Review Summary
See a synthesized overview of the key takeaways from verified reviews of Darktrace / NETWORK.
See a synthesized overview of the key takeaways from verified reviews of Darktrace / NETWORK.
Darktrace is a Cambridge, UK-based firm concentrating on the mitigation of cyber disruptions globally. The company employs a unique AI technology used by thousands of businesses globally to counteract, identify, react to, and recover from cyber-attacks. With a team of over 2200 people spread over 30 global offices, Darktrace is dedicated to containing the global impacts of cyber threats.
Do You Manage Peer Insights at Darktrace?
Access Vendor Portal to update and manage your profile.
I value that the product detects anomalous network behavior beyond static rules, for example endpoints connecting to previously unseen domains or IP addresses or showing unusual communication patterns. During our POC, it surfaced concrete misuse on the guest Wi-Fi (including access to illegal football streaming services), which demonstrated practical detection value. The option for a local appliance is a clear advantage for privacy and governance, because telemetry can be processed on-premises and sensitive data can remain under the organization's control. I also appreciate the ability to tune thresholds and create custom alerts, as well as the integration benefits across the Darktrace ecosystem-using Network together with Identity and Email typically improves investigation context and confidence. Finally, the active response capability is distinctive: when configured, it can attempt to terminate suspicious sessions by injecting TCP FIN packets for the relevant connection/port, supporting rapid containment while the alert is validated.
Love the autonomous mode, knowing that automatic actions will take place against abnormal network traffic, meaning you don't have to immediately down tools to deal with an alert. I like the ai assistant to help breakdown the details in an alert and explain what's going on, and overall I appreciate the alerts to give me a deep understanding of what is happening in our network.
Three standout features for our team are: 1. Self-learning AI and pattern of life modeling. Unlike legacy security tools that rely on historical data or signatures, Darktrace uses unsupervised machine learning to develop a pattern of life for users, devices, and network segments, which allows it to detect exploits, insider threats, and novel attacks. 2. Continuous Network Traffic Monitoring and Deep Packet Inspection: Darktrace monitors all network traffic across the environment (N/S and E/W), in real time. Our board is always blown away by the sheer volume of data being analyzed on an annual basis. 3. Alert Aggregation: The aggregation and contextualization of alerts across the environment to reduce alert fatigue.
Licensing tied to IP addresses can scale quickly and was the primary drawback in our evaluation.
As mentioned previously I have a strong dislike of the UI, I find tuning models to be quite tricky and I also found that sometimes picking up device DNS can be inaccurate so you have to rely more on IP addresses than DNS names
The initial noise and tuning overhead requires a significant time investment, and while that time is saved on the backend with faster MTTR and detections, you have to plan that tuning time into the deployment time. There's also a significant learning curve for the junior analysts due to the amount of detail and data provided by the platform.