No more typing reviews! Try our Samantha, our new voice AI agent.

Kaspersky Threat Intelligence Portal vs NetWitness NDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 9, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Kaspersky Threat Intelligen...
Ranking in Threat Intelligence Platforms (TIP)
20th
Average Rating
7.0
Reviews Sentiment
7.8
Number of Reviews
2
Ranking in other categories
No ranking in other categories
NetWitness NDR
Ranking in Threat Intelligence Platforms (TIP)
35th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
15
Ranking in other categories
Endpoint Protection Platform (EPP) (49th), Endpoint Detection and Response (EDR) (57th), Security Orchestration Automation and Response (SOAR) (23rd), Network Detection and Response (NDR) (19th), Extended Detection and Response (XDR) (39th)
 

Mindshare comparison

As of May 2026, in the Threat Intelligence Platforms (TIP) category, the mindshare of Kaspersky Threat Intelligence Portal is 1.4%, up from 1.0% compared to the previous year. The mindshare of NetWitness NDR is 1.3%, up from 1.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms (TIP) Mindshare Distribution
ProductMindshare (%)
Kaspersky Threat Intelligence Portal1.4%
NetWitness NDR1.3%
Other97.3%
Threat Intelligence Platforms (TIP)
 

Featured Reviews

Abdelrahman Hussein - PeerSpot reviewer
CTI & Threat Hunter at Telecom Egypt
Provides useful real-time threat intelligence features but has limited capabilities
We use the product to search for IoCs. It is a good tool, but we do not use all its capabilities. We have only done a POC of the product. The real-time threat intelligence features are useful. The tool has good capabilities. It has a database of IoCs The solution is limited. I have been using…
reviewer1799727 - PeerSpot reviewer
Manager, IT Security Operations at a non-profit with 11-50 employees
Reliable and good support but can be expensive
I have no real complaints about the solution. Threat detection could be better. They need to enhance their threat intelligence feeds. We would like to have more IOCs or more trade intelligence to not only rely on the intelligence of the engineer in charge but to have some threat intelligence and some seeds of IOCs and to have the host have some artificial intelligence to reduce the number of false positives. I don't see this solution being very scalable. The solution is pricey.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution improved our overall security posture."
"The real-time threat intelligence features are useful."
"This solution allows us to locate the malware in real-time."
"It helps our security team respond more accurately when there are threats, then we get less false positives or negatives."
"NetWitness Endpoint's most valuable features are its interoperability across many different operating systems and the ease of pivoting from network to endpoint via a single console."
"We use it for IT security purposes; this is our central log management solution, so we incorporate all of our servers and PCs into this software and can monitor the logs from there."
"It's a scalable solution. We have around five to eight customers using RSA NetWitness Endpoint, and we hope to increase the number of users."
"NetWitness Endpoint has enabled us to detect attacks that bypass the first stage of cybersecurity, like zero-day and advanced attacks."
"I would highly recommend the solution. Just go ahead and get it."
"Ability to isolate the machine when there are malicious files."
 

Cons

"The solution is limited."
"More insights would be helpful. We have multiple solutions for threat intelligence. If someone has a bigger view or full eye on all the incidents, it will be beneficial."
"RSA NetWitness Network could improve on integration with non-native application integration."
"We would like to see the hunting and investigation features of this solution improved, in order to provide better visibility of issues."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"The deployment process is complex. I don't know why, but this solution will suddenly stop working. Logs stop coming. Often, one thing or another stops working. Most of the time, one of my team members is working with troubleshooting and working with technical support. Log passing is also one of the biggest challenge."
"I don't see this solution being very scalable."
"NetWitness Endpoint's blocking feature does not work properly - if there's a malicious process, it's not possible to kill it via a custom rule unless and until it's flagged as malicious."
"This solution needs an upgrade in reporting. I have heard from RSA that they are working on this, but as of yet it is not available."
"RSA NetWitness Network could improve on integration with non-native application integration."
 

Pricing and Cost Advice

Information not available
"With RSA, there is flexibility in choosing the service, products, and the range that meets your requirement, as well as they are flexible in terms of pricing."
"The price of the solution depends on the environment. If the environment is large then it will cost more. However, the larger the environment with more endpoints, you will receive an increased discount. If the environment is very small, then you might think it is expensive. It is always better to buy in bulk to receive a discount. The minimum number of assets is usually 500, with discounts on 1000 and 2000."
"It is highly scalable. It can be bought based on your requirements."
"NetWitness Endpoint is less costly than its competitors, but it offers fewer features."
"It is an expensive product."
"The pricing is not very economical. It is a quite costly product for India. One thing is that when you purchase it, you have to purchase a module separately."
"I do not have any opinion on the pricing or licensing of the product."
"They can easily adjust if you have the requirements which are required. If you have a budget cut or a budget constraint, they can bend."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms (TIP) solutions are best for your needs.
893,164 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Comms Service Provider
16%
Healthcare Company
14%
Construction Company
10%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What needs improvement with Kaspersky Threat Intelligence Services?
More insights would be helpful. We have multiple solutions for threat intelligence. If someone has a bigger view or full eye on all the incidents, it will be beneficial. So, to include everything i...
What is your experience regarding pricing and costs for Kaspersky Threat Intelligence Services?
For the business side, it's a great solution. The solution improved our overall security posture. I would recommend using it. It has a lot of information, monitors for Dark Web Services, data leaka...
Ask a question
Earn 20 points
 

Also Known As

Kaspersky Threat Intelligence
RSA ECAT, NetWitness Network
 

Overview

 

Sample Customers

Telefonica, VimpelCom, Monclick, Ezenta
ADP, Ameritas, Partners Healthcare
Find out what your peers are saying about Kaspersky Threat Intelligence Portal vs. NetWitness NDR and other solutions. Updated: April 2026.
893,164 professionals have used our research since 2012.