Try our new research platform with insights from 80,000+ expert users

Darktrace vs Fortra's Tripwire Enterprise comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 15, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Darktrace
Ranking in Intrusion Detection and Prevention Software (IDPS)
1st
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
82
Ranking in other categories
Email Security (8th), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (6th), Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (2nd)
Fortra's Tripwire Enterprise
Ranking in Intrusion Detection and Prevention Software (IDPS)
17th
Average Rating
8.0
Reviews Sentiment
7.2
Number of Reviews
8
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2025, in the Intrusion Detection and Prevention Software (IDPS) category, the mindshare of Darktrace is 18.0%, down from 19.0% compared to the previous year. The mindshare of Fortra's Tripwire Enterprise is 1.7%, up from 1.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Intrusion Detection and Prevention Software (IDPS) Market Share Distribution
ProductMarket Share (%)
Darktrace18.0%
Fortra's Tripwire Enterprise1.7%
Other80.3%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

Malebo Lethoba Group - PeerSpot reviewer
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
The functions I find most valuable in Darktrace are the AI analyst as well as the detection.The autonomous response capabilities of Darktrace are not crucial for me because it doesn't work in a network where there are no core switches. In a modern network, the autonomous response doesn't work, especially when sitting in a shared data center.If I'm running a traditional network where I am not in a shared data center with a layer two dedicated for my resources, then it can work for me. However, if I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
reviewer2093205 - PeerSpot reviewer
It has excellent scalability and allows you to execute custom COCR rules, letting you fine-tune agent monitoring
I'm using Tripwire Enterprise version 9.0. In my company, thirty to forty people use Tripwire Enterprise, mainly different types of engineers, governance, risk, compliance, and cybersecurity personnel. I advise people planning to use Tripwire Enterprise to take the training because the solution has a fairly complex interface. You can do a lot of work with it, but it isn't very easy. Tripwire Enterprise is a sophisticated tool. I rate the tool an eight on a scale of one to ten because it does an excellent job of handling the unique challenges of maintaining NERC CIP compliance and monitoring industrial controls.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"A simple, powerful AI solution that just does all the work for you when you turn it on."
"It's a very stable product."
"I have found the automation and AI features to be valuable. If someone were to come in to the office at midnight and log in, Darktrace would flag it."
"The active threat dashboard is the most valuable feature of this solution."
"The most valuable feature is the endpoint protection."
"Its most valuable feature is its ability to identify malicious connected IPs from outside and the attacks that get through to the inside."
"Artificial intelligence and machine learning functionalities are valuable."
"The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network."
"Even if you change a single word in Notepad, it will let you know whether it was added, removed, or modified."
"File monitoring is the most valuable feature of the solution."
"The product supports different platforms."
"We use Tripwire Enterprise as a tool to test the vulnerability of a network. That is the most valuable feature of the product for us."
"What's most valuable in Tripwire Enterprise is the ability to execute custom COCR rules that lets me fine-tune how I monitor Linux and Windows agents."
"The most valuable feature is integrity management. I had some discussions with service providers, and they also agreed."
"Its reporting features are great. It gives you an in-depth report. Its customization is also great, and it is working fine."
"The most valuable feature is the integrity."
 

Cons

"There aren't so many third-party vendor platforms natively integrated with the platform."
"The interface and dashboards could be improved for ease-of-use."
"It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not."
"It takes time to go through the interface and pick up things. If it were a more straightforward interface, then it would free up time."
"I think there is some MSSP missing."
"Its threat analyzer could be better. It should also have agents. They should improve this product by installing agents for the machine to get more visibility. Currently, they are monitoring only the network. They should also monitor the agents from inside. It should also have a better pricing plan because it is an expensive product."
"The solution's user interface and stability could be improved."
"Pricing bothers me and this is one of the major factors when choosing a solution."
"It needs more local support from the OEM side. It would be great if this can be improved."
"The initial setup is complex."
"The Windows online integration license needs to be improved."
"The main way that it can be improved is through better reporting."
"The deployment with certain systems can be difficult and it needs to be simplified."
"Cloud monitoring could be better. It would also be better if the company followed a pay-as-you-use model."
"A lot of network devices need a custom integration."
"An area for improvement in Tripwire Enterprise is stability, as my company had stability issues with the last few versions of the solution. Tripwire Enterprise has been a bit buggy."
 

Pricing and Cost Advice

"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"There is an annual license to use Darktrace."
"It is a very expensive product."
"It is pretty expensive, but it is worth it. Its licensing is yearly."
"Darktrace is quite an expensive solution."
"If you consider the features and the cost of market leaders, we are satisfied with the pricing."
"I am using a demo of Darktrace for deployment and testing which is free."
"This solution is expensive."
"The licensing depends on the equipment, how many devices and the types of devices."
"Cloud monitoring could be better. It could also be cheaper. It would be better if the company followed a pay-as-you-use model."
"Tripwire is more expensive than Netwrix."
report
Use our free recommendation engine to learn which Intrusion Detection and Prevention Software (IDPS) solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
Manufacturing Company
11%
University
11%
Government
8%
Non Profit
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business5
Large Enterprise3
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Tripwire Enterprise?
The product supports different platforms.
What needs improvement with Tripwire Enterprise?
The solution has some limitations in OT, IoT, and AIX. The product must provide whitelisting services.
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
1. Aetna 2. Adobe 3. ADP 4. Airbus 5. Amazon 6. American Express 7. Aon 8. ATT 9. Bank of America 10. Barclays 11. Baxter International 12. Bechtel 13. Boeing 14. Cisco Systems 15. CocaCola 16. Comcast 17. Dell 18. ETRADE 19. ExxonMobil 20. Ford Motor Company 21. General Electric 22. General Motors 23. Google 24. JPMorgan Chase 25. Kraft Foods 26. Lockheed Martin 27. McDonald's 28. Merck 29. Microsoft 30. Morgan Stanley 31. Nike 32. Oracle
Find out what your peers are saying about Darktrace vs. Fortra's Tripwire Enterprise and other solutions. Updated: September 2025.
867,370 professionals have used our research since 2012.