Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed

ExtraHop Reviews & Product Details

ExtraHop Overview

What is ExtraHop?

ExtraHop is the cybersecurity partner enterprises trust to reveal cyber risk and build business resilience. The ExtraHop RevealX platform for network detection and response and network performance management uniquely delivers the instant visibility and unparalleled decryption capabilities organizations need to expose the cyber risks and performance issues that other tools can’t see. When organizations have full network transparency with ExtraHop, they can investigate smarter, stop threats faster, and keep operations running. RevealX deploys on premises or in the cloud. It addresses the following use cases: - Ransomware - Zero trust - Software supply chain attacks - Lateral movement and C2 communication - Security hygiene - Network and Application Performance Management - IDS - Forensics and more A few of our differentiators: Continuous and on-demand PCAP: Full packet processing is superior to NetFlow and yields higher quality detections. Strategic decryption across a variety of protocols, including SSL/TLS, MS-RPC, WinRM, and SMBv3, gives you better visibility into early-stage threats hiding in encrypted traffic as they attempt to move laterally across your network. Protocol coverage: RevealX decodes more than 70 network protocols. Cloud-scale machine learning: Rather than relying on limited "on-box" compute power for analysis and detections, RevealX uses sophisticated cloud-hosted and cloud-scale machine learning workloads to identify suspicious behavior in real time and create high-fidelity alerts. ExtraHop was named a Leader in The Forrester Wave™: Network Analysis and Visibility, Q2 2023. Key Technology Integration and Go-to-Market Partners: CrowdStrike: RevealX integrates with CrowdStrike Falcon® LogScale, Falcon Insight XDR, Falcon Threat Graph, and Falcon Intelligence. Splunk SOAR AWS Google Cloud Security Founded in 2007, ExtraHop is privately held and headquartered in Seattle, Wash. To learn more, visit www.extrahop.com.

ExtraHop Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

ExtraHop Reveal(x) provides cloud-native visibility, detection, and response for the hybrid enterprise.

How do you position yourself against your competitors?

ExtraHop offers a single, independently top-rated, industry-leading platform for network detection and response (NDR), network performance management (NPM), IDS, and forensics.

The ExtraHop RevealX platform provides better visibility across more layers of the network than competing NDR and NPM solutions for a variety of reasons, including:
1) We capture full packets, instead of relying on partial packets, NetFlow, or deep packet analysis.
2) We decode more than 70 network, database, application, and internet protocols, including Microsoft protocols like Kerberos, MSRPC, LDAP, WINRM, SMBv3, and NTLM. This facilitates faster troubleshooting and MTTR on the performance side and faster MTTD and MTTR on the security side.
3) We decrypt SSL and TLS 1.3 passively and in real time, at speeds up to 100 Gbps, so you can maintain visibility while leveraging the latest encryption standards and also detect encrypted Microsoft protocol attacks and living off the land techniques.


Seller Details
Company Website
Year Founded
2007
HQ Location
Seattle, Washington
Twitter
@ExtraHop
11,028 Twitter followers
LinkedIn® Page
www.linkedin.com
725 employees on LinkedIn®
Description

ExtraHop Networks is a leading provider of cloud-native network detection and response solutions. The company specializes in delivering real-time visibility and analytics for IT environments, enabling organizations to monitor application performance, detect security threats, and optimize network operations. ExtraHop's platform leverages machine learning and advanced analytics to provide deep insights into network traffic and user behavior, helping enterprises enhance their security posture and improve operational efficiency. For more information, visit their website at https://www.extrahop.com/.


ML
Overview Provided by:

Recent ExtraHop Reviews

Verified User
A
Verified UserMid-Market (51-1000 emp.)
5.0 out of 5
"Great Product!"
One of the great things about ExtraHop is how it works like an IDS for us. Where our existing EDR failed to detect anomalous activity, ExtraHop im...
Dev S.
DS
Dev S.Enterprise (> 1000 emp.)
5.0 out of 5
"Extrahop Reveal(x) 360- An absolute must for Network Visibility"
Extrahop provides East-West network visibility and can customize rules, providing deep packet inspection capability to our security team. Extrahop ...
Verified User
I
Verified UserEnterprise (> 1000 emp.)
5.0 out of 5
"RevealX from a daily user perspective"
Overall, RevealX is easy to use and provides great visibility into the network. ExtraHop has very thorough documentation and if you can't find what...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

ExtraHop Media

ExtraHop Demo - Mitre
ExtraHop Reveal(x) provides especially strong coverage of late stage TTP categories, with 89% coverage of the TTPs in the Lateral Movement, Command & Control, and Exfiltration stages, and 100% coverage of TTPs labeled as “Requires Network.”
ExtraHop Demo - Activity Map
With a real-time view across the hybrid enterprise, including into sessions with SSL/TLS cryptography, ExtraHop Reveal(x) makes it easy for analysts, SOC managers, and executives to focus on high priority threats, likely targets, and critical workloads.
ExtraHop Demo - DCSync
By uniting rule and behavior-based analytics, ExtraHop Reveal(x) detects and triages known and unknown threats with more accuracy and deeper context than log or agent-based solutions.
ExtraHop Demo - Main Dashboard
Securing the modern enterprise means protecting a complex web of workloads consisting of hardware, applications, and data spread across edge, core, remote workforce, and cloud deployments. With ExtraHop Reveal(x), you can unify security controls across hybrid, multicloud, and IoT environments wit...
ExtraHop Demo - Pie Graph
ExtraHop Reveal(x) provides full context and one-click investigation workflows for every detection so tier 1 analysts can perform like tier 3 experts.
Play ExtraHop Video
Play ExtraHop Video
Play ExtraHop Video
Play ExtraHop Video
Play ExtraHop Video

Official Downloads

Answer a few questions to help the ExtraHop community
Have you used ExtraHop before?
Yes

67 ExtraHop Reviews

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
67 ExtraHop Reviews
4.6 out of 5
67 ExtraHop Reviews
4.6 out of 5

ExtraHop Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for ExtraHopQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
JH
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

I like that ExtraHop identifies the alert in a mannert that is easy to follow. It gives the risk level of the alert, shows the metrics, breaks down the records for the incident, shows the packets involved, and even includes a pcap of the packets that can be used in WireShark to analyze further. It also gives the Mitre techniques as well as mitigation options to mitigate the attack. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

I haven't found to many things I dislike about ExtraHop. It is not an automated system that will block an attack as it is happening, but it does e-mail out alerts so that I have the ability to begin investigating the incident as soon as possible leading to a faster mitigation scenario. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

As an ISP our network security is very important. ExtraHop is a tool to help ensure we are seeing any attack in realtime, giving us the ability to troubleshoot and mitigate the issue in a speedy manner. We have the abilty to isolate traffic quickly when an issue arises. Review collected by and hosted on G2.com.

Verified User in Telecommunications
IT
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

Overall, RevealX is easy to use and provides great visibility into the network. ExtraHop has very thorough documentation and if you can't find what you're looking for the support and training teams are always willing to help. I've experienced a quick turnaround for questions around the product. The training team is excellent at maintain user engagement in a virtual setting. The product is also super customizable which is great for unique use and abuse cases.

I use RevealX almost daily, my top three pros from a technical perspective are the increased visibility of the network, customizing doesn't mean learning a new language, and low barrier to entry for analysts who are new to networking and security. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

My top three cons for the product are that when adjusting baseline metrics, the baseline completely resets and there is a 3-4 week period before the baseline is calculated. Going off the above, it does not perform "lookback" searches for detections, meaning I can't craft a detection today and then see if the logic matches any stored data in the tool. Some of the customization areas need a bit of work so that they tie into the other features of the product. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

ExtraHop enables us to have better visibility. This has resulted in us making configuration changes on hardware and network devices to decrease our attack surface. Review collected by and hosted on G2.com.

Verified User in Higher Education
AH
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

ExtraHOP provides great visibility for performance and security issues in our environment. Many of the detections, dashboards, and device groups provide easy starting points for learning to use extraHOP. Then, building custom dashboards and detections is very simple. We use extraHOP every day to assist us resolving problemes. The customer support and partnership we have with extraHOP has been key to our success. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

You need to really understand your environment from the network layer to the application layers. extraHOP provides many options, but you need to determine what works best for your environment. It does take some time for planning the implementation properly but the planning and design time is worth it. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

extraHOP has helped us solve authentication issues, storage issues, server issues, network performance issues, security problems and other application problems. We had many blind spots and extraHOP has helped us gain visibility to many of our services. Review collected by and hosted on G2.com.

Verified User in Internet
AI
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

We've tested the product using reputable 3rd party pentesters manual and automated. And we've compared it with other products. The difference between seeing that you are being compromised and not seeing it is huge. How do you choose a competitive product that is cheaper if it doesn't see that you are being compromised? Or how do you rest at night knowing that you've done everything you can to safeguard your network? Extrahop's visibility is far above the rest. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

It is pricey. So if you are Misinformed and think that backups, firewalls, and anti-virus solutions are going to save you then you aren't going to understand the price of this product. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

Mainly keeping our company from experiencing a ransomware event. We have staff dedicated to keeping their eye on the product and chasing down alerts 24/7/365. Review collected by and hosted on G2.com.

Verified User in Computer Software
AC
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

With ExtraHop deployed in our network we now have real-time visibiltity and insights into network traffice and performance. Helps us troubleshoot, optimize and secure the network. ExtraHop platform is very easy to use, and has an intuitive easy to follow layout helping us review detections quickly. ExtraHop delivered on promises and provided excelent customer service. This is a tool that I use everyday to keep on eye on the network security. Deploying the devices in the infrastructure can be as simple as connecting to the network and mirroing all traffic to the device. This allows quick visability on the overall network performance and health. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

It can be expensive to deploy, can generate many false positives and has limited integrations into other tools and platforms. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

ExtraHop is helping us monitor network security, identify bottlenecks and improve overal performance and security related to overall network hygine. Review collected by and hosted on G2.com.

KM
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Seller invite
Incentivized Review
What do you like best about ExtraHop?

1. Seamless monitoring.

2. Simple and straightforward rule tuning.

3. Dashboard capabilities Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

1. Lot of false positives.

2. Machine learning model is not flexible to the requirements.

3. Sometimes performance issues. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

Its providing detections that are required to ensure all the permiters are covered. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ExtraHop?

ExtraHop provides valuable insight into network activities and alerts on anomalies that you can't get from just monitoring logs. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

Number one issue with ExtraHop is SIEM integration if there is no native connector available. building it through a java script trigger is not user friendly.

Number two issue is threat feeds. We have a high-fidelity threat feed we'd like to add, but we have to make a cludgey system where we download the feed, gzip it, then upload it back to ExtraHop. Please build in native STIX/TAXII feeds to the product.

I'd say trigger complexity is also a downside to ExtraHop. Not many security analysts will be able to understand and write the java code necessary for triggers. It would be nice to have a building block method for triggers where novices could build out most of it with pre-defined blocks fo code, something like a visual workflow. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

There are activities that only occur on the network and will not show up in logs. ExtraHop is able to perform threat and anomaly detection on endopint and application communications that you won't get from your other security applications.

Packet capture is not an easy system to setup. If you purchase the ETA, you have access to valuable packet information that can make a difference in a incident investigation. Review collected by and hosted on G2.com.

RT
Senior IT Security Engineer
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ExtraHop?

Extrahop looks at both on-prem and cloud traffic. It analyzes packets for security anomalies at a scale that I have not seen happen before. It also does application performance at a level that gives a very detailed visibility Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

I do hope they would come up with their proprietary agents for the cloud nodes instead of using rpcapd, which I find can be a bit unstable especially in high-traffic scenarios Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

Extrahop was able to show us some east -west traffic that should not have been happening. We also had a constant stream of complaints about the datawarehouse being slow and always having the network blamed. But once we had Extrahop we were able to pin-point and prove that the delay was happening at the database level not at the network layer. We could never have seen this without Extrahop Review collected by and hosted on G2.com.

Dev S.
DS
Security Lead
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
(Original )Information
What do you like best about ExtraHop?

Extrahop provides East-West network visibility and can customize rules, providing deep packet inspection capability to our security team. Extrahop Packet capturing feature plays a vital role in network forensics. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

Extrahop should extend its partnership with threat researchers and vendors to enrich its intel feeds and database for actionable intel on detections. Also, extend its partnership for API integration with tools like Tanium/SCCM, PAN firewalls etc Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

Extrahop provides visibility for network traffic that helps with East-West network segmentation. Extrahop Reveal(x) 360 helps during investigations and One-Click containment during an Incident reducing the response time to a greater extent. Review collected by and hosted on G2.com.

MR
Server Admin
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ExtraHop?

I like being able to drill down into the options and get the data I want. I can easily change my mind and go back or what I am looking for. Review collected by and hosted on G2.com.

What do you dislike about ExtraHop?

After taking some technical training for the product, I found that you need to invest the time to make a good dashboard for your needs. Having everything at your finger tips is valuable and makes it quick to figure out issues. Review collected by and hosted on G2.com.

What problems is ExtraHop solving and how is that benefiting you?

Big issue this has solved is user password lock outs, Where it's coming from and who it is. Also it has helped with being able to see traffic from server to server. Review collected by and hosted on G2.com.