Vectra AI Pros

DW
Operations Manager at a healthcare company with 51-200 employees
One of the core features is that Vectra AI triages threats and correlates them with compromised host devices. From a visibility perspective, we can better track the threat across the network. Instead of us potentially finding one device that has been impacted without Vectra AI, it will give us the visibility of everywhere that threat went. Therefore, visibility has increased for us.
View full review »
AG
Sr. Specialist - Enterprise Security at a mining and metals company with 5,001-10,000 employees
The most useful feature is the anomaly detection because it's not signature-based. It picks up the initial part of any attack, like the recon and those aspects of the kill chain, very well.
View full review »
TS
Senior Security Engineer at a manufacturing company with 10,001+ employees
It does a reliable job of parsing out the logs of all the network traffic so that we can ingest them into our SIEM and utilize them for threat hunting and case investigations. It is pretty robust and reliable. The administration time that we spend maintaining it or troubleshooting it is very low. So, the labor hour overhead is probably our largest benefit from it. We spend 99% of our time in Vectra investigating cases, responding to incidents, or hunting, and only around 1% of our time is spent patching, troubleshooting, or doing anything else. That's our largest benefit from Vectra.
View full review »
Buyer's Guide
Vectra AI
January 2023
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: January 2023.
670,523 professionals have used our research since 2012.
FH
Head of IT Security, Acting CISO at a retailer with 10,001+ employees
Cognito Streams gives you a detailed view of what happens in the network in the form of rich metadata. It is just a super easy way to capture network traffic for important protocols, giving us an advantage. This is very helpful on a day-to-day basis.
View full review »
PR
Head of Information Security at a financial services firm with 51-200 employees
The administrative privilege detection feature is the most valuable feature. The admin accounts are often highly accessible to the high-risk component of the environment. If those accounts are compromised or are being used in a suspicious manner, that's high-fidelity events for us to look into.
View full review »
DH
Security Center Coordinator at a comms service provider with 11-50 employees
It keeps up with the network traffic, which is a good thing. It provides more context to plain alerts compared to using an older system. So, it helps an analyst reduce the information overload.
View full review »
FU
SOC Administrator at The National Commercial Bank
What I like best about Vectra AI is that it alerts you about suspicious activities.
View full review »

Vectra AI Cons

DW
Operations Manager at a healthcare company with 51-200 employees
I would like to see data processed onshore. Right now, the cloud components, like Office 365, must be processed on servers outside of Australia. I would like to see a future adoption of onshore processing.
View full review »
AG
Sr. Specialist - Enterprise Security at a mining and metals company with 5,001-10,000 employees
The reporting from Cognito Detect is very limited and doesn't give you too many options. If I want to prepare a customized report on a particular host, even though I see the data, I have to manually prepare the report. The reporting features that are built into the tool are not very helpful.
View full review »
TS
Senior Security Engineer at a manufacturing company with 10,001+ employees
They use a proprietary logging format that is probably 90% similar to Bro Logs. Their biggest area of improvement is finishing out the remaining 10%. That 10% might not be beneficial to their ML engine, but that's fine. The industry standard is Zeek Logs or Bro Logs, or Bro or Zeek, depending on how old you are. While they have 90% of those fields, they're still missing some fields. In very rare instances, some community rules do not have the fields that they need, and we had to modify community rules for our logs. So, their biggest area of improvement would be to just finish their matching of the Zeek standard.
View full review »
Buyer's Guide
Vectra AI
January 2023
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: January 2023.
670,523 professionals have used our research since 2012.
FH
Head of IT Security, Acting CISO at a retailer with 10,001+ employees
If you hit a certain number of rules, triage filters, or groups, the UX responds more slowly. However, we have a complex network and a lot of rules. So, our setup might not be a typical implementation example. We even had UX engineers onsite, and they looked at issues, improvements, and user feedback. Since then, it has gotten a lot better, they even built in features that we specifically requested for our company.
View full review »
PR
Head of Information Security at a financial services firm with 51-200 employees
Integration with other security components needs improvement. It should have true integration as opposed to just being a separate pane of glass.
View full review »
DH
Security Center Coordinator at a comms service provider with 11-50 employees
I would like more integrations with IOCs and threats currently on the Internet. I would also like to know which threats are based on zero-day attacks, current botnets, etc. Therefore, I would like more information on external threats.
View full review »
FU
SOC Administrator at The National Commercial Bank
An area for improvement in Vectra AI is reporting because it currently needs some details. For example, when you download a report from Vectra AI, you won't see complete information about the alerts or triggers. Another area for improvement in the tool is that sometimes, an alert has high severity, yet it's marked as low severity. Vectra AI should have a mechanism to change the severity level from low to high or critical.
View full review »
Buyer's Guide
Vectra AI
January 2023
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: January 2023.
670,523 professionals have used our research since 2012.