We use it to understand our network and traffic. We are basically getting visibility into our infrastructure.
We are using its latest version. It has both deployments. There is one cloud, and there is one on-prem.
We use it to understand our network and traffic. We are basically getting visibility into our infrastructure.
We are using its latest version. It has both deployments. There is one cloud, and there is one on-prem.
The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network.
With Antigena Email, you know from where most of your spam is coming and which country is spamming you a lot.
They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity.
I have been using it for three months.
It is stable.
It is scalable. Currently, we have just two users of this solution, but it covers all the devices that we have.
The customer success manager has been helpful. Their support is pretty good.
We used Microsoft.
It was straightforward. The installation took 30 minutes to an hour. We had training before doing the installation.
We used a consultant. We have just two engineers who are doing the deployment and maintenance.
It is pretty expensive, but it is worth it. Its licensing is yearly.
I would recommend it, but you just need to make sure that your organization is big enough. It's not worth it when the organization is small. I would recommend it for organizations with more than 5,000 devices on their network.
I would rate it an eight out of 10.
We use Darktrace for security, and to give us better visibility.
If a user is exfiltrating data, normally we don't have the tools to detect it. With Darktrace, it detects this data. Also, if there is any command-and-control then this solution will highlight that.
The most valuable feature is that it gives us visibility of rogue traffic that is on the network.
The detection capabilities are good.
This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.
Integration with SOAR systems may be helpful, depending on the SOAR.
Stability-wise, Darktrace is very good. It runs in the background 24/7.
The scalability is good because it covers our whole network.
We have 1,000 business and IT users and for our environment, the scalability is very good.
The technical support is good. I would rate them an eight out of ten.
We did not use another similar solution prior to Darktrace.
The initial setup was very straightforward. It took approximately two months to complete the implementation and deployment.
We used a consultant to assist us with the implementation.
One person is enough for the deployment and maintenance.
There may have been others that we looked at but this is the main one we evaluated.
My advice for anybody who is looking into implementing Darktrace is to do a proof of concept first. Try to out because it's quite useful for providing visibility in the network.
Overall, this is a good product that seems to be working well.
I would rate this solution an eight out of ten.
I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user.
Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better.
It has been close to two months, and I am probably using the latest version.
It is definitely stable.
So far, we haven't had any problems. It is definitely scalable.
We don't have more than 12 people who use this solution.
I never had any technical support problems. It is up to the mark.
I have worked with Elastic SIEM and QRadar. Elastic SIEM is entirely different, so there is no one-to-one comparison. It is like comparing apples with oranges, but overall, Darktrace is quite interesting. A new user can easily learn it without much help.
I never did any setup. I'm just an end-user.
My advice is to always go for a PoC before implementing Darktrace. That's because Darktrace can get a lot of personally-identified information, which may not be a good thing for some companies. So, before going for this technology, you should do a PoC, and once everything is compliant with the rules and regulations of the company, you can go for it.
I would rate it an eight out of 10.
I'm currently heading cybersecurity for 1,500 entities. Some of them have deployed Vectra, and some of them have deployed Darktrace. Darktrace has been in the UK market for a while, whereas Vectra is a not-so-old player in the UK market.
We are using the latest version of Darktrace but not their latest offering. They are now also providing email security over the Darktrace platform, but we have not been utilizing that. We have been utilizing their network detection and response and some part of automated incident response (IR) capability.
We have a hybrid infrastructure. Some centers are deployed in the cloud, and some centers are deployed on-prem. The management platform is currently on-prem, but the plan is to move it to SaaS.
In terms of features, the data or information they collect and unsupervised machine learning are very valuable. Its unsupervised machine learning has reduced our team's effort. Both Darktrace and Vectra work on unsupervised machine learning that learns the behavior or develops a profile on its own, which allows our security team to do some other tasks rather than spending time on Darktrace or Vectra.
Because of unsupervised machine learning, its detection capability is quite good. Along with that, if we utilize the integration feature properly, the automated incident response capability of Darktrace is quite useful.
In terms of improvements, fine-tuning is the area where we have to spend some time because it works on unsupervised machine learning. It would be good if they can improve their algorithm or technical functionality to reduce the fine-tuning effort.
They can also come up with something at the endpoint level. So far, Darktrace has been a network detection response (NDR) solution. It does not offer much at the endpoint level or on user-client devices or servers. There should be more visibility at the endpoint level. It would be good to have the detection and response at the endpoint level by Darktrace.
It should also have integration with an agile environment so that we can have continuous development and continuous integration in the application development environment. This is currently not there. It should also have internet-facing platform visibility, which is currently missing.
They also need to improve the reporting and management dashboards. Currently, these are not so easy for a non-technical person. All these features would make Darktrace much better, and they would also be helpful in selling more solutions.
I have been using this solution for maybe six or seven years. At my previous workplace, we were one of the early adopters of Darktrace's unsupervised machine learning technology.
Its stability is fine. We are utilizing a mix of their deployment capability. We have appliance-based and sensor-based deployments. Performance-wise, sensor-based ones are slower than appliance-based ones. An appliance also has dedicated hardware.
In terms of scalability, it is fine. We have deployed Darktrace for around 7,000 to 8,000 users for one part of an entity, and it has been working fine. I don't see any issue in terms of its scalability.
Currently, it has around 7,000 to 8,000 users, but it is getting extended. We are in the process of extending the Darktrace capability to other entities. We are talking about 1,500 entities and 120,000 users in different dispersed and segregated environments.
They've been quite okay in their responses. This solution is definitely complex, so sometimes we don't get the expected level of information or answer straight away, but they have been okay in responding and following up. I would rate them a seven out of ten.
From the initial deployment perspective, it was quite straightforward. We just need to make some configuration changes and then Darktrace works on spanning. It gets a copy of all the data from the network, and it starts building the profile. It has a pretty straightforward deployment.
I would rate Darktrace a seven out of ten. It is a good solution, but it requires some improvements.
Our primary use case of this solution is for visibility. We try to get the global view of our network from an audit perspective on any given day, and figure out how that will impact our business. I'm a project coordinator and we are customers of Darktrace.
The primary feature we are using is the artificial intelligence and machine learning functionality for reviewing and predicting network traffic and network attacks. Although we're not yet fully using the product, I like the Antigena feature which is their proactive or reactive feature, depending on the deployed antivirus center. Darktrace is for people who understand network security very well, and who have probably been in that scene for quite some time. If you're inclined towards mathematical machine learning, artificial intelligence, and to some degree, data science, this is definitely a tool for you.
It's sometimes a challenge getting logs from different sources. I would probably want to see if there was a way to improve that, to enable gathering of more information.
We've been using this solution for close to four months.
Full deployment took around two weeks, mainly because the solution takes a little time to learn about your network.
The technical support is excellent. They walk you through the process and do a great job.
The initial setup was quite simple; plug in two or three cables, they give you the requirements that you need and off you go. The configuration and learning how to tweak it is a little more complicated and involved, but the initial setup was easy. Deployment took around two to three weeks because the solution sat on the network for about 14 days doing some variable analysis and trending.
It's a good solution. I would suggest that if it's suitable for your requirements, get it.
I would rate this solution a nine out of 10.
We mostly use it for investigating cases. It is deployed on-premises. We have some new projects for this year to extend Darktrace to the cloud.
It is a stable solution.
It can have more integration with orchestration or event management solutions. They can provide more knowledge or research information for analysts for investigating cases and detecting anomalies in networks.
I have been using this solution for a year.
It is a stable solution. We don't have any problems with that.
It has got good scalability, but you need to buy many appliances to scale it. We have ten users of this solution from the incident response team.
We don't directly raise tickets with Darktrace. We use a local partner for support.
We didn't use any other solution previously. We are trying to introduce ExtraHop. The main difference is the capacity and the ability to see encrypted traffic.
It is not a complex setup, but it requires a lot of time. It took two or three months the first time, but it was a very smart installation.
We have a partner.
It is expensive. I don't have the price for other competitors.
I would recommend this solution. You need to have a good plan for its initial installation. It requires a lot of work in the network.
I would rate Darktrace an eight out of ten.
We use the solution for email, network and cloud security.
The network security and AR response are the main things.
The product is expensive, but it is a very good product. The user interface is also good.
I have been using Darktrace for two years.
The product is stable.
I rate the solution’s stability a nine out of ten.
The solution’s scalability is pretty straightforward. We’ve around 3500 users using this solution.
I rate the solution’s scalability an eight out of ten.
I contact technical support on occasion and ask questions, and they are responsive. I can get them on call or email. I’m very happy with the support.
Positive
The initial setup was quick and painless.
The product is very expensive.
The product is expensive, but it is a quality product. If you look apart from the cost, it's a good product followed by very good support. If you're willing to spend the money, it is worth consideration.
Overall, I rate the solution an eight out of ten.
Our primary use case is incident response.
One thing I appreciate is Antigena Email, which is for email protection.
One of the most valuable features is Behavior analytics.
One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent.
For example, if a user is sent an unauthorized file via SMB, Darktrace would only flag that SMB traffic occurred between the two users. It wouldn't be able to tell us which file was sent, so we would have to manually investigate the incident to determine what happened.
It would be helpful if Darktrace could flag the specific file that was being transferred in SMB traffic incidents. This would make it much easier to investigate these incidents and take appropriate action.
In future releases, I would like to see more playbooks.
I have been using this solution for a year now.
I would rate the stability a ten out of ten.
I would rate the scalability an eight out of ten. There are five end users in our analyst team.
The customer service and support are really good. That's one of the things that I've come to appreciate about Darktrace.
Any concern that you give to them, they come on board and arrange a meeting where you could possibly do some practical work with them. They would take on the incident, and they would say, "Okay. Let's set this incident together."
Positive
We used Sophos. We chose Darktrace because of its reliability. Unlike other solutions that rely heavily on signature-based logins, Darktrace operates by learning the behavior of individual users. This means that what may seem normal to me could be considered abnormal for someone else, and Darktrace can effectively block such anomalies. This feature has proven to be immensely helpful.
The initial setup is very easy. I would rate my experience with the initial setup a ten out of ten, where one is difficult and ten is easy to set up.
It took around an hour to set up.
The deployment process is pretty self-sufficient. It handles network closure and device discovery.
One person is sufficient for the deployment process.
The solution is quite expensive. I would rate the licensing model an eight out of ten.
I would recommend it based on its excellent behavior analytics and AI implementation.
Overall, I would rate the solution an eight out of ten.
The tool offers us visibility into network traffic.
The tool gives us alerts whenever an admin is trying to connect.
I am impressed with the product's ability to give insights into network traffic.
I would like to see a feature where the tool ingests information from an anti-malware product that is present at the endpoint.
I am using the product since September.
The solution is stable.
The tool's deployment is easy.
The tool's pricing is costly.
I would rate the tool a nine out of ten. You need to use the tool on a trial basis so that you can get comfortable with it.
We are a consulting company and sell Darktrace to our customers. Our company is in West Africa. I'm the company CEO.
Darktrace can observe networks and respond to those observations. It provides great network protection, is innovative and flexible.
I think Darktrace needs to improve its collaboration with local partners. That would include training and improving the technical skills of vendors. Desktop and mobile device protection could also be improved.
We've been selling this solution for two years.
The solution is stable.
Our customers report that the technical support is very good.
Positive
The initial setup is reasonably straightforward although the process requires some preparation beforehand. The size of deployment varies greatly, we've deployed in companies ranging in size from 200 up to 5,000 users.
Licensing costs are expensive, although I think the high cost is partly a currency issue because we're based in West Africa.
I rate this solution eight out of 10.
