

Darktrace and ExtraHop Reveal(x) are prominent players in the cybersecurity domain, focusing on network threat detection and response. Darktrace often has the upper hand due to its advanced AI and network visibility features, while ExtraHop is preferred for its data integration and comprehensive behavioral analysis capabilities.
Features: Darktrace is noted for its meaningful alerts, powerful AI analytics, and extensive network visibility. It offers robust customization and integration options, alongside self-learning capabilities that rapidly identify threats. ExtraHop Reveal(x) excels in network behavior detection and alerting, providing deep packet visibility and customizable dashboards. It integrates seamlessly with other tools and employs machine learning-driven behavioral analysis.
Room for Improvement: Darktrace can enhance its solution by reducing false positives, improving endpoint visibility, and streamlining third-party integrations. Its pricing structure is also considered steep, necessitating more flexible models. ExtraHop Reveal(x) should work on better integration with other security solutions and refine its reporting and GUI design. Both solutions could benefit from refining their licensing models and costs, with Darktrace needing simpler analysis processes and ExtraHop requiring stronger integration with Microsoft Sentinel.
Ease of Deployment and Customer Service: Darktrace supports on-premises, hybrid, and cloud deployments. Customers report generally positive experiences with technical support, although complex deployments show room for improvement. ExtraHop Reveal(x) is versatile in deployment but may require additional integration effort. Users value its quick and knowledgeable technical support despite some integration complexities.
Pricing and ROI: Darktrace tends to be perceived as expensive, with mixed opinions on its pricing structure. Clients find the cost justified by its advanced threat detection and prevention capabilities. ExtraHop Reveal(x) also has high costs, with additional charges for integration and features. Users recognize its value, especially for data analysis and network visibility, though cost concerns remain. Both solutions face challenges in pricing, impacting affordability, but they offer considerable ROI in cybersecurity protection.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
I would rate their technical support nine out of ten.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
For stability, I would rate Darktrace an eight out of ten.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Currently, we have to check manually as we do not receive any notifications about new patches, maintenance, or firmware releases.
I would like to see improvements in areas where events are getting dropped; we're not able to view complete insights.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
If I want to know a specific IP and which server it has been connected to, it's easy to gather those kinds of trees from the NDR.
The solution offers a friendly GUI for security features.
| Product | Mindshare (%) |
|---|---|
| Darktrace | 16.9% |
| ExtraHop Reveal(x) | 8.2% |
| Other | 74.9% |

| Company Size | Count |
|---|---|
| Small Business | 45 |
| Midsize Enterprise | 19 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 4 |
| Large Enterprise | 9 |
Darktrace revolutionizes network security with AI-driven alerts, anomaly detection, and robust visibility across networks. It autonomously detects threats, minimizing the need for human oversight, and offers efficient IP identification with minimal false positives.
Darktrace uses advanced AI analytics to enhance network protection. Its powerful real-time threat response capabilities and self-learning enable thorough monitoring and insightful analysis of network activities. While providing scalable and reliable security, users seek improvements in false positive reduction, user-friendly interfaces, and pricing. Enhanced third-party integration, more effective dashboards, and centralized automation features remain top priorities. Users benefit greatly from its Antigena feature, offering automated responses like blocking suspicious connections for robust network defense.
What Are Darktrace's Key Features?In industries employing Darktrace, it is pivotal in securing LAN networks, analyzing behavioral patterns, and detecting internal and external threats. Adoption alongside platforms like F5 and SAP enhances incident response, traffic analysis, and threat identification, utilizing Antigena for proactive security measures.
ExtraHop Reveal(x) offers advanced network visibility and threat detection through seamless integration with CrowdStrike. It enhances security with machine learning-driven behavioral analysis and customizable dashboards.
ExtraHop Reveal(x) excels in network detection and response by decrypting SSL traffic and providing real-time packet inspection. Users benefit from its dynamic triggers and historical data tracing. The platform is valued for its depth of information, powerful analytics, and cloud-based administration. It allows effective monitoring of attack chains and integrates with other solutions to boost security. However, there is room for improvement in pricing flexibility, licensing models, and integration capabilities, particularly with Microsoft Sentinel.
What are ExtraHop Reveal(x)'s Key Features?ExtraHop Reveal(x) is employed across industries for network traffic monitoring, malware detection, and real-time analysis. Analysts use it for server-to-server networking insights and application troubleshooting. Companies leverage its capabilities for behavioral analytics and compliance monitoring without deploying sensors on individual devices.
We monitor all Network Traffic Analysis (NTA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.