I really appreciate how Darktrace/Network helps us identify anomalous network activity, insider threats, and compromised devices that traditional security controls might miss. Its AI-driven technology can do in minutes what would take humans years to detect and respond to, making my small team function like a big SOC. My favorite feature is the AI analyst, which analyzes particular alerts and does all the work to correlate them. The initial setup was also pretty straightforward, with the vendor assisting with configuration and making the process a breeze. Those guys are great at what they do. Review collected by and hosted on G2.com.
I think the user interface. While it looks awesome and highly technical, it isn't very friendly to use. For instance, doing manual investigations is pretty difficult. The alerts do not give much to go with. With the user interface, I think it's very challenging because of the amount of information there, and it's not always obvious where to begin your investigation. With the manual investigations specifically, some alerts do not immediately provide enough context to understand the root cause or impact. You'd need to be extremely technical and familiar and use different screens to investigate further. I just wish all pertinent information was there at once. Review collected by and hosted on G2.com.