Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Cofense Triage
Score 9.4 out of 10
Enterprise companies (1,001+ employees)
Cofense Triage accelerates phishing qualification, investigation, and response by automating standard responses to suspicious emails to make analysts more efficient and driving out actionable intelligence, and providing incident response playbook.N/A
Darktrace
Score 8.3 out of 10
N/A
Darktrace AI interrupts in-progress cyber-attacks, including ransomware, email phishing, and threats to cloud environments. It's able to detect and establish baselines for your organization so it can make the distinction between what is and what isn't normal network activity for your organization. This allows it to tackle complex cyber-attacks as they happen and prevent future cyber-attacks from happening.N/A
Lastline
Score 10.0 out of 10
N/A
Lastline in San Mateo, California offers a network detection and response solution designed to provide network traffic analysis (NTA) to protect enterprise networks against sophisticated threats in real-time.N/A
Pricing
Cofense TriageDarktraceLastline
Editions & Modules
No answers on this topic
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cofense TriageDarktraceLastline
Free Trial
YesNoNo
Free/Freemium Version
NoNoNo
Premium Consulting/Integration Services
NoNoNo
Entry-level Setup FeeOptionalNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Cofense TriageDarktraceLastline
Considered Multiple Products
Cofense Triage
Chose Cofense Triage
Cofense UI is easy to use and is very understandable. There are other factors which Cofense is better than KnowBe4 with.
Chose Cofense Triage
Triage is more relevant, as real threats are identified there
Chose Cofense Triage
Triage is an excellent solution for analysing and triaging emails. It has a set of rules which can be used to rate the risk of meaages, these rules are updated on a daily basis to keep up with known IOCs of attackers. The support from Cofense is also excellent and reaching out …
Chose Cofense Triage
Cofense Triage is the product that has been used in the organization for almost 3 years now the overall performance triage shows is always good and never disappointing with every new release of the version they come up with the features which customers tell them as feedback or …
Chose Cofense Triage
This product provided a value where we had a gap.
Chose Cofense Triage
The main purpose we [chose] Cofense Triage [is to] secure our environment from phishing emails. The phrasing of reported emails is accurate. It has abundant information about reported emails.
Chose Cofense Triage
The sandbox integration here allowed for more advanced threats to be identified without the worry of accidental data loss.
Chose Cofense Triage
Cofense Triage has a much better GUI and rate of understanding the mails when reported by the user. The overall setup with other Cofense products gives an excellent opportunity to complete the email security suite of the organization. The info and intel provided within Cofense …
Chose Cofense Triage
Cofense is easier to use and is at least 6-12 months ahead in functionality.
Chose Cofense Triage
The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did …
Darktrace
Chose Darktrace
Darktrace does a very good job at complementing our other security tools by adding an additional level of automated security. It is important to point out that the automation is optional. We ran Darktrace in "manual" mode until we were comfortable enough to switch it to a …
Chose Darktrace
Darktrace allows you to get under the hood in a way that few other services of this type allow.
Chose Darktrace
Its capabilities to respond to a threat both manual than automated way makes Darktrace one of the best NDR in the market. The rules editor allows the right flexibility to build a set of rules sized for the infrastructure, while the third parties integrations and modules helps …
Chose Darktrace
Darktrace is better in terms of scalability, ease of integration, and ongoing support
Chose Darktrace
The product's capacity to provide insights into network traffic is impressive. The organisation was able to find any malware harming the devices with their assistance. We really value network monitoring and self-learning monitoring tools.
Chose Darktrace
We looked into several competitors and are still looking, due to the problems Darktrace has with false positives. Darktrace is attractive as their support is generally good, and working with the product is relatively easy.
Chose Darktrace
We have not evaluated others as they seem to be in their own class.
Chose Darktrace
The weekly reports was why we chose DarkTrace.
Chose Darktrace
We did NOT select Darktrace. OSSIM/AlienVault is a more mature product and it provided better intelligence and reporting. The end user interface is much easier to use - and you can tell built form engineers who have had to do the work. My suggestion for anyone considering …
Lastline

No answer on this topic

Features
Cofense TriageDarktraceLastline
Incident Response Platforms
Comparison of Incident Response Platforms features of Product A and Product B
Cofense Triage
6.4
Ratings
33% below category average
Darktrace
-
Ratings
Lastline
-
Ratings
Integration with Other Security Systems5.00 Ratings00 Ratings00 Ratings
Attack Chain Visualization6.10 Ratings00 Ratings00 Ratings
Centralized Dashboard7.70 Ratings00 Ratings00 Ratings
Live Response for Rapid Remediation6.70 Ratings00 Ratings00 Ratings
Best Alternatives
Cofense TriageDarktraceLastline
Small Businesses
ThreatDown, powered by Malwarebytes
ThreatDown, powered by Malwarebytes
Score 9.5 out of 10
Auvik
Auvik
Score 8.8 out of 10
NinjaOne
NinjaOne
Score 9.0 out of 10
Medium-sized Companies
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.2 out of 10
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
Enterprises
CrowdStrike Falcon
CrowdStrike Falcon
Score 9.1 out of 10
SolarWinds NetFlow Traffic Analyzer (NTA)
SolarWinds NetFlow Traffic Analyzer (NTA)
Score 9.2 out of 10
Cisco Meraki MX
Cisco Meraki MX
Score 9.0 out of 10
All AlternativesView all alternativesView all alternativesView all alternatives
User Ratings
Cofense TriageDarktraceLastline
Likelihood to Recommend
7.5
(0 ratings)
8.0
(0 ratings)
-
(0 ratings)
Likelihood to Renew
10.0
(0 ratings)
9.7
(0 ratings)
-
(0 ratings)
Usability
10.0
(0 ratings)
6.5
(0 ratings)
-
(0 ratings)
Availability
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Performance
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Support Rating
-
(0 ratings)
7.0
(0 ratings)
-
(0 ratings)
In-Person Training
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Implementation Rating
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Configurability
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Product Scalability
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Vendor post-sale
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
Vendor pre-sale
10.0
(0 ratings)
-
(0 ratings)
-
(0 ratings)
User Testimonials
Cofense TriageDarktraceLastline
Likelihood to Recommend
The tool is very helpful in improving Phishing detection capabilities as it streamlines the process of analyzing user reports a lot. Besides it has a built-in mechanism of rating reporters(end-users) based on their historical performance. Downside - tool requires continuous resource investment to deliver best result. Tool is not helping too much in improving user-education, because automated response process is not immediate and is prone to errors
Read full review
Darktrace would be well suited to any environment really; the only constraint would be the budget. The cost scales on the number of devices to be monitored by the product, so it can be quite expensive in larger environments. Any company that would benefit from having 24/7 monitoring of their network would find that this product would suit that need perfectly. It can also create a number of reports, which is useful if you have any requirement to present periodic figures and statistics for your network. There are also additional features available and in development such as Antigena, which can be configured to allow potential threats to be automatically mitigated; it can block connections to a certain address, using certain ports, or it can enforce "normal behaviour" where it will only allow a machine to communicate in a way that Darktrace has observed before and considers normal. This has huge benefits particularly for 24/7 organisations where you don't have the ability to have someone monitoring the network personally at all times, as it could stop a malware outbreak in its tracks.
Read full review
No answers on this topic
Pros
  • Separating links and attachments contained in the email, and checking to see if they are known malicious.
  • Clustering like emails to save time when responding.
  • Providing risks scores with each cluster to give an estimate on which clusters should be addressed first.
Read full review
  • Uses it Al model UEBA to detect anomalies in the behaviour of not only the users in a corporate network but also the routers, servers, and endpoints in that network.
  • Provides a visualisation of both egress and outbound network traffics flowing in and out of the organisation.
  • Darktrace comes with it autonomous AI model detection and responses capabilities.
  • Darktrace as an AI next generation NDR solution, prevents ,contains and quarantines malicious traffics from and into the corporate network.
Read full review
No answers on this topic
Cons
  • YARA rules, while the functionality is fantastic I've found that the documentation can be a bit confusing. Although, that might just be my personal experience.
  • Rare glitches make the send notification button unusable. This can be remediated by navigating to a different report, but [it] is a bit of a pain in the moment.
  • I would like to see a dark mode get added as well, but that's obviously a tertiary concern.
Read full review
  • The system has so many features and places to tweak we found it hard to tune for our use.
  • We met regularly with someone from Darktrace to assist us in processing the alerts
  • The process for mail scanning requires you to reroute mail traffic
Read full review
No answers on this topic
Likelihood to Renew
Cofense is stable and provides easy to use solution to aid the investigation of emails as well as managing simulated phishing campaigns.
Read full review
It's a powerfull product that help administrators to provide email security to our organization.
Good metrics about received emails that help us to determine in doubt case if the email is a false positive or it's malware.
They're improving the product releasing continuous updates and have mobile phone app to manage it.
Read full review
No answers on this topic
Usability
The interface is easy and intuitive.
Read full review
The Darktrace toolset is very expansive, allowing it to handle many different tasks, but this leads to a user interface that is sometimes not at all intuitive. Icons don't always make sense visually, and the associated tool tips do not always provide enough detail on what action the button performs
Read full review
No answers on this topic
Reliability and Availability
We've experienced zero downtime.
Read full review
No answers on this topic
No answers on this topic
Performance
No slowness seen.
Read full review
No answers on this topic
No answers on this topic
Support Rating
No answers on this topic
Darktrace support is excellent in my experience. They send a competent engineer on-site to provide on-boarding training. They were also very responsive in responding to questions and concerns. Having an individual point of contact who is a competent network and security engineer is not a common experience, at least for me.
Read full review
No answers on this topic
In-Person Training
Training was through, relevant and easy to follow.
Read full review
No answers on this topic
No answers on this topic
Alternatives Considered
The other product had a lot of fails on the auto-processing and did not integrate well with our current environment. One issue had to do with the way it sends the submissions to its processing engine—our email gateway configuration would have blocked this traffic. I also did not like the user interface.
Read full review
We did NOT select Darktrace. OSSIM/AlienVault is a more mature product and it provided better intelligence and reporting. The end user interface is much easier to use - and you can tell built form engineers who have had to do the work. My suggestion for anyone considering Darktrace, is to get the price upfront; do a 30/60 onsite trail; and do the same thing, at the same time, with AlienVault. AlientVault will win every time. I say that because that's exactly what I did.
Read full review
No answers on this topic
Scalability
We've experienced zero downtime
Read full review
No answers on this topic
No answers on this topic
Return on Investment
  • The biggest impact has been the time saved.
  • My company had nothing of this sort previously and we were stuck trying to make use of free resources and doing things very manually. Triage was a huge life saver in this area.
  • The ability to quickly respond to several users at once has been a great help.
Read full review
  • One big positive is how it helps us with the security assessments that clients have done on us. They are looking to see if we know how we might have unusual/malicious traffic running on the network.
  • If you have a small network and only need 1 appliance, it can be a good ROI and peace of mind.
  • You could go down a hole in trying to spend time looking at all of your traffic with this software. You need to focus only on what it is showing as potential bad traffic.
Read full review
No answers on this topic
ScreenShots

Cofense Triage Screenshots

Screenshot of Triage DashboardScreenshot of Triage Dashboard Cluster DetailsScreenshot of Triage Cluster DetailsScreenshot of Triage Cluster Malicious AttachmentScreenshot of Triage Cluster HeadersScreenshot of Triage Reporter Details

Lastline Screenshots

Screenshot of Lastline Defender sees every malicious behavior programmed into a piece of malware.Screenshot of Lastline Defender's informed AI can distill petabytes of network activity data down to a very small number of actual multi-faceted security incidents.Screenshot of Lastline Defender delivers a blueprint of an intrusion showing all infected hosts, lateral movement, external communications with C&C servers, and more.Screenshot of The timeline shows the specific sequence of activities that took place during a cyber attack.