TrustRadius Insights for Darktrace are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.
Pros
Comprehensive AI-based NDR solution: Users have found Darktrace to be a comprehensive AI-based network detection and response solution. Several reviewers appreciate its ability to detect anomalies in user behavior as well as network infrastructure like routers, servers, and endpoints.
Effective prevention of malicious traffic: Many users highly appreciate Darktrace's autonomous AI model detection and response capabilities. They applaud its effectiveness in preventing, containing, and quarantining malicious traffic in the corporate network.
Valuable security features: Darktrace's ability to block malicious attachments and phishing emails is regarded as a valuable feature by users. They find it reassuring that Darktrace provides excellent security to corporate email systems, enhancing overall cybersecurity measures.
Loading Reviews List....
Darktrace Reviews
4 Reviews
Professional, Scientific, and Technical ServicesLaw Practice1Information Technology & Services2Market Research1
We use Darktrace's NETWORK and EMAIL services to monitor for and act upon anomalous activity. Their use of AI algorithms allows the detection system to instantly halt all threatening traffic. In addition, the EMAIL service uses similar technology to weed out malicious email, perform email link locking and blocking, and more to keep your users and network safe.
Pros
detects anomalous network activity
automatically act on detected threats
email link locking
email link blocking
Cons
The dashboard offers a lot of data but can also be very confusing to use
Tooltips for icons could be more detailed
Likelihood to Recommend
Darktrace is an enterprise-level product that is not affordable for most small or mid-sized companies. The period during which the appliance learns your network can be time consuimg as many false-positives are alerted. It is important that your staff anticipates this and has the time to help train the device.
VU
Verified User
Manager in Information Technology (Information Technology & Services company, 201-500 employees)
Darktrace is one of the best solutions when it comes to monitor your network with an NDR. Extremely scalable and with a fantastic way of correlating network communications, this is one of the best solutions in the market. We use it not only to monitor our customer's infrastructures, but we also integrate it with several modules, giving the SoC Analysts great room for moving and responding.
Pros
Network monitoring
PCAP Parsing
Correlation rules
Behavioural rules
Cons
Backup management
Asset inventory
Advanced queries scalability
Likelihood to Recommend
Darktrace is a product well suited for the vast majority of infrastructures and helps monitoring and responding to threats based on the network in a very elastic way. This is a product based on on-premise infrastructures that hosts its machines locally, of course it can be technically difficult to monitor an entire On-Cloud infrastructure but even there there's room for sensors and monitoring, not to mention the SaaS and mail integration that completes the product.
VU
Verified User
Analyst in Information Technology (Information Technology & Services company, 11-50 employees)
We have been using Darktrace for Threat Detection, Network Visibility, Antigena features/PREVENT for automated responses and to be in compliance. It's AI and ML capabilities to continuously monitor network traffic and user behavior are exceptional. It gives an in-depth visibility to our network. We have integrated it with Microsoft365 for Emails which helps detect phishing emails, malicious attachment blocking, spam filtering and malicious link blocking.
Pros
It detects anomalies or deviations from this baseline, it can raise alerts or take automated actions to investigate and mitigate the issue.
It's "Antigena" feature can take automated actions in response to detected threats. You can have antigena for both network and emails and the system will do the blocks at it's own
It integrates with Microsoft365 to identify and respond to email-based threats, including phishing attempts and malicious attachments.
Cons
Whitelisting email or IP are not straight forward
Although the GUI is great but it's too complex
If filters can be easier to implements
Likelihood to Recommend
It's best suited for network anamoly detection and prompt action via antigena for network It's also best suited for Email security and malicious email detections Since, the detections are AI based you may get some false positives from time to time Right after implementation it's difficult to handle due to it's learning behavior Requires some time to learn It not the best for Intrusion prevention scenarios but does a great job for threat detections
VU
Verified User
Professional in Information Technology (Market Research company, 51-200 employees)
We use Darktrace in our main office. It helps us meet security assessment requirements of our clients that want to know how we know if there are bad actors in our environment.
Pros
Its very strong in recognizing unusual traffic. It learns what is normal and what is not normal.
It helps to show if our users are hitting malicious websites or not. That is a nice bonus to help with our security awareness and know if our training is doing its job.
Their weekly reports to us help highlight the most egregious traffic on our network. They are an extra set of eyes for us.
Cons
You have to have an appliance on each segment of your network. If you are not back hauling your traffic to your central data center, then each location has to have an appliance in order to cover that location.
They gather so much detailed information that it is hard at time to decipher what I'm looking at.
The way they name actions is unusual and should be changed. They need to label the parts of network traffic better.
Likelihood to Recommend
It's excellent at using its AI engine to learn your environment when it first gets set up. Then over time it know what it has seen in the past and what it hasn't, so you can investigate what could be malicious traffic or not. It shouldn't be considered the end all, be all for networking monitoring, but just another tool to use.
VU
Verified User
Technician in Information Technology (Law Practice company, 201-500 employees)