Darktrace AI interrupts in-progress cyber-attacks, including ransomware, email phishing, and threats to cloud environments. It's able to detect and establish baselines for your organization so it can make the distinction between what is and what isn't normal network activity for your organization. This allows it to tackle complex cyber-attacks as they happen and prevent future cyber-attacks from happening.
N/A
Symantec Advanced Threat Protection
Score 9.2 out of 10
N/A
Symantec Advanced Threat Protection is a single unified solution that uncovers, prioritizes, and
remediates advanced attacks. The product fuses intelligence from endpoint, network, and email
control points, as well as Symantec’s massive global sensor network, to stop threats that evade
individual security products. It leverages existing Symantec Endpoint Protection and
Symantec Email Security.cloud investments, so it does not require the deployment of any new
agents. It includes functionality…
Darktrace would be well suited to any environment really; the only constraint would be the budget. The cost scales on the number of devices to be monitored by the product, so it can be quite expensive in larger environments. Any company that would benefit from having 24/7 monitoring of their network would find that this product would suit that need perfectly. It can also create a number of reports, which is useful if you have any requirement to present periodic figures and statistics for your network. There are also additional features available and in development such as Antigena, which can be configured to allow potential threats to be automatically mitigated; it can block connections to a certain address, using certain ports, or it can enforce "normal behaviour" where it will only allow a machine to communicate in a way that Darktrace has observed before and considers normal. This has huge benefits particularly for 24/7 organisations where you don't have the ability to have someone monitoring the network personally at all times, as it could stop a malware outbreak in its tracks.
I think Symantec ATP is more of a medium or large-scale product where a company has a lot of endpoints. It is burdensome for smaller companies with limited IT support to try and get the product up and running. In addition I feel the new own, Broadcomm, is also trying to angle their product more to the large customer base. A medium or large scale customer in the need of end-to-end protection for their network really cannot go wrong with the product once configured correctly.
Uses it Al model UEBA to detect anomalies in the behaviour of not only the users in a corporate network but also the routers, servers, and endpoints in that network.
Provides a visualisation of both egress and outbound network traffics flowing in and out of the organisation.
Darktrace comes with it autonomous AI model detection and responses capabilities.
Darktrace as an AI next generation NDR solution, prevents ,contains and quarantines malicious traffics from and into the corporate network.
It was easy to install on machines in an active directory environment, and maintain/update whenever we needed without having to physically go to clients.
The interface was pretty well locked down for clients, which was good in order to stop accidental meddling.
Symantec has good online resources for current threats, including messages or warning signs and what to do/where to find them on a machine in case SATP cannot deal with it on its own.
Supplier support - Really dire. Technical support off shore was passable, but account management was non existent. Really reflects on Symantec poorly given our spend per annum with them.
Cost per annum. At the upper end of protection systems. With little or no account support this was poor value.
Symantec Advanced Threat Protection has done a sufficient job at identifying true positives. However, the UI could be improved and the amount of false positives is a little too frequent for my liking
The Darktrace toolset is very expansive, allowing it to handle many different tasks, but this leads to a user interface that is sometimes not at all intuitive. Icons don't always make sense visually, and the associated tool tips do not always provide enough detail on what action the button performs
Darktrace support is excellent in my experience. They send a competent engineer on-site to provide on-boarding training. They were also very responsive in responding to questions and concerns. Having an individual point of contact who is a competent network and security engineer is not a common experience, at least for me.
We did NOT select Darktrace. OSSIM/AlienVault is a more mature product and it provided better intelligence and reporting. The end user interface is much easier to use - and you can tell built form engineers who have had to do the work. My suggestion for anyone considering Darktrace, is to get the price upfront; do a 30/60 onsite trail; and do the same thing, at the same time, with AlienVault. AlientVault will win every time. I say that because that's exactly what I did.
Proofpoint Advanced Threat Protection is a software with a high potential to detect and respond quickly to threats that target email, however Symantec Advanced Threat Protection provides a more complete protection that protects the entire network or devices and endpoints that are managed on a daily basis and has incredible ease of use. While Proofpoint Advanced Threat Protection is not a software that is very easy to use, it requires high maintenance and its protection is based on attacks that enter through email; this is why Symantec Advanced Threat Protection was finally chosen.
One big positive is how it helps us with the security assessments that clients have done on us. They are looking to see if we know how we might have unusual/malicious traffic running on the network.
If you have a small network and only need 1 appliance, it can be a good ROI and peace of mind.
You could go down a hole in trying to spend time looking at all of your traffic with this software. You need to focus only on what it is showing as potential bad traffic.