State of the space ·
Network detection and response, usually shortened to NDR, is the part of security that watches traffic moving between systems and catches the attackers that firewalls and endpoint tools miss. Every one of the eight vendors on this map now ships some level of agentic capability, ranging from AI that sorts alerts to software that runs a full investigation on its own. What none of them has changed is the way they charge.All eight still price by coverage, which means the fee is based on the size of the environment being watched, and the agent's work never appears as a line of its own.
Sources:category analysis,NDR comparison,Vendr
May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
Unordered list
Bold text
Emphasis
Superscript
Subscript
Procurement data published this year gives the clearest picture yet of how the category actually transacts.Darktrace lists 12 to 22% above Vectraand 8 to 18% above ExtraHop for the same NDR scope, and multi-module bundles routinely close 15 to 30% below list. Since the Thoma Bravo acquisition, buyers report that Darktrace discounts less on small deals and more on the large multi-module ones. The pricing model itself has not moved, and what has changed is how hard buyers push against it.
Source:VendorBenchmark,Vendr
A newer group of agentic SOC vendors has started selling directly against this category. Their argument, as they make it, is that detection quality has become similar across vendors and thatthe valuable work is the triage, investigation, and response after an alert fires. We report that as their sales claim, and we note that it is aimed at work the NDR vendors genuinely perform with AI and do not charge for as a separate item.
Source:market analysis
At RSAC 2026,CrowdStrike, Cisco, and Palo Alto all released agentic SOC productsthat take NDR data as input and sell the triage and investigation layer separately. The vendors on this map now share the alert pipeline with platform agents that charge for steps NDR includes in coverage.
Source:VentureBeat
The category's center of gravity keeps moving toward the cloud.The younger half of this map detects from cloud telemetry instead of network appliances, and all four established vendors now sell cloud sensors alongside their original deployments. Buying guides published this year treat cloud and OT coverage as standard evaluation criteria instead of extras.
Source:category review
Darktrace listed on the London Stock Exchange, and Bain Capital took ExtraHop private at about $900 million.The whole category priced by devices, sensors, and bandwidth in those years, largely because that is what security budgets were set up to buy.
Investors and buyers began questioning what "AI-powered" actually meantacross the category, and vendors answered by competing on the quality of their signal instead of the volume of it. Vectra planted its flag on fewer, higher-confidence detections during this period. The pricing models came through the scrutiny untouched.
Ownership changed hands.Thoma Bravo took Darktrace private for about $5.3 billion, Cisco closed its $28 billion purchase of Splunk, and Corelight raised $150 million to keep building the evidence layer.The new owners tightened the existing coverage model instead of replacing it.
Darktrace bought Cado Securityand folded cloud forensics into its autonomous investigation product, while generative assistants for summarizing and investigating alerts spread across the rest of the category.Product autonomy kept increasing while the pricing metrics stayed exactly where they were.
Autonomous SOC platforms now run triage and investigation on top of NDR signaland sell that layer as a product of its own. NDR pricing, for now, remains coverage-based.
Journalist first, analyst second
The core platform ingests network, cloud, email, identity, endpoint, and OT telemetry to build a continuously updated behavioral model of an organization, using self-learning AI to flag deviations that indicate a potential attack, without relying solely on signatures or threat intelligence feeds.
Darktrace does not publish list prices. Historically, pricing has been quote based and driven by deployment scope, typically the number of devices, users, or data sources monitored, along with which modules a customer licenses, such as network, email, cloud, or OT security. Contracts are generally structured as annual subscriptions negotiated directly with Darktrace or through its channel partners, following a proof of value trial period before commercial commitment.
Public evidence does not indicate a distinct usage-based meter for AI or autonomous response features. Darktrace RESPOND and other AI-driven modules appear to be sold as licensed add-on modules within the broader platform subscription rather than metered separately by the volume of autonomous actions taken. Pricing not public.
The core platform ingests network, identity, and cloud metadata and applies the Attack Signal Intelligence machine learning engine to detect attacker behaviors such as lateral movement, command and control activity, and privilege escalation, then prioritizes alerts by risk score for SOC analysts.
Vectra AI does not publish list prices. Public procurement and reseller listings indicate the platform is sold primarily as an annual subscription, typically scoped by network bandwidth or by the number of hosts, workloads, and identities monitored, rather than by per-seat licensing. Packaging separates network detection, identity detection, and cloud detection as modules that can be purchased individually or combined within a single platform subscription.
Contracts are negotiated directly with Vectra AI or through channel partners and managed security service provider (MSSP) resellers, with multi-year terms common in enterprise and public sector deals based on publicly available procurement records. No evidence was found of a separate usage-based meter tied specifically to AI or machine learning processing; the detection engine is bundled into the core subscription rather than billed as a discrete add-on.
Pricing not public. No official price list, per-unit rate card, or standard discount schedule was located in company documentation as of the research cutoff.
Physical, virtual, and cloud sensors built on Zeek that capture and analyze network traffic to generate structured logs, extracted files, and full packet capture. Sensors are deployed at network taps or cloud VPC mirrors and feed downstream SIEM, SOAR, and data lake systems.
Corelight does not publish list prices. Public procurement records and reseller quotes indicate pricing is structured primarily around sensor throughput capacity, typically licensed by bandwidth tier (for example gigabit thresholds for physical or virtual sensors), plus a separate subscription for cloud analytics such as Investigator, and additional fees for extended data retention and premium detection content packages.
Contracts are typically annual or multi-year subscriptions bundling sensor hardware or software licenses with software maintenance and cloud service access. Government and education pricing is available through resellers and cooperative purchasing vehicles, sometimes reflected in published state or federal procurement schedules.
Corelight has not published a distinct usage-based meter for its AI Investigator capability. Public materials describe AI-driven investigation as part of the Investigator product tier rather than as a separately metered add-on, so pricing not public for any standalone AI consumption unit.
The core platform ingests DNS queries, network flow data, and logs to detect compromise indicators continuously rather than relying solely on point-in-time scans. It maps findings against the MITRE ATT&CK framework and provides a compromise level score intended to help security teams prioritize response.
Lumu does not publish pricing on its website, and no procurement or public filing data on pricing metrics was located as of the research cutoff. Industry commentary and Lumu's own marketing describe packaging tiers that reportedly scale with elements such as number of protected devices, data volume ingested, or number of network endpoints, but no verifiable figures or contract terms are publicly available to confirm this structure.
Pricing not public. Lumu's sales process is presented as consultative, requiring prospective customers to request a demo or quote directly, which is typical for mid-market and enterprise security vendors that negotiate contracts individually based on organization size and deployment scope.
There is no public evidence that Lumu separately meters or prices its Playbooks automation feature apart from the core platform subscription. No public information confirms whether automation actions carry usage-based or consumption-based pricing distinct from the base compromise assessment service.
RevealX is ExtraHop's flagship network detection and response platform. It ingests network traffic, decrypts and analyzes it using machine learning models trained on network behavior, and surfaces threats such as ransomware activity, command-and-control traffic, and lateral movement. RevealX is available as a cloud-delivered SaaS product (RevealX 360) and as a self-managed on-premises deployment.
ExtraHop does not publish list pricing for RevealX or RevealX 360 on its website. Historically, and per third-party procurement and reseller listings, ExtraHop has priced its network detection and response products based on network traffic volume, typically measured in sustained Mbps or Gbps of monitored traffic, along with the number of sensors or deployment scale required to cover an organization's network segments.
Contracts are typically structured as annual or multi-year subscriptions, consistent with standard enterprise security software procurement, and sold through direct sales and channel partners. Public sector and government pricing is available through partners on cooperative purchasing vehicles, though specific unit pricing is not disclosed publicly.
Pricing not public. There is no evidence of a separate, distinctly metered charge for AI or machine learning detection capability; ML-based threat detection appears bundled into the core RevealX and RevealX 360 platform tiers rather than sold as a separate agent-based add-on.
FortiAI is Fortinet's generative AI assistant embedded across FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiManager. It provides natural language search, alert summarization, and automated incident narrative generation to help security operations center analysts triage events faster. Fortinet documentation describes FortiAI as a feature layered into existing product licenses rather than a standalone product with its own SKU.
Fortinet does not publish list prices for FortiGate appliances, FortiGuard subscriptions, or FortiAI capability on its corporate website; pricing is quoted through its channel of resellers and distributors and varies by appliance model, throughput tier, and bundled service term. Fortinet's public 10-K filings describe revenue as split between product revenue, largely hardware and perpetual software license sales, and service revenue, which includes FortiCare support and FortiGuard security subscription bundles sold on one, three, or five year terms.
FortiAI generative assistance and FortiGuard AI-powered detection services are documented as features included within existing FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiGuard subscription tiers rather than sold under a separate meter or usage-based price. Fortinet has not published a standalone price list, consumption unit, or per-agent fee for FortiAI as of the research cutoff date.
Public sector and enterprise customers typically procure Fortinet products through negotiated reseller contracts, and Fortinet's SEC filings note volume-based and multi-year discounting is common in large deployments, though specific discount percentages are not publicly disclosed. In the absence of a published price list for AI-specific functionality, pricing not public applies to FortiAI and FortiGuard AI-powered services as distinct billable units.
Formerly Cisco Stealthwatch, Secure Network Analytics ingests NetFlow and other telemetry from switches, routers, and firewalls to build behavioral baselines and detect anomalies such as lateral movement, data exfiltration, and encrypted traffic threats without requiring dedicated sensors on every segment. It integrates with Cisco Identity Services Engine and other Cisco security products for automated policy enforcement.
Cisco does not publish list pricing for Secure Network Analytics; the product is sold through Cisco's channel and direct sales teams, typically licensed by network flow volume or number of monitored devices as part of broader Cisco Secure or networking bundles. Pricing not public.
Splunk products, including Enterprise Security and SOAR, have historically been licensed by data ingest volume per day, with Splunk having introduced workload-based and consumption-based pricing tiers prior to the Cisco acquisition. Cisco has indicated it intends to maintain Splunk's existing licensing models in the near term while exploring longer-term integration with Cisco's own enterprise agreement structures. Public sources do not confirm a unified pricing meter across Secure Network Analytics and Splunk as of the cutoff date.
There is no publicly documented separate price meter specifically for AI or automation features within Secure Network Analytics or Splunk's AI Assistant; these capabilities appear to be bundled into existing product tiers rather than billed as a discrete add-on based on available public documentation.
About this data
Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.