• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. ThreatBook TDP NDR
Logo of ThreatBook TDP NDR

ThreatBook TDP NDR

byThreatBook
in Network Detection and Response
5.0

Overview

Product Information on ThreatBook TDP NDR

Updated 13th October 2025

What is ThreatBook TDP NDR?

ThreatBook TDP NDR is a software designed to identify, analyze, and respond to network-based threats within enterprise environments. The software uses network detection and response capabilities to monitor network traffic, detect anomalies, and provide insights into potential security incidents. It leverages threat intelligence and behavioral analysis to uncover hidden risks and deliver detailed threat context. The software supports the investigation of security events by providing automated alerts, forensic data, and visualization of attack paths. It aims to enhance threat visibility, streamline incident response, and support security teams in mitigating risks posed by advanced persistent threats and malware.

ThreatBook TDP NDR Pricing

ThreatBook TDP NDR software uses a subscription-based pricing model, where fees are generally determined by the scale of deployment, including factors such as the number of assets, data bandwidth, or specific security features required. Pricing may vary depending on selected modules, support options, and service levels, typically offered on annual or multi-year terms. No Profile found

Overall experience with ThreatBook TDP NDR

Manager, IT Security and Risk Management
1B - 3B USD, Manufacturing
FAVORABLE

“Critical supply chain breach prevented, but machine-to-cloud visibility remains limited”

5.0
Jun 3, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.
There are no reviews in this category.
CRITICAL

About Company

Company Description

Updated 5th July 2024

ThreatBook is a provider of cyber threat detection and response services. We developed new approaches to deliver high-fidelity, efficient, and actionable security intelligence. We integrated these capabilities with a full life cycle threat detection system and incident response mechanisms to enhance protection across cloud, network, and endpoints. This helps enterprises respond to threats efficiently, reduce complexity, and improve security operations.

Company Details

Updated 26th February 2025
Company type
Private
Year Founded
2015
Head office location
Beijing, China
Number of employees
501 - 1000
Website
https://threatbook.cn/next/en

Do You Manage Peer Insights at ThreatBook?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top ThreatBook TDP NDR Alternatives

Logo of Darktrace / NETWORK
1. Darktrace / NETWORK
4.8
(623 Ratings)
Logo of Vectra AI Platform
2. Vectra AI Platform
4.8
(472 Ratings)
Logo of RevealX
3. RevealX
4.7
(273 Ratings)
View All Alternatives

Peer Discussions

ThreatBook TDP NDR Reviews and Ratings

5.0

(146 Ratings)

Rating Distribution

5 Star
92%
4 Star
8%
3 Star
0%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?
  • Manager, IT Security and Risk Management
    1B-10B USD
    Manufacturing
    Review Source

    Critical supply chain breach prevented, but machine-to-cloud visibility remains limited

    5.0
    Jun 3, 2026
    This incident alone validated the deployment, as the compromised workstation. haddirect network access to production quality databases containing unreleased customer product specifications. The AI-driven alert aggregation engine transformed our security operations, reducing daily raw detections from over 5,000 to approximately 80 high-fidelity actionable incidents. This consolidation allowed our lean 6-person SOC team to effectively manage the entire manufacturing footprint across all five parks without analyst burnout or alert fatigue. Perhaps most critically for our 24/7 production environment, the full deployment - passive optical taps at core aggregation points across five industrial parks, zero change management tickets, zero production line impact - was completed by. oursmall team. injust 6 days. No maintenance windows required, no production downtime, no OT engineering team involvement, and no impact on the manufacturing execution systems controlling CNC machining centers, SMT assembly lines, or automated quality inspection stations.
  • Manager, IT Security and Risk Management
    1B-10B USD
    Manufacturing
    Review Source

    Critical supply chain breach prevented, but machine-to-cloud visibility remains limited

    5.0
    Jun 3, 2026
    This incident alone validated the deployment, as the compromised workstation. haddirect network access to production quality databases containing unreleased customer product specifications. The AI-driven alert aggregation engine transformed our security operations, reducing daily raw detections from over 5,000 to approximately 80 high-fidelity actionable incidents. This consolidation allowed our lean 6-person SOC team to effectively manage the entire manufacturing footprint across all five parks without analyst burnout or alert fatigue. Perhaps most critically for our 24/7 production environment, the full deployment - passive optical taps at core aggregation points across five industrial parks, zero change management tickets, zero production line impact - was completed by. oursmall team. injust 6 days. No maintenance windows required, no production downtime, no OT engineering team involvement, and no impact on the manufacturing execution systems controlling CNC machining centers, SMT assembly lines, or automated quality inspection stations.
  • Read All 150 Reviews

    Get unlimited access to verified peer reviews and insights

    Read unlimited Gartner-vetted product reviews
    View and share valuable product insights
    Download full product profiles
    Review products you use today

Recommended Gartner Insights

  • Critical Capabilities for Network Detection and Response
  • Magic Quadrant for Network Detection and Response
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

Reviewer Insights for: ThreatBook TDP NDR
Deciding Factors: ThreatBook TDP NDR Vs. Market Average
Performance of ThreatBook TDP NDR Across Market Features

ThreatBook TDP NDR Likes & Dislikes

Like

Supplier workstation lateral movement caught in 6 minutes before MES database breach. A third-party quality inspection contractor workstation with legitimate network access attempted SMB connections to our MES order database - invisible to firewall segmentation and endpoint controls - but TDP east-west traffic analysis detected the anomalous session enumeration pattern immediately. The MES database contained unreleased iPhone and MacBook component specifications and delivery schedules for our top global customers. SOC isolated the workstation within 15 minutes, preventing a catastrophic supply chain confidentiality breach that would have exposed billions in customer IP. Chengdu CNC Modbus anomaly caught in 4 minutes, preventing core manufacturing IP theft. A calibration contractor issued unauthorized Modbus reads targeting tolerance parameters and spindle speed configurations on our CNC centers - proprietary manufacturing IP accumulated over decades of Apple component production. TDP OT protocol DPI detected abnormal Modbus function codes and read frequency deviation from normal calibration patterns, alerting within 4 minutes. The contractor had embedded unauthorized read commands within legitimate temperature calibration routines. Without TDP protocol-level anomaly detection, this IP exfiltration would have gone completely undetected by traditional IT security tools. 340 undocumented OT devices discovered. in 7 days, closing 22segmentation gaps. TDP passive asset discovery identified 340 previously unregistered OT. endpoint. acrossour fiveparks - ARM embedded controllers on assembly lines, RTSP surveillance cameras with default credentials, and legacy Windows XP HMIs controlling active production equipment.

Like

Supplier workstation lateral movement caught in 6 minutes before MES database breach. A third-party quality inspection contractor workstation with legitimate network access attempted SMB connections to our MES order database - invisible to firewall segmentation and endpoint controls - but TDP east-west traffic analysis detected the anomalous session enumeration pattern immediately. The MES database contained unreleased iPhone and MacBook component specifications and delivery schedules for our top global customers. SOC isolated the workstation within 15 minutes, preventing a catastrophic supply chain confidentiality breach that would have exposed billions in customer IP. Chengdu CNC Modbus anomaly caught in 4 minutes, preventing core manufacturing IP theft. A calibration contractor issued unauthorized Modbus reads targeting tolerance parameters and spindle speed configurations on our CNC centers - proprietary manufacturing IP accumulated over decades of Apple component production. TDP OT protocol DPI detected abnormal Modbus function codes and read frequency deviation from normal calibration patterns, alerting within 4 minutes. The contractor had embedded unauthorized read commands within legitimate temperature calibration routines. Without TDP protocol-level anomaly detection, this IP exfiltration would have gone completely undetected by traditional IT security tools. 340 undocumented OT devices discovered. in 7 days, closing 22segmentation gaps. TDP passive asset discovery identified 340 previously unregistered OT. endpoint. acrossour fiveparks - ARM embedded controllers on assembly lines, RTSP surveillance cameras with default credentials, and legacy Windows XP HMIs controlling active production equipment.

Like

Supplier workstation lateral movement caught in 6 minutes before MES database breach. A third-party quality inspection contractor workstation with legitimate network access attempted SMB connections to our MES order database - invisible to firewall segmentation and endpoint controls - but TDP east-west traffic analysis detected the anomalous session enumeration pattern immediately. The MES database contained unreleased iPhone and MacBook component specifications and delivery schedules for our top global customers. SOC isolated the workstation within 15 minutes, preventing a catastrophic supply chain confidentiality breach that would have exposed billions in customer IP. Chengdu CNC Modbus anomaly caught in 4 minutes, preventing core manufacturing IP theft. A calibration contractor issued unauthorized Modbus reads targeting tolerance parameters and spindle speed configurations on our CNC centers - proprietary manufacturing IP accumulated over decades of Apple component production. TDP OT protocol DPI detected abnormal Modbus function codes and read frequency deviation from normal calibration patterns, alerting within 4 minutes. The contractor had embedded unauthorized read commands within legitimate temperature calibration routines. Without TDP protocol-level anomaly detection, this IP exfiltration would have gone completely undetected by traditional IT security tools. 340 undocumented OT devices discovered. in 7 days, closing 22segmentation gaps. TDP passive asset discovery identified 340 previously unregistered OT. endpoint. acrossour fiveparks - ARM embedded controllers on assembly lines, RTSP surveillance cameras with default credentials, and legacy Windows XP HMIs controlling active production equipment.

User Sentiment About ThreatBook TDP NDR