The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff.
Chief Information Security Officer at a consultancy with 201-500 employees
The solution's reports are intuitive and informative
Pros and Cons
- "The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
- "This solution can reduce the resources required to run a security operation center by two-thirds."
- "The level of tracking within the network from the transmission level up to the machine level can use improvement."
- "The level of tracking within the network from the transmission level up to the machine level can use improvement."
What is most valuable?
What needs improvement?
The level of tracking within the network from the transmission level up to the machine level can use improvement.
The solution works similarly to an intrusion prevention system at the network level. It would be a nice improvement to have an add-on that can act at the post level.
The cost of the solution can be reduced to make it more appealing to customers.
For how long have I used the solution?
I have been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is stable.
Buyer's Guide
Darktrace
March 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution is scalable but costly to do.
How are customer service and support?
The customer support team is responsive and tries to resolve the issue proactively.
How was the initial setup?
The setup is straightforward and easy to integrate.
What's my experience with pricing, setup cost, and licensing?
The setup cost for the entry-level is pricy.
What other advice do I have?
I rate the solution a nine out of ten.
It takes a team of five to maintain the solution.
This solution can reduce the resources required to run a security operation center by two-thirds.
The solution's reports are intuitive and informative.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Support Engineer at CCTZ
Secure, beneficial unusual email detection, and high availability
Pros and Cons
- "The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
- "Darktrace has helped our organization be secure from network spam and attacks."
- "Darktrace could improve its features, such as monitoring and detecting ransomware."
- "Darktrace could improve its features, such as monitoring and detecting ransomware."
What is our primary use case?
Darktrace is used for network security.
How has it helped my organization?
Darktrace has helped our organization be secure from network spam and attacks.
What is most valuable?
The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network.
What needs improvement?
Darktrace could improve its features, such as monitoring and detecting ransomware.
For how long have I used the solution?
I have been using Darktrace for approximately three months.
What do I think about the stability of the solution?
Darktrace is a stable solution.
What do I think about the scalability of the solution?
The scalability of Darktrace is good.
We have four companies that are using this solution.
How are customer service and support?
I have not used the support from Darktrace.
How was the initial setup?
The initial setup of Darktrace was simple. The deployment of Darktrace took approximately two weeks.
What's my experience with pricing, setup cost, and licensing?
I am using a demo of Darktrace for deployment and testing which is free.
Which other solutions did I evaluate?
My company chose Darktrace because it helped other companies that needed some help with metrics monitoring and spam monitoring.
What other advice do I have?
I would recommend this solution to others.
I rate Darktrace a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Darktrace
March 2026
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Head of Security at DFCC
Stable security solution that offers behavioral analytics for the monitoring of traffic
Pros and Cons
- "The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic."
- "The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic."
- "The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
- "The dashboard and reporting for this solution could be improved as it is currently complex."
What is our primary use case?
We are a financial Institute and make use of the IDS solution. We have the SIM called QRadar. We analyze all the traffic clouds with Darktrace and SIM.
What is most valuable?
The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic.
What needs improvement?
Sometimes the solution gives some false positives which could be improved. The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
The technical support is very good but we would like to get some information from APAC because we are in APAC region.
Which solution did I use previously and why did I switch?
We considered McAfee and other solutions but based on budget and features, we decided to go with Darktrace.
How was the initial setup?
The initial setup is straightforward and so is the maintenance.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Manager at Yarix S.r.l.
Simple to set up with an excellent Enterprise Immune System and Cyber AI Analyst
Pros and Cons
- "The initial setup is simple."
- "The Enterprise Immune System, Cyber Artificial Intelligence Analyst, and Antigena technology are all very useful aspects of the product."
- "There aren't so many third-party vendor platforms natively integrated with the platform."
- "The solution could have better integration capabilities."
What is our primary use case?
We primarily use the solution for network traffic analysis, to identify potential threats running on our customers' ICP environment, and to generate alerts to our SOC.
What is most valuable?
The Enterprise Immune System, Cyber Artificial Intelligence Analyst, and Antigena technology are all very useful aspects of the product.
The solution is quite stable.
The scalability is great.
The initial setup is simple.
What needs improvement?
It can always improve here and there, however, in general, it's already quite complete.
The solution could have better integration capabilities. There aren't so many third-party vendor platforms natively integrated with the platform.
They need a better-automated response setup.
For how long have I used the solution?
I've been using the solution for a few years at this point.
What do I think about the stability of the solution?
The solution is stable. There are no bugs or glitches. it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
I've found the solution's scalability to be very good. It can scale from one endpoint to many thousands of endpoints. We have a lot of implementations that are quite sizable for our customers.
We have 20 to 30 clients on the solution at this time.
How are customer service and support?
Technical support is fine. That said, we are very skilled and therefore we don't require the help of technical support all that often.
How was the initial setup?
We find the implementation process to be quite painless. We only had to identify the right place in which put the appliances, and then they start learning.
We were able to deploy same day. it's a pretty fast process.
We have a team dedicated to the delivery that manages Darktrace and other technical solutions and they are in charge of implementation in the customers' ICP environment. More or less, we have more than ten people handling this.
What about the implementation team?
We are capable of handling implementations for our clients.
What's my experience with pricing, setup cost, and licensing?
Our clients pay a yearly licensing fee. I can't speak to the exact costs involved. We have a variety of clients who have licenses with Darktrace.
What other advice do I have?
We are partners of Darktrace.
We utilize both cloud and on-premises deployments.
I would recommend the solution to other companies and clients.
I'd rate the product at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Infrastructure Sup at Capital Development Services
Provides visibility into our infrastructure and helps in identifying most vulnerable devices
Pros and Cons
- "The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network."
- "The ability to see what we have not seen before is most valuable."
- "They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity."
- "They just need to work on their price."
What is our primary use case?
We use it to understand our network and traffic. We are basically getting visibility into our infrastructure.
We are using its latest version. It has both deployments. There is one cloud, and there is one on-prem.
What is most valuable?
The ability to see what we have not seen before is most valuable. It is very interesting to find out the most vulnerable devices in our network.
With Antigena Email, you know from where most of your spam is coming and which country is spamming you a lot.
What needs improvement?
They just need to work on their price. In terms of features, we are trying to understand all the features that we have. We're still exploring everything that we have so that we can fully utilize it. At this point in time, it is not about the features. It is more about utilization. We're just trying to utilize everything to full capacity.
For how long have I used the solution?
I have been using it for three months.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable. Currently, we have just two users of this solution, but it covers all the devices that we have.
How are customer service and support?
The customer success manager has been helpful. Their support is pretty good.
Which solution did I use previously and why did I switch?
We used Microsoft.
How was the initial setup?
It was straightforward. The installation took 30 minutes to an hour. We had training before doing the installation.
What about the implementation team?
We used a consultant. We have just two engineers who are doing the deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It is pretty expensive, but it is worth it. Its licensing is yearly.
What other advice do I have?
I would recommend it, but you just need to make sure that your organization is big enough. It's not worth it when the organization is small. I would recommend it for organizations with more than 5,000 devices on their network.
I would rate it an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Team Lead Manager with 501-1,000 employees
Gives us visibility of rogue network traffic, prevents data exfiltration, good technical support
Pros and Cons
- "The most valuable feature is that it gives us visibility of rogue traffic that is on the network."
- "Overall, this is a good product that seems to be working well."
- "This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."
- "This product needs more in terms of prevention."
What is our primary use case?
We use Darktrace for security, and to give us better visibility.
How has it helped my organization?
If a user is exfiltrating data, normally we don't have the tools to detect it. With Darktrace, it detects this data. Also, if there is any command-and-control then this solution will highlight that.
What is most valuable?
The most valuable feature is that it gives us visibility of rogue traffic that is on the network.
The detection capabilities are good.
What needs improvement?
This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.
Integration with SOAR systems may be helpful, depending on the SOAR.
What do I think about the stability of the solution?
Stability-wise, Darktrace is very good. It runs in the background 24/7.
What do I think about the scalability of the solution?
The scalability is good because it covers our whole network.
We have 1,000 business and IT users and for our environment, the scalability is very good.
How are customer service and support?
The technical support is good. I would rate them an eight out of ten.
Which solution did I use previously and why did I switch?
We did not use another similar solution prior to Darktrace.
How was the initial setup?
The initial setup was very straightforward. It took approximately two months to complete the implementation and deployment.
What about the implementation team?
We used a consultant to assist us with the implementation.
One person is enough for the deployment and maintenance.
Which other solutions did I evaluate?
There may have been others that we looked at but this is the main one we evaluated.
What other advice do I have?
My advice for anybody who is looking into implementing Darktrace is to do a proof of concept first. Try to out because it's quite useful for providing visibility in the network.
Overall, this is a good product that seems to be working well.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a computer software company with 5,001-10,000 employees
Descriptive GUI, stable, and easy to understand for new users
Pros and Cons
- "I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user."
- "I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive, with a lot of video animations where we can easily see how the data is transferred between various points, and it is also quite easy to understand for a new user."
- "Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better."
- "Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution."
What is most valuable?
I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user.
What needs improvement?
Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better.
For how long have I used the solution?
It has been close to two months, and I am probably using the latest version.
What do I think about the stability of the solution?
It is definitely stable.
What do I think about the scalability of the solution?
So far, we haven't had any problems. It is definitely scalable.
We don't have more than 12 people who use this solution.
How are customer service and support?
I never had any technical support problems. It is up to the mark.
Which solution did I use previously and why did I switch?
I have worked with Elastic SIEM and QRadar. Elastic SIEM is entirely different, so there is no one-to-one comparison. It is like comparing apples with oranges, but overall, Darktrace is quite interesting. A new user can easily learn it without much help.
How was the initial setup?
I never did any setup. I'm just an end-user.
What other advice do I have?
My advice is to always go for a PoC before implementing Darktrace. That's because Darktrace can get a lot of personally-identified information, which may not be a good thing for some companies. So, before going for this technology, you should do a PoC, and once everything is compliant with the rules and regulations of the company, you can go for it.
I would rate it an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a real estate/law firm with 1,001-5,000 employees
Provides a higher level of threat detection, detects any type of attack, and very useful for an autonomous response
Pros and Cons
- "The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
- "The Antigena feature is most valuable, because once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment."
- "They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there."
- "They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune."
What is our primary use case?
We use it to protect IoT devices. Darktrace does network traffic analysis. So, by analyzing all traffic patterns in your environment, you can detect any type of anomalous activity, as far as the network is concerned.
I have been using its latest version. Its deployment depends on the environment. It can do sensors in the cloud, and it can also do on-prem.
How has it helped my organization?
It provided a higher level of threat detection.
What is most valuable?
The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response.
What needs improvement?
They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there.
For how long have I used the solution?
I used it for about a year.
What do I think about the stability of the solution?
It is a very stable product. We didn't have any issues.
What do I think about the scalability of the solution?
It has sensors that you can install. So, it can scale on-prem and off-prem in the cloud.
It is being used extensively. We have 2,000 employees. We use it to protect IoT devices. We also use it to protect Windows servers, desktops, and laptops. Its usage would increase if the net grows, but it's probably not going to grow too much bigger than 2,000 employees.
How are customer service and technical support?
The support from Darktrace is very helpful.
Which solution did I use previously and why did I switch?
We didn't use any other solution previously.
How was the initial setup?
It was pretty straightforward. You just monitor everything from your core switch. It monitors everything in and out.
We got it up in half an hour, but it still has to learn. You still have to give it some time to learn about the environment, and that's usually going to be at least two weeks.
What about the implementation team?
We brought in their guy to the site. In terms of maintenance, it is automatically set up to reach out to their website and pull down updates and stuff. We don't have to worry about that too much.
What's my experience with pricing, setup cost, and licensing?
It was $3,600 a month or $2,000 plus or so. I am not sure.
Its licensing is pretty simple.
Which other solutions did I evaluate?
We were thinking about getting another solution called Vector, but we didn't. We brought Darktrace in.
What other advice do I have?
Darktrace is a pretty good company. The only thing that they need to really work on is just being able to get rid of some of those false positives. Once the solution is tuned up, it pretty much just runs.
I would advise making sure that you do a really good PoC of the product so that you can be sure that it makes sense in your environment.
I would rate it a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Network Detection and Response (NDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Extended Detection and Response (XDR) Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
Fortinet FortiGate
Cloudflare
CrowdStrike Falcon
Wazuh
Datadog
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Cortex XDR by Palo Alto Networks
SentinelOne Singularity Complete
Microsoft Defender for Office 365
IBM Security QRadar
Microsoft Sentinel
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- How does Network Detection and Response (NDR) Differ from SIEM?
- What aspects of network security are more concerning to small and medium-sized enterprises?
- What are the best practices for Security Operations Center (SOC)?
- What is the future of the Network Operation Center (NOC)?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?















