Try our new research platform with insights from 80,000+ expert users
Head of Security at a financial services firm with 201-500 employees
Real User
Sep 6, 2022
Stable security solution that offers behavioral analytics for the monitoring of traffic
Pros and Cons
  • "The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic."
  • "The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."

What is our primary use case?

We are a financial Institute and make use of the IDS solution. We have the SIM called QRadar. We analyze all the traffic clouds with Darktrace and SIM.

What is most valuable?

The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic.

What needs improvement?

Sometimes the solution gives some false positives which could be improved. The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved. 

For how long have I used the solution?

I have been using this solution for three years. 

Buyer's Guide
Darktrace
December 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.

What do I think about the stability of the solution?

This is a stable solution. 

What do I think about the scalability of the solution?

This is a scalable solution. 

How are customer service and support?

The technical support is very good but we would like to get some information from APAC because we are in APAC region.

Which solution did I use previously and why did I switch?

We considered McAfee and other solutions but based on budget and features, we decided to go with Darktrace.

How was the initial setup?

The initial setup is straightforward and so is the maintenance. 

What about the implementation team?

The deployment was done in-house.

What other advice do I have?

I would rate this solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Manager at a computer software company with 11-50 employees
Real User
Feb 22, 2022
Simple to set up with an excellent Enterprise Immune System and Cyber AI Analyst
Pros and Cons
  • "The initial setup is simple."
  • "There aren't so many third-party vendor platforms natively integrated with the platform."

What is our primary use case?

We primarily use the solution for network traffic analysis, to identify potential threats running on our customers' ICP environment, and to generate alerts to our SOC.

What is most valuable?

The Enterprise Immune System, Cyber Artificial Intelligence Analyst, and Antigena technology are all very useful aspects of the product.

The solution is quite stable.

The scalability is great.

The initial setup is simple.

What needs improvement?

It can always improve here and there, however, in general, it's already quite complete. 

The solution could have better integration capabilities. There aren't so many third-party vendor platforms natively integrated with the platform. 

They need a better-automated response setup.

For how long have I used the solution?

I've been using the solution for a few years at this point. 

What do I think about the stability of the solution?

The solution is stable. There are no bugs or glitches. it doesn't crash or freeze. It's reliable. 

What do I think about the scalability of the solution?

I've found the solution's scalability to be very good. It can scale from one endpoint to many thousands of endpoints. We have a lot of implementations that are quite sizable for our customers.

We have 20 to 30 clients on the solution at this time. 

How are customer service and support?

Technical support is fine. That said, we are very skilled and therefore we don't require the help of technical support all that often.

How was the initial setup?

We find the implementation process to be quite painless. We only had to identify the right place in which put the appliances, and then they start learning.

We were able to deploy same day. it's a pretty fast process. 

We have a team dedicated to the delivery that manages Darktrace and other technical solutions and they are in charge of implementation in the customers' ICP environment. More or less, we have more than ten people handling this.

What about the implementation team?

We are capable of handling implementations for our clients. 

What's my experience with pricing, setup cost, and licensing?

Our clients pay a yearly licensing fee. I can't speak to the exact costs involved. We have a variety of clients who have licenses with Darktrace.

What other advice do I have?

We are partners of Darktrace.

We utilize both cloud and on-premises deployments. 

I would recommend the solution to other companies and clients.

I'd rate the product at a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Darktrace
December 2025
Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,422 professionals have used our research since 2012.
reviewer1264764 - PeerSpot reviewer
Customer Solution Manager at a tech services company with 51-200 employees
Real User
Feb 13, 2022
Beneficial artificial intelligence module, high quality support, and powerful
Pros and Cons
  • "The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network."
  • "The module can improve so that every time it's more intelligent."

What is our primary use case?

Darktrace just scans the entire network and documentation. We then automatically evaluate which behaviors are normal and which are not normal. You can determine what possible risks are in the network.

What is most valuable?

The most valuable feature of Darktrace and the most valuable feature is the artificial intelligence module because that is the tool that determines automatically if there is any risk or not in the network.

You don't need a human operator to be involved. The tool can operate by itself... By itself. That's the best and the most important feature because that reduces the amount of time that a person needs to spend on the tool.

The solution is powerful and very useful, it has the ability to avert many attacks.

The tool does almost 95 percent of the work and you only need to run some features to obtain reports.

What needs improvement?

The module can improve so that every time it's more intelligent.

For how long have I used the solution?

I have been using Darktrace for approximately three years.

What do I think about the stability of the solution?

The stability of Darktrace is good.

What do I think about the scalability of the solution?

Darktrace is a scalable solution.

How are customer service and support?

The support from Darktrace is very good, it is perfect.

How was the initial setup?

Darktrace is installed in an appliance and that appliance is installed in the network. 

What about the implementation team?

We have one engineer that does the maintenance of Darktrace. They do the implementation and scanning of the network.

The solution does not require a lot of maintenance, it does most of the operations automatically.

We provide technical services.

What's my experience with pricing, setup cost, and licensing?

The cost of the solution is expensive for smaller businesses. They will not be able to afford it or might not need this type of security solution.

The license is by device,  if you have 1,000 devices, then the cost is going to be high.

What other advice do I have?

My advice to others is for them to try to determine what are their costs in security. Then they can determine the benefit of Darktrace. They need to first acknowledge what their costs are and then they can start pricing what solution would be best.

I rate Darktrace a ten out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1200357 - PeerSpot reviewer
Team Lead Manager with 501-1,000 employees
Real User
Jan 15, 2022
Gives us visibility of rogue network traffic, prevents data exfiltration, good technical support
Pros and Cons
  • "The most valuable feature is that it gives us visibility of rogue traffic that is on the network."
  • "This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious."

What is our primary use case?

We use Darktrace for security, and to give us better visibility.

How has it helped my organization?

If a user is exfiltrating data, normally we don't have the tools to detect it. With Darktrace, it detects this data. Also, if there is any command-and-control then this solution will highlight that.

What is most valuable?

The most valuable feature is that it gives us visibility of rogue traffic that is on the network.

The detection capabilities are good.

What needs improvement?

This product needs more in terms of prevention. The detection capabilities work well but once a threat has been detected, Darktrace should work to prevent it from doing anything malicious.

Integration with SOAR systems may be helpful, depending on the SOAR.

What do I think about the stability of the solution?

Stability-wise, Darktrace is very good. It runs in the background 24/7.

What do I think about the scalability of the solution?

The scalability is good because it covers our whole network.

We have 1,000 business and IT users and for our environment, the scalability is very good. 

How are customer service and support?

The technical support is good. I would rate them an eight out of ten.

Which solution did I use previously and why did I switch?

We did not use another similar solution prior to Darktrace.

How was the initial setup?

The initial setup was very straightforward. It took approximately two months to complete the implementation and deployment.

What about the implementation team?

We used a consultant to assist us with the implementation.

One person is enough for the deployment and maintenance.

Which other solutions did I evaluate?

There may have been others that we looked at but this is the main one we evaluated.

What other advice do I have?

My advice for anybody who is looking into implementing Darktrace is to do a proof of concept first. Try to out because it's quite useful for providing visibility in the network.

Overall, this is a good product that seems to be working well.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SOC Manager at a computer software company with 51-200 employees
Real User
Jan 9, 2022
Good visibility, secure, with a variety of modules for investigating various behaviors
Pros and Cons
  • "The platform has many modules, and each module examines a different situation in the behavior."
  • "It's a very complex platform."

What is our primary use case?

Darktrace is a platform that is used to check all infrastructures. They check the compartmental in the network.

What is most valuable?

It is a very good platform for understanding what is going on in your network or in your environment because it checks all the activities. This is the same when I use activities on the device, server, network, and web, it checks it all.

The platform has many modules, and each module examines a different situation in the behavior.

What needs improvement?

It's a very complex platform.

For how long have I used the solution?

I have been working with Darktrace for approximately one year.

What do I think about the stability of the solution?

Darktrace is a stable product.

What do I think about the scalability of the solution?

It's a scalable platform.

How are customer service and support?

The technical support is not very good.  I believe that the support must be very quick and operational. Support will need to grow in Italy, but I'm not sure about the other side.

What's my experience with pricing, setup cost, and licensing?

It's an expensive solution.

What other advice do I have?

While it is complex, and difficult to use, once you understand the correct way to use it, it's a very good platform. I would rate Darktrace a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
PeerSpot user
reviewer1393731 - PeerSpot reviewer
Consultant at a computer software company with 5,001-10,000 employees
Real User
Dec 7, 2021
Descriptive GUI, stable, and easy to understand for new users
Pros and Cons
  • "I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user."
  • "Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better."

What is most valuable?

I have used multiple solutions, but its graphical user interface is quite interesting and quite descriptive. There are a lot of video animations, and we can easily see how the data is transferred between various points. That's something really interesting. It is also quite easy to understand for a new user.

What needs improvement?

Its documentation is not up to the mark. At times, I have a lot of trouble finding a solution. Even when I posted questions on the community chats, it took a lot of time for me to get answers. That's something that can be improved. Darktrace can focus on creating a more interactive community. If there are more people from Darktrace to focus on community chats, it would be better.

For how long have I used the solution?

It has been close to two months, and I am probably using the latest version.

What do I think about the stability of the solution?

It is definitely stable.

What do I think about the scalability of the solution?

So far, we haven't had any problems. It is definitely scalable.

We don't have more than 12 people who use this solution.

How are customer service and support?

I never had any technical support problems. It is up to the mark.

Which solution did I use previously and why did I switch?

I have worked with Elastic SIEM and QRadar. Elastic SIEM is entirely different, so there is no one-to-one comparison. It is like comparing apples with oranges, but overall, Darktrace is quite interesting. A new user can easily learn it without much help.

How was the initial setup?

I never did any setup. I'm just an end-user.

What other advice do I have?

My advice is to always go for a PoC before implementing Darktrace. That's because Darktrace can get a lot of personally-identified information, which may not be a good thing for some companies. So, before going for this technology, you should do a PoC, and once everything is compliant with the rules and regulations of the company, you can go for it.

I would rate it an eight out of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1666347 - PeerSpot reviewer
Security Engineer at a real estate/law firm with 1,001-5,000 employees
Vendor
Sep 15, 2021
Provides a higher level of threat detection, detects any type of attack, and very useful for an autonomous response
Pros and Cons
  • "The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response."
  • "They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there."

What is our primary use case?

We use it to protect IoT devices. Darktrace does network traffic analysis. So, by analyzing all traffic patterns in your environment, you can detect any type of anomalous activity, as far as the network is concerned. 

I have been using its latest version. Its deployment depends on the environment. It can do sensors in the cloud, and it can also do on-prem.

How has it helped my organization?

It provided a higher level of threat detection.

What is most valuable?

The Antigena feature is most valuable. Once it learns your environment, Antigena can step in and block a denial of service attack, a ransomware attack, or just about anything that doesn't belong in the environment. It can detect any type of attack that hits the environment because it understands what normal looks like for the network. It is very useful for an autonomous response. 

What needs improvement?

They just need to make it a little bit more accurate as far as their alerts are concerned. It does generate some false positives that you have to tune. You have to do a lot of tuning when you first get it because of the false positives, but once it is all tuned up and ready to go, it will do its thing from there. 

For how long have I used the solution?

I used it for about a year.

What do I think about the stability of the solution?

It is a very stable product. We didn't have any issues.

What do I think about the scalability of the solution?

It has sensors that you can install. So, it can scale on-prem and off-prem in the cloud.

It is being used extensively. We have 2,000 employees. We use it to protect IoT devices. We also use it to protect Windows servers, desktops, and laptops. Its usage would increase if the net grows, but it's probably not going to grow too much bigger than 2,000 employees.

How are customer service and technical support?

The support from Darktrace is very helpful.

Which solution did I use previously and why did I switch?

We didn't use any other solution previously. 

How was the initial setup?

It was pretty straightforward. You just monitor everything from your core switch. It monitors everything in and out.

We got it up in half an hour, but it still has to learn. You still have to give it some time to learn about the environment, and that's usually going to be at least two weeks.

What about the implementation team?

We brought in their guy to the site. In terms of maintenance, it is automatically set up to reach out to their website and pull down updates and stuff. We don't have to worry about that too much.

What's my experience with pricing, setup cost, and licensing?

It was $3,600 a month or $2,000 plus or so. I am not sure. 

Its licensing is pretty simple.

Which other solutions did I evaluate?

We were thinking about getting another solution called Vector, but we didn't. We brought Darktrace in.

What other advice do I have?

Darktrace is a pretty good company. The only thing that they need to really work on is just being able to get rid of some of those false positives. Once the solution is tuned up, it pretty much just runs.

I would advise making sure that you do a really good PoC of the product so that you can be sure that it makes sense in your environment.

I would rate it a nine out of 10. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Group IT Manager at a manufacturing company with 1,001-5,000 employees
Real User
Jul 7, 2021
Advanced Cybersecurity Artificial Intelligence, plenty of features, and impressive threat detection
Pros and Cons
  • "I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network."
  • "In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from."

What is our primary use case?

Darktrace is used for cybersecurity, you can buy it as a physical appliance or solution as a service on the cloud. I tried the on-premises solution to detect any threat over our network.

How has it helped my organization?

Darktrace played an important role in the security detection strategy by reducing the time lost in detecting, analyzing, and incident resolving. This is due to its friendly user interface that shows you in simple graphs and analytics the output for any log over your network whether it is computer, device, switch, access point, etc...

What is most valuable?

I have found the most valuable features to be artificial intelligence for cybersecurity, advanced machine learning capabilities, enterprise Immune System, Antigena Network, and Antigena Email. The way the solution detects the threat over the network before it spreads is very good. It notifies you of what the threat is exactly doing and gives you all the details about the execution of that application that had created the threat over your network.

There is an included library of threat detections, not only locally, but threats being experienced all around the world. It is similar to a database of all the threats and what is done by cybersecurity administrators across the internet. By collecting events and information all around the world makes Darktrace more proactive in dealing with threat notifications and cybersecurity detection. The service is very comprehensive and can cover all security areas.

It has simple tracking capabilities and a graphical interface that can assist you with coding, you do not need to be a guru. The dashboards are user-friendly and you do not need an application to access your work, it is all done through any browser. Additionally, there is a mobile application that is one of the best features because you can see any threats from your phone. There is a playbook that can give you instructions. For example, if you see your network servers are being injected by ransomware you can stop the session and be notified of which person on what computer triggered the threat.

The solution is very professional. Everybody would like to have an application on their phone to be more proactive about security anywhere and this solution delivers.

What needs improvement?

In an upcoming release, there could be more customizable playbooks or a library of playbooks to choose from. Since it is collecting all scenarios that might happen from any threat, new playbooks may be discovered and customers will have the privilege to use them in their environment. Other than that, Darktrace is leading in every aspect.

For how long have I used the solution?

I have been using this solution for one month.

What do I think about the stability of the solution?

Very Stable

What do I think about the scalability of the solution?

We have a number of employees using the solution in my organization which includes administrators and management.

How are customer service and technical support?

Technical support is excellent. You can communicate with them by sending an email, WhatsApp messages, or other types of communication. They have their support in many places around the world so what ever your time zone is, they are available.

The support you do receive is excellent.

Which solution did I use previously and why did I switch?

I have used other solutions previously but non had this intelligence,

How was the initial setup?

The installation is very easy. I was shocked by the simplicity of the management, implementation, and dashboards. 

What about the implementation team?

I have implemented it using Darktrace Team who were very professional.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is not cheap. It is not a one-time purchase, there is a subscription that needs to be paid every one to five years depending on your choice. It is expensive but you can reduce the price by only using the services that you want. There is some flexibility, for example, if you only want to have email inspections, network inspections, endpoint inspections, or brief analytics of the reports and controls over your infrastructure, can reduce the prices accordingly. Not choosing all the features can reduce the price. When comparing this solution to competitors in the market it is expensive. However, you are paying for a valuable solution with plenty of features. Their artificial and cyber intelligence is working extremely well. I am a consultant and work with a variety of solutions by myself, attend training, and understand people who are working with these solutions.

I need to know the advantage, disadvantages, weaknesses, and what makes the solution better than the others. Darktrace proves at some point that the value of money you are paying for the solution is reasonable for the advanced technology you are receiving as it covers many solutions that can cost much  much more than darktrace where as i you bought Darktrace you reducing all the complexity to one simple solution. 

Which other solutions did I evaluate?

I have evaluated many other solutions.

What other advice do I have?

My advice to those wanting to implement this solution is if they want to experience artificial intelligence, advanced cybersecurity, and high-level detection, this solution is the one. 

I rate Darktrace a nine out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros sharing their opinions.