Darktrace AI interrupts in-progress cyber-attacks, including ransomware, email phishing, and threats to cloud environments. It's able to detect and establish baselines for your organization so it can make the distinction between what is and what isn't normal network activity for your organization. This allows it to tackle complex cyber-attacks as they happen and prevent future cyber-attacks from happening.
N/A
Microsoft Defender XDR
Score 8.9 out of 10
N/A
Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.
Its capabilities to respond to a threat both manual than automated way makes Darktrace one of the best NDR in the market. The rules editor allows the right flexibility to build a set of rules sized for the infrastructure, while the third parties integrations and modules helps …
The product's capacity to provide insights into network traffic is impressive. The organisation was able to find any malware harming the devices with their assistance. We really value network monitoring and self-learning monitoring tools.
We looked into several competitors and are still looking, due to the problems Darktrace has with false positives. Darktrace is attractive as their support is generally good, and working with the product is relatively easy.
We did NOT select Darktrace. OSSIM/AlienVault is a more mature product and it provided better intelligence and reporting. The end user interface is much easier to use - and you can tell built form engineers who have had to do the work. My suggestion for anyone considering …
Darktrace does a very good job at complementing our other security tools by adding an additional level of automated security. It is important to point out that the automation is optional. We ran Darktrace in "manual" mode until we were comfortable enough to switch it to a …
We saw CrowdStrike but Microsoft Defender XDR was already in our computer. It was cheaper too cause we had Micrsoft license. CrowdStrike look cool but had many buttons and hard to read. My team like Microsoft Defender XDR because it looks same like other Microsoft thing. We …
Our product in that area, for instance as a security platform and for us it is for the moment really bad point. We started to move in that direction that there is that disconnect from the client management. So if there is some action that needs to be executed detected by …
As a business already using Microsoft 365 and Azure, the seamless integration with Microsoft Defender XDR provided a unified security approach, streamlining management and operations.
Avast had very limited capabilities, especially in terms of automation. We had to have some employees available 24/7 to monitor and take necessary actions. Microsoft Defender is so much more advanced.
We have a microsoft ecosystem and we can easily implement Microsoft Defender XDR in a breeze. Using few option, we can actually start logging and managing all the data.
I've used Trend Micro, but it's not exactly the same because Trend Micro is equivalent to one of the parts of Defender XDR, which is Defender for Endpoint. But Trend Micro has also a portal that combines all the incidents like Defender XDR, but I think the Microsoft one is much …
Microsoft Defender XDR is more seamless than Sophos Intercept X as it is better integrated into the Microsoft 365 suite. Sophos Intercept X is a little bit cheaper per year than Microsoft Defender XDR though, and definitely worth looking into if you are looking for a security …
It really was the first and most logical option since it is an integral part of the platform that we want to protect and so far the results have been optimal.
We used the MS XDR as this is a bundle that we bought when we subscribed to the M365 platform, so having it was a bonus as we stated earlier, but due to limitation on licenses in Sentinelone, having this is just a blessing for us, so we can reduce around 200 licenses and can …
The Microsoft 365 Defender is a product that has a lot of advantages over other similar products. This is because Microsoft 365 Defender integrates seamlessly with both Microsoft 365 services, is capable of detecting threats in real time, and has the capability of automating …
For the Identity Protection, Microsoft 365 Defender helps me to have fewer headaches from resetting passwords and securing the hacked account, it forces the security layers that help to achieve this solution.For the Endpoint, I have bought too many apps to secure endpoints but …
We use sophos endpoint protection and xg firewalls in conjunction with microsoft 365 defender. We dont believe defender is robust enough to be our only security solution but it works well as another line of defense from threats to our organization especially our ever growing …
We have used and find great value with competitors to Microsoft 365 Defender. Many of these services were utilized before customers began the total cloud shift that has been seen with certain industries. It is difficult to compare these products apples to apples. What I will …
As already stated, the main advantage of Defender is being able to use a single console to manage it and all the other 365 applications. I can state that it provides a more effective protection than Bitdefender MDR and Trend Micro Apex One while I consider CrowdStrike on the …
We use Microsoft products and have a large group of users. It works easily with our system. There is a great deal of knowledge base out there, often a little overwhelming. But we feel it's the best tool for our network to use parallel to the rest of our back-end.
Firstly Microsoft 365 Defender offers effortless integration with other Microsoft solutions over the products evaluated. Compared to Microsoft 365 Defender the evaluated products should improve the integration and its web interfaces. Few challenges were encountered when …
Microsoft is a known leader in the cyber security space and the trust microsoft has is greater than any other product. The pricing though bit on the higher side , but it ensures a proper support with using the product which makes it more preferred in our organisation.it is …
Darktrace would be well suited to any environment really; the only constraint would be the budget. The cost scales on the number of devices to be monitored by the product, so it can be quite expensive in larger environments. Any company that would benefit from having 24/7 monitoring of their network would find that this product would suit that need perfectly. It can also create a number of reports, which is useful if you have any requirement to present periodic figures and statistics for your network. There are also additional features available and in development such as Antigena, which can be configured to allow potential threats to be automatically mitigated; it can block connections to a certain address, using certain ports, or it can enforce "normal behaviour" where it will only allow a machine to communicate in a way that Darktrace has observed before and considers normal. This has huge benefits particularly for 24/7 organisations where you don't have the ability to have someone monitoring the network personally at all times, as it could stop a malware outbreak in its tracks.
Suit Really in everything, what is modern cloud work especially really if you work in a global company where your IT team is not always operational hour of the business users so that everything is really in the cloud can be managed from everywhere, but we do not access to local resources anymore. That's really a good point. What is always a little bit the pressure point is that general things in cloud things are moving fast so it's always difficult to keep the teams that is using these words up to date
Uses it Al model UEBA to detect anomalies in the behaviour of not only the users in a corporate network but also the routers, servers, and endpoints in that network.
Provides a visualisation of both egress and outbound network traffics flowing in and out of the organisation.
Darktrace comes with it autonomous AI model detection and responses capabilities.
Darktrace as an AI next generation NDR solution, prevents ,contains and quarantines malicious traffics from and into the corporate network.
The software uses advanced AI and machine learning algorithms to monitor activities and detect any anomalies immediately, protecting our financial data.
Automated responses to known threats reduce the impact of possible incidents and improve our security posture.
Microsoft 365 Defender easily combines with other Microsoft 365 services and external security solutions, providing a complete and unified security solution.
Microsoft 365 Defenders risk assessment and remediation tool can be improved while tackling and preventing the attack.
As there are multiple new attacks are getting discovered to prevent and remediate those attacks the Microsoft 365 Defenders database should be keep updated and ready.
The Microsoft 365 Defenders capability to identify the insider attacker can be improved.
Automate response generated to remediate the attack can be strengthen.
All though most of the features are upto mark, there are certain times where there have been misses to detect spam, phising emails. this might be due to the subject and content of the email being more sophisticated than standard .
The Darktrace toolset is very expansive, allowing it to handle many different tasks, but this leads to a user interface that is sometimes not at all intuitive. Icons don't always make sense visually, and the associated tool tips do not always provide enough detail on what action the button performs
Darktrace support is excellent in my experience. They send a competent engineer on-site to provide on-boarding training. They were also very responsive in responding to questions and concerns. Having an individual point of contact who is a competent network and security engineer is not a common experience, at least for me.
Their support throughout our onboarding of the product was fabulous. They not only took the time to carefully explain to teams not as well equipped with the lingo but explained to the tech team how to teach the other teams to be successful. They never once seemed impatient or annoyed with basic questions and didn’t pretend to know something when they needed to research an answer
Microsoft Provides a good training for the Microsoft 365 Defender and has a good learning paths to learn and take the exams and get your Certifications.
seemless and almost transparent. can be deployed by script if needed so every endpoint on our system get's it. if you have intune it gets dumped on the the endpoint by policy so nothing escapes it
We did NOT select Darktrace. OSSIM/AlienVault is a more mature product and it provided better intelligence and reporting. The end user interface is much easier to use - and you can tell built form engineers who have had to do the work. My suggestion for anyone considering Darktrace, is to get the price upfront; do a 30/60 onsite trail; and do the same thing, at the same time, with AlienVault. AlientVault will win every time. I say that because that's exactly what I did.
We chose Microsoft Defender XDR for the ability to correlament the dangers in the Microsoft Ecosystem, Strong Automation, and email, Identification, Estruction, Establishment Points and Cloud Apps in the same platform. This gave us the end-to-end visibility without the need to sew several devices simultaneously.
One big positive is how it helps us with the security assessments that clients have done on us. They are looking to see if we know how we might have unusual/malicious traffic running on the network.
If you have a small network and only need 1 appliance, it can be a good ROI and peace of mind.
You could go down a hole in trying to spend time looking at all of your traffic with this software. You need to focus only on what it is showing as potential bad traffic.
Cost-Efficiency: Microsoft Defender XDR often proves cost-effective compared to implementing multiple standalone security solutions, consolidating threat detection and response capabilities.
Time Savings: Its centralized dashboard and automated features can save time for security teams, allowing them to focus on critical tasks