Using a centralized combination of network and endpoint analysis, behavioral analysis, data science techniques and threat intelligence, NetWitness NDR helps analysts detect and resolve known and unknown attacks while automating and orchestrating the incident response lifecycle. With these capabilities on one platform, security teams can collapse disparate tools and data into a powerful, blazingly fast user interface.

| Product | Mindshare (%) |
|---|---|
| NetWitness NDR | 3.3% |
| Darktrace | 16.6% |
| Vectra AI | 12.5% |
| Other | 67.6% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Network Detection and Response (NDR) | Mar 28, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Mar 28, 2026 | Download |
| Comparison | NetWitness NDR vs Darktrace | Mar 28, 2026 | Download |
| Comparison | NetWitness NDR vs Vectra AI | Mar 28, 2026 | Download |
| Comparison | NetWitness NDR vs TrendAI Vision One | Mar 28, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| CrowdStrike Falcon | 4.3 | N/A | 97% | 138 interviewsAdd to research |
| Microsoft Defender for Endpoint | 4.1 | N/A | 95% | 213 interviewsAdd to research |
NetWitness XDR offers a straightforward pricing model without setup costs, ensuring a smooth integration for users. Pricing methods typically involve subscription-based models, accommodating per-user or per-device licensing options. The pricing range is adaptable, catering to organizations of different sizes and complexities, providing comprehensive extended detection and response solutions.
| Company Size | Count |
|---|---|
| Small Business | 7 |
| Midsize Enterprise | 2 |
| Large Enterprise | 3 |
| Company Size | Count |
|---|---|
| Small Business | 74 |
| Midsize Enterprise | 54 |
| Large Enterprise | 116 |
NetWitness NDR was previously known as RSA ECAT, NetWitness Network.
ADP, Ameritas, Partners Healthcare
| Author info | Rating | Review Summary |
|---|---|---|
| Manager, IT Security Operations at a non-profit with 11-50 employees | 3.0 | We use this stable NDR solution, finding it easy to use with good support. However, threat detection needs improvement with more intelligence, as it's not very scalable and is expensive. |
| Senior Cyber Security Analyst (SAFe Agile) at a transportation company with 1,001-5,000 employees | 3.5 | I use NetWitness Endpoint for anomaly detection and forensics, appreciating its interoperability and easy pivoting. However, its blocking feature is ineffective, requiring improvements like proper process and IP blocking, which it currently lacks. |
| Associate Vice President - IT Security at Inspira Enterprise | 4.5 | I rate RSA NetWitness Network 9/10, praising its stable unified dashboard and good support, delivering ROI. Improvements are needed for non-native integration and scalability. I advise due diligence for cost-effective deployment. |
| Senior Cybersecurity Consultant at CIA Botswana | 5.0 | I find RSA NetWitness Endpoint excellent for instant threat detection, malware analysis, and endpoint visibility. It's stable, scalable, and easy to use with great built-in features. Installation was simple, support is good, and I rate it 10/10. |
| Information Security Engineer at Nhq Distribution Ltd | 4.0 | I use RSA NetWitness Endpoint for IT security and log management. I value its user behavior analytics, but wish for better integration and an improved dashboard. It's a stable, scalable solution that I recommend. |
| Information Security Specialist at Masria Digital payments | 4.5 | I find this stable network security solution has a flexible, easy interface and straightforward setup. However, I'd like improved hunting and investigation features for better visibility. I rate it 9/10. |
| Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees | 4.0 | I rate this stable, scalable solution an 8/10 for its machine isolation and good ROI, despite customer support being slow. My main concerns are the missing reporting engine and the UI timing out too quickly. |
| Cyber Security Consultant at Mideast Data Systems | 4.0 | I've used RSA NetWitness Endpoint for seven years and find its stability very good. While I recommend it as an evolved XDR solution, I believe its threat intelligence needs improvement and hard-coded IPs hinder migration. |