State of the space ·

Network Defense Agents

Network Defense Agents AMS Map
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

Network detection and response, usually shortened to NDR, is the part of security that watches traffic moving between systems and catches the attackers that firewalls and endpoint tools miss. Every one of the eight vendors on this map now ships some level of agentic capability, ranging from AI that sorts alerts to software that runs a full investigation on its own. What none of them has changed is the way they charge.All eight still price by coverage, which means the fee is based on the size of the environment being watched, and the agent's work never appears as a line of its own.

Positions: Monetizely analysisPublic data only

Who is on this map

Darktrace
Vectra AI
Corelight
Lumu
ExtraHop
data
Fortinet
Cisco (Secure Network Analytics / Splunk)

What this category does

The task list agents can take over

Heading

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

Pricing

Heading 1

Heading 2

Heading 3

Heading 4

Heading 5
Heading 6

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

Block quote

Ordered list

  1. Item 1
  2. Item 2
  3. Item 3

Unordered list

  • Item A
  • Item B
  • Item C

Text link

Bold text

Emphasis

Superscript

Subscript

Procurement data published this year gives the clearest picture yet of how the category actually transacts.Darktrace lists 12 to 22% above Vectraand 8 to 18% above ExtraHop for the same NDR scope, and multi-module bundles routinely close 15 to 30% below list. Since the Thoma Bravo acquisition, buyers report that Darktrace discounts less on small deals and more on the large multi-module ones. The pricing model itself has not moved, and what has changed is how hard buyers push against it.

Source:VendorBenchmark,Vendr

Competitive wedge

A newer group of agentic SOC vendors has started selling directly against this category. Their argument, as they make it, is that detection quality has become similar across vendors and thatthe valuable work is the triage, investigation, and response after an alert fires. We report that as their sales claim, and we note that it is aimed at work the NDR vendors genuinely perform with AI and do not charge for as a separate item.

Source:market analysis

Platform pressure

At RSAC 2026,CrowdStrike, Cisco, and Palo Alto all released agentic SOC productsthat take NDR data as input and sell the triage and investigation layer separately. The vendors on this map now share the alert pipeline with platform agents that charge for steps NDR includes in coverage.

Source:VentureBeat

Market

The category's center of gravity keeps moving toward the cloud.The younger half of this map detects from cloud telemetry instead of network appliances, and all four established vendors now sell cloud sensors alongside their original deployments. Buying guides published this year treat cloud and OT coverage as standard evaluation criteria instead of extras.

Source:category review

No items found.

The long arc

2021Appliance pricing

Darktrace listed on the London Stock Exchange, and Bain Capital took ExtraHop private at about $900 million.The whole category priced by devices, sensors, and bandwidth in those years, largely because that is what security budgets were set up to buy.

2023AI scrutiny

Investors and buyers began questioning what "AI-powered" actually meantacross the category, and vendors answered by competing on the quality of their signal instead of the volume of it. Vectra planted its flag on fewer, higher-confidence detections during this period. The pricing models came through the scrutiny untouched.

2024Consolidation

Ownership changed hands.Thoma Bravo took Darktrace private for about $5.3 billion, Cisco closed its $28 billion purchase of Splunk, and Corelight raised $150 million to keep building the evidence layer.The new owners tightened the existing coverage model instead of replacing it.

2025Investigation deepens

Darktrace bought Cado Securityand folded cloud forensics into its autonomous investigation product, while generative assistants for summarizing and investigating alerts spread across the rest of the category.Product autonomy kept increasing while the pricing metrics stayed exactly where they were.

2026Agentic competition

Autonomous SOC platforms now run triage and investigation on top of NDR signaland sell that layer as a product of its own. NDR pricing, for now, remains coverage-based.

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
Darktrace
M · M · Infl
SHIPPED AGENTIC PRODUCTS

The core platform ingests network, cloud, email, identity, endpoint, and OT telemetry to build a continuously updated behavioral model of an organization, using self-learning AI to flag deviations that indicate a potential attack, without relying solely on signatures or threat intelligence feeds.

Placement:
M
 on independence,
M
 on job width, and
Inflecting
 on the value curve.

Darktrace does not publish list prices. Historically, pricing has been quote based and driven by deployment scope, typically the number of devices, users, or data sources monitored, along with which modules a customer licenses, such as network, email, cloud, or OT security. Contracts are generally structured as annual subscriptions negotiated directly with Darktrace or through its channel partners, following a proof of value trial period before commercial commitment.

Public evidence does not indicate a distinct usage-based meter for AI or autonomous response features. Darktrace RESPOND and other AI-driven modules appear to be sold as licensed add-on modules within the broader platform subscription rather than metered separately by the volume of autonomous actions taken. Pricing not public.

HOW THEY CHARGE TODAY
Vectra AI
M · M · Infl
SHIPPED AGENTIC PRODUCTS

The core platform ingests network, identity, and cloud metadata and applies the Attack Signal Intelligence machine learning engine to detect attacker behaviors such as lateral movement, command and control activity, and privilege escalation, then prioritizes alerts by risk score for SOC analysts.

Placement:
M
 on independence,
M
 on job width, and
Inflecting
 on the value curve.

Vectra AI does not publish list prices. Public procurement and reseller listings indicate the platform is sold primarily as an annual subscription, typically scoped by network bandwidth or by the number of hosts, workloads, and identities monitored, rather than by per-seat licensing. Packaging separates network detection, identity detection, and cloud detection as modules that can be purchased individually or combined within a single platform subscription.

Contracts are negotiated directly with Vectra AI or through channel partners and managed security service provider (MSSP) resellers, with multi-year terms common in enterprise and public sector deals based on publicly available procurement records. No evidence was found of a separate usage-based meter tied specifically to AI or machine learning processing; the detection engine is bundled into the core subscription rather than billed as a discrete add-on.

Pricing not public. No official price list, per-unit rate card, or standard discount schedule was located in company documentation as of the research cutoff.

HOW THEY CHARGE TODAY
Corelight
M · S · Infl
SHIPPED AGENTIC PRODUCTS

Physical, virtual, and cloud sensors built on Zeek that capture and analyze network traffic to generate structured logs, extracted files, and full packet capture. Sensors are deployed at network taps or cloud VPC mirrors and feed downstream SIEM, SOAR, and data lake systems.

Placement:
M
 on independence,
S
 on job width, and
Inflecting
 on the value curve.

Corelight does not publish list prices. Public procurement records and reseller quotes indicate pricing is structured primarily around sensor throughput capacity, typically licensed by bandwidth tier (for example gigabit thresholds for physical or virtual sensors), plus a separate subscription for cloud analytics such as Investigator, and additional fees for extended data retention and premium detection content packages.

Contracts are typically annual or multi-year subscriptions bundling sensor hardware or software licenses with software maintenance and cloud service access. Government and education pricing is available through resellers and cooperative purchasing vehicles, sometimes reflected in published state or federal procurement schedules.

Corelight has not published a distinct usage-based meter for its AI Investigator capability. Public materials describe AI-driven investigation as part of the Investigator product tier rather than as a separately metered add-on, so pricing not public for any standalone AI consumption unit.

HOW THEY CHARGE TODAY
Lumu
M · S · Lin
SHIPPED AGENTIC PRODUCTS

The core platform ingests DNS queries, network flow data, and logs to detect compromise indicators continuously rather than relying solely on point-in-time scans. It maps findings against the MITRE ATT&CK framework and provides a compromise level score intended to help security teams prioritize response.

Placement:
M
 on independence,
S
 on job width, and
Linear
 on the value curve.

Lumu does not publish pricing on its website, and no procurement or public filing data on pricing metrics was located as of the research cutoff. Industry commentary and Lumu's own marketing describe packaging tiers that reportedly scale with elements such as number of protected devices, data volume ingested, or number of network endpoints, but no verifiable figures or contract terms are publicly available to confirm this structure.

Pricing not public. Lumu's sales process is presented as consultative, requiring prospective customers to request a demo or quote directly, which is typical for mid-market and enterprise security vendors that negotiate contracts individually based on organization size and deployment scope.

There is no public evidence that Lumu separately meters or prices its Playbooks automation feature apart from the core platform subscription. No public information confirms whether automation actions carry usage-based or consumption-based pricing distinct from the base compromise assessment service.

HOW THEY CHARGE TODAY
ExtraHop
M · S · Infl
SHIPPED AGENTIC PRODUCTS

RevealX is ExtraHop's flagship network detection and response platform. It ingests network traffic, decrypts and analyzes it using machine learning models trained on network behavior, and surfaces threats such as ransomware activity, command-and-control traffic, and lateral movement. RevealX is available as a cloud-delivered SaaS product (RevealX 360) and as a self-managed on-premises deployment.

Placement:
M
 on independence,
S
 on job width, and
Inflecting
 on the value curve.

ExtraHop does not publish list pricing for RevealX or RevealX 360 on its website. Historically, and per third-party procurement and reseller listings, ExtraHop has priced its network detection and response products based on network traffic volume, typically measured in sustained Mbps or Gbps of monitored traffic, along with the number of sensors or deployment scale required to cover an organization's network segments.

Contracts are typically structured as annual or multi-year subscriptions, consistent with standard enterprise security software procurement, and sold through direct sales and channel partners. Public sector and government pricing is available through partners on cooperative purchasing vehicles, though specific unit pricing is not disclosed publicly.

Pricing not public. There is no evidence of a separate, distinctly metered charge for AI or machine learning detection capability; ML-based threat detection appears bundled into the core RevealX and RevealX 360 platform tiers rather than sold as a separate agent-based add-on.

HOW THEY CHARGE TODAY
data
SHIPPED AGENTIC PRODUCTS
Placement:
 on independence,
 on job width, and
 on the value curve.
HOW THEY CHARGE TODAY
Fortinet
M · S · Infl
SHIPPED AGENTIC PRODUCTS

FortiAI is Fortinet's generative AI assistant embedded across FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiManager. It provides natural language search, alert summarization, and automated incident narrative generation to help security operations center analysts triage events faster. Fortinet documentation describes FortiAI as a feature layered into existing product licenses rather than a standalone product with its own SKU.

Placement:
M
 on independence,
S
 on job width, and
Inflecting
 on the value curve.

Fortinet does not publish list prices for FortiGate appliances, FortiGuard subscriptions, or FortiAI capability on its corporate website; pricing is quoted through its channel of resellers and distributors and varies by appliance model, throughput tier, and bundled service term. Fortinet's public 10-K filings describe revenue as split between product revenue, largely hardware and perpetual software license sales, and service revenue, which includes FortiCare support and FortiGuard security subscription bundles sold on one, three, or five year terms.

FortiAI generative assistance and FortiGuard AI-powered detection services are documented as features included within existing FortiAnalyzer, FortiSIEM, FortiSOAR, and FortiGuard subscription tiers rather than sold under a separate meter or usage-based price. Fortinet has not published a standalone price list, consumption unit, or per-agent fee for FortiAI as of the research cutoff date.

Public sector and enterprise customers typically procure Fortinet products through negotiated reseller contracts, and Fortinet's SEC filings note volume-based and multi-year discounting is common in large deployments, though specific discount percentages are not publicly disclosed. In the absence of a published price list for AI-specific functionality, pricing not public applies to FortiAI and FortiGuard AI-powered services as distinct billable units.

HOW THEY CHARGE TODAY
Cisco (Secure Network Analytics / Splunk)
M · M · Infl
SHIPPED AGENTIC PRODUCTS

Formerly Cisco Stealthwatch, Secure Network Analytics ingests NetFlow and other telemetry from switches, routers, and firewalls to build behavioral baselines and detect anomalies such as lateral movement, data exfiltration, and encrypted traffic threats without requiring dedicated sensors on every segment. It integrates with Cisco Identity Services Engine and other Cisco security products for automated policy enforcement.

Placement:
M
 on independence,
M
 on job width, and
Inflecting
 on the value curve.

Cisco does not publish list pricing for Secure Network Analytics; the product is sold through Cisco's channel and direct sales teams, typically licensed by network flow volume or number of monitored devices as part of broader Cisco Secure or networking bundles. Pricing not public.

Splunk products, including Enterprise Security and SOAR, have historically been licensed by data ingest volume per day, with Splunk having introduced workload-based and consumption-based pricing tiers prior to the Cisco acquisition. Cisco has indicated it intends to maintain Splunk's existing licensing models in the near term while exploring longer-term integration with Cisco's own enterprise agreement structures. Public sources do not confirm a unified pricing meter across Secure Network Analytics and Splunk as of the cutoff date.

There is no publicly documented separate price meter specifically for AI or automation features within Secure Network Analytics or Splunk's AI Assistant; these capabilities appear to be bundled into existing product tiers rather than billed as a discrete add-on based on available public documentation.

HOW THEY CHARGE TODAY

Not covered

Corelightbuilds the evidence pipeline that most of the other tools on this page depend on, on top of Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies toNetography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.