# Best Network Detection and Response (NDR) Software

## How Many Network Detection and Response (NDR) Software Products Does G2 Track?

**Total Products under this Category:** 70

### Category Stats (Jul 2026)

- **Average Rating:** 4.39/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** ManageEngine ADAudit Plus (+0.22%) - Among all products in this category, ManageEngine ADAudit Plus recorded the largest rating increase compared to last month

_Last updated: July 30, 2026_

## How Does G2 Rank Network Detection and Response (NDR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,600+ Authentic Reviews
- 70+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Network Detection and Response (NDR) Software
 ![G2 Grid® for Network Detection and Response (NDR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/network-detection-and-response-ndr/grids.png?focus%5B%5D=19387&focus%5B%5D=1405921&focus%5B%5D=130021&focus%5B%5D=129114&focus%5B%5D=27617&focus%5B%5D=1293&focus%5B%5D=5691&focus%5B%5D=30501)

Highlighted products: Progress WhatsUp Gold, Sophos NDR, TrendAI Vision One, Darktrace / NETWORK, Cortex XDR, ExtraHop, ManageEngine ADAudit Plus, and Rapid7 Next-Gen SIEM.

Underlying data: [Grid® JSON](https://www.g2.com/categories/network-detection-and-response-ndr/grids.json?focus%5B%5D=progress-whatsup-gold&focus%5B%5D=sophos-ndr&focus%5B%5D=trendai-vision-one&focus%5B%5D=darktrace-network&focus%5B%5D=palo-alto-networks-cortex-xdr&focus%5B%5D=extrahop&focus%5B%5D=manageengine-adaudit-plus&focus%5B%5D=rapid7-next-gen-siem)

**Sponsored**

### Google Security Operations

Google Security Operations offers a unified experience across SIEM, SOAR, and threat intelligence to drive better detection, investigation, and response. Collect security telemetry data, apply threat intel to identify high priority threats, drive response with playbook automation, case management, and collaboration. It also provides Gemini-native agentic defense to help autonomously handle workflows like alert triage, threat hunting, and detection engineering. Google Security Operations also supports AI Threat Defense to monitor, detect, and respond to threats from code you do not own or cannot patch.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2380&secure%5Bchosen_at%5D=2026-07-31T17%3A19%3A24Z&secure%5Bdisplayable_resource_id%5D=1081&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=neighbor_category&secure%5Bplacement_resource_ids%5D%5B%5D=1081&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=30500&secure%5Bresource_id%5D=2380&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fnetwork-detection-and-response-ndr%3Fopen_modal_url%3D%252Fproducts%252Fguardsix%252Fwishlists%253Fhost_path%253D%25252Fcategories%25252Fnetwork-detection-and-response-ndr%2526source%253Dcategory&secure%5Btoken%5D=7a7dc9d77cde0a5c290484414bd4ab0e5377ef8721ca8779fd32078d559f475e&secure%5Burl%5D=https%3A%2F%2Fcloud.google.com%2Fsecurity%2Fproducts%2Fsecurity-operations%3Futm_source%3DG2%26utm_medium%3Ddisplay%26utm_campaign%3DCloud-SS-DR-GCP-1713658-GCP-DR-NA-US-en-G2-Display-Banner-All-%2525epid%21-%2525ecid%21-securityops%26utm_content%3D%257Bdevice%257D-%257Badgroupid%257D-%257Bnetwork%257D-%257Btargetid%257D-%257Bloc_physical_ms%257D-%257Bcampaignid%257D&secure%5Burl_type%5D=custom_url)

### [Progress WhatsUp Gold](https://www.g2.com/products/progress-whatsup-gold/reviews)

WhatsUp Gold is an IT infrastructure monitoring software designed to help users identify and resolve network issues swiftly, often before they impact end users. This solution provides comprehensive visibility into network performance and availability, enabling IT professionals to maintain optimal operations across their infrastructure. With its interactive mapping interface, WhatsUp Gold allows users to visualize the status of all devices connected to their network, making it easier to monitor both on-premise and cloud-based resources. Targeted primarily at IT administrators and network engineers, WhatsUp Gold is particularly beneficial for organizations that rely heavily on network performance for their daily operations. Its user-friendly design caters to both seasoned professionals and those new to network management, offering a range of features that streamline the monitoring process. The software is designed to support various use cases, from small businesses needing basic monitoring capabilities to large enterprises requiring advanced network management solutions. One of the standout features of WhatsUp Gold is its customizable drag-and-drop dashboards, which provide users with the flexibility to tailor their monitoring experience according to specific needs. These dashboards present real-time data on device status and performance, allowing users to quickly assess the health of their network. Additionally, the software’s automatic discovery and mapping capabilities enable users to visualize their entire network topology, ensuring that no device goes unnoticed during monitoring. WhatsUp Gold also emphasizes optimization, helping users manage network traffic and bandwidth utilization effectively. By providing actionable insights and unified views of network performance, the software empowers IT teams to troubleshoot issues efficiently. The ability to identify and resolve network and server problems proactively not only enhances operational efficiency but also improves overall user satisfaction by minimizing downtime. In summary, WhatsUp Gold offers a robust and interactive solution for IT infrastructure monitoring, combining ease of use with powerful features. Its focus on real-time visibility, customization, and proactive troubleshooting makes it a valuable tool for organizations looking to enhance their network management capabilities.

**Average Rating:** 4.4/5.0

**Total Reviews:** 380

#### How Do G2 Users Rate Progress WhatsUp Gold?

- **Quality of Support:** 8.8/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Progress WhatsUp Gold?

- **Seller:** [Progress Software](https://www.g2.com/sellers/progress-software)
- **Company Website:** www.progress.com
- **Year Founded:** 1981
- **HQ Location:** Burlington, MA.
- **Twitter:** @ProgressSW  
48,773 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=ab257d11ab0255eaaae8c28635f37e0e64277d81eae954d5985edfd545cd2d69&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fprogress-software%2F&secure%5Burl_type%5D=linkedin_company_website)  
4,205 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** Network Engineer, Network Administrator
- **Top Industries:** Information Technology and Services, Education Management
- **Company Size:** 58% Medium, 26% Large

#### What Do G2 Reviewers Say About Progress WhatsUp Gold?

_AI-generated summary from verified user reviews_

##### Pros

- Users find Progress WhatsUp Gold **easy to use** , with clear alerts and real-time monitoring that enhances network management.
- Users value the **real-time monitoring** of Progress WhatsUp Gold, which simplifies network management and enhances responsiveness.
- Users value the **real-time monitoring and clear alerts** from Progress WhatsUp Gold, enhancing network management efficiency.
- Users value the **clear and real-time alert notifications** from Progress WhatsUp Gold, enhancing their network management efficiency.
- Users appreciate the **user-friendly interface** of Progress WhatsUp Gold, making network monitoring straightforward and efficient.

##### Cons

- Users find WhatsUp Gold to be **expensive** due to costly add-ons for features that should be standard.
- Users find the **poor interface design** of Progress WhatsUp Gold to hinder usability and create confusion during operation.
- Users find the **complex setup** of Progress WhatsUp Gold challenging, requiring technical expertise for effective configuration.
- Users note a **high learning curve** with Progress WhatsUp Gold, making initial configuration challenging and time-consuming.
- Users often find the **outdated interface** of Progress WhatsUp Gold confusing, hindering their overall experience and efficiency.

#### What Are Recent G2 Reviews of Progress WhatsUp Gold?

**["Reliable Network Monitoring with Room for UI Improvement"](https://www.g2.com/survey_responses/progress-whatsup-gold-review-12619683)**

**Rating:** 4.5/5.0 stars

_— Udit P._

[Read full review](https://www.g2.com/survey_responses/progress-whatsup-gold-review-12619683)

**["User-Friendly Interface, Comprehensive Monitoring"](https://www.g2.com/survey_responses/progress-whatsup-gold-review-13021374)**

**Rating:** 4.5/5.0 stars

_— Zidani B._

[Read full review](https://www.g2.com/survey_responses/progress-whatsup-gold-review-13021374)

#### What Are G2 Users Discussing About Progress WhatsUp Gold?

- [What is Progress WhatsUp Gold used for?](https://www.g2.com/discussions/what-is-progress-whatsup-gold-used-for)
- [How much does WhatsUp gold cost?](https://www.g2.com/discussions/how-much-does-whatsup-gold-cost)
- [What is up monitoring tool?](https://www.g2.com/discussions/what-is-up-monitoring-tool)
- [How does WhatsUp gold work?](https://www.g2.com/discussions/how-does-whatsup-gold-work)
- [What is WhatsUp Gold monitoring tool?](https://www.g2.com/discussions/what-is-whatsup-gold-monitoring-tool) - 1 comment

### [Sophos NDR](https://www.g2.com/products/sophos-ndr/reviews)

Sophos NDR works together with your managed endpoints and firewalls to monitor network activity for suspicious and malicious patterns they cannot see. It detects abnormal traffic flows from unmanaged systems and IoT devices, rogue assets, insider threats, previously unseen zero-day attacks, and unusual patterns deep within the network.

**Average Rating:** 4.8/5.0

**Total Reviews:** 16

#### How Do G2 Users Rate Sophos NDR?

- **Metadata Enrichment:** 9.8/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.9/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 9.8/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.4/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Sophos NDR?

- **Seller:** [Sophos](https://www.g2.com/sellers/sophos)
- **Year Founded:** 1985
- **HQ Location:** Oxfordshire
- **Twitter:** @Sophos  
36,759 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=e7bb09f1d9ceb61adf28e57fdaf53266846612b2c5e7a5d2a80d0008113c9990&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5053%2F&secure%5Burl_type%5D=linkedin_company_website)  
5,500 employees on LinkedIn®
- **Ownership:** LSE:SOPH

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 100% Small

#### What Are Recent G2 Reviews of Sophos NDR?

**["Visibilidad completa y detección avanzada en tiempo real"](https://www.g2.com/survey_responses/sophos-ndr-review-12609724)**

**Rating:** 4.5/5.0 stars

_— Rafael L._

[Read full review](https://www.g2.com/survey_responses/sophos-ndr-review-12609724)

**["Network Awareness That Adds Real Depth to Security"](https://www.g2.com/survey_responses/sophos-ndr-review-12128206)**

**Rating:** 5.0/5.0 stars

_— Santosh K._

[Read full review](https://www.g2.com/survey_responses/sophos-ndr-review-12128206)

### [TrendAI Vision One](https://www.g2.com/products/trendai-vision-one/reviews)

TrendAI Vision One is a cloud-native security operations platform, serving cloud, hybrid, and on-premises environments. It combines ASM and XDR in a single console to effectively manage cyber risk across your organization. The platform provides powerful risk insights, earlier threat detection, and automated risk and threat response options. Utilize the platform’s predictive machine learning and advanced security analytics for a broader perspective and advanced context. TrendAI Vision One integrates with its own expansive protection platform portfolio and industry-leading global threat intelligence, in addition to a broad ecosystem of purpose-built and API-driven third-party integrations.

**Average Rating:** 4.7/5.0

**Total Reviews:** 246

#### How Do G2 Users Rate TrendAI Vision One?

- **Metadata Enrichment:** 7.2/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.7/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 8.1/10 (Category avg: 8.6/10)
- **Network Visibility:** 8.7/10 (Category avg: 8.9/10)

#### Who Is the Company Behind TrendAI Vision One?

- **Seller:** [TrendAI](https://www.g2.com/sellers/trendai)
- **Company Website:** www.trendmicro.com
- **Year Founded:** 1988
- **HQ Location:** Tokyo
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=454c2fb5d9ffdec950c31f62cc45f1b76a4b9ce72ef5e5a91b06fad1ee8584b7&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F4312%2F&secure%5Burl_type%5D=linkedin_company_website)  
8,040 employees on LinkedIn®
- **Ownership:** OTCMKTS:TMICY

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 52% Large, 33% Medium

#### What Do G2 Reviewers Say About TrendAI Vision One?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **centralized visibility** of TrendAI Vision One, enhancing operations across diverse environments effortlessly.
- Users value the **comprehensive security coverage** of TrendAI Vision One, praising its intuitive dashboard and automation features.
- Users find TrendAI Vision One's **ease of use** invaluable, with intuitive dashboards and automated threat management enhancing security.
- Users value the **centralized and user-friendly platform** of TrendAI Vision One, enhancing management across various geographies.
- Users value the **effective threat detection** of TrendAI Vision One, enhancing visibility and reducing alert fatigue for security teams.

##### Cons

- Users find the **interface complex** , with a steep learning curve that challenges effective usage during high-pressure situations.
- Users note **integration issues** with third-party tools, making TrendAI Vision One less flexible and user-friendly than desired.
- Users find the **learning curve steep** for TrendAI Vision One, making setup and feature utilization challenging.
- Users note that the **pricing is on the higher side** , making it less accessible compared to competitors.
- Users note the **limited features** of TrendAI Vision One, highlighting the need for improved reporting and DLP options.

#### What Are Recent G2 Reviews of TrendAI Vision One?

**["Scalable Security with Easy Setup, Needs Better Training Support"](https://www.g2.com/survey_responses/trendai-vision-one-review-12800247)**

**Rating:** 4.5/5.0 stars

_— Andrew W._

[Read full review](https://www.g2.com/survey_responses/trendai-vision-one-review-12800247)

**["Unified XDR Platform Delivering Enhanced Visibility, Faster Detection, and Proactive Threat Response"](https://www.g2.com/survey_responses/trendai-vision-one-review-12375604)**

**Rating:** 5.0/5.0 stars

_— Nishant K._

[Read full review](https://www.g2.com/survey_responses/trendai-vision-one-review-12375604)

#### What Are G2 Users Discussing About TrendAI Vision One?

- [What is Trend Micro Vision One (XDR) used for?](https://www.g2.com/discussions/what-is-trend-micro-vision-one-xdr-used-for) - 1 comment, 2 upvotes
- [How does XDR work?](https://www.g2.com/discussions/how-does-xdr-work) - 1 comment, 2 upvotes
- [How can Trend Micro XDR solve your detection and response challenges?](https://www.g2.com/discussions/how-can-trend-micro-xdr-solve-your-detection-and-response-challenges) - 1 comment
- [What is Trend Micro XDR?](https://www.g2.com/discussions/what-is-trend-micro-xdr)
- [What does Trend Micro XDR allow you to do?](https://www.g2.com/discussions/what-does-trend-micro-xdr-allow-you-to-do) - 1 comment

### [Darktrace / NETWORK](https://www.g2.com/products/darktrace-network/reviews)

Darktrace / NETWORK™ is the industry’s most advanced Network Detection and Response (NDR) solution. It learns what normal behavior is for your entire modern network, using Self-Learning AI to detect and autonomously contain any activity that could cause business disruption including known, novel and insider threats. - Sophisticated agentic AI to automate triage and investigation at speed and scale - Recognized as a Leader in the 2025 Gartner® Magic Quadrant™ for NDR - Over 10,000 customers globally

**Average Rating:** 4.5/5.0

**Total Reviews:** 44

#### How Do G2 Users Rate Darktrace / NETWORK?

- **Metadata Enrichment:** 9.3/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.2/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 9.3/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.3/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Darktrace / NETWORK?

- **Seller:** [Darktrace](https://www.g2.com/sellers/darktrace)
- **Company Website:** www.darktrace.com
- **Year Founded:** 2013
- **HQ Location:** Cambridgeshire, England
- **Twitter:** @Darktrace  
18,177 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=135b6c23b3a9e309b159fca717d84aafed8cc711e65da3de0cae9184091cd6d3&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F5013440%2F&secure%5Burl_type%5D=linkedin_company_website)  
2,607 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Financial Services, Information Technology and Services
- **Company Size:** 60% Medium, 32% Large

#### What Do G2 Reviewers Say About Darktrace / NETWORK?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive monitoring** capabilities of Darktrace, enhancing efficiency and confidence in network security management.
- Users appreciate the **self-learning AI technology** of Darktrace/Network for its exceptional threat detection and real-time response.
- Users highlight the **rapid threat detection** capabilities of Darktrace, boosting network security and user confidence.
- Users commend the **responsive customer support** of Darktrace, enhancing their learning and adoption experience effectively.
- Users value the **autonomous cyber AI** of Darktrace, effectively enhancing proactive cybersecurity with real-time threat detection.

##### Cons

- Users find a significant **learning curve** with Darktrace as AI generates many alerts during the initial setup phase.
- Users find the product **expensive** , particularly affecting smaller organizations with limited security budgets and high implementation costs.
- Users report **alert issues** with Darktrace, noting frequent false positives and a challenging initial learning period.
- Users find the **complex setup** of Darktrace challenging, needing strong skills and significant resources for effective management.
- Users report occasional **false positives** requiring IT intervention, impacting the overall efficiency of Darktrace's network monitoring.

#### What Are Recent G2 Reviews of Darktrace / NETWORK?

**["Darktrace Network: Intuitive, AI-Driven Cybersecurity with Real-Time Threat Detection"](https://www.g2.com/survey_responses/darktrace-network-review-12679592)**

**Rating:** 5.0/5.0 stars

_— Daniel S._

[Read full review](https://www.g2.com/survey_responses/darktrace-network-review-12679592)

**["AI-Powered Security, Needs a Friendlier UI"](https://www.g2.com/survey_responses/darktrace-network-review-12984323)**

**Rating:** 5.0/5.0 stars

_— Verified User_

[Read full review](https://www.g2.com/survey_responses/darktrace-network-review-12984323)

#### What Are G2 Users Discussing About Darktrace / NETWORK?

- [How does Darktrace collect data?](https://www.g2.com/discussions/how-does-darktrace-collect-data)
- [What is Darktrace and how it works?](https://www.g2.com/discussions/what-is-darktrace-and-how-it-works)
- [What can Darktrace do?](https://www.g2.com/discussions/what-can-darktrace-do)
- [What is Darktrace Antigena network?](https://www.g2.com/discussions/what-is-darktrace-antigena-network)
- [What is Darktrace Enterprise immune system?](https://www.g2.com/discussions/what-is-darktrace-enterprise-immune-system) - 1 comment

### [Cortex XDR](https://www.g2.com/products/palo-alto-networks-cortex-xdr/reviews)

Cortex XDR is the industry’s first extended detection and response platform that stops modern attacks by integrating data from any source. With Cortex XDR, you can harness the power of AI, analytics and rich data to detect stealthy threats. Your SOC team can cut through the noise and focus on what matters most with intelligent alert grouping and incident scoring. Cross-data insights accelerate investigations, so you can streamline incident response and recovery. Cortex XDR delivers peace of mind with best-in-class endpoint protection that achieved the highest combined protection and detection scores in the MITRE ATT&CK® round 3 evaluation. The Cortex XDR platform collects and analyzes all data, so you can gain complete visibility and holistic protection to secure what’s next.

**Average Rating:** 4.5/5.0

**Total Reviews:** 77

#### How Do G2 Users Rate Cortex XDR?

- **Metadata Enrichment:** 10.0/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.6/10 (Category avg: 8.9/10)
- **Network Visibility:** 10.0/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Cortex XDR?

- **Seller:** [Palo Alto Networks](https://www.g2.com/sellers/palo-alto-networks)
- **Company Website:** www.paloaltonetworks.com
- **Year Founded:** 2005
- **HQ Location:** Santa Clara, CA
- **Twitter:** @PaloAltoNtwks  
128,951 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=283fa006a7b7db5565e608e4d1bc1dafae45bdf4b312f2cd5bb208ac9271f81d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F30086%2F&secure%5Burl_type%5D=linkedin_company_website)  
22,313 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Information Technology and Services
- **Company Size:** 41% Medium, 38% Large

#### What Do G2 Reviewers Say About Cortex XDR?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **important alert notifications** from Cortex XDR, which enhance security without overwhelming them.
- Users appreciate the **simplicity and manageability** of Cortex XDR, finding it easy to navigate and utilize effectively.
- Users love the **unique features** of Cortex XDR, especially its effective threat detection without compromising system speed.
- Users praise the **unified detection and response capability** of Cortex XDR, enhancing threat investigation efficiency and accuracy.
- Users value the **unified detection and response capability** of Cortex XDR for swift and precise threat investigations.

##### Cons

- Users find **limited features** in Cortex XDR, with restrictions affecting core OS functionalities and usability issues on lower-end systems.
- Users experience a **noticeable performance impact** on lower-end systems with the Cortex XDR agent installed.
- Users face **compatibility issues** with Cortex XDR, restricting core functionalities and software installations on their machines.
- Users find the **system complexity** challenging, often struggling with management and a steep learning curve.
- Users find the **complex management** of Cortex XDR challenging due to its steep learning curve and customization difficulties.

#### What Are Recent G2 Reviews of Cortex XDR?

**["A robust XDR platform which simplifies Threat Investigation"](https://www.g2.com/survey_responses/cortex-xdr-review-13174259)**

**Rating:** 5.0/5.0 stars

_— Ajeet U._

[Read full review](https://www.g2.com/survey_responses/cortex-xdr-review-13174259)

**["Solid detection depth, but plan for a learning curve"](https://www.g2.com/survey_responses/cortex-xdr-review-13173649)**

**Rating:** 4.5/5.0 stars

_— Joshuva A._

[Read full review](https://www.g2.com/survey_responses/cortex-xdr-review-13173649)

#### What Are G2 Users Discussing About Cortex XDR?

- [What is an advantage of Cortex XDR cloud based analysis?](https://www.g2.com/discussions/what-is-an-advantage-of-cortex-xdr-cloud-based-analysis)
- [How does cortex XDR use machine learning?](https://www.g2.com/discussions/how-does-cortex-xdr-use-machine-learning)
- [What is Cortex XDR?](https://www.g2.com/discussions/what-is-cortex-xdr) - 1 comment

### [ExtraHop](https://www.g2.com/products/extrahop/reviews)

ExtraHop is the cybersecurity partner enterprises trust to reveal cyber risk and build business resilience. The ExtraHop RevealX platform for network detection and response and network performance management uniquely delivers the instant visibility and unparalleled decryption capabilities organizations need to expose the cyber risks and performance issues that other tools can’t see. When organizations have full network transparency with ExtraHop, they can investigate smarter, stop threats faster, and keep operations running. RevealX deploys on premises or in the cloud. It addresses the following use cases: - Ransomware - Zero trust - Software supply chain attacks - Lateral movement and C2 communication - Security hygiene - Network and Application Performance Management - IDS - Forensics and more A few of our differentiators: Continuous and on-demand PCAP: Full packet processing is superior to NetFlow and yields higher quality detections. Strategic decryption across a variety of protocols, including SSL/TLS, MS-RPC, WinRM, and SMBv3, gives you better visibility into early-stage threats hiding in encrypted traffic as they attempt to move laterally across your network. Protocol coverage: RevealX decodes more than 70 network protocols. Cloud-scale machine learning: Rather than relying on limited "on-box" compute power for analysis and detections, RevealX uses sophisticated cloud-hosted and cloud-scale machine learning workloads to identify suspicious behavior in real time and create high-fidelity alerts. ExtraHop was named a Leader in The Forrester Wave™: Network Analysis and Visibility, Q2 2023. Key Technology Integration and Go-to-Market Partners: CrowdStrike: RevealX integrates with CrowdStrike Falcon® LogScale, Falcon Insight XDR, Falcon Threat Graph, and Falcon Intelligence. Splunk SOAR AWS Google Cloud Security Founded in 2007, ExtraHop is privately held and headquartered in Seattle, Wash. To learn more, visit www.extrahop.com.

**Average Rating:** 4.6/5.0

**Total Reviews:** 68

#### How Do G2 Users Rate ExtraHop?

- **Metadata Enrichment:** 9.1/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 9.3/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.8/10 (Category avg: 8.9/10)

#### Who Is the Company Behind ExtraHop?

- **Seller:** [ExtraHop Networks](https://www.g2.com/sellers/extrahop-networks)
- **Year Founded:** 2007
- **HQ Location:** Seattle, Washington
- **Twitter:** @ExtraHop  
10,695 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=03b8d5e060cbe70fe5e5509ca10b34638477d3e3220671072d97532dbf9392a8&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fextrahop-networks%2F&secure%5Burl_type%5D=linkedin_company_website)  
761 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Hospital & Health Care, Transportation/Trucking/Railroad
- **Company Size:** 69% Large, 26% Medium

#### What Do G2 Reviewers Say About ExtraHop?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **all-in-one solution** of ExtraHop, enabling complete network visibility and excellent support from knowledgeable teams.
- Users value the **comprehensive monitoring** provided by ExtraHop, enabling detailed traffic analysis and enhanced network visibility.
- Users find **Easy Deployment** of ExtraHop to be seamless, enhancing network visibility with excellent support from the Customer Success teams.
- Users value the **responsive support** from ExtraHop's knowledgeable Customer Success teams, enhancing their overall experience.

#### What Are Recent G2 Reviews of ExtraHop?

**["One stop shop for network detections and notifications Easy to use and easy to understand."](https://www.g2.com/survey_responses/extrahop-review-9197231)**

**Rating:** 5.0/5.0 stars

_— Jeff H._

[Read full review](https://www.g2.com/survey_responses/extrahop-review-9197231)

**["Complete visibility on network activity"](https://www.g2.com/survey_responses/extrahop-review-10580190)**

**Rating:** 5.0/5.0 stars

_— Verified User in Insurance_

[Read full review](https://www.g2.com/survey_responses/extrahop-review-10580190)

#### What Are G2 Users Discussing About ExtraHop?

- [Is ExtraHop a startup?](https://www.g2.com/discussions/is-extrahop-a-startup)
- [What is ExtraHop appliance?](https://www.g2.com/discussions/what-is-extrahop-appliance)
- [Is ExtraHop a SIEM?](https://www.g2.com/discussions/is-extrahop-a-siem)
- [What is ExtraHop?](https://www.g2.com/discussions/what-is-extrahop)

### [ManageEngine ADAudit Plus](https://www.g2.com/products/manageengine-adaudit-plus/reviews)

ADAudit Plus is a UBA-driven auditor that helps keep your AD, Azure AD, file systems (including Windows, NetApp, EMC, Synology, Hitachi, and Huawei), Windows servers, and workstations secure and compliant. ADAudit Plus transforms raw and noisy event log data into real-time reports and alerts, enabling you to get full visibility into activities happening across your Windows Server ecosystem in just a few clicks. More than 10,000 organizations across the world trust ADAudit Plus to: 1. Instantly notify them about changes in their Windows Server environments. 2. Continuously track Windows user logon activity. 3. Monitor the active and idle time spent by employees at their workstations. 4. Detect and troubleshoot AD account lockouts. 5. Provide a consolidated audit trail of privileged user activities across their domains. 6. Track changes and sign-ins in Azure AD. 7. Audit file accesses across Windows, NetApp, EMC, Synology, Hitachi, and Huawei file systems. 8. Monitor file integrity across local files residing on Windows systems. 9. Mitigate insider threats by leveraging UBA and response automation. 10. Generate audit-ready compliance reports for SOX, the GDPR, and other IT mandates.

**Average Rating:** 4.6/5.0

**Total Reviews:** 59

#### How Do G2 Users Rate ManageEngine ADAudit Plus?

- **Metadata Enrichment:** 5.8/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.3/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 6.7/10 (Category avg: 8.6/10)
- **Network Visibility:** 5.8/10 (Category avg: 8.9/10)

#### Who Is the Company Behind ManageEngine ADAudit Plus?

- **Seller:** [Zoho](https://www.g2.com/sellers/zoho-b00ca9d5-bca8-41b5-a8ad-275480841704)
- **Year Founded:** 1996
- **HQ Location:** Austin, TX
- **Twitter:** @Zoho  
137,880 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=9c8e45ddb296c32c6c5597ef9ba945c94562c57624f7bd1dcf1a9e9931f71578&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F38373%2F&secure%5Burl_type%5D=linkedin_company_website)  
30,766 employees on LinkedIn®
- **Phone:** +1 (888) 900-9646 

#### Who Uses This Product?

- **Top Industries:** Hospital & Health Care, Information Technology and Services
- **Company Size:** 59% Medium, 32% Large

#### What Do G2 Reviewers Say About ManageEngine ADAudit Plus?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **depth of reporting** in ADAudit Plus, enhancing visibility into AD environments with prebuilt options.
- Users value the **intuitive dashboard usability** of ADAudit Plus, offering easy navigation and comprehensive reporting options.
- Users appreciate the **easy setup and extensive reporting options** in ManageEngine ADAudit Plus for effective monitoring.
- Users value the **dashboard design** of ADAudit Plus for its comprehensive overview and detailed reporting options.
- Users value the **intuitive dashboard and extensive reporting options** in ADAudit Plus for effective Active Directory management.

##### Cons

- Users find the **limited alert levels** insufficient for fine-tuning notifications, despite helpful reporting options and search features.
- Users find the **data overload** from numerous reporting options overwhelming, making it hard to locate specific reports.
- Users find the product **expensive** , which impacts their overall satisfaction despite its features and capabilities.
- Users experience **false positives** with alerts, which could be improved by more granularity in severity levels.
- Users are frustrated with the **high resource usage** of ManageEngine ADAudit Plus, impacting system performance significantly.

#### What Are Recent G2 Reviews of ManageEngine ADAudit Plus?

**["Easy Setup, Powerful Reporting, and Great Value"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)**

**Rating:** 4.5/5.0 stars

_— Ryan A._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-12999020)

**["Great Tool for Active Directory Auditing and Investigations"](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)**

**Rating:** 5.0/5.0 stars

_— Jose R._

[Read full review](https://www.g2.com/survey_responses/manageengine-adaudit-plus-review-13001820)

#### What Are G2 Users Discussing About ManageEngine ADAudit Plus?

- [What does AD audit do?](https://www.g2.com/discussions/what-does-ad-audit-do)
- [Is Ad audit plus a SIEM?](https://www.g2.com/discussions/is-ad-audit-plus-a-siem)
- [What is ManageEngine Audit Plus?](https://www.g2.com/discussions/what-is-manageengine-audit-plus)
- [What does ADAudit plus do?](https://www.g2.com/discussions/what-does-adaudit-plus-do)

### [Rapid7 Next-Gen SIEM](https://www.g2.com/products/rapid7-next-gen-siem/reviews)

Rapid7 InsightIDR is a SaaS SIEM for modern threat detection and response. InsightIDR enables security analysts to work more efficiently and effectively, by unifying diverse data sources, providing early and reliable out of the box detections, and delivering rich visual investigations and automation to expedite response. With a lightweight cloud deployment and intuitive UI and onboarding experience, InsightIDR customers recognize an accelerated return on their investment and start seeing valuable insights from Day 1. With InsightIDR, teams can advance their threat detection and response program without adding headcount.

**Average Rating:** 4.4/5.0

**Total Reviews:** 69

#### How Do G2 Users Rate Rapid7 Next-Gen SIEM?

- **Metadata Enrichment:** 8.3/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.9/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 8.0/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.0/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Rapid7 Next-Gen SIEM?

- **Seller:** [Rapid7](https://www.g2.com/sellers/rapid7)
- **Year Founded:** 2000
- **HQ Location:** Boston, MA
- **Twitter:** @rapid7  
124,405 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=04bdb542ee8372d372b62e305f57e5c7aefbd59efac3d6831f78fcc71f4f819c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F39624%2F&secure%5Burl_type%5D=linkedin_company_website)  
3,274 employees on LinkedIn®
- **Ownership:** NASDAQ:RPD

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer Software
- **Company Size:** 67% Medium, 30% Large

#### What Do G2 Reviewers Say About Rapid7 Next-Gen SIEM?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Rapid7 Next-Gen SIEM, facilitating effortless log management and integration.
- Users appreciate the **easy integrations** of Rapid7 Next-Gen SIEM, enhancing compatibility with various third-party tools effortlessly.
- Users value the **easy integrations** with third-party tools, enhancing functionality and streamlining security management.
- Users appreciate the **effective threat detection** capabilities of Rapid7 Next-Gen SIEM, enhancing investigation speed and efficiency.
- Users appreciate the **visibility** of Rapid7 Next-Gen SIEM, enabling easy search and understanding of log data.

##### Cons

- Users find the **limited features** of Rapid7 Next-Gen SIEM restrictive compared to larger competitors, hindering alert creation.
- Users find the **alerting capabilities limited** , making it challenging to create timely and effective alerts.
- Users find the **alert management limited** , making it challenging to create effective and timely alerts.
- Users find the **difficult customization** process frustrating, especially when creating alerts and setting patterns.
- Users find the **difficult setup** of Rapid7 Next-Gen SIEM frustrating, especially for creating alerts and patterns.

#### What Are Recent G2 Reviews of Rapid7 Next-Gen SIEM?

**["Intuitive, High-Performance SIEM with Great Support and Cost-Effective Value"](https://www.g2.com/survey_responses/rapid7-next-gen-siem-review-12711350)**

**Rating:** 4.5/5.0 stars

_— Nihal J._

[Read full review](https://www.g2.com/survey_responses/rapid7-next-gen-siem-review-12711350)

**["Fast, Easy Queries with a Powerful Plain-Text-to-LEQL AI Feature"](https://www.g2.com/survey_responses/rapid7-next-gen-siem-review-13140538)**

**Rating:** 4.0/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/rapid7-next-gen-siem-review-13140538)

#### What Are G2 Users Discussing About Rapid7 Next-Gen SIEM?

- [What is InsightIDR used for?](https://www.g2.com/discussions/what-is-insightidr-used-for)
- [What is rapid7 InsightVM?](https://www.g2.com/discussions/what-is-rapid7-insightvm)
- [Is rapid7 a SIEM?](https://www.g2.com/discussions/is-rapid7-a-siem)
- [What is rapid7 used for?](https://www.g2.com/discussions/insightidr-what-is-rapid7-used-for)
- [What is InsightIDR?](https://www.g2.com/discussions/what-is-insightidr)

### [Verizon Network Detection and Response](https://www.g2.com/products/verizon-network-detection-and-response/reviews)

Network Detection and Response is a cloud-delivered network security platform that helps you take action against threats and identify future threats with speed, accuracy and scale.

**Average Rating:** 3.6/5.0

**Total Reviews:** 16

#### How Do G2 Users Rate Verizon Network Detection and Response?

- **Metadata Enrichment:** 8.3/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.0/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 8.5/10 (Category avg: 8.6/10)
- **Network Visibility:** 8.7/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Verizon Network Detection and Response?

- **Seller:** [Verizon](https://www.g2.com/sellers/verizon)
- **Year Founded:** 1983
- **HQ Location:** Basking RIdge, NJ
- **Twitter:** @Verizon  
1,486,564 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=11cabcb908a83f580e768918da49ce0dfbf7d794aa8582ec174ea41463d1a184&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F1103%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,704 employees on LinkedIn®
- **Ownership:** NYSE:VZ

#### Who Uses This Product?

- **Company Size:** 44% Small, 31% Large

#### What Are Recent G2 Reviews of Verizon Network Detection and Response?

**["Verizon Network Detection and Response: Very Reliable Tool for Threat Detection and Instant Response"](https://www.g2.com/survey_responses/verizon-network-detection-and-response-review-9215039)**

**Rating:** 5.0/5.0 stars

_— Sigit P._

[Read full review](https://www.g2.com/survey_responses/verizon-network-detection-and-response-review-9215039)

**["An Effective Network Detection and Response Solution"](https://www.g2.com/survey_responses/verizon-network-detection-and-response-review-9549778)**

**Rating:** 4.5/5.0 stars

_— Jack M._

[Read full review](https://www.g2.com/survey_responses/verizon-network-detection-and-response-review-9549778)

### [Heimdal](https://www.g2.com/products/heimdal/reviews)

Accommodate all your cybersecurity needs under one convenient roof with the Heimdal® Unified Cybersecurity Platform. Our cybersecurity solutions can be used as standalone products or integrated into one another as part of a cohesive and unified XDR platform. Whether you’re a reseller, distributor, MSSP, or an organization committed to bolstering your online security, we provide an array of cutting-edge products to make your mission smoother. Heimdal® is a fast-growing cybersecurity company focused on continuous technological innovation. Since its establishment in 2014 in Copenhagen, based on the winning idea of CTF World Champions, Heimdal has experienced spectacular growth by proactively building products that anticipate threatscape trends. The company offers a multi-layeredand unified security suite that combines threat prevention, patch and asset management, endpoint rights management, antivirus and mail security which together secure customers against cyberattacks and keep critical information and intellectual property safe. Heimdal has been recognized as a thought leader in the industry and has won multiple international awards both for its solutions and for its educational content creation. The Heimdal line of products currently consists of 10 products and 2 services. The former category encompasses DNS Security for Endpoints & Network, Patch & Asset Management, Privileged Access Management, Application Control, Next-Gen Endpoint Antivirus, Ransomware Encryption Protection, Email Security, Email Fraud Prevention, and Remote Desktop. The latter is represented by Endpoint Detection & Response, as well as eXtended Detection & Response, or EDR and XDR for short. Currently, Heimdal’s cybersecurity solutions are deployed in more than 45 countries and supported regionally from offices in 15+ countries, by 175+ highly qualified specialists. Heimdal is ISAE 3000 certified and secures more than 2 million endpoints for over 10,000 companies. The company supports its partners without concessions on the basis of predictability and scalability. The common goal is to create a sustainable ecosystem and a strategic partnership.

**Average Rating:** 4.4/5.0

**Total Reviews:** 76

#### How Do G2 Users Rate Heimdal?

- **Quality of Support:** 9.5/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Heimdal?

- **Seller:** [Heimdal®](https://www.g2.com/sellers/heimdal)
- **Company Website:** heimdalsecurity.com
- **Year Founded:** 2014
- **HQ Location:** Copenhagen, Denmark
- **Twitter:** @HeimdalSecurity  
5,086 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=4243d36e84d7125b091c9f78c8d63c35f03d88a7252b4c7df5584fd2fa0a49c1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fheimdal-security%2F&secure%5Burl_type%5D=linkedin_company_website)  
277 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Computer & Network Security, Construction
- **Company Size:** 58% Medium, 27% Small

#### What Do G2 Reviewers Say About Heimdal?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **simple and straightforward user interface** of Heimdal, making it accessible for entry-level personnel.
- Users commend Heimdal's **exceptional customer support** , noting prompt responses and professional assistance that often exceeds expectations.
- Users value the **robust security** of Heimdal, noting its reliability and user-friendly interface for effective defense.
- Users praise Heimdal for its **reliable security solutions** , delivering consistent performance and dependable support for their needs.
- Users value Heimdal for its **reliable security solutions** and responsive 24/7 support, enhancing user confidence.

##### Cons

- Users face significant **access issues** with Heimdal's admin portal, finding navigation complex and essential resources hard to locate.
- Users find the **complex interface** of Heimdal frustrating, struggling with navigation and accessing essential features.
- Users find the **limited customization options** frustrating, particularly in navigating the complex admin portal and UI.
- Users find Heimdal **not user-friendly** due to its complex admin portal and difficult navigation for essential tasks.
- Users report challenges with **poor customer support** during initial setup, affecting overall experience and efficiency.

#### What Are Recent G2 Reviews of Heimdal?

**["Clear Patch Management and Endpoint Visibility That Builds Compliance Confidence"](https://www.g2.com/survey_responses/heimdal-review-13056558)**

**Rating:** 4.5/5.0 stars

_— Verified User in Airlines/Aviation_

[Read full review](https://www.g2.com/survey_responses/heimdal-review-13056558)

**["Automated patching makes life easier, but remote desktop needs work"](https://www.g2.com/survey_responses/heimdal-review-12879665)**

**Rating:** 5.0/5.0 stars

_— Kris B._

[Read full review](https://www.g2.com/survey_responses/heimdal-review-12879665)

### [Cisco Secure Network Analytics](https://www.g2.com/products/cisco-secure-network-analytics/reviews)

Stealthwatch is the only solution that detects threats across your private network, public clouds, and even in encrypted traffic.

**Average Rating:** 4.4/5.0

**Total Reviews:** 31

#### How Do G2 Users Rate Cisco Secure Network Analytics?

- **Metadata Enrichment:** 8.9/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.9/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 10.0/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.7/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Cisco Secure Network Analytics?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 52% Large, 33% Small

#### What Are Recent G2 Reviews of Cisco Secure Network Analytics?

**["Great network analytics tool by Cisco"](https://www.g2.com/survey_responses/cisco-secure-network-analytics-review-8647472)**

**Rating:** 4.5/5.0 stars

_— Verified User in Information Technology and Services_

[Read full review](https://www.g2.com/survey_responses/cisco-secure-network-analytics-review-8647472)

**["Cisco Secure Network Review"](https://www.g2.com/survey_responses/cisco-secure-network-analytics-review-8728642)**

**Rating:** 5.0/5.0 stars

_— Harsh P._

[Read full review](https://www.g2.com/survey_responses/cisco-secure-network-analytics-review-8728642)

### [NetWitness Platform](https://www.g2.com/products/netwitness-platform/reviews)

NetWitness is a comprehensive threat detection, investigation and response platform that combines visibility, analytics, insight, and automation into a single solution. It collects and analyzes data across all capture points (logs, packets, netflow, endpoint and IoT) and computing platforms (physical, virtual and cloud), enriching data with threat intelligence and business context.

**Average Rating:** 3.9/5.0

**Total Reviews:** 23

#### How Do G2 Users Rate NetWitness Platform?

- **Metadata Enrichment:** 8.3/10 (Category avg: 8.5/10)
- **Quality of Support:** 7.6/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 6.7/10 (Category avg: 8.6/10)
- **Network Visibility:** 8.3/10 (Category avg: 8.9/10)

#### Who Is the Company Behind NetWitness Platform?

- **Seller:** [NetWitness](https://www.g2.com/sellers/netwitness)
- **Year Founded:** 1997
- **HQ Location:** Bedford, MA
- **Twitter:** @Netwitness  
1,621 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=8ae249a18b34c6a0f632d7c0953c6bcf05c3692f1f32add16a5d89d58de98cdb&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnetwitness-platform%2F&secure%5Burl_type%5D=linkedin_company_website)  
194 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 54% Large, 33% Medium

#### What Do G2 Reviewers Say About NetWitness Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users value the **centralized management** of NetWitness Platform for its comprehensive threat hunting capabilities across various data sources.
- Users appreciate the **converged capabilities** of NetWitness Platform, which streamline threat hunting and reduce tool sprawl.
- Users appreciate the **packet capture and replay capabilities** of NetWitness Platform, essential for thorough forensic investigations.
- Users appreciate the **ability to capture full network packets** , enhancing their deep forensic investigation capabilities.
- Users value the **centralized view** offered by the Management Console, enhancing efficiency in threat hunting across diverse environments.

##### Cons

- Users find the **complex implementation** of NetWitness Platform challenging, needing significant technical expertise for deployment and upgrades.
- Users find the **initial deployment and upgrades complicated** , often necessitating significant technical expertise and leading to instability.
- Users find the **initial setup complex** , often needing extensive technical expertise, and face challenges during upgrades.
- Users find the **deployment difficulties** of NetWitness Platform challenging, needing extensive expertise and facing upgrade instability.
- Users find the **expertise required** for initial deployment and upgrades complicates their experience with NetWitness Platform.

#### What Are Recent G2 Reviews of NetWitness Platform?

**["All-in-One Security Console for Centralized Threat Hunting"](https://www.g2.com/survey_responses/netwitness-platform-review-12381089)**

**Rating:** 5.0/5.0 stars

_— Verified User in Information Services_

[Read full review](https://www.g2.com/survey_responses/netwitness-platform-review-12381089)

**["A Powerhouse in Endpoint, Network, and SIEM Integration."](https://www.g2.com/survey_responses/netwitness-platform-review-11524038)**

**Rating:** 4.0/5.0 stars

_— pushpendra Y._

[Read full review](https://www.g2.com/survey_responses/netwitness-platform-review-11524038)

#### What Are G2 Users Discussing About NetWitness Platform?

- [What is one of the biggest differentiators for RSA NetWitness platform?](https://www.g2.com/discussions/what-is-one-of-the-biggest-differentiators-for-rsa-netwitness-platform)
- [What types of data can the RSA NetWitness platform capture and process?](https://www.g2.com/discussions/what-types-of-data-can-the-rsa-netwitness-platform-capture-and-process)
- [What is NetWitness used for?](https://www.g2.com/discussions/what-is-netwitness-used-for) - 1 comment
- [What does RSA NetWitness do?](https://www.g2.com/discussions/what-does-rsa-netwitness-do)

### [Blumira Automated Detection & Response](https://www.g2.com/products/blumira-automated-detection-response/reviews)

Blumira is an integrated security operations platform built for growing teams and the partners supporting them to gain complete visibility into their environment, identify and address risk faster, and deliver advanced security and compliance. The platform includes: - Managed Detections for automated threat hunting to identify attacks early - AI Investigation with 98.5% accurate, human-in-the-loop triage validated against real cases - Rapid Response with automation and 1-click actions to contain and block threats immediately - One Year of Data Retention with unlimited log ingestion to satisfy compliance requirements - Advanced Reporting and dashboards for forensics and easy investigation - Endpoint & Identity Protection (EDR/ITDR) for real-time remediation across devices and users - 24/7 Security Operations support for critical priority issues

**Average Rating:** 4.6/5.0

**Total Reviews:** 122

#### How Do G2 Users Rate Blumira Automated Detection & Response?

- **Metadata Enrichment:** 6.7/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.5/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 8.9/10 (Category avg: 8.6/10)
- **Network Visibility:** 7.9/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Blumira Automated Detection & Response?

- **Seller:** [Blumira](https://www.g2.com/sellers/blumira)
- **Company Website:** www.blumira.com
- **Year Founded:** 2018
- **HQ Location:** Ann Arbor, Michigan
- **Twitter:** @blumira  
1 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=2a04d201c0abee0744509c17e4beed4ccbdbde532e5d35f04981851a7ee48cfa&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fblumira%2F&secure%5Burl_type%5D=linkedin_company_website)  
67 employees on LinkedIn®

#### Who Uses This Product?

- **Who Uses This:** IT Manager
- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 51% Medium, 36% Small

#### What Do G2 Reviewers Say About Blumira Automated Detection & Response?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **ease of use** of Blumira, noting the quick setup and responsive support team.
- Users value the **responsive and personalized support** from Blumira's SOC team, enhancing their overall experience significantly.
- Users find the **setup process incredibly easy** , with intuitive integration and immediate alert functionalities boosting security management.
- Users value the **reliable real-time alerting** of Blumira, enhancing their experience without overwhelming them with unnecessary notifications.
- Users value the **reliable real-time alerting** of Blumira, appreciating its clarity and ease of management.

##### Cons

- Users find the **limited customization** in detection filters a drawback, despite helpful support for creating custom detections.
- Users face issues with **false positives** from alerts, which can disrupt business functions and waste valuable time.
- Users find the **pricing model inflexible and expensive** , making it difficult to meet their budgetary needs.
- Users face challenges with **false positives** in Blumira, leading to frustration and wasted time on repetitive alerts.
- Users note the **insufficient information** available on data intake, making search and usability challenging.

#### What Are Recent G2 Reviews of Blumira Automated Detection & Response?

**["Breeze From Sales to Onboarding With an Intuitive, Easy-to-Configure UI"](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)**

**Rating:** 5.0/5.0 stars

_— Blake C._

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-12984186)

**["A well-rounded detection system with fantastic support"](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)**

**Rating:** 5.0/5.0 stars

_— Jeremy A._

[Read full review](https://www.g2.com/survey_responses/blumira-automated-detection-response-review-10479545)

#### What Are G2 Users Discussing About Blumira Automated Detection & Response?

- [What are the benefits and drawbacks of using Blumira for threat detection?](https://www.g2.com/discussions/what-are-the-benefits-and-drawbacks-of-using-blumira-for-threat-detection)
- [What is cloud SIEM?](https://www.g2.com/discussions/what-is-cloud-siem)
- [What does the term Siem stand for?](https://www.g2.com/discussions/what-does-the-term-siem-stand-for)
- [What does Blumira do?](https://www.g2.com/discussions/what-does-blumira-do)
- [What is Blumira automated detection & response?](https://www.g2.com/discussions/what-is-blumira-automated-detection-response)

### [Corelight](https://www.g2.com/products/corelight/reviews)

Corelight's Open Network Detection and Response (NDR) Platform improves network detection coverage, accelerates incident response, and reduces operational costs by consolidating NDR, intrusion detection (IDS), and PCAP functionality in a single solution and by providing security analysts with machine learning-assisted investigations and one-click-pivots from prioritized alerts to the evidence needed to investigate and remediate them. Network Detection and Response platforms monitor and analyze network traffic, delivering telemetry into existing SIEM, XDR, or SaaS-based solutions. Corelight’s platform is unique because our detections and visibility engineering are community driven—with continuous content creation from Zeek®, Suricata IDS, and other Intel communities. And our integration with CrowdStrike XDR enables cross platform (EDR+NDR) analytics. This provides you with the most complete network visibility, powerful analytics, and threat hunting capabilities, and accelerates investigation across your entire kill chain. Corelight also delivers a comprehensive suite of network security analytics that help organizations identify more than 75 adversarial TTPs across the MITRE ATT&CK® spectrum including Exfiltration, Command and Control (C2), and Lateral Movement. These detections reveal known and unknown threats via hundreds of unique insights and alerts across machine learning, behavioral analysis, and signature-based approaches. CORELIGHT PRODUCTS + SERVICES Open NDR Platform Appliance, Cloud, Software, Virtual and SaaS Sensors IDS Fleet Manager Investigator Threat Hunting Platform Smart PCAP Corelight Training CERTIFICATIONS FIPS 140-2

**Average Rating:** 4.6/5.0

**Total Reviews:** 20

#### How Do G2 Users Rate Corelight?

- **Metadata Enrichment:** 8.6/10 (Category avg: 8.5/10)
- **Quality of Support:** 9.1/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 9.0/10 (Category avg: 8.6/10)
- **Network Visibility:** 9.1/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Corelight?

- **Seller:** [Corelight](https://www.g2.com/sellers/corelight)
- **Year Founded:** 2013
- **HQ Location:** San Francisco, CA
- **Twitter:** @corelight\_inc  
4,227 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=93887355efbb4d86e0cb68a5d54ea5b7289fd77ba26178d31fc6a761d658f522&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcorelight&secure%5Burl_type%5D=linkedin_company_website)  
474 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services, Computer & Network Security
- **Company Size:** 50% Large, 50% Medium

#### What Do G2 Reviewers Say About Corelight?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise Corelight for its **comprehensive security** features, effectively detecting threats and simplifying network event analysis.
- Users value Corelight for its **effective network telemetry** , simplifying the detection of security threats and vulnerabilities.
- Users value the **great network telemetry** of Corelight, enhancing security event visibility and threat detection efficiency.
- Users commend Corelight for its **exceptional network security** capabilities, effectively detecting threats and simplifying event analysis.
- Users appreciate the **robust security features** of Corelight, enabling effective detection of network threats and smooth operation.

##### Cons

- Users find Corelight's **complex coding** challenging, making it difficult for novice security analysts to navigate effectively.
- Users find the **complex configuration** of Corelight challenging, especially for novice security analysts requiring specialized knowledge.
- Users find Corelight's setup and management **complex and not suitable for novice security analysts** , requiring specialized knowledge and costly training.
- Users find the **complex setup** of Corelight challenging, especially for novice security analysts needing specialized knowledge.
- Users find the **learning curve challenging** , particularly for novice security analysts needing specialized training for effective use.

#### What Are Recent G2 Reviews of Corelight?

**["Best NDR solution Guardians of Network"](https://www.g2.com/survey_responses/corelight-review-8692252)**

**Rating:** 5.0/5.0 stars

_— Aman P._

[Read full review](https://www.g2.com/survey_responses/corelight-review-8692252)

**["Corelight the Threat Hunters"](https://www.g2.com/survey_responses/corelight-review-11196044)**

**Rating:** 4.5/5.0 stars

_— Andy V._

[Read full review](https://www.g2.com/survey_responses/corelight-review-11196044)

### [Cisco Adaptive Wireless IPS Software](https://www.g2.com/products/cisco-adaptive-wireless-ips-software/reviews)

Cisco Adaptive Wireless Intrusion Prevention System (IPS) offers advanced network security for dedicated monitoring and detection of wireless network anomalies, unauthorized access, and RF attacks. Fully integrated with the Cisco Unified Wireless Network, this solution delivers integrated visibility and control across the network, without the need for an overlay solution.

**Average Rating:** 4.3/5.0

**Total Reviews:** 16

#### How Do G2 Users Rate Cisco Adaptive Wireless IPS Software?

- **Metadata Enrichment:** 8.5/10 (Category avg: 8.5/10)
- **Quality of Support:** 8.2/10 (Category avg: 8.9/10)
- **Multi-Network Monitoring:** 8.3/10 (Category avg: 8.6/10)
- **Network Visibility:** 8.7/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Cisco Adaptive Wireless IPS Software?

- **Seller:** [Cisco](https://www.g2.com/sellers/cisco)
- **Year Founded:** 1984
- **HQ Location:** San Jose, CA
- **Twitter:** @Cisco  
720,366 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=476aeabc5a712d049453edd5c54ea0318890d9e60d93782e37fe028224df1cbd&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fcisco%2F&secure%5Burl_type%5D=linkedin_company_website)  
95,545 employees on LinkedIn®
- **Ownership:** NASDAQ:CSCO

#### Who Uses This Product?

- **Company Size:** 63% Medium, 25% Large

#### What Are Recent G2 Reviews of Cisco Adaptive Wireless IPS Software?

**["Securing Wireless Networks with Cisco Adaptive Wireless IPS"](https://www.g2.com/survey_responses/cisco-adaptive-wireless-ips-software-review-9025295)**

**Rating:** 4.5/5.0 stars

_— umesh s._

[Read full review](https://www.g2.com/survey_responses/cisco-adaptive-wireless-ips-software-review-9025295)

**["Cisco Adaptive Wireless IPS Software."](https://www.g2.com/survey_responses/cisco-adaptive-wireless-ips-software-review-9051686)**

**Rating:** 5.0/5.0 stars

_— Varun Preet S._

[Read full review](https://www.g2.com/survey_responses/cisco-adaptive-wireless-ips-software-review-9051686)

- &lsaquo; Prev‹ Prev
- 1
- [2](/categories/network-detection-and-response-ndr?order=g2_score&page=2#product-list)
- [3](/categories/network-detection-and-response-ndr?order=g2_score&page=3#product-list)
- [4](/categories/network-detection-and-response-ndr?order=g2_score&page=4#product-list)
- [5](/categories/network-detection-and-response-ndr?order=g2_score&page=5#product-list)
- [Next &rsaquo;Next ›](/categories/network-detection-and-response-ndr?order=g2_score&page=2#product-list)

Spotlight Categories

[Identity Verification Software](https://www.g2.com/categories/identity-verification)

[Operational Risk Management Software](https://www.g2.com/categories/operational-risk-management)

[Mobile Marketing Software](https://www.g2.com/categories/mobile-marketing)

[Board Management Software](https://www.g2.com/categories/board-management)

[Accounts Receivable Software](https://www.g2.com/categories/accounts-receivable)

Similar Categories

- [Business VPN](/categories/business-vpn)
- [DNS Security Solutions](/categories/dns-security-solutions)
- [Firewall Software](/categories/firewall-software)
- [Intrusion Detection and Prevention Systems (IDPS)](/categories/intrusion-detection-and-prevention-systems-idps)

- [Microsegmentation](/categories/microsegmentation)
- [Network Access Control (NAC)](/categories/network-access-control-nac)
- [Network Sandboxing](/categories/network-sandboxing)
- [Network Security Policy Management (NSPM)](/categories/network-security-policy-management-nspm)

- [Network Traffic Analysis (NTA)](/categories/network-traffic-analysis-nta)
- [Software-Defined Perimeter (SDP)](/categories/software-defined-perimeter-sdp)
- [Unified Threat Management (UTM)](/categories/unified-threat-management-utm)

[Browse Network Detection and Response (NDR) Themes](/categories/network-detection-and-response-ndr/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Network detection and response (NDR) software is used to document business network activity for security threats and alert relevant parties or automate threat remediation. These tools work by monitoring east-west traffic and comparing them to established baselines. When traffic behavior deviates from normal functionality, the solution will detect the issue and assist in forensic investigation. Many tools include or integrate with other solutions that automate incident response processes to minimize the threat’s impact.

These tools are used by security professionals and IT staff to observe network traffic and detect anomalies related to user behavior. Other, older technologies may offer one component of network threat detection or incident response, but NDR combines the functionality of numerous security solutions. These tools use artificial intelligence and machine learning to analyze user behavior as well as existing security data; security professionals can then use that data to develop streamlined discovery and response workflows.

[Network traffic analysis (NTA)](https://www.g2.com/categories/network-traffic-analysis-nta) is a similar emerging technology related to NDR. NTA is the core technology behind NDR; it refers to the analytical and monitoring capabilities used to develop baselines and response frameworks as NDR. But NTA solutions do not have the same level of response automation and end-user, behavioral anomaly detection used to trigger incident response. [Endpoint detection and response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr) has a similar name, but products within that category only detect issues at the device level while NDR provides visibility to threats across the entire network.

To qualify for inclusion in the Network Detection and Response (NDR) category, a product must:

- Analyze network traffic in real time
- Utilize AI or ML to develop baselines for network behavior 
- Automate threat and anomaly detection across the network
- Deploy network forensics upon detection for investigation and remediation

Show More

* * *

## How Do You Choose the Right Network Detection and Response (NDR) Software?

### What You Should Know About Network Detection and Response (NDR) Software

### What is Network Detection and Response (NDR) Software?

Network detection and response (NDR) software documents a company’s network activity while automating threat remediation and reporting cyber threats to IT and security teams. NDR enables an organization to consolidate IT security services into one solution and simplifies network protection.

NDR is critical because it provides an end-to-end view of network activity. For example, certain malicious activity may not be reflected in network logs but will be visible by network tools as soon as they interact with systems throughout the network.&nbsp;

Since NDR software uses artificial intelligence (AI) and machine learning (ML) to analyze network traffic, it is highly adept at detecting malicious behavior as well as reporting and remediating such activity in real time.&nbsp;

### What are the Common Features of Network Detection and Response (NDR) System?

NDR system usually includes the following:

**AI and ML:** NDR uses AI and ML in its software solution. IT and security professionals can use the data to develop streamlined discovery and response workflows across an organization’s network.

**Automated threat detection:** When traffic behavior deviates from normal functionality, an NDR solution detects the issue and automatically assists in an investigation. NDR software includes or integrates with other solutions that automate incident response processes to minimize the threat’s impact.

### What are the Benefits of Network Detection and Response (NDR)&nbsp; Software?

There are several benefits to using NDR software.

**Automatically detects anomalies** : NDR software automatically detects anomalies in network traffic by applying non-signature-based detection techniques and using behavioral analytics, AI, and ML.

**Monitors all traffic flows** : NDR solutions monitor all traffic entering or exiting the network so there is visibility to identify and mitigate security incidents, regardless of where a threat comes from. Giving this end-to-end view of the network offers IT and security teams greater visibility across the network to mitigate traffic threats.

**Analyzes network in real time** : NDR analyzes an organization’s network for threats in real time or near real time. It provides timely alerts for IT and security teams, improving incident response times.

**Narrows down incident response** : NDR solutions attribute malicious behavior to specific IP addresses and perform forensic analyses through AI and ML to determine how threats have moved across a network environment. This leads to faster, more efficient incident response.&nbsp;

**Who Uses Network Detection and Response (NDR) Software?**

**Network IT and cybersecurity staff:** These workers use NDR software to observe network traffic and detect anomalies related to user behavior.

**Industries** : Organizations in all industries, especially technology or highly sensitive data-oriented sectors like financial services, seek NDR solutions to help protect their networks.

### What Are Alternatives to Network Detection and Response (NDR) Software?

Network traffic analysis (NTA) software and endpoint detection response (EDR) software are alternatives to NDR software.

[Network traffic analysis (NTA) software](https://www.g2.com/categories/network-traffic-analysis-nta): NTA software is similar to NDR tools in that it monitors network traffic and looks for suspicious activity while providing real-time analysis and alerting IT administrators. The main difference is that it also analyzes network performance and pinpoints reasons for slow downloads.&nbsp;

[Endpoint detection & response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr)[software](https://www.g2.com/categories/endpoint-detection-response-edr): EDR tools are similar to NDR solutions, focusing on network activity. It detects, investigates, and removes malicious software penetrating a network’s devices. These tools give greater visibility of a system’s overall health, including each specific device’s state. Companies use these tools to mitigate endpoint penetrations quickly and prevent data loss, theft, or system failures.&nbsp;

### Challenges with Network Detection and Response (NDR) Software

There are some challenges IT teams can encounter with NDR software.

**Sophisticated hackers:** With high volumes of data traveling across an organization’s network, hackers create more sophisticated threats that can hide their tracks and avoid detection by blending in with traffic patterns. Attackers can also make threats move in small and infrequent batches to avoid detection.

**Budget constraints:** As hackers become more sophisticated, organizations must keep their NDR solutions up-to-date to keep up with the latest threats. Budget constraints could prevent IT and security teams from doing so.

### How to Buy Network Detection and Response (NDR) Software

#### Requirements Gathering (RFI/RFP) for Network Detection and Response (NDR) Software&nbsp;

If an organization is just starting and looking to purchase NDR software, G2 can help.

The manual work necessary in security and compliance causes multiple pain points. If the company is large and has a lot of networks, data, or devices in its organization, it may need to shop for scalable NDR&nbsp; solutions. Users should think about the pain points in their security to help create a checklist of criteria. Additionally, the buyer must determine the number of employees who will need to use this software and if they currently have the skills to administer it.&nbsp;

Taking a holistic overview of the business and identifying pain points can help the team springboard into creating a checklist of criteria. The list is a detailed guide that includes necessary and nice-to-have features, including budget features, number of users, integrations, security staff skills, cloud or on-premises solutions, and more.

Depending on the deployment scope, producing an RFI, a one-page list with bullet points describing what is needed from NDR software, might be helpful.

#### Compare Network Detection and Response (NDR) Software Products

**Create a long list**

Vendor evaluations are essential to the software buying process, from meeting the business functionality needs to implementation. For ease of comparison, after all demos are complete, it helps to prepare a consistent list of questions regarding specific needs and concerns to ask each vendor.

**Create a short list**

From the long list of vendors, it is helpful to narrow the list of vendors and come up with a shorter list of contenders, preferably no more than three to five. With this list, businesses can produce a matrix to compare the features and pricing of the various solutions.

**Conduct demos**

To ensure a comprehensive comparison, the user should demo each solution on the short list with the same use cases. This allows the business to evaluate like for like and see how each vendor stacks up against the competition.&nbsp;

#### Selection of Network Detection and Response (NDR) Software

**Choose a selection team**

Before getting started, creating a winning team that will work together throughout the process, from identifying pain points to implementation, is crucial. The selection team should include organization members with the right interests, skills, and participation time.&nbsp;

A good starting point is to aim for three to five people who fill roles such as the primary decision maker, project manager, process owner, system owner, or staffing subject matter expert, as well as a technical lead, head administrator, or security administrator. The vendor selection team in smaller companies may have fewer participants who will multitask and take on more responsibilities.

**Compare notes**

The selection team should compare notes, facts, and figures noted during the process, such as costs, security capabilities, and alert and incident response times.

**Negotiation**

Just because something is written on a company’s pricing page does not mean it's final. It is crucial to open up a conversation regarding pricing and licensing. For example, the vendor may be willing to give a discount for multi-year contracts or for recommending the product to others.

**Final decision**

After this stage, and before going all in, it is recommended to roll out a test run or pilot program to test adoption with a small sample size of users. If the tool is well used and received, the buyer can be confident that the selection was correct. If not, it might be time to return to the drawing board.

### What Does Network Detection and Response (NDR) Software Cost?

NDR software is considered a long-term investment. This means there must be a careful evaluation of vendors, and the software should be tailored to each organization's specific requirements. Once NDR software is purchased, deployed, and integrated into an organization’s security system, the cost could be high, so the evaluation stage of selecting the right tool is crucial.&nbsp;

The chosen NDR vendor should continue to provide support for the platform with flexibility and open integration. Pricing can be pay-as-you-go, and costs may also vary depending on whether unified threat management is self-managed or fully managed.

#### Return on Investment (ROI)

As organizations consider recouping the money spent on the software, it is critical to understand the costs that will be saved in terms of efficiency. In the long run, the investment must be worth preventing downtime, loss of revenue, and any reputation damage that a security breach would cause.