Darktrace vs NetWitness XDR comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Darktrace
Ranking in Network Detection and Response (NDR)
1st
Average Rating
8.2
Number of Reviews
66
Ranking in other categories
Email Security (11th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), AI-Powered Chatbots (3rd), Cloud Security Posture Management (CSPM) (14th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Attack Surface Management (ASM) (5th)
NetWitness XDR
Ranking in Network Detection and Response (NDR)
11th
Average Rating
8.0
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (53rd), Threat Intelligence Platforms (23rd), Endpoint Detection and Response (EDR) (49th), Security Orchestration Automation and Response (SOAR) (21st), Extended Detection and Response (XDR) (25th)
 

Mindshare comparison

As of July 2024, in the Extended Detection and Response (XDR) category, the mindshare of Darktrace is 10.1%, down from 14.2% compared to the previous year. The mindshare of NetWitness XDR is 0.4%, down from 0.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR)
Unique Categories:
Email Security
3.4%
Intrusion Detection and Prevention Software (IDPS)
20.9%
Endpoint Protection Platform (EPP)
0.2%
Threat Intelligence Platforms
0.8%
 

Featured Reviews

Winston Lewis - PeerSpot reviewer
Mar 30, 2023
We can integrate it with our firewall to automatically block things
We use Darktrace to monitor our network and block URLs from certain countries. Darktrace is integrated with our firewall, so the blocking is automatic.  We allow customers to access our Wi-Fi as guests, and some of them were going to restricted sites. Darktrace showed us what they were doing so we…
HS
Aug 11, 2022
Advanced threat detection undermined by issues with blocking
I primarily use NetWitness Endpoint to detect anomalies like the presence of web shields that are not detected by traditional antivirus solutions. I also use it for digital forensics and containment NetWitness Endpoint has enabled us to detect attacks that bypass the first stage of cybersecurity,…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a very simple product to use."
"I find it very good in the way that they show the past events, including the attack history."
"I am impressed with the product's ability to give insights into network traffic."
"The product offers us a very good user interface and we've found the network visibility to be very good so far."
"The platform has many modules, and each module examines a different situation in the behavior."
"It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
"Provides great network protection."
"I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network."
"The interface of this solution is very flexible and easy to use."
"It is stable. We have been using it for some time, without any issues."
"Ability to isolate the machine when there are malicious files."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"The most valuable feature of RSA NetWitness Network is the single unified dashboard from which you can manage all the different products of RSA. Additionally, the integration with native applications is good."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"They have recently updated the features and the most valuable ones are the instant threat response, ease of use, web interface, integration, and easy access. RSA NetWitness Endpoint is very compatible with other solutions and technologies. However, they do not rely on third-party solutions and have most features built-in."
"The most valuable feature is the way it captures the traffic, and it contains every detail of the communication."
 

Cons

"I think there is some MSSP missing."
"I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint."
"The solution could be easier to use."
"We'd like threat hunting, and we'd like to see a global solution that can automate vulnerability scans. I know it is something they are working on."
"It could build in integrations for some complementary products, but it has an assistant plugin so this is not really a big deal."
"It is expensive, but everything else has been great so far."
"It would be useful if there was a way to check to see if there are certain devices that are not in sync with the solution. I'm not sure if this is an option or not."
"Darktrace could improve its features, such as monitoring and detecting ransomware."
"I would like to see Security Orchestration and Response Automation (SOAR) integration."
"The initial setup requires a high level of skill."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"Its price could be improved. It is an expensive product. Its training is also too expensive. It would be great if they can have a better pricing scheme for the training."
"The threat intelligence could improve in RSA NetWitness Endpoint."
"The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge."
"RSA NetWitness Network could improve on integration with non-native application integration."
"Threat detection could be better."
 

Pricing and Cost Advice

"I am using a demo of Darktrace for deployment and testing which is free."
"The product is expensive."
"Our customers feel that the price of Darktrace is quite high compared to other solutions."
"The pricing is reasonable."
"Darktrace is quite an expensive solution."
"Darktrace is pricey, but the price is reasonable for what the solution does, and it's comparable to other products."
"Darktrace is expensive. You can pay for the license yearly."
"In the ballpark, we're talking about $30K, $50K, and up. It can even be as much as $50K or $100K."
"It is highly scalable. It can be bought based on your requirements."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"I do not have any opinion on the pricing or licensing of the product."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
"We are on a three-year contract to use RSA NetWitness Network."
"The cost depends on the number of endpoints that you want to monitor, but it is not expensive."
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
8%
Manufacturing Company
7%
Government
7%
Financial Services Firm
16%
Computer Software Company
15%
Government
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What is your experience regarding pricing and costs for NetWitness XDR?
The solution is expensive. I'd rate it at a one or two out of five. They need to adjust it to keep up with the competition. I cannot speak to the exact pricing of the product.
What needs improvement with NetWitness XDR?
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to n...
 

Also Known As

No data available
RSA ECAT, NetWitness Network
 

Learn More

Video not available
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Darktrace vs. NetWitness XDR and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.