"The price point for the product was too high for what our possible use case could be."
"The pricing model is a little too high and could be more flexible."
"This is quite an expensive product so the pricing is something that can be improved."
"The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
"Darktrace would tell you, for example, if there was a ransomware attack, but it wouldn't stop the attack."
"Darktrace is a closed technology, meaning we know very little about how it works, including the architecture, which is significant. As a result, when we implement the system and find we're getting many false positives, we have minimal insight into why it's happening and what we can do to fix it. We don't know how the solution is configured, the criteria for threats to be determined, or the product's inner workings. We understand that they have to ensure privacy and their copyright, but we want to see some documentation or public research into the security Darktrace provides."
"It can have more integration with orchestration or event management solutions."
"There aren't so many third-party vendor platforms natively integrated with the platform."
 

Pricing and Cost Advice

"The price is on the higher side, but it's okay."
"I feel it is fairly priced."
"The pricing is a little bit on the expensive side."
"I am using the Community edition."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"Its pricing is kind of in line with its competitors and everybody else out there."
"It is "expensive" and flexible."
"The price of the product is not very economical."
"It's a yearly fee and depends on what you are looking for."
"It is expensive. I don't have the price for other competitors."
"The price of Darktrace is high and could be reduced. We pay approximately $30,000 to $54,000 annually."
"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"I am using a demo of Darktrace for deployment and testing which is free."
"The solution is about $6,000 per quarter."
"If you consider the features and the cost of market leaders, we are satisfied with the pricing."
"This solution is expensive."
"The pricing is reasonable."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
Financial Services Firm
11%
Government
10%
Real Estate/Law Firm
8%
Computer Software Company
7%
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise2
Large Enterprise1
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise29
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Corelight?
I have a fortunate experience with pricing, setup costs, and licensing of Corelight Open NDR, as being a principal ar...
What needs improvement with Corelight?
Corelight Open NDR does not need any improvements or additional features in the next releases. The product is excelle...
What is your primary use case for Corelight?
I have been using Corelight Open NDR solution for approximately three years. I leverage the Suricata engine heavily f...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Corelight Open NDR
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
CarrefourEdnonGrand Canyon EducationSektorCERTTietoevryVolkswagen Financial Services
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Find out what your peers are saying about Corelight Open NDR vs. Darktrace and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.