Identity Rules vs. Netwrix Threat Prevention

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Identity Rules
Score 0.0 out of 10
N/A
Identity Rules is a unified Identity Threat Detection and Response (ITDR) and Identity Visibility and Intelligence Platform (IVIP) developed for security teams at regulated enterprises. The platform combines real-time detection of identity-based threats with continuous visibility and intelligence across human and non-human identities, spanning Active Directory, Okta, Microsoft Entra ID, AWS IAM, Google Workspace, Oracle Database, and Linux environments. Key…N/A
Netwrix Threat Prevention
Score 8.2 out of 10
N/A
Netwrix Threat Prevention, formerly StealthINTERCEPT, is a real-time monitoring and blocking solution that helps organizations proactively stop identity-based and file system threats before they cause damage.N/A
Pricing
Identity RulesNetwrix Threat Prevention
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Identity RulesNetwrix Threat Prevention
Free Trial
NoNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Identity RulesNetwrix Threat Prevention
Best Alternatives
Identity RulesNetwrix Threat Prevention
Small Businesses

No answers on this topic

No answers on this topic

Medium-sized Companies
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
Enterprises
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
ManageEngine ADAudit Plus
ManageEngine ADAudit Plus
Score 9.0 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Identity RulesNetwrix Threat Prevention
Likelihood to Recommend
-
(0 ratings)
8.0
(1 ratings)
Support Rating
-
(0 ratings)
9.0
(1 ratings)
User Testimonials
Identity RulesNetwrix Threat Prevention
Likelihood to Recommend
Identity Rules
No answers on this topic
Netwrix
If you have an environment where there is heavy changes being made to your AD, then this is a great tool to have. Now, if your environment is being managed by one person and has very little change activity, then I would stick with searching the windows log files.
Read full review
Pros
Identity Rules
No answers on this topic
Netwrix
  • Providing a user-friendly report for user account lock outs.
  • A forensic tool for identifying when accounts get deleted.
Read full review
Cons
Identity Rules
No answers on this topic
Netwrix
  • The web based reporting console could more user friendly.
Read full review
Support Rating
Identity Rules
No answers on this topic
Netwrix
They are very knowledgeable and willing to assist with any issue that may occur. We have not had to call support very often because they make sure there is a subject matter expert in place before concluding the implementation.
Read full review
Alternatives Considered
Identity Rules
No answers on this topic
Netwrix
Varonis did a good job compared to the same things that StealthIntercept does. When it comes to configuring the reports within StealthIntercept, the configuration portion is easier. However, the web console in Varonis looked better and is a bit easier to navigate.
Read full review
Return on Investment
Identity Rules
No answers on this topic
Netwrix
  • This tool has helped to identify user mistakes.
  • This tool has been helpful with identifying systems brute force attaching.
Read full review
ScreenShots

Identity Rules Screenshots

Screenshot of Executive dashboard showing the identity activity funnel — from monitored activities (18) to anomalies detected (4) to active incidents (0) — for a selected date range. Adjacent timeline visualizes incident detection and total AI-driven  analysis events per day, with headline KPIs for active incidents, human vs. non-human identities involved, activities analyzed, and anomalies analyzed.Screenshot of Assets tab of the executive dashboard, delivering a unified inventory of 17 identities, 116 human accounts, 170 non-human identities (NHI), 599 entitlements, and 728 anomalies. Account risk distribution (Critical, High, Medium, Low) sits alongside behavioral anomaly indicators such as "NHI credential never expires" (169) and "NHI credential not rotated" (164), plus account state breakdown between active, locked, deleted, privileged, and shared accounts.Screenshot of Security incident management workspace where SOC and IAM teams triage identity threats across all connected systems. Each incident is displayed with source application (Google Workspace shown here), severity (Critical / High / Medium / Low), lifecycle state (New, In Triage, Closed), 
AI-calculated confidence score, and final verdict — including labels like Token Theft, Lateral Movement, Password Spraying, Legitimate Activity, Business Exception, and Insufficient Evidence.Screenshot of Detailed incident view for a high-severity case: "NHI account without owner and insecure credentials in Google Workspace". The AI Analysis tab maps the finding to MITRE ATT&CK tactic TA0006 (Credential Access) and technique T1556 (Modify Authentication Process) at 80% confidence, showing affected accounts, related activities, and correlated anomalies. An AI-generated Quality Assessment panel surfaces assumptions, evidence gaps, and cross-incident correlations so analysts can act with full context.Screenshot of Analytics view organizing every identity anomaly by MITRE ATT&CK tactic and technique. isplayed here: TA0006 (Credential Access) with 7 detections across 2 techniques, and TA0003 (Persistence) with 2 detections across 2 techniques. The right-hand panel drills into T1556 (Modify uthentication 
Process) showing each individual detection with application, stage, verdict (Legitimate Activity, Business Exception), severity, and affected accounts — giving SOC teams a native ATT&CK-aligned view of their identity attack surface.Screenshot of Interactive graph visualization of account relationships. Central node shows a Linux "root" account on Ubuntu, connected via directional edges to its two entitlements — "root" and "docker" privileged access on Ubuntu Linux. The legend explains node types (accounts, entitlements, child nodes, parent nodes), giving IAM and security teams a visual map of how privileges are structured across systems.