We use the solution for email, network and cloud security.
Manager, Information Security at a manufacturing company with 1,001-5,000 employees
A hybrid quality solution for email, network and cloud security
What is our primary use case?
What is most valuable?
The network security and AR response are the main things.
What needs improvement?
The product is expensive, but it is a very good product. The user interface is also good.
For how long have I used the solution?
I have been using Darktrace for two years.
Buyer's Guide
Darktrace
June 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
The product is stable.
I rate the solution’s stability a nine out of ten.
What do I think about the scalability of the solution?
The solution’s scalability is pretty straightforward. We’ve around 3500 users using this solution.
I rate the solution’s scalability an eight out of ten.
How are customer service and support?
I contact technical support on occasion and ask questions, and they are responsive. I can get them on call or email. I’m very happy with the support.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was quick and painless.
What's my experience with pricing, setup cost, and licensing?
The product is very expensive.
What other advice do I have?
The product is expensive, but it is a quality product. If you look apart from the cost, it's a good product followed by very good support. If you're willing to spend the money, it is worth consideration.
Overall, I rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Information Security Analyst at INFRATEL CORPORATION ZAMBIA LIMITED
Efficient behaviour analytics features and offers high stability
Pros and Cons
- "One thing I appreciate is Antigena Email, which is for email protection."
- "One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent."
What is our primary use case?
Our primary use case is incident response.
How has it helped my organization?
One thing I appreciate is Antigena Email, which is for email protection.
What is most valuable?
One of the most valuable features is Behavior analytics.
What needs improvement?
One thing I would like is for Darktrace to flag SMB traffic more accurately. Currently, it only flags that SMB traffic has occurred, but it doesn't specify which file was being transferred. This makes it difficult to investigate incidents involving SMB traffic, as we don't have concrete evidence of what was being sent.
For example, if a user is sent an unauthorized file via SMB, Darktrace would only flag that SMB traffic occurred between the two users. It wouldn't be able to tell us which file was sent, so we would have to manually investigate the incident to determine what happened.
It would be helpful if Darktrace could flag the specific file that was being transferred in SMB traffic incidents. This would make it much easier to investigate these incidents and take appropriate action.
In future releases, I would like to see more playbooks.
For how long have I used the solution?
I have been using this solution for a year now.
What do I think about the stability of the solution?
I would rate the stability a ten out of ten.
What do I think about the scalability of the solution?
I would rate the scalability an eight out of ten. There are five end users in our analyst team.
How are customer service and support?
The customer service and support are really good. That's one of the things that I've come to appreciate about Darktrace.
Any concern that you give to them, they come on board and arrange a meeting where you could possibly do some practical work with them. They would take on the incident, and they would say, "Okay. Let's set this incident together."
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used Sophos. We chose Darktrace because of its reliability. Unlike other solutions that rely heavily on signature-based logins, Darktrace operates by learning the behavior of individual users. This means that what may seem normal to me could be considered abnormal for someone else, and Darktrace can effectively block such anomalies. This feature has proven to be immensely helpful.
How was the initial setup?
The initial setup is very easy. I would rate my experience with the initial setup a ten out of ten, where one is difficult and ten is easy to set up.
It took around an hour to set up.
What about the implementation team?
The deployment process is pretty self-sufficient. It handles network closure and device discovery.
One person is sufficient for the deployment process.
What's my experience with pricing, setup cost, and licensing?
The solution is quite expensive. I would rate the licensing model an eight out of ten.
What other advice do I have?
I would recommend it based on its excellent behavior analytics and AI implementation.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Darktrace
June 2025

Learn what your peers think about Darktrace. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
Cyber Security Engineer at Natica IT Consulting at Natica IT Consulting
A user-friendly cyber defense solution with useful dashboards
Pros and Cons
- "I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good."
- "It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper."
What is our primary use case?
Our customers use Darktrace to monitor network traffic.
What is most valuable?
I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good.
What needs improvement?
It should be easier to access the Darktrace portal and its documentation. Only the customer can access their portal and support. It could be cheaper.
What do I think about the stability of the solution?
Darktrace is relatively stable.
What do I think about the scalability of the solution?
Darktrace is scalable. It's very good. We have two big banks in Turkey using this solution.
How was the initial setup?
The initial setup is straightforward. It takes me about half an hour to deploy this solution.
What about the implementation team?
We implement this solution.
What's my experience with pricing, setup cost, and licensing?
Darktrace is expensive. You can pay for the license yearly.
What other advice do I have?
I would recommend this solution to potential users. But the cloud solution is challenging to use in Turkey.
On a scale from one to ten, I would give Darktrace an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Team Lead - Cyber Security & Compliance at Al Tuwairqi Group
Easy to deploy, stable, and scalable
Pros and Cons
- "The AI-based pattern is the most valuable feature."
- "There is a high ratio of false positive information."
What is our primary use case?
The solution is used as an anti-phishing tool.
What is most valuable?
The AI-based pattern is the most valuable feature. The AI monitors users' patterns in how they draft and send emails, so if there is a change in the pattern the email is flagged.
What needs improvement?
There is a high ratio of false positive information. For example, AI capabilities can sometimes make it difficult to distinguish between a legitimate email and a phishing email. This is one of the features that need to be manually sorted out and aligned. We need to improve this feature by putting DNS into the micro.
For how long have I used the solution?
I have been using the solution for three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support team is good and they provide support on a priority level.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
The cost is moderate.
What other advice do I have?
I give the solution an eight out of ten.
Our organization chose Darktrace because of its phishing capabilities.
Darktrace is the best way to secure a gateway and I recommend the solution to others.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer:
Chief Information Security Officer at a consultancy with 201-500 employees
The solution's reports are intuitive and informative
Pros and Cons
- "The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
- "The level of tracking within the network from the transmission level up to the machine level can use improvement."
What is most valuable?
The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff.
What needs improvement?
The level of tracking within the network from the transmission level up to the machine level can use improvement.
The solution works similarly to an intrusion prevention system at the network level. It would be a nice improvement to have an add-on that can act at the post level.
The cost of the solution can be reduced to make it more appealing to customers.
For how long have I used the solution?
I have been using the solution for two and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable but costly to do.
How are customer service and support?
The customer support team is responsive and tries to resolve the issue proactively.
How was the initial setup?
The setup is straightforward and easy to integrate.
What's my experience with pricing, setup cost, and licensing?
The setup cost for the entry-level is pricy.
What other advice do I have?
I rate the solution a nine out of ten.
It takes a team of five to maintain the solution.
This solution can reduce the resources required to run a security operation center by two-thirds.
The solution's reports are intuitive and informative.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Support Engineer at CCTZ
Secure, beneficial unusual email detection, and high availability
Pros and Cons
- "The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network."
- "Darktrace could improve its features, such as monitoring and detecting ransomware."
What is our primary use case?
Darktrace is used for network security.
How has it helped my organization?
Darktrace has helped our organization be secure from network spam and attacks.
What is most valuable?
The most valuable features of Darktrace are the tracing of unusual external emails and monitoring the local network.
What needs improvement?
Darktrace could improve its features, such as monitoring and detecting ransomware.
For how long have I used the solution?
I have been using Darktrace for approximately three months.
What do I think about the stability of the solution?
Darktrace is a stable solution.
What do I think about the scalability of the solution?
The scalability of Darktrace is good.
We have four companies that are using this solution.
How are customer service and support?
I have not used the support from Darktrace.
How was the initial setup?
The initial setup of Darktrace was simple. The deployment of Darktrace took approximately two weeks.
What's my experience with pricing, setup cost, and licensing?
I am using a demo of Darktrace for deployment and testing which is free.
Which other solutions did I evaluate?
My company chose Darktrace because it helped other companies that needed some help with metrics monitoring and spam monitoring.
What other advice do I have?
I would recommend this solution to others.
I rate Darktrace a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Head of Security at DFCC
Stable security solution that offers behavioral analytics for the monitoring of traffic
Pros and Cons
- "The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic."
- "The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved."
What is our primary use case?
We are a financial Institute and make use of the IDS solution. We have the SIM called QRadar. We analyze all the traffic clouds with Darktrace and SIM.
What is most valuable?
The most valuable feature has been the behavioral analytics that allows us to monitor all the traffic.
What needs improvement?
Sometimes the solution gives some false positives which could be improved. The dashboard and reporting for this solution could be improved as it is currently complex. The GUI for this solution could also be improved.
For how long have I used the solution?
I have been using this solution for three years.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
The technical support is very good but we would like to get some information from APAC because we are in APAC region.
Which solution did I use previously and why did I switch?
We considered McAfee and other solutions but based on budget and features, we decided to go with Darktrace.
How was the initial setup?
The initial setup is straightforward and so is the maintenance.
What about the implementation team?
The deployment was done in-house.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Manager at Yarix S.r.l.
Simple to set up with an excellent Enterprise Immune System and Cyber AI Analyst
Pros and Cons
- "The initial setup is simple."
- "There aren't so many third-party vendor platforms natively integrated with the platform."
What is our primary use case?
We primarily use the solution for network traffic analysis, to identify potential threats running on our customers' ICP environment, and to generate alerts to our SOC.
What is most valuable?
The Enterprise Immune System, Cyber Artificial Intelligence Analyst, and Antigena technology are all very useful aspects of the product.
The solution is quite stable.
The scalability is great.
The initial setup is simple.
What needs improvement?
It can always improve here and there, however, in general, it's already quite complete.
The solution could have better integration capabilities. There aren't so many third-party vendor platforms natively integrated with the platform.
They need a better-automated response setup.
For how long have I used the solution?
I've been using the solution for a few years at this point.
What do I think about the stability of the solution?
The solution is stable. There are no bugs or glitches. it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
I've found the solution's scalability to be very good. It can scale from one endpoint to many thousands of endpoints. We have a lot of implementations that are quite sizable for our customers.
We have 20 to 30 clients on the solution at this time.
How are customer service and support?
Technical support is fine. That said, we are very skilled and therefore we don't require the help of technical support all that often.
How was the initial setup?
We find the implementation process to be quite painless. We only had to identify the right place in which put the appliances, and then they start learning.
We were able to deploy same day. it's a pretty fast process.
We have a team dedicated to the delivery that manages Darktrace and other technical solutions and they are in charge of implementation in the customers' ICP environment. More or less, we have more than ten people handling this.
What about the implementation team?
We are capable of handling implementations for our clients.
What's my experience with pricing, setup cost, and licensing?
Our clients pay a yearly licensing fee. I can't speak to the exact costs involved. We have a variety of clients who have licenses with Darktrace.
What other advice do I have?
We are partners of Darktrace.
We utilize both cloud and on-premises deployments.
I would recommend the solution to other companies and clients.
I'd rate the product at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Extended Detection and Response (XDR) Email Security Intrusion Detection and Prevention Software (IDPS) Network Traffic Analysis (NTA) Network Detection and Response (NDR) AI-Powered Chatbots Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Attack Surface Management (ASM) AI-Powered Cybersecurity PlatformsPopular Comparisons
Cloudflare
CrowdStrike Falcon
Wazuh
Microsoft Defender for Office 365
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Trellix Endpoint Security Platform
Proofpoint Email Protection
Tenable Security Center
Cloudflare One
Trend Vision One
Buyer's Guide
Download our free Darktrace Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- I'm building a next-gen AI powered threat intelligence platform. What's missing from existing solutions?
- Which is better - SentinelOne or Darktrace?
- What are the pros and cons of Darktrace vs CrowdStrike Falcon vs alternative EPP solutions?
- Which alternative solutions (other than Darktrace) do you recommend for an SMB?
- How does Crowdstrike Falcon compare with Darktrace?
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?