• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In

Overview

Product Information on Darktrace / Forensic Acquisition & Investigation

Updated 13th October 2025

What is Darktrace / Forensic Acquisition & Investigation?

Cado Security is a software designed for cloud forensics and incident response, enabling organizations to investigate security incidents across cloud, container, and hybrid environments. The software automates evidence collection, processing, and analysis from various infrastructure sources, including cloud platforms and virtualized environments. It provides capabilities for timeline reconstruction, artifact analysis, and data visualization to support security teams in identifying and understanding potential threats. By centralizing and accelerating forensic workflows, the software addresses challenges related to the complexity and scale of modern cloud environments, helping organizations improve their response to security events and reduce time to resolution.

Darktrace / Forensic Acquisition & Investigation Pricing

Cado Security software utilizes a subscription-based pricing model, where fees are charged according to tiered plans based on the number of data sources, case volume, and available features. The software generally provides flexible options for enterprise deployment, and pricing details may vary based on specific organizational requirements and selected modules. Custom quotes are often provided for tailored configurations and large-scale needs.

Overall experience with Darktrace / Forensic Acquisition & Investigation

It Security & Risk Management Associate
<50M USD, IT Services
FAVORABLE

“Comprehensive Network Visibility and Investigation Tools Ease Incident Response Challenges”

5.0
Apr 3, 2026
From a SOC analyst's point of view, Daktrace's Forensic Acquisition & Investigation feels like one of those tools that really shows its value once you've spent some time with it, even if it doesn't feel completely intuitive right from the start. What jumps out immediately is how much visibility it gives you. It pulls together network activity, device behavior, and historical context in a way that saves a lot of time compared to switching between several different tools. When you're in the middle of an investigation, having the timeline style view of events, and being able to quickly pivot between connections, devices, and protocols, is genuinely helpful. Overall, once you get past the initial learning curve, the platform really helps streamline investigations and gives you the clarity you need when responding to incidents.
There are no reviews in this category.
CRITICAL

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Peer Discussions

Recommended Gartner Insights

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

  1. Home
  2. /
  3. Darktrace / Forensic Acquisition & Investigation
Logo of Darktrace / Forensic Acquisition & Investigation

Darktrace / Forensic Acquisition & Investigation

byDarktrace
in Cloud Investigation and Response Automation (CIRA)
4.8

About Company

Company Description

Updated 25th July 2024

Darktrace is a Cambridge, UK-based firm concentrating on the mitigation of cyber disruptions globally. The company employs a unique AI technology used by thousands of businesses globally to counteract, identify, react to, and recover from cyber-attacks. With a team of over 2200 people spread over 30 global offices, Darktrace is dedicated to containing the global impacts of cyber threats.

Company Details

Updated 26th February 2025
Year Founded
2013
Head office location
Cambridge, United Kingdom
Number of employees
1001 - 5000
Annual Revenue
500M-1B USD
Website
https://darktrace.com/

Do You Manage Peer Insights at Darktrace?

Access Vendor Portal to update and manage your profile.

Darktrace / Forensic Acquisition & Investigation Likes & Dislikes

Like

Strong visibility across network activity Really useful timeline and pivoting features Remote forensic data collection

Like

Detailed investigation capabilities and useful for incident analysis

Like

real time threat detection - value the ability to quickly identify and respond to threats in the cloud environment comprehensive forensics - in depth forensics capabilities allow the teams to conduct thorough investigations ease of integration - many users appreciate the ease of integrating with existing applications/framework

Dislike

Hard to learn for new analysts Searches and filtering are slow sometimes Limited guidance

Dislike

Learning time period and also when having large data sets it can be complex to navigate

Dislike

set up complexity - initial set up and deployment can be complex, especially for some teams UI - some users have reported the UI is not intuitive enough Reporting capabilities - would like for extra customisation with reports

Top Darktrace / Forensic Acquisition & Investigation Alternatives

Darktrace / Forensic Acquisition & Investigation Reviews and Ratings

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • It Security & Risk Management Associate
    <50M USD
    IT Services
    Review Source

    Comprehensive Network Visibility and Investigation Tools Ease Incident Response Challenges

    5.0
    Apr 3, 2026
    From a SOC analyst's point of view, Daktrace's Forensic Acquisition & Investigation feels like one of those tools that really shows its value once you've spent some time with it, even if it doesn't feel completely intuitive right from the start. What jumps out immediately is how much visibility it gives you. It pulls together network activity, device behavior, and historical context in a way that saves a lot of time compared to switching between several different tools. When you're in the middle of an investigation, having the timeline style view of events, and being able to quickly pivot between connections, devices, and protocols, is genuinely helpful. Overall, once you get past the initial learning curve, the platform really helps streamline investigations and gives you the clarity you need when responding to incidents.
  • Cyber Security Analyst
    <50M USD
    IT Services
    Review Source

    Platform Assists in Analyzing Large Volumes of Network Security Data

    5.0
    Mar 26, 2026
    Overall good experience, it provides capabilities for captuing/analyzing network data which can help on the investigation process and better understand security events. Also helping when working with large volumes of network data because it can require some familiarity with the platform.
  • Solutions Engineer
    50M-1B USD
    IT Services
    Review Source

    Enhancing Threat Detection and Response in Cloud Environments

    4.0
    Oct 24, 2024
    Significant improvements in our threat detection and incident response capabilities. Being able to identify potential security incidents in cloud environments.
  • Manager, IT Security and Risk Management
    50M-1B USD
    Media
    Review Source

    Great product for cloud and on-prem forensics analysis

    4.0
    Dec 1, 2023
    no additional comments on the implementation of Cado. It was easy to build terraform for the deployment which met our standards
  • Cybersecurity Analyst
    1B-10B USD
    Media
    Review Source

    Overall positive experience with Cado Response

    5.0
    Aug 7, 2023
    I have had an overall positive experience working both with the Cado Response tool and Cado the company. They are still growing, but the improvements that have been made over the last couple of years to Cado Response have been great, and the constant innovation from their side means that they often anticipate our needs before we do. The newness of the tool means that there are some features that are not fully fleshed out or things they haven't gotten to yet, but their support is quick to respond to requests for help and to prioritize the things that we ask about.
Showing Result 1-5 of 5

4.8

(5 Ratings)

Rating Distribution

5 Star
60%
4 Star
40%
3 Star
0%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.3

Integration & Deployment

5.0

Service & Support

4.5

Product Capabilities

4.8

Logo of Binalyze AIR
1. Binalyze AIR
4.6
(14 Ratings)
Logo of Cortex XDR
2. Cortex XDR
4.4
(10 Ratings)
Logo of OpenText EnCase Forensic
3. OpenText EnCase Forensic
4.2
(9 Ratings)
View All Alternatives
Reviewer Insights for: Darktrace / Forensic Acquisition & Investigation