


NetWitness NDR and Microsoft Sentinel are competing products in the network detection and response space. Microsoft Sentinel holds an advantage in feature richness, making it worth its price.
Features: NetWitness NDR offers comprehensive threat detection, network traffic analysis, and incident response capabilities. Microsoft Sentinel features cloud-native architecture, AI-driven insights, and seamless integration with Microsoft products.
Room for Improvement: NetWitness NDR could improve its user interface, integration capabilities with third-party applications, and simplify setup processes. Microsoft Sentinel can enhance its non-Microsoft product integration, reduce false positives, and improve KQL query documentation.
Ease of Deployment and Customer Service: Microsoft Sentinel provides cloud-based deployment, simplifying scalability and integration with existing Microsoft services backed by extensive support. NetWitness NDR offers both cloud and on-premise options, requiring more complex initial setups but provides a dedicated support team.
Pricing and ROI: NetWitness NDR presents an upfront setup cost with flexible agreements, cost-effective for network-centric security organizations. Microsoft Sentinel offers a pay-as-you-go pricing model with strong potential ROI due to reduced setup expenses and cost alignment with usage.
```| Product | Market Share (%) |
|---|---|
| Microsoft Sentinel | 13.0% |
| Torq | 4.9% |
| NetWitness NDR | 1.2% |
| Other | 80.9% |


| Company Size | Count |
|---|---|
| Small Business | 38 |
| Midsize Enterprise | 22 |
| Large Enterprise | 45 |
| Company Size | Count |
|---|---|
| Small Business | 10 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
Torq is the enterprise AI SOC solution that effectively combines adaptive insights and automation to handle critical threats efficiently. It manages threat lifecycles, swiftly moving from triage to response, ensuring effective risk management.
Torq is designed to streamline security operations by aggregating telemetry across your security stack. It investigates significant risks and manages threats from triage to containment and remediation. This AI-driven tool enhances the capabilities of your SecOps team, allowing them to achieve more impactful results without introducing complicated processes.
What are the key features of Torq?In industries like finance and healthcare, Torq shows effectiveness by adapting to specific risk scenarios often encountered in these fields. Its integration with existing infrastructures makes it a valuable asset for maintaining stringent security standards, essential for protecting critical data and operations in diverse high-stakes environments.
Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution that lets you see and stop threats before they cause harm. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can:
- Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds
- Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft
- Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft
- Respond to incidents rapidly with built-in orchestration and automation of common tasks
To learn more about our solution, ask questions, and share feedback, join our Microsoft Security, Compliance and Identity Community.
Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness NDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.
We monitor all Security Orchestration Automation and Response (SOAR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.