Best Extended Detection and Response (XDR) Platforms - Page 2

How Many Extended Detection and Response (XDR) Platforms Products Does G2 Track?

Total Products under this Category: 103

Category Stats (Sep 2026)

  • Average Rating: 4.55/5 (↑0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Singularity AI SIEM (+3.53%) - Among all products in this category, Singularity AI SIEM recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Extended Detection and Response (XDR) Platforms Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 6,500+ Authentic Reviews
  • 103+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Extended Detection and Response (XDR) Platforms

G2 Grid® for Extended Detection and Response (XDR) Platforms plotting products by satisfaction and market presence

Highlighted products: Sophos Endpoint, CrowdStrike Falcon Endpoint Protection Platform, CrowdStrike Falcon Cloud Security, TrendAI Vision One, Check Point Endpoint Security, ESET PROTECT, Cynet, and SentinelOne Singularity Endpoint.

Underlying data: [Grid® JSON](https://www.g2.com/categories/extended-detection-and-response-xdr-platforms/grids.json?focus%5B%5D=sophos-endpoint&focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=crowdstrike-falcon-cloud-security&focus%5B%5D=trendai-vision-one&focus%5B%5D=check-point-endpoint-security&focus%5B%5D=eset-protect&focus%5B%5D=cynet&focus%5B%5D=sentinelone-singularity-endpoint)

Todyl Security Platform

Todyl is an AI-powered Cybersecurity and Assurance Platform for threat, risk, and compliance management delivered through a single agent and a single portal. Our platform defends against modern, advanced threats spanning identity, endpoint, network, cloud, SaaS, and more. We also simplify meeting and demonstrating extensive compliance and insurance requirements with centralized data collection and reporting, easy-to-use assessment tools, a built-in risk register, and dashboards to cut back on manual reporting and spreadsheet sprawl. Our platform delivers a layered approach to cybersecurity, spanning SASE, Micro-Segmentation (LZT), Endpoint Security, SIEM, MXDR, and GRC all delivered through the same agent, in a cloud native platform. It’s easy to implement as a cost effective, fully integrated single solution that can consolidate and simplify your security and compliance programs. You can also deploy individual modules to meet your current needs, with a simple toggle within the UI to add or trial new modules when you need them. And an integrated Assurance Marketplace helps you complete your security program with additional services like incident response and penetration testing, and streamlined access to cyber insurance providers.

Average Rating: 4.7/5.0

Total Reviews: 106

How Do G2 Users Rate Todyl Security Platform?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)
  • Unified Visibility: 10.0/10 (Category avg: 9.0/10)
  • Threat Hunting: 10.0/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 7.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Todyl Security Platform?

  • Seller: Todyl
  • Company Website:
  • Year Founded: 2015
  • HQ Location: Denver, CO
  • LinkedIn® Page: www.linkedin.com
    120 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Owner, President
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 76% Small, 7% Medium

What Do G2 Reviewers Say About Todyl Security Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Todyl, highlighting its intuitive interface and seamless integration capabilities.
  • Users highlight the responsive and accessible customer support of Todyl, enhancing their overall experience and efficiency.
  • Users praise the convenient deployment and comprehensive integration features of Todyl Security Platform for enhanced security.
  • Users value the comprehensive security offered by Todyl, appreciating its ease of installation and cost-effectiveness.
  • Users praise the deployment ease of Todyl, appreciating its intuitive interface and seamless integration across platforms.
Cons
  • Users find there are improvements needed in customization, integrations, and the steep learning curve for Todyl's platform.
  • Users report integration issues with Todyl, noting limited API capabilities and inconsistencies with third-party connections.
  • Users find the reporting options inadequate, lacking ease of access and integration for strategic reviews.
  • Users notice the limited features in Todyl, particularly in customization, API, and reporting capabilities.
  • Users find the reporting tools inadequate, making it hard to extract useful insights for strategic reviews.

What Are Recent G2 Reviews of Todyl Security Platform?

Bitdefender GravityZone XDR

Bitdefender Business Solutions Group is the business cybersecurity division of Bitdefender, delivering GravityZone — a unified platform that consolidates endpoint protection (EPP), endpoint detection and response (EDR), extended detection and response (XDR), and managed detection and response (MDR) into a single agent and console. Bitdefender GravityZone serves mid-market organizations with lean IT and security teams, protecting endpoints, identities, email, network, and cloud workloads. Effortless Security. Unmatched Protection For more information, visit https://www.bitdefender.com/en-us/business/.

Average Rating: 4.1/5.0

Total Reviews: 107

How Do G2 Users Rate Bitdefender GravityZone XDR?

  • Has the product been a good partner in doing business?: 8.1/10 (Category avg: 9.2/10)
  • Unified Visibility: 8.7/10 (Category avg: 9.0/10)
  • Threat Hunting: 9.2/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind Bitdefender GravityZone XDR?

  • Seller: Bitdefender
  • Company Website:
  • Year Founded: 2001
  • HQ Location: Bucuresti, Romania
  • Twitter: @Bitdefender
    114,121 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,344 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 56% Small, 35% Medium

What Do G2 Reviewers Say About Bitdefender GravityZone XDR?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of deployment and administration of Bitdefender GravityZone XDR, enhancing security management efficiency.
  • Users praise the responsive and helpful customer support of Bitdefender GravityZone XDR, enhancing their overall experience.
  • Users find Bitdefender GravityZone XDR to be extremely easy to use, facilitating seamless implementation and management.
  • Users value the efficiency of Bitdefender GravityZone XDR, enjoying streamlined deployment and seamless integration with existing systems.
  • Users value the robust security features of Bitdefender GravityZone XDR, effectively protecting against emerging threats and vulnerabilities.
Cons
  • Users find the setup and configuration complex, making it challenging for non-technical users to navigate.
  • Users face configuration issues that can complicate the setup process and lead to operational disruptions.
  • Users experience a difficult configuration process, particularly during the initial setup and policy adjustments.
  • Users find the user interface cumbersome, complicating navigation and management for those handling numerous devices.
  • Users express concerns about poor management control, requiring dedicated personnel and facing integration challenges and update issues.

What Are Recent G2 Reviews of Bitdefender GravityZone XDR?

What Are G2 Users Discussing About Bitdefender GravityZone XDR?

Darktrace / NETWORK

Darktrace / HYBRID NETWORK uses Adaptive AI to continuously learn behavior across your infrastructure, combining NDR, CDR, OT security, ITDR, exposure management, attack path modelling and forensic investigations into a single solution. - Unify visibility - Detect and contain known, novel and insider threats - AI-led triage and investigations - Increase resilience Named a Leader in the 2025 and 2026 Gartner® Magic Quadrant™ for NDR and the only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS.

Average Rating: 4.5/5.0

Total Reviews: 44

How Do G2 Users Rate Darktrace / NETWORK?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)

Who Is the Company Behind Darktrace / NETWORK?

  • Seller: Darktrace
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Cambridgeshire, England
  • Twitter: @Darktrace
    18,177 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,597 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Financial Services, Information Technology and Services
  • Company Size: 60% Medium, 32% Large

What Do G2 Reviewers Say About Darktrace / NETWORK?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the excellent monitoring capabilities of Darktrace, offering impressive visibility and efficient network analysis.
  • Users appreciate the self-learning AI technology of Darktrace/Network, effectively adapting to threats without extensive configuration.
  • Users commend Darktrace's rapid threat detection, ensuring robust security with minimal manual intervention for maximum efficiency.
  • Users commend the responsive customer support of Darktrace/Network, enhancing learning and facilitating efficient troubleshooting.
  • Users highlight the autonomous AI-driven cybersecurity of Darktrace, which effectively detects and responds to threats in real time.
Cons
  • Users report a significant learning curve with Darktrace as the AI generates numerous alerts during initial setup.
  • Users note that the product can be expensive, particularly for smaller organizations with constrained budgets and significant training costs.
  • Users experience alert issues with Darktrace, needing extensive manual tuning to manage false positives during the learning phase.
  • Users find the complex setup of Darktrace challenging, requiring skilled teams for effective management and configuration.
  • Users experience false positives occasionally, requiring IT support to resolve issues affecting network connectivity.

What Are Recent G2 Reviews of Darktrace / NETWORK?

What Are G2 Users Discussing About Darktrace / NETWORK?

Field Effect MDR

Field Effect delivers intelligence-grade managed detection and response for the AI era. Built on Federated Smart Compute™ and nation-state tradecraft, our holistic MDR platform uncovers weaknesses early, blocks attacks in real time, and reduces risk across the entire threat surface—endpoint, network, cloud, and more. With an 18-second median time to detect, Field Effect helps MSPs and overwhelmed IT teams outpace agentic attacks and achieve premium protection with the team they have.

Average Rating: 4.8/5.0

Total Reviews: 43

How Do G2 Users Rate Field Effect MDR?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Unified Visibility: 9.0/10 (Category avg: 9.0/10)
  • Threat Hunting: 8.6/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 8.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Field Effect MDR?

  • Seller: Field Effect
  • Company Website:
  • Year Founded: 2016
  • HQ Location: Ottawa
  • Twitter: @fieldeffectsoft
    1,304 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    149 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 52% Small, 27% Medium

What Do G2 Reviewers Say About Field Effect MDR?

AI-generated summary from verified user reviews

Pros
  • Users commend the ease of use in Field Effect MDR, particularly enjoying simple setup and deployment processes.
  • Users value the responsive and helpful customer support of Field Effect MDR, ensuring effective implementation and issue resolution.
  • Users appreciate the comprehensive alert notifications of Field Effect MDR, enabling timely identification of vulnerabilities and issues.
  • Users commend the easy initial setup of Field Effect MDR, allowing for quick deployment and seamless integration.
  • Users value the 24/7 threat detection of Field Effect MDR, ensuring immediate identification and isolation of cybersecurity threats.
Cons
  • Users find alert issues with Field Effect MDR, often needing additional support due to unclear notifications and false alarms.
  • Users find the inefficient alert system difficult to manage due to overwhelming volume and lack of detail.
  • Users find the learning curve steep, necessitating additional time for onboarding and user adaptation to the Field Effect MDR.
  • Users find the communication issues frustrating, often needing to simplify technical info for clients, leading to extra support requests.
  • Users experience integration issues with Field Effect MDR, leading to reporting challenges and account disruptions during system interactions.

What Are Recent G2 Reviews of Field Effect MDR?

What Are G2 Users Discussing About Field Effect MDR?

Rapid7 Next-Gen SIEM

Rapid7 InsightIDR is a SaaS SIEM for modern threat detection and response. InsightIDR enables security analysts to work more efficiently and effectively, by unifying diverse data sources, providing early and reliable out of the box detections, and delivering rich visual investigations and automation to expedite response. With a lightweight cloud deployment and intuitive UI and onboarding experience, InsightIDR customers recognize an accelerated return on their investment and start seeing valuable insights from Day 1. With InsightIDR, teams can advance their threat detection and response program without adding headcount.

Average Rating: 4.4/5.0

Total Reviews: 68

How Do G2 Users Rate Rapid7 Next-Gen SIEM?

  • Has the product been a good partner in doing business?: 8.7/10 (Category avg: 9.2/10)
  • Unified Visibility: 8.6/10 (Category avg: 9.0/10)
  • Threat Hunting: 8.5/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Rapid7 Next-Gen SIEM?

  • Seller: Rapid7
  • Year Founded: 2000
  • HQ Location: Boston, MA
  • Twitter: @rapid7
    124,405 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    8,746 employees on LinkedIn®
  • Ownership: NASDAQ:RPD

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 68% Medium, 31% Large

What Do G2 Reviewers Say About Rapid7 Next-Gen SIEM?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of use of Rapid7 Next-Gen SIEM unparalleled, with simple implementation and clear alerts.
  • Users appreciate the easy integrations of Rapid7 Next-Gen SIEM, benefiting from pre-built connections with numerous third-party tools.
  • Users appreciate the pre-built integrations of Rapid7 Next-Gen SIEM, making it easy to connect with various third-party tools.
  • Users appreciate the seamless integration of UEBA and deception tools for efficient threat detection across the network.
  • Users value the excellent visibility provided by Rapid7 Next-Gen SIEM, enabling easy log searches and clear alerts.
Cons
  • Users find the limited features of Rapid7 Next-Gen SIEM restrict overall functionality and alert setup capabilities.
  • Users find the alerting issues cumbersome, particularly when trying to create and set up pattern-based alerts.
  • Users find the limited alert management capabilities frustrating, complicating the creation of effective and timely alerts.
  • Users find the difficult customization in Rapid7 Next-Gen SIEM limits their ability to create effective alerts.
  • Users find the difficult setup of Rapid7 Next-Gen SIEM hinders effective alert creation and pattern configurations.

What Are Recent G2 Reviews of Rapid7 Next-Gen SIEM?

What Are G2 Users Discussing About Rapid7 Next-Gen SIEM?

Cisco SecureX

Cisco SecureX is the broadest, most integrated security platform that connects the breadth of Cisco's integrated security portfolio and the customer's infrastructure for a consistent experience.

Average Rating: 4.3/5.0

Total Reviews: 12

How Do G2 Users Rate Cisco SecureX?

  • Has the product been a good partner in doing business?: 8.3/10 (Category avg: 9.2/10)
  • Unified Visibility: 8.3/10 (Category avg: 9.0/10)
  • Threat Hunting: 8.3/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Cisco SecureX?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Company Size: 58% Large, 25% Medium

What Do G2 Reviewers Say About Cisco SecureX?

AI-generated summary from verified user reviews

Pros
  • Users find Cisco SecureX to be easy to use, providing a seamless and bug-free cloud security experience.
  • Users praise the cloud security solutions of Cisco SecureX, highlighting its ease of use and effective access control.
  • Users value the centralized management of Cisco SecureX, streamlining security operations and improving incident response efficiency.
  • Users value the intuitive dashboard of Cisco SecureX, enhancing threat visibility and streamlining incident response efficiency.
  • Users value the easy integrations of Cisco SecureX, allowing for streamlined workflows across various security tools effortlessly.
Cons
  • Users find the complex implementation of Cisco SecureX challenging, especially when integrating with other tools and features.
  • Users find Cisco SecureX to be expensive, as it slightly exceeds many budgets for security software.
  • Users face integration issues with Cisco SecureX, finding the initial setup complex, especially with third-party tools.
  • Users report experiencing slow performance, especially during high data processing, impacting workflow efficiency at crucial times.
  • Users express concerns about the training issues requiring team involvement for every new update of Cisco SecureX.

What Are Recent G2 Reviews of Cisco SecureX?

What Are G2 Users Discussing About Cisco SecureX?

ReliaQuest GreyMatter

ReliaQuest’s agentic AI security operations platform, GreyMatter, allows security teams to detect threats at the source, contain them in under 5 minutes, and eliminate Tier 1 and Tier 2 work for faster investigation and response. GreyMatter orchestrates 6 agentic AI personas with 200+ agent skills and 400+ AI tools to exponentially scale security operations and help organizations predict what's next.

Average Rating: 4.6/5.0

Total Reviews: 19

How Do G2 Users Rate ReliaQuest GreyMatter?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)
  • Unified Visibility: 10.0/10 (Category avg: 9.0/10)
  • Threat Hunting: 10.0/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind ReliaQuest GreyMatter?

  • Seller: ReliaQuest
  • Company Website:
  • Year Founded: 2007
  • HQ Location: Tampa, Florida, United States
  • Twitter: @ReliaQuest
    2,577 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,106 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Consumer Services
  • Company Size: 37% Medium, 26% Small

What Do G2 Reviewers Say About ReliaQuest GreyMatter?

AI-generated summary from verified user reviews

Pros
  • Users value the exceptional visibility and integration capabilities of ReliaQuest GreyMatter, enhancing security operations across environments.
  • Users value the centralized management of ReliaQuest GreyMatter, enhancing visibility and streamlining security operations effectively.
  • Users highlight the exceptional customer support of ReliaQuest GreyMatter, enhancing satisfaction and streamlining security operations.
  • Users praise the ease of use of ReliaQuest GreyMatter, highlighting its straightforward setup and seamless integrations.
  • Users highlight the seamless integration with existing tools, streamlining security operations and enhancing overall efficiency.
Cons
  • Users note UX improvement needs in ReliaQuest GreyMatter, citing alert delays, slow report loading, and clunky Android app experience.
  • Users find the complexity of configurations in ReliaQuest GreyMatter can hinder usability and require significant fine-tuning.
  • Users experience an inefficient alert system with delays, duplicates, and slow report loading, affecting overall usability.
  • Users find the learning curve steep for advanced workflows, though documentation and support help eventually.
  • Users find login issues with the ReliaQuest GreyMatter app, particularly on Android, making the sign-in process frustrating.

What Are Recent G2 Reviews of ReliaQuest GreyMatter?

UnderDefense MAXI

UnderDefense is an Agentic AI SOC & Compliance Automation platform trusted by 200+ enterprises in the US and EU. It works on top of the security stack you already own — no rip-and-replace, no added headcount — so your team spends its time on decisions, not triage. ◆ 10+ years of operations with zero ransomware incidents ◆ 250+ integrations across any SIEM, EDR, or cloud stack ◆ 24/7 IR team available whenever you need urgent support WHAT WE OFFER AGENTIC AI SOC UnderDefense Agentic AI SOC works on top of your existing security stack, turning every security team into a machine-speed defense unit without tool replacement or headcount expansion. It takes over the investigative routine that pulls your team away from strategic decisions: enrichment, correlation, triage. ▸ Investigation at Machine Speed: Agentic AI SOC accesses tools, enriches data, and performs deep cross-environment investigations at machine speed. It correlates, triages, and forms conclusions, offloading all repetitive work from your team. ▸ 2 Minutes Per Alert: Complete SIEM queries, threat intel checks, and cross-system correlations in 2 minutes. Every step fully observable and auditable. ▸ Human at Every Decision Point: The platform verifies suspicious activity with end-users via Slack or Teams, then routes containment decisions to your team or our 24/7 IR experts. COMPLIANCE AUTOMATION Stop chasing spreadsheets. UnderDefense MAXI Compliance AI automatically collects continuous evidence across ISO 27001, SOC 2, PCI DSS, GDPR, and HIPAA, and publishes your live posture through a shareable Trust Center link. ▸ 40% audit-ready in the first 40 minutes ▸ 2X faster time-to-compliance vs. traditional audit ▸ 24/7 continuous monitoring — posture always current, not point-in-time WHY WE ARE BETTER ✓ No rip-and-replace: Works with your current SIEM (Splunk, Sentinel, Chronicle, QRadar, Elastic), EDR, and cloud tools. Logs stay in your data lake. ✓ True Multi-Environment Coverage: Comprehensive visibility across on-premises, cloud (AWS, GCP, Azure), SaaS, network, identity, and OT/SCADA environments. ✓ The Only Agentic AI SOC with on-prem deployment: Full AI SOC inside your own infrastructure. No telemetry leaving your environment. Air-gapped available. ✓ Right-Sized for Any Enterprise: Detection engineering and support tailored to your organization, not a one-size-fits-all template. Start your free trial at underdefense.com

Average Rating: 4.9/5.0

Total Reviews: 43

How Do G2 Users Rate UnderDefense MAXI?

  • Has the product been a good partner in doing business?: 9.6/10 (Category avg: 9.2/10)

Who Is the Company Behind UnderDefense MAXI?

  • Seller: UnderDefense
  • Year Founded: 2017
  • HQ Location: New York, NY
  • Twitter: @underdefense
    153 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    133 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO
  • Top Industries: Information Technology and Services, Marketing and Advertising
  • Company Size: 56% Medium, 35% Small

What Do G2 Reviewers Say About UnderDefense MAXI?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the visibility provided by UnderDefense MAXI, allowing them to focus on relevant security alerts effectively.
  • Users commend UnderDefense MAXI for its outstanding customer support, ensuring rapid responses and clear guidance throughout their cybersecurity needs.
  • Users appreciate the expert cybersecurity support from UnderDefense MAXI, enhancing their security posture and alert management.
  • Users commend the accuracy of information provided by UnderDefense MAXI, enhancing their security management and decision-making.
  • Users value the exceptional issue resolution by UnderDefense, enhancing security management with quick and effective solutions.
Cons
  • Users desire more automation in UnderDefense MAXI, seeking greater control over the dashboard and updates.
  • Users desire more control over the dashboard and automated updates for a better experience with UnderDefense MAXI.
  • Users note the limited integration requiring extra setup time, which can be a hurdle for new users.
  • Users note the setup difficulty requiring time and effort to properly integrate tools before full functionality can be enjoyed.

What Are Recent G2 Reviews of UnderDefense MAXI?

ExtraHop

ExtraHop is the cybersecurity partner enterprises trust to reveal cyber risk and build business resilience. The ExtraHop RevealX platform for network detection and response and network performance management uniquely delivers the instant visibility and unparalleled decryption capabilities organizations need to expose the cyber risks and performance issues that other tools can’t see. When organizations have full network transparency with ExtraHop, they can investigate smarter, stop threats faster, and keep operations running. RevealX deploys on premises or in the cloud. It addresses the following use cases: - Ransomware - Zero trust - Software supply chain attacks - Lateral movement and C2 communication - Security hygiene - Network and Application Performance Management - IDS - Forensics and more A few of our differentiators: Continuous and on-demand PCAP: Full packet processing is superior to NetFlow and yields higher quality detections. Strategic decryption across a variety of protocols, including SSL/TLS, MS-RPC, WinRM, and SMBv3, gives you better visibility into early-stage threats hiding in encrypted traffic as they attempt to move laterally across your network. Protocol coverage: RevealX decodes more than 70 network protocols. Cloud-scale machine learning: Rather than relying on limited "on-box" compute power for analysis and detections, RevealX uses sophisticated cloud-hosted and cloud-scale machine learning workloads to identify suspicious behavior in real time and create high-fidelity alerts. ExtraHop was named a Leader in The Forrester Wave™: Network Analysis and Visibility, Q2 2023. Key Technology Integration and Go-to-Market Partners: CrowdStrike: RevealX integrates with CrowdStrike Falcon® LogScale, Falcon Insight XDR, Falcon Threat Graph, and Falcon Intelligence. Splunk SOAR AWS Google Cloud Security Founded in 2007, ExtraHop is privately held and headquartered in Seattle, Wash. To learn more, visit www.extrahop.com.

Average Rating: 4.6/5.0

Total Reviews: 68

How Do G2 Users Rate ExtraHop?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Unified Visibility: 9.7/10 (Category avg: 9.0/10)
  • Threat Hunting: 9.6/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 9.6/10 (Category avg: 8.8/10)

Who Is the Company Behind ExtraHop?

  • Seller: ExtraHop Networks
  • Year Founded: 2007
  • HQ Location: Seattle, Washington
  • Twitter: @ExtraHop
    10,695 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    774 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Hospital & Health Care, Transportation/Trucking/Railroad
  • Company Size: 69% Large, 26% Medium

What Do G2 Reviewers Say About ExtraHop?

AI-generated summary from verified user reviews

Pros
  • Users value the all-in-one monitoring solution of ExtraHop, appreciating its comprehensive visibility and insightful analysis of network traffic.
  • Users value the comprehensive monitoring capabilities of ExtraHop, enhancing network visibility and analysis effectively.
  • Users appreciate the easy deployment of ExtraHop, benefiting from seamless installation on both physical and virtual networks.
  • Users value the responsive support from ExtraHop's knowledgeable Customer Success teams, enhancing their overall experience and satisfaction.

What Are Recent G2 Reviews of ExtraHop?

What Are G2 Users Discussing About ExtraHop?

Open Threat Management (OTM) Platform

Seceon Open Threat Management Platform is a software designed for cybersecurity threat detection and response. The software integrates security monitoring, threat intelligence, and automated response capabilities to help organizations identify and mitigate cyber threats in real time. It ingests data from multiple sources, including network traffic, endpoints, and cloud environments, and applies machine learning and analytics to detect anomalies and threats. Through automation, the software streamlines incident response processes, supports compliance requirements, and assists security teams in reducing the time to detect and remediate security incidents. Seceon Open Threat Management Platform addresses the business problem of manual and fragmented security monitoring by offering a unified view and AI-driven analysis for proactive threat management.

Average Rating: 4.5/5.0

Total Reviews: 18

How Do G2 Users Rate Open Threat Management (OTM) Platform?

  • Has the product been a good partner in doing business?: 8.6/10 (Category avg: 9.2/10)
  • Unified Visibility: 9.7/10 (Category avg: 9.0/10)
  • Threat Hunting: 9.6/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 9.7/10 (Category avg: 8.8/10)

Who Is the Company Behind Open Threat Management (OTM) Platform?

  • Seller: Seceon
  • Year Founded: 2015
  • HQ Location: Westford, Massachusetts, United States
  • Twitter: @Seceon_Inc
    1,209 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    177 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 48% Medium, 33% Small

What Do G2 Reviewers Say About Open Threat Management (OTM) Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the comprehensive visibility provided by OTM, simplifying threat detection and enhancing response capabilities effectively.
  • Users appreciate the comprehensive visibility provided by the Open Threat Management Platform, streamlining threat detection and response.
  • Users appreciate the comprehensive visibility of the OTM Platform, facilitating quick and automated threat detection and response.
  • Users appreciate the comprehensive visibility of the OTM Platform, enhancing threat detection and response efficiency.
  • Users appreciate the user-friendly dashboard of the OTM Platform, enabling quick threat detection and streamlined workflows.
Cons
  • Users experience a steep learning curve with Seceon OTM, which can hinder new users from fully utilizing its features.
  • Users find the complex implementation of the OTM Platform challenging due to high resource requirements and a steep learning curve.
  • Users feel there is limited customization in Seceon OTM, impacting dashboard and report flexibility for security teams.
  • Users face poor customer support, often finding it less responsive than expected during critical integration issues.
  • Users experience slow performance with the OTM Platform, noting lags during alert analysis that hinder efficiency.

What Are Recent G2 Reviews of Open Threat Management (OTM) Platform?

What Are G2 Users Discussing About Open Threat Management (OTM) Platform?

NetWitness Platform

NetWitness is a comprehensive threat detection, investigation and response platform that combines visibility, analytics, insight, and automation into a single solution. It collects and analyzes data across all capture points (logs, packets, netflow, endpoint and IoT) and computing platforms (physical, virtual and cloud), enriching data with threat intelligence and business context.

Average Rating: 3.9/5.0

Total Reviews: 23

How Do G2 Users Rate NetWitness Platform?

  • Has the product been a good partner in doing business?: 8.5/10 (Category avg: 9.2/10)
  • Unified Visibility: 10.0/10 (Category avg: 9.0/10)
  • Threat Hunting: 10.0/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind NetWitness Platform?

  • Seller: NetWitness
  • Year Founded: 1997
  • HQ Location: Bedford, MA
  • Twitter: @Netwitness
    1,621 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    204 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 54% Large, 33% Medium

What Do G2 Reviewers Say About NetWitness Platform?

AI-generated summary from verified user reviews

Pros
  • Users value the centralized management of NetWitness Platform, which simplifies threat hunting across various data sources.
  • Users appreciate the centralized threat hunting capabilities of the NetWitness Platform, reducing tool sprawl and enhancing security efficiency.
  • Users value the packet capture and replay capabilities of NetWitness Platform for in-depth forensic investigations.
  • Users value the ability to capture full network packets for deep forensic investigation, enhancing their analytic capabilities.
  • Users appreciate the centralized view of the Management Console, simplifying threat hunting across diverse data sources.
Cons
  • Users find the complex implementation of NetWitness Platform challenging, needing expert skills for initial setup and upgrades.
  • Users face complexity in initial setup and upgrades with NetWitness Platform, requiring significant technical expertise and stability concerns.
  • Users face a complex setup for the NetWitness Platform, often needing extensive technical expertise for deployment and upgrades.
  • Users face deployment difficulties with the NetWitness Platform, often requiring advanced technical skills and experiencing upgrade instability.
  • Users find the expertise required for initial setup and upgrades complex, leading to deployment challenges.

What Are Recent G2 Reviews of NetWitness Platform?

What Are G2 Users Discussing About NetWitness Platform?

Carbon Black Cloud

The Carbon Black Cloud security platform helps you strengthen and unify security tools to see more and stop more. Carbon Black unifies visibility across your endpoints, networks, and containers to enable you to stop threats targeting your organization with speed and confidence. Carbon Black protects against the full spectrum of modern cyber-attacks, including emerging threats and ransomware. Top SOC teams, IR firms and MSSPs have adopted Carbon Black as a core component of their prevention, detection, and response capability stack. Carbon Black is available via MSSP or directly.

Average Rating: 4.1/5.0

Total Reviews: 38

How Do G2 Users Rate Carbon Black Cloud?

  • Has the product been a good partner in doing business?: 9.2/10 (Category avg: 9.2/10)

Who Is the Company Behind Carbon Black Cloud?

  • Seller: Broadcom
  • Year Founded: 1991
  • HQ Location: San Jose, CA
  • Twitter: @broadcom
    63,909 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    44,602 employees on LinkedIn®
  • Ownership: NASDAQ: CA

Who Uses This Product?

  • Top Industries: Financial Services
  • Company Size: 56% Medium, 33% Large

What Do G2 Reviewers Say About Carbon Black Cloud?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of Carbon Black Cloud, highlighting its intuitive interface and manageable block/whitelist features.
  • Users appreciate the easy installation and robust protection offered by Carbon Black Cloud for their digital infrastructure.
  • Users value the robust security features of Carbon Black Cloud, ensuring comprehensive protection for their digital infrastructure.
  • Users value the advanced antivirus protection of Carbon Black Cloud, ensuring 24/7 security against various threats.
  • Users appreciate the advanced AI-powered security of Carbon Black Cloud, providing affordable 24/7 protection effortlessly.
Cons
  • Users report agent removal issues with VMware Carbon Black Cloud, causing disruptions during critical tasks like exams.
  • Users face significant compatibility issues as the tool needs extensive customization and lacks integration with Microsoft OS.
  • Users find complex implementation challenging, particularly in creating global blocks and whitelists without individual policy updates.
  • Users face complex installation issues with VMware Carbon Black Cloud, leading to interruptions during critical tasks like exams.
  • Users find it challenging to manage configuration issues, especially when needing global blocks or whitelists.

What Are Recent G2 Reviews of Carbon Black Cloud?

What Are G2 Users Discussing About Carbon Black Cloud?

Heimdal

Accommodate all your cybersecurity needs under one convenient roof with the Heimdal® Unified Cybersecurity Platform. Our cybersecurity solutions can be used as standalone products or integrated into one another as part of a cohesive and unified XDR platform. Whether you’re a reseller, distributor, MSSP, or an organization committed to bolstering your online security, we provide an array of cutting-edge products to make your mission smoother. Heimdal® is a fast-growing cybersecurity company focused on continuous technological innovation. Since its establishment in 2014 in Copenhagen, based on the winning idea of CTF World Champions, Heimdal has experienced spectacular growth by proactively building products that anticipate threatscape trends. The company offers a multi-layeredand unified security suite that combines threat prevention, patch and asset management, endpoint rights management, antivirus and mail security which together secure customers against cyberattacks and keep critical information and intellectual property safe. Heimdal has been recognized as a thought leader in the industry and has won multiple international awards both for its solutions and for its educational content creation. The Heimdal line of products currently consists of 10 products and 2 services. The former category encompasses DNS Security for Endpoints & Network, Patch & Asset Management, Privileged Access Management, Application Control, Next-Gen Endpoint Antivirus, Ransomware Encryption Protection, Email Security, Email Fraud Prevention, and Remote Desktop. The latter is represented by Endpoint Detection & Response, as well as eXtended Detection & Response, or EDR and XDR for short. Currently, Heimdal’s cybersecurity solutions are deployed in more than 45 countries and supported regionally from offices in 15+ countries, by 175+ highly qualified specialists. Heimdal is ISAE 3000 certified and secures more than 2 million endpoints for over 10,000 companies. The company supports its partners without concessions on the basis of predictability and scalability. The common goal is to create a sustainable ecosystem and a strategic partnership.

Average Rating: 4.4/5.0

Total Reviews: 80

How Do G2 Users Rate Heimdal?

  • Has the product been a good partner in doing business?: 9.4/10 (Category avg: 9.2/10)

Who Is the Company Behind Heimdal?

  • Seller: Heimdal®
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Copenhagen, Denmark
  • Twitter: @HeimdalSecurity
    5,086 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    284 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Construction
  • Company Size: 56% Medium, 30% Small

What Do G2 Reviewers Say About Heimdal?

AI-generated summary from verified user reviews

Pros
  • Users praise the easy setup of Heimdal, appreciating its straightforward installation and quick integration with their systems.
  • Users find that file transfer with Heimdal is seamless and reliable, enhancing overall productivity and ease of use.
  • Users commend Heimdal for its exceptional issue resolution support, providing quick and professional solutions exceeding expectations.
  • Users value the reliable patch management of Heimdal, delivering consistent performance without issues during monthly updates.
  • Users value the reliable security and user-friendly interface of Heimdal, enhancing overall satisfaction and support.
Cons
  • Users find the complex interface of Heimdal difficult to navigate, complicating their overall experience and functionality.
  • Users find the admin portal complex and illogical, making navigation frustrating and cumbersome for essential tasks.
  • Users find the customer support lacking during initial setup, which causes issues with product deployment and upgrades.
  • Users find the poor interface design of Heimdal difficult to navigate, complicating essential tasks and access.
  • Users experience restart issues with Heimdal, feeling unprotected after scans until the software is rebooted.

What Are Recent G2 Reviews of Heimdal?

Vectra AI Platform

The Vectra AI Platform helps security teams detect and stop real attacks that evade traditional security controls across network, identity, cloud, and SaaS environments. It provides real-time visibility into how attackers move through hybrid and multi-cloud environments, enabling teams to understand attack activity early and respond before incidents escalate. By correlating attacker behavior across the full attack lifecycle, the platform reduces alert noise and surfaces high-confidence threats that matter most. Analysts spend less time triaging isolated alerts and more time investigating complete attack stories with the context needed to take decisive action. Vectra AI unifies detection, investigation, and coordinated response across identity, endpoint, and network controls. Its approach is aligned with real-world defensive techniques, reflected in the highest number of vendor references in MITRE D3FEND and recognition as a Leader in the 2025 Gartner® Magic Quadrant™ for Network Detection and Response. Organizations worldwide rely on Vectra AI to detect attacks others miss and demonstrate measurable improvements in security operations.

Average Rating: 4.3/5.0

Total Reviews: 20

How Do G2 Users Rate Vectra AI Platform?

  • Has the product been a good partner in doing business?: 8.1/10 (Category avg: 9.2/10)
  • Unified Visibility: 10.0/10 (Category avg: 9.0/10)
  • Threat Hunting: 10.0/10 (Category avg: 9.2/10)

Who Is the Company Behind Vectra AI Platform?

  • Seller: Vectra AI
  • Year Founded: 2011
  • HQ Location: San Jose, CA
  • Twitter: @Vectra_AI
    3,269 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    682 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services
  • Company Size: 75% Large, 15% Medium

What Do G2 Reviewers Say About Vectra AI Platform?

AI-generated summary from verified user reviews

Pros
  • Users find the ease of understanding with the Vectra AI Platform enhances their learning experience significantly.
  • Users find Vectra AI Platform to have an easy-to-use interface and a clear learning method for new users.

What Are Recent G2 Reviews of Vectra AI Platform?

Blumira Automated Detection & Response

Blumira is an integrated security operations platform built for growing teams and the partners supporting them to gain complete visibility into their environment, identify and address risk faster, and deliver advanced security and compliance. The platform includes: - Managed Detections for automated threat hunting to identify attacks early - AI Investigation with 98.5% accurate, human-in-the-loop triage validated against real cases - Rapid Response with automation and 1-click actions to contain and block threats immediately - One Year of Data Retention with unlimited log ingestion to satisfy compliance requirements - Advanced Reporting and dashboards for forensics and easy investigation - Endpoint & Identity Protection (EDR/ITDR) for real-time remediation across devices and users - 24/7 Security Operations support for critical priority issues

Average Rating: 4.6/5.0

Total Reviews: 122

How Do G2 Users Rate Blumira Automated Detection & Response?

  • Has the product been a good partner in doing business?: 9.3/10 (Category avg: 9.2/10)
  • Unified Visibility: 8.5/10 (Category avg: 9.0/10)
  • Threat Hunting: 8.3/10 (Category avg: 9.2/10)
  • Rule-Based Detection: 8.3/10 (Category avg: 8.8/10)

Who Is the Company Behind Blumira Automated Detection & Response?

  • Seller: Blumira
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Ann Arbor, Michigan
  • Twitter: @blumira
    1 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    55 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: IT Manager
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 51% Medium, 36% Small

What Do G2 Reviewers Say About Blumira Automated Detection & Response?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the easy setup of Blumira Automated Detection & Response, enabling quick integration and efficient use.
  • Users appreciate the responsive customer support of Blumira, finding it reliable and personal for their IT needs.
  • Users praise the setup ease of Blumira, appreciating its quick integration and automated alert features.
  • Users appreciate the reliable real-time alerting of Blumira, valuing its clarity and ease of use for all techs.
  • Users value the reliable real-time alerting of Blumira, appreciating its ease of use and helpful implementation.
Cons
  • Users find limited customization with detection filters, relying on support for creating necessary custom detections.
  • Users express concern over false positives that can disrupt business functions and lead to frustration with repeated alerts.
  • Users find Blumira's pricing expensive, citing inflexible models and insufficient features in lower tiers.
  • Users express frustration over false positives that waste time and complicate the overall experience with Blumira.
  • Users express concern over insufficient information, desiring better data accessibility and clearer deployment status.

What Are Recent G2 Reviews of Blumira Automated Detection & Response?

What Are G2 Users Discussing About Blumira Automated Detection & Response?

Lauren Worth
LW
Researched and written by Lauren Worth
Updated October 3, 2024