Try our new research platform with insights from 80,000+ expert users

Darktrace vs ThreatBook comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 31, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Darktrace
Ranking in Network Detection and Response (NDR)
1st
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
82
Ranking in other categories
Email Security (10th), Intrusion Detection and Prevention Software (IDPS) (1st), Network Traffic Analysis (NTA) (1st), Extended Detection and Response (XDR) (6th), AI-Powered Chatbots (3rd), Cloud Security Posture Management (CSPM) (15th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (2nd)
ThreatBook
Ranking in Network Detection and Response (NDR)
14th
Average Rating
9.6
Reviews Sentiment
7.5
Number of Reviews
2
Ranking in other categories
Threat Intelligence Platforms (16th)
 

Featured Reviews

Malebo Lethoba Group - PeerSpot reviewer
Have found the AI analyst and detection functions highly valuable for network operations while managing complexity in initial setup
The functions I find most valuable in Darktrace ( /products/darktrace-reviews ) are the AI analyst as well as the detection.The autonomous response capabilities of Darktrace are not crucial for me because it doesn't work in a network where there are no core switches. In a modern network, the autonomous response doesn't work, especially when sitting in a shared data center.If I'm running a traditional network where I am not in a shared data center with a layer two dedicated for my resources, then it can work for me. However, if I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
RG
Enhancement in incident response through reduced false positives and contextual intelligence
ThreatBook has positively impacted our organization by allowing us to detect all alerts and threats effectively. In the past, we needed to search logs from various sources, including terminals, DI servers, and firewalls, collecting a lot of logs and searching the internet for contextual information about threat actors. After using ThreatBook TDP, all alerts and contexts are easily displayed on the dashboard, making it very helpful for us. During the incident response scenario, ThreatBook saves us over 80% of the time for each incident. We usually took about one day or two days for attribution and understanding how the attacker attacked us, but after using ThreatBook TDP, we usually take around one or two hours to finish all these tasks. Additionally, their AI techniques save a lot of time, allowing me to ask in natural language for explanations about the meaning and target of the attacker.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We liked their approach to identifying intrusions or network anomalies using AI."
"Darktrace's most valuable features are that it understands the network environment and is able to trace the traffic and alert on anomalies."
"The most beneficial feature in Darktrace is identifying phishing emails with the help of the AI engine and machine learning."
"It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
"t was pretty as far as the granularity of what you were getting out of it."
"The AI-based pattern is the most valuable feature."
"I am impressed with the product's ability to give insights into network traffic."
"The most valuable features of Darktrace are its full capabilities. You have visibility of everything."
"ThreatBook saves us over 80% of time for each incident, reducing the usual time taken from one or two days for attribution to just one or two hours, thanks to their AI techniques."
"ThreatBook saves us over 80% of the time for each incident."
 

Cons

"It would be helpful if they could recognize incidents and simplify the customer's challenge to identify what is happening."
"In the next version, I'd like to see penetration testing."
"There aren't so many third-party vendor platforms natively integrated with the platform."
"I believe their network monitoring device licensing module could use some improvement."
"In a shared environment, it doesn't work, and there are still some integration issues."
"It is expensive, but everything else has been great so far."
"Getting logs from different sources can be a challenge."
"The pricing model is a little too high and could be more flexible."
"It would be great if ThreatBook could integrate with our ITSM system to streamline the tasks and incident management"
"We’ve seen strong ROI through reduced incident response times, increased threat visibility, and less time wasted on false positives."
 

Pricing and Cost Advice

"Darktrace is quite an expensive solution."
"All of the other modules, such as the licensing modules, are on par. It's one for one."
"The tool's pricing is costly."
"The pricing is expensive. It costs over $100,000 a year."
"They are too expensive compared with other vendors."
"There is an annual license to use Darktrace."
"It is inexpensive considering what it can do and the competition."
"The cost of the solution can be reduced to make it more appealing to customers."
Information not available
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Manufacturing Company
8%
Financial Services Firm
8%
Government
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What is your experience regarding pricing and costs for ThreatBook?
The procurement process is easy because ThreatBook is a subscription model, and when I need it, I just pay for it. The billing experience is clear with no extra fees; all the costs are clearly show...
What needs improvement with ThreatBook?
It would be great if ThreatBook could integrate with our ITSM system to streamline the tasks and incident management, and I hope this feature will be provided in the future. Everything is perfect, ...
What is your primary use case for ThreatBook?
Mainly, we use ThreatBook TDP to monitor the east-west and north-south network traffic, detect abnormal behaviors, and provide contextual intelligence to support our threat hunting and incident res...
 

Comparisons

No data available
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Information Not Available
Find out what your peers are saying about Darktrace vs. ThreatBook and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.