

Darktrace and Palo Alto Networks Advanced Threat Prevention are key players in the cybersecurity product category. Darktrace has the upper hand due to its AI-powered autonomous response and extensive visibility capabilities.
Features: Darktrace leverages AI-driven capabilities for automatic threat detection, comprehensive network visibility, and an intuitive interface. Palo Alto Networks integrates sandboxing technology with robust firewall capabilities, detailed traffic management, and comprehensive threat prevention.
Room for Improvement: Darktrace can improve false positive management, enhance integration with other platforms, and streamline its user interface. Palo Alto Networks could benefit from refining IPS functionalities, enhancing scalability, and advancing AI analytics. Consistent pricing across systems remains a challenge.
Ease of Deployment and Customer Service: Darktrace offers flexible deployment options such as on-premises, hybrid, and cloud environments, but users face challenges with complexity and response times. Palo Alto Networks offers reliable technical support and flexible deployments, though its initial setup remains complex. Both companies receive positive feedback for their customer service, yet response time improvements are needed.
Pricing and ROI: Darktrace is viewed as expensive, particularly for smaller entities, yet its advanced capabilities offer high ROI. Palo Alto also faces high-cost perceptions, but offers good value through scalable solutions. Both guarantee significant ROI in enhancing security and preventing breaches, with Darktrace potentially requiring a physical appliance, impacting swift deployment.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
It offers insights into security threats, despite the inability to quantify its impact in numbers.
The technical support from Darktrace is of high quality.
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
The challenge lies in waiting for a response after logging a ticket.
I rate technical support from Palo Alto as eight out of ten.
I have proof of this rating - when I escalate a case, I receive a reply from TAC support after two days.
Overall, I find the technical support from Palo Alto Networks quite good, although getting a hold of the TAC can be challenging and sometimes requires long phone calls.
Darktrace has high scalability, and I would rate it a nine out of ten.
Since it's cloud-based, it expands easily.
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Palo Alto Networks Advanced Threat Prevention is scalable and works well wherever enforcement points exist.
The stability of Darktrace is excellent, rated ten out of ten.
The appliance itself has never let me down.
For stability, I would rate Darktrace an eight out of ten.
Proper sizing of the firewall models ensures that the system does not experience crippling performance issues.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Palo Alto needs to focus on how to bring that technology to end users and how easy it is to use, especially in a hybrid environment where users work from various locations.
The behavioral detection capabilities could be expanded to address all threats at the perimeter, reducing the reliance on endpoint detection and response systems.
The product is considered expensive compared to others.
The pricing is costly in USD, and they charge based on device counts.
The licensing cost is approximately eight dollars a year.
Palo Alto Networks Advanced Threat Prevention requires an add-on license and is considered expensive compared to competitors like Cisco AMP and FortiGate firewalls.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
As traditional signature-based mechanisms become less effective due to the evolving nature of attacks, this solution's focus on behavioral analysis is crucial.
We are satisfied with the analytic capabilities of Palo Alto Networks Advanced Threat Prevention, especially the reporting features available in the Palo Alto portal in terms of their application visibility interface, which is very good for us to get visibility on all critical applications and the associated users, as well as the risks associated with every category of traffic.
| Product | Mindshare (%) |
|---|---|
| Darktrace | 10.3% |
| Palo Alto Networks Advanced Threat Prevention | 4.5% |
| Other | 85.2% |


| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 20 |
| Large Enterprise | 29 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 4 |
| Large Enterprise | 14 |
Darktrace revolutionizes network security with AI-driven alerts, anomaly detection, and robust visibility across networks. It autonomously detects threats, minimizing the need for human oversight, and offers efficient IP identification with minimal false positives.
Darktrace uses advanced AI analytics to enhance network protection. Its powerful real-time threat response capabilities and self-learning enable thorough monitoring and insightful analysis of network activities. While providing scalable and reliable security, users seek improvements in false positive reduction, user-friendly interfaces, and pricing. Enhanced third-party integration, more effective dashboards, and centralized automation features remain top priorities. Users benefit greatly from its Antigena feature, offering automated responses like blocking suspicious connections for robust network defense.
What Are Darktrace's Key Features?In industries employing Darktrace, it is pivotal in securing LAN networks, analyzing behavioral patterns, and detecting internal and external threats. Adoption alongside platforms like F5 and SAP enhances incident response, traffic analysis, and threat identification, utilizing Antigena for proactive security measures.
Palo Alto Networks Advanced Threat Prevention provides comprehensive security with application control, real-time threat detection, and seamless integration with cloud services. Known for its high performance and ease of use, it addresses diverse security challenges for modern organizations.
Palo Alto Networks Advanced Threat Prevention integrates machine learning, behavioral analysis, anti-malware protection, and WildFire sandboxing to deliver proactive defense against threats. Its features include advanced firewall capabilities, comprehensive bandwidth management, and robust reporting. Integration with cloud-based URL filtering enhances organizational security efforts. While the tool offers significant protection, areas like pricing, ease of use, false positive management, and documentation clarity require improvement. Expanding AI capabilities and optimizing support will enhance threat prevention and user experience.
What are the most important features?Palo Alto Networks Advanced Threat Prevention is implemented across industries for server protection and LAN/WAN traffic security, providing solutions for network testing and application control. Organizations benefit from features like GlobalProtect VPN, anti-spyware, and vulnerability protections, ensuring security through efficient deployment both on-premises and in the cloud.
We monitor all Intrusion Detection and Prevention Software (IDPS) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.