No more typing reviews! Try our Samantha, our new voice AI agent.

Darktrace vs Rapid7 InsightIDR vs Trellix Intrusion Prevention System comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Darktrace14.8%
Vectra AI11.2%
ExtraHop Reveal(x)6.1%
Other67.9%
Network Detection and Response (NDR)
Security Information and Event Management (SIEM) Mindshare Distribution
ProductMindshare (%)
Rapid7 InsightIDR2.1%
Splunk Enterprise Security7.1%
IBM Security QRadar5.2%
Other85.6%
Security Information and Event Management (SIEM)
Intrusion Detection and Prevention Software (IDPS) Mindshare Distribution
ProductMindshare (%)
Trellix Intrusion Prevention System3.1%
Darktrace10.5%
Fortinet FortiGate10.3%
Other76.1%
Intrusion Detection and Prevention Software (IDPS)
 

Featured Reviews

AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Has supported compliance needs for mid-sized organizations but lacks customization and advanced integration
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as a SIEM solution is. This is where it can improve if we keep in front the feature sets of a complete SIEM solution. Most common in the market is QRadar, but it is depleting now. It has been taken over by some other products such as Splunk and LogRhythm. If we compare these things with Rapid7 InsightIDR, then there are definitely some gaps that need to be filled. Data retention is also one concern because Rapid7 InsightIDR is cloud-based and operates on a subscription model. Whatever data you want to retain, it has to be paid for separately or it has a cost. Other solutions that are on-premises can have their own infrastructure or they provide some data retention for a month or in some capacity-wise, they provide that solution to them which makes them more attractive.
BS
Large account Manager at Softcell Technologies Limited
Has offered reliable threat protection and detailed network insights but could expand features beyond existing capabilities
The best features of Trellix Intrusion Prevention System include advanced ATP (Advanced Threat Protection), which uses signatures, behavior analysis, and machine learning to stop zero-day exploits and malware advanced persistent threats (APTs). They track and collect data from APTs, which allows them to track malicious files entering the environment. The system offers inline prevention and real-time automatic blocking of malicious packets before they reach the network. It integrates with the Trellix ecosystem and provides application visibility and control. The solution provides deep insight into network traffic, applications, and protocols for better information. All packets coming through the application are analyzed and reported. They share intelligence updates regularly to protect from different malicious files and sector-specific threats. It supports both on-premise and cloud environments.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a stable solution."
"The technical support from Darktrace is very good, including support from their resellers."
"We are able to detect a lot of things, actually, and see what is happening in our network."
"The most valuable feature is the alerts. The alerts are meaningful. The event rolls up into meaningful and actionable alerts rather than just being noise."
"Its AI technology supports cybersecurity by learning my environment and accurately responding to threats."
"The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
"The Antigena feature is most valuable, because once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment."
"I would 100% recommend Darktrace."
"I've used other products such as QRadar and other SIEM solutions and I find this solution is much more simplified and user-friendly."
"InsightIDR has allowed us to find potential security issues that we did not know existed, and get remediation quickly."
"Intelligent alerting to avoid the common problem of alert fatigue associated with traditional SIEMs."
"It improves because several sensors are deployed within the on-premise environment. It can be very efficient if the customer implements and operates it effectively."
"The solution is very cost-effective because they are not charging based on the EPS but on the number of assets."
"The solution is very stable and works very well for what I need it to do."
"Great coverage of all systems within our network from endpoint to firewall."
"InsightIDR’s ability to process millions of transactions per day, and to notify me of the most critical ones, is priceless."
"The feature I found most valuable is the network threat analyzer in the security platform. It also integrates with GTI, or Global Threat Intelligence. Otherwise, I just use the basic features."
"We feel safer now."
"The solution is very stable, reliable, and free of bugs or glitches, and it does not crash or freeze."
"The product is worth the investment."
"Great monitoring feature."
"The most valuable features are the customization of the signature and the unlimited amount of custom signatures in IPS."
"McAfee NSP is much more stable than Cisco."
"Overall the solution is very good. It offers great protection and gives us a good overview of what is on the network."
 

Cons

"The technical support is not very good."
"The dashboard and reporting for this solution could be improved as it is currently complex."
"The level of tracking within the network from the transmission level up to the machine level can use improvement."
"The user interface and the configuration are a bit complex and should be improved or simplified."
"There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market."
"It can have more integration with orchestration or event management solutions. They can provide more knowledge or research information for analysts for investigating cases and detecting anomalies in networks."
"The Darktrace Mobile app needs improvement as it's currently limited in functionality, and the learning AI takes a while to adapt to new devices, flagging new users as threats for up to a month before recognizing them as regular network users."
"Darktrace could improve by being more user-friendly."
"I would like the ability to adjust the threshold of certain existing alerts. Currently the only option is to change the notifications or create my own alert."
"One thing that springs to mind is easier API integration with ITSMs."
"Personally, I feel it would greatly benefit from more supported log sources."
"They should add more configuration and security features to it."
"InsightIDR's integration with other solutions could be improved. Also, I'd like more control from the portal over what's happening on the endpoint side. For example, when I see an attack on an endpoint, I want to be able to stop it from the portal."
"The main problem lies in the processes within the client's operating systems."
"The APIs can be further improved in Rapid7."
"Cloud risk assessment is one area where I think they need a lot of improvement."
"The pricing could be improved."
"Trellix Intrusion Prevention System does not provide virtual patching."
"Integration with Global Thereat Intelligence could be better. Also, I think management solutions are end of life now at McAfee. Network threat analyzer may be used for endpoint quarantines. Integration between these sides, as well as endpoint APO, will help you quarantine the risky endpoints."
"The Network Security Managers could be more stable, agile, and work faster."
"Currently, the settings and confirmations on the McAfee console are complex and complicated for our branches."
"The management console needs to be less complex and easier to navigate."
"In terms of high-security attacks, not all of them are developed. You cannot do a rule that includes all high severities."
"Some of the documentation is not as straightforward as it could be."
 

Pricing and Cost Advice

"There is an annual license to use Darktrace."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"It was $3,600 a month or $2,000 plus or so. I am not sure. Its licensing is pretty simple."
"The pricing is subscription-based and it is high."
"The pricing is a little high compared to the competition."
"The solution is about $6,000 per quarter."
"It is a very expensive product."
"I am using a demo of Darktrace for deployment and testing which is free."
"The pricing and licensing are competitive."
"​Accurately predict your licensing counts as this is a subscription based product.​"
"The solution has a mid-range price point in the market"
"It is a reasonably priced solution."
"It is on a yearly basis. For our own company, for about 250 users, it was 16,000 euros a year."
"Rapid7 InsightIDR is a cheaply priced product. On a scale of one to ten, where one is very expensive, and ten is very cheap, I rate the product's price at seven or eight."
"Rapid7 InsightIDR's pricing is reasonable but we have challenges with the Minimum Order Quantity. It is not reasonable for customers who have less than one hundred devices. If they can reduce Minimum Order Quantity, it is good. You have to pay around 5000-6000 dollars per year for the product. The pricing includes maintenance and support costs."
"The team is very willing to work with companies. My suggestion is to call the Rapid7 sales department and see how they can help.​"
"The tool is competitively priced."
"I rate the product’s pricing an eight out of ten."
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
895,990 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
9%
Financial Services Firm
9%
Computer Software Company
9%
Government
7%
Financial Services Firm
9%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
7%
Manufacturing Company
12%
Comms Service Provider
11%
Financial Services Firm
10%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise29
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise6
Large Enterprise6
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is a...
What needs improvement with Rapid7 InsightIDR?
If we pitch Rapid7 InsightIDR against solutions such as SIEMs from Splunk or LogRhythm, it is not as customizable as ...
What needs improvement with McAfee Network Security Platform?
Trellix Intrusion Prevention System does not provide virtual patching. Patching involves updates on the OS side to ad...
What is your primary use case for McAfee Network Security Platform?
We do not use Trellix Intrusion Prevention System; rather, we sell the Trellix Intrusion Prevention System solution. ...
What advice do you have for others considering McAfee Network Security Platform?
I have experience working with other tools, specifically Trellix solutions such as DLP, EDR, and MDR, as well as with...
 

Also Known As

No data available
InsightIDR
McAfee Network Security Platform, McAfee NSP, IntruShield Network Intrusion Prevention System, IntruShield Network IPS
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Liberty Wines, Pioneer Telephone, Visier
Desjardins Group, HollyFrontier, Nubia, Agbar, WNS Global Services, INAIL, Universidad de Las Américas Puebla (UDLAP), Cook County, China Pacific Insurance, Bank Central Asia, California Department of Corrections and Rehabilitation, City of Chicago, Macquarie Telecom, Sutherland Global Services, Texas Tech University Health Sciences Center, United Automotive Electronic Systems
Find out what your peers are saying about Darktrace, Vectra AI, TrendAI and others in Network Detection and Response (NDR). Updated: May 2026.
895,990 professionals have used our research since 2012.