IT Central Station is now PeerSpot: Here's why

Vectra AI Pros

SW
Operational Security Manager at a financial services firm with 1,001-5,000 employees
The most valuable feature for Cognito Detect, the main solution, is that external IDS's create a lot of alerts. When I say a lot of alerts I really mean a lot of alerts. Vectra, on the other hand, contextualizes everything, reducing the number of alerts and pinpointing only the things of interest. This is a key feature for me. Because of this, a non-trained analyst can use it almost right away.
The key feature for me for Detect for Office 365 is that it can also concentrate all the information and detection at one point, the same as the network solution does. This is the key feature for me because, while accessing data from Office 365 is possible using Microsoft interfaces, they are not really user-friendly and are quite confusing to use. But Detect for Office 365 is aggregating all the info, and it's only the interesting stuff.
View full review »
DW
Operations Manager at a healthcare company with 51-200 employees
One of the core features is that Vectra AI triages threats and correlates them with compromised host devices. From a visibility perspective, we can better track the threat across the network. Instead of us potentially finding one device that has been impacted without Vectra AI, it will give us the visibility of everywhere that threat went. Therefore, visibility has increased for us.
View full review »
TS
Senior Security Engineer at a manufacturing company with 10,001+ employees
It does a reliable job of parsing out the logs of all the network traffic so that we can ingest them into our SIEM and utilize them for threat hunting and case investigations. It is pretty robust and reliable. The administration time that we spend maintaining it or troubleshooting it is very low. So, the labor hour overhead is probably our largest benefit from it. We spend 99% of our time in Vectra investigating cases, responding to incidents, or hunting, and only around 1% of our time is spent patching, troubleshooting, or doing anything else. That's our largest benefit from Vectra.
View full review »
Buyer's Guide
Vectra AI
July 2022
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: July 2022.
620,068 professionals have used our research since 2012.
BV
Project Manager at a university with 1,001-5,000 employees
It has helped us to organize our security. We get a better overview on what is happening on the network, which has helped us get quicker responses to users. If we see malicious activity, then we can quickly take action on it. Previously, we weren't getting an overview as fast as we are now, so we can now provide a quicker response.
View full review »
FH
Head of IT Security, Acting CISO at a retailer with 10,001+ employees
Cognito Streams gives you a detailed view of what happens in the network in the form of rich metadata. It is just a super easy way to capture network traffic for important protocols, giving us an advantage. This is very helpful on a day-to-day basis.
View full review »
Mark Davies - PeerSpot reviewer
Security Operations Specialist at a tech services company with 1,001-5,000 employees
The dashboard gives me a scoring system that allows me to prioritize things that I should look at. I may not necessarily care so much about one event, whereas if I have a single botnet detection or a brute force attack, I really want to get on top of those.
View full review »
PR
Head of Information Security at a financial services firm with 51-200 employees
The administrative privilege detection feature is the most valuable feature. The admin accounts are often highly accessible to the high-risk component of the environment. If those accounts are compromised or are being used in a suspicious manner, that's high-fidelity events for us to look into.
View full review »
DH
Security Center Coordinator at a comms service provider with 11-50 employees
It keeps up with the network traffic, which is a good thing. It provides more context to plain alerts compared to using an older system. So, it helps an analyst reduce the information overload.
View full review »

Vectra AI Cons

SW
Operational Security Manager at a financial services firm with 1,001-5,000 employees
Vectra is still limited to packet management. It's only monitoring packet exchanges. While it can see a lot of things, it can't see everything, depending on where it's deployed. It has its limits and that's why I still have my SIEM.
The main improvement I can see would be to integrate with more external solutions.
View full review »
DW
Operations Manager at a healthcare company with 51-200 employees
I would like to see data processed onshore. Right now, the cloud components, like Office 365, must be processed on servers outside of Australia. I would like to see a future adoption of onshore processing.
View full review »
TS
Senior Security Engineer at a manufacturing company with 10,001+ employees
They use a proprietary logging format that is probably 90% similar to Bro Logs. Their biggest area of improvement is finishing out the remaining 10%. That 10% might not be beneficial to their ML engine, but that's fine. The industry standard is Zeek Logs or Bro Logs, or Bro or Zeek, depending on how old you are. While they have 90% of those fields, they're still missing some fields. In very rare instances, some community rules do not have the fields that they need, and we had to modify community rules for our logs. So, their biggest area of improvement would be to just finish their matching of the Zeek standard.
View full review »
Buyer's Guide
Vectra AI
July 2022
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: July 2022.
620,068 professionals have used our research since 2012.
BV
Project Manager at a university with 1,001-5,000 employees
In comparison with a lot of systems I used in the past, the false positives are really a burden because they are taking a lot of time at this moment.
View full review »
FH
Head of IT Security, Acting CISO at a retailer with 10,001+ employees
If you hit a certain number of rules, triage filters, or groups, the UX responds more slowly. However, we have a complex network and a lot of rules. So, our setup might not be a typical implementation example. We even had UX engineers onsite, and they looked at issues, improvements, and user feedback. Since then, it has gotten a lot better, they even built in features that we specifically requested for our company.
View full review »
Mark Davies - PeerSpot reviewer
Security Operations Specialist at a tech services company with 1,001-5,000 employees
I'd like to be able to get granular reports and to be able to output them into formats that are customizable and more useful. The reporting GUI is lacking.
View full review »
PR
Head of Information Security at a financial services firm with 51-200 employees
Integration with other security components needs improvement. It should have true integration as opposed to just being a separate pane of glass.
View full review »
DH
Security Center Coordinator at a comms service provider with 11-50 employees
I would like more integrations with IOCs and threats currently on the Internet. I would also like to know which threats are based on zero-day attacks, current botnets, etc. Therefore, I would like more information on external threats.
View full review »
Buyer's Guide
Vectra AI
July 2022
Learn what your peers think about Vectra AI. Get advice and tips from experienced pros sharing their opinions. Updated: July 2022.
620,068 professionals have used our research since 2012.