No more typing reviews! Try our Samantha, our new voice AI agent.

Darktrace vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
Darktrace users experience substantial returns through threat prevention and reduced downtime, despite deployment challenges and difficulty measuring returns.
Sentiment score
6.9
Trellix NDR boosts security confidence, offers up to 200% ROI, reduces costs, and enhances threat detection and response efficiency.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
Systems Specialist/ Administrator at ALFA International Company Limited.
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
It has saved us money and time, and the overall investment has been profitable.
Network & Security Lead at Net-International
 

Customer Service

Sentiment score
7.6
Darktrace's customer service is praised for responsiveness and efficiency, though some suggest improvements for complex issues.
Sentiment score
7.2
Trellix Network Detection and Response support is well-rated but can face delays, with room for improvement on complex issues.
The technical support from Darktrace is of high quality.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
Head of Technology Operations at Pobl Group
The challenge lies in waiting for a response after logging a ticket.
Group Cybersecurity Administrator at Tharisa
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
They help and support us promptly, allowing us to resolve issues immediately.
Network & Security Lead at Net-International
 

Scalability Issues

Sentiment score
7.6
Darktrace is praised for its scalability, supporting diverse user bases and integrating well with existing infrastructures.
Sentiment score
7.3
Trellix Network Detection and Response offers scalable cloud solutions, smooth transitions, and efficient support for diverse enterprise environments.
Darktrace has high scalability, and I would rate it a nine out of ten.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
Since it's cloud-based, it expands easily.
Head of Technology Operations at Pobl Group
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response is scalable.
Network & Security Lead at Net-International
Trellix Network Detection and Response is designed to scale based on our workloads, and it performs well when we scale.
Cyber Security Engineer II (Vulnerability & Threat Management) at FICO
 

Stability Issues

Sentiment score
8.5
Darktrace is highly rated for stability and reliability, with effective monitoring and an intuitive interface despite occasional traffic impacts.
Sentiment score
7.7
Trellix Network Detection and Response is stable and reliable with minor performance issues, requiring experts for deeper maintenance.
The stability of Darktrace is excellent, rated ten out of ten.
Head of Technology Operations at Pobl Group
The appliance itself has never let me down.
Group Cybersecurity Administrator at Tharisa
For stability, I would rate Darktrace an eight out of ten.
Security Analyst at a healthcare company with 10,001+ employees
Trellix Network Detection and Response is somewhat stable but there is a bit of downtime sometimes during the off-hours.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Room For Improvement

Darktrace needs improved integration, automation, usability, pricing, support, and clarity, plus better endpoint protection and third-party tool integration.
Trellix users desire better firewall integration, AI, reporting, UI, customization, threat intelligence, onboarding, documentation, support, and automation.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
Solution Architect at a tech services company with 51-200 employees
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
Security Analyst at a healthcare company with 10,001+ employees
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

Darktrace is costly yet valued for advanced features, offering flexible module selection with negotiable discounts and yearly contracts.
Trellix NDR is seen as pricey yet valued for quality, with customers desiring more cost-effective options despite reliability.
The product is considered expensive compared to others.
Solution Architect at a tech services company with 51-200 employees
The pricing is costly in USD, and they charge based on device counts.
Group Cybersecurity Administrator at Tharisa
The licensing cost is approximately eight dollars a year.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
The price for Trellix Network Detection and Response is reasonable.
IT Manager at Gigabit Technologies Pvt Ltd
I am sure the ROI was definitely fine for this because we were using this tool for three years.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Valuable Features

Darktrace offers AI-driven threat detection, real-time monitoring, and autonomous response with scalability and ease of integration for enhanced security.
Trellix Network Detection excels in threat detection, malware analysis, and integrates seamlessly with existing security tools for real-time response.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
Group Cybersecurity Administrator at Tharisa
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
Security Analyst at a healthcare company with 10,001+ employees
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

Darktrace
Ranking in Network Detection and Response (NDR)
1st
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Email Security (10th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Extended Detection and Response (XDR) (7th), Cloud Security Posture Management (CSPM) (10th), Cloud-Native Application Protection Platforms (CNAPP) (9th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (5th), AI Observability (6th)
Trellix Network Detection a...
Ranking in Network Detection and Response (NDR)
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
Advanced Threat Protection (ATP) (10th)
 

Mindshare comparison

As of June 2026, in the Network Detection and Response (NDR) category, the mindshare of Darktrace is 14.3%, down from 24.1% compared to the previous year. The mindshare of Trellix Network Detection and Response is 3.0%, up from 2.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Network Detection and Response (NDR) Mindshare Distribution
ProductMindshare (%)
Darktrace14.3%
Trellix Network Detection and Response3.0%
Other82.7%
Network Detection and Response (NDR)
 

Featured Reviews

AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Hassan Sheikh - PeerSpot reviewer
Network & Security Lead at Net-International
Integrated sensors have improved traffic inspection and now provide resilient east-west threat control
I believe Trellix Network Detection and Response can be improved by integrating machine learning into its detection response capabilities. Additionally, incorporating failover kits integrated into the sensors could be beneficial. It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features. While Trellix Network Detection and Response sensors are highly capable, I think it would be advantageous to include features such as Layer 7 profiles, application profile filters, web filters, IDx, IP feature sets, signature detection features, and routing and switching capabilities all in one device. While the user interface of Trellix Network Detection and Response is very good, I suggest implementing a customizable dashboard. Additionally, there should be report generation for critical attacks and high alert severities, displayed graphically on the dashboard, and providing options to extract files in Excel format for better visibility.
report
Use our free recommendation engine to learn which Network Detection and Response (NDR) solutions are best for your needs.
896,692 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
9%
Financial Services Firm
9%
Computer Software Company
9%
Government
7%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise29
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise21
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
What is your experience regarding pricing and costs for FireEye Network Security?
The price for Trellix Network Detection and Response is reasonable. The pricing is reasonable, and I do not need to bargain with Trellix or customers.
What needs improvement with FireEye Network Security?
The negative aspect is support. When I need urgent support from Trellix, there is a response after four hours or three hours, which is my main concern regarding the negative point of Trellix Networ...
What is your primary use case for FireEye Network Security?
I am working with Trellix Network Detection and Response as part of my overall experience with these products today. Trellix Network Detection and Response is used for threat and response use cases...
 

Also Known As

No data available
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Darktrace vs. Trellix Network Detection and Response and other solutions. Updated: April 2026.
896,692 professionals have used our research since 2012.