ZeroFox Reviews (166)

Reviews

ZeroFox Reviews (166)

4.4
166 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the product for its ease of use and responsive support, which streamline the takedown process and enhance brand protection. The platform's ability to automate alerts and provide actionable intelligence helps organizations manage digital risks effectively. However, some users note that the takedown times can be lengthy, which may hinder immediate response efforts.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Yelen M.
YM
Yelen M.
Marketing Associate
"Effective Scam Monitoring with Room for Improvements"
4/5
What do you like best about ZeroFox?

I like that ZeroFox makes it easy to track potential threats and scams that could damage our company's name. The status feature of the platform is really clear, showing if an issue is new, reopened, or if a takedown was requested, accepted, or denied, which helps me manage the issues efficiently. My former account manager, Larissa, was very attentive, and typically, both account managers and the platform escalate relevant issues, which reduces my work. Also, the initial setup was straightforward since we received regular updates via an Excel file from our account manager. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

It's often repetitive because the same issues from the past are reopened. And also disappointing when registrars don't accept the takedown but there's nothing much we can do about it. When there's a reopened issue, we'd appreciate more clarity on why an issue was closed initially and why it was reopened, more intelligence in the platform regarding false positives and to continue disregarding false positives for future scans. Another complexity has been to delimit and update the list of whitelisted domains. Review collected by and hosted on G2.com.

Andrea P.
AP
Andrea P.
Security Engineer
Mid-Market (51-1000 emp.)
"Comprehensive, Easy-to-Use Brand Protection with Strong Service and Onboarding"
4/5
What do you like best about ZeroFox?

What I like best about ZeroFox is how comprehensive yet straightforward it is to use for brand protection. It covers the full workflow end-to-end — from phishing website detection and submitting takedown requests, to dark web monitoring for potential data leaks — without being overly complex to operate day to day.

I also appreciate the level of service from their team. The launch/onboarding configuration was well handled, and the recurring check-in meetings are genuinely useful. They actively listen to customer feedback and it’s clear they take it seriously. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

What I dislike is mostly around some usability and customization details. Access control could be more granular, especially RBAC and visibility controls, so different teams can be limited to only the assets or alert types relevant to them (for example, allowing marketing to view impersonation-related alerts without access to data leak or dark web monitoring). Today, achieving that kind of separation can require duplicating configurations, which adds unnecessary overhead.

Alert search and day-to-day alert handling could also be improved to make investigation and triage faster. Reporting could also be stronger, particularly around more customizable customer reports (e.g., filtering and trending by geolocation and industry, and risk scoring based on alerts and monitored assets).

Finally, the physical security module feels very US-oriented and would benefit from stronger coverage and relevance for European organizations. Overall these are smaller details, but addressing them would make the platform even better. Review collected by and hosted on G2.com.

RC
Rodolfo C.
Enterprise (> 1000 emp.)
"Reliable Intel and Takedown Precision, Needs Automation"
4.5/5
What do you like best about ZeroFox?

I like using ZeroFox for intelligence research because it helps maintain awareness, especially for a CTI analyst. It provides visibility on things that we're not getting from other vendors and delivers reports in a timely manner. I also appreciate the ability to check for chatters in the underground world, the functionality to takedown domains trying to impersonate our company, and staying informed on the latest campaigns or intel. The ZeroFox Intelligence Research really stands out for me. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

I don't like that the takedowns feature is not automated and grab the evidence by itself instead of asking for proof from the client. Implementing an automation for takedowns where it does the research on its own would be better. CrowdStrike is already doing that. Review collected by and hosted on G2.com.

GK
Guru Charan K.
Security delivery analyst
Enterprise (> 1000 emp.)
"A Powerful and Proactive Digital Risk Protection Partner"
5/5
What do you like best about ZeroFox?

The platform's ease of use is a major highlight; the dashboard is incredibly intuitive, allowing us to quickly assess our external risk posture without a steep learning curve. This simplicity encourages high adoption, and it has become a tool we rely on with high frequency of use - it's integrated into our security team's daily operational checks.

The ease of implementation was also impressive. We were up and running in less than a day, with our core assets configured and alerts flowing in. It also offers great ease of integration; we've connected it to our SIEM via its API, which allows us to correlate external threat data with our internal logs for a more unified security view.

The sheer number of features is comprehensive. We get immense value from the automated takedown services for phishing sites and the proactive intelligence on fraudulent domains and executive impersonations.

Finally, the customer support has been excellent. On the few occasions we've needed assistance - once to help fine-tune a complex alerting rule - our account manager was responsive, knowledgeable, and provided a clear resolution quickly. It's a complete package that delivers tangible results. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

While the platform is powerful, the initial volume of alerts can feel a bit overwhelming until everything is properly tuned. In our first couple of weeks, we saw a noticeable number of false positives, which meant extra manual review along with ongoing rule tweaks and adjustments.

Also, although the main dashboard is easy to use, I think the reporting module could offer more flexibility. I’d like to be able to create more granular, bespoke reports directly in the UI, rather than exporting raw data and manipulating it elsewhere. Strengthening the advanced alert-filtering logic as well (for example, supporting multi-conditional rules) would be a welcome improvement and would help us narrow in on the most critical threats even faster. Review collected by and hosted on G2.com.

Verified User in Non-Profit Organization Management
EN
Verified User in Non-Profit Organization Management
Enterprise (> 1000 emp.)
"ZeroFox Streamlines High-Volume Takedowns with Best-in-Class Automation"
4.5/5
What do you like best about ZeroFox?

ZeroFox takedown capabilities are second to none. We have a high volume of takedown requests and the automated process is streamlined and effective. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

There may be risk with future renewals as they are moving a few SKUs away from unlimited quantity. However, the account executive is transparent with the change as we move closer to renewal. Review collected by and hosted on G2.com.

Folakunmi A.
FA
Folakunmi A.
Security Engineer
Enterprise (> 1000 emp.)
"Great for Takedowns"
4/5
What do you like best about ZeroFox?

I love the account takedown feature in ZeroFox. I also like the domain takedown tool, which is pretty handy. Additionally, I appreciate that it helps take down apps masking my own from the Play Store and Cloud Store. Another feature I love is the intro it gives into the dark web, especially if any customer data or organizational data is being sold there. It's a very beautiful capability. The initial setup of ZeroFox was quite easy and straightforward. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

I would say for users with infected hosts and users with compromised credentials, sometimes we get some behind alerts in the sense that we don't get to see the URL. You're saying you're having a compromised credential, but you don't even know the domain at which this compromised credential is for. Then two, sometimes we don't get enough visibility into the dark web alerts. We just see the Telegram alert and think it can be done better in that aspect. Review collected by and hosted on G2.com.

Bachar Y.
BY
Bachar Y.
Manager
Small-Business (50 or fewer emp.)
"Efficient Brand Protection, Could Improve Discovery"
4/5
What do you like best about ZeroFox?

I find ZeroFox to be doing good, especially the tool and the search feature, which help in shutting down malicious websites. The response from the portal is also good, and the integration makes it nice and easy to submit a request. The integration with our SSO environment makes submitting a ticket very easy; you just copy the website or URL and submit the follow-up. Furthermore, the platform is accessible from an iPad, phone, or portal, which makes it easy to reach and submit the environment. Scanning or searching for the public website is also helpful. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

The Discovery sometimes is not good. I don't know because maybe it's very big. And maybe it's consuming a lot of the Internet because nowadays, the new AI tools, it's always nowadays instead of ZeroFox discover the website or the patent, we are getting information from our client or somebody from legal to department that we have discover a site. So that should be something in ZeroFox to be able to do more discovery and depend on what we give the name, the patent, and all these things. Review collected by and hosted on G2.com.

AH
Ahmad H.
Cyber Security Associate
Enterprise (> 1000 emp.)
"Comprehensive Threat Intelligence with Room for Improvement"
4/5
What do you like best about ZeroFox?

I use ZeroFox at my job mainly for brand insight, threat intel, and brand image protection. I appreciate that it helps me look out for possible threat leads and close any gaps visible to threat actors publicly. I like that I can look through frequently updated databases and breaches, meaning I never miss out on any recent activity related to both publicly and privately held breaches. I also really appreciate having a team that handles all the nitty gritty stuff, like legal work and going back and forth with companies and platforms. The initial setup was rather simple—just identifying our assets, providing asset details, and handling escalations and submissions. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

I really think the intelligence search needs to be revamped to include more filters and more parameters. For example, you should be able to select a specific time range or a date range. You should be able to expand each indexed item and view all the parameters in detail. Review collected by and hosted on G2.com.

Lizeth Yanira G.
LG
Lizeth Yanira G.
Small-Business (50 or fewer emp.)
"Centralized Monitoring, But Late Notifications"
4/5
What do you like best about ZeroFox?

What I like most about ZeroFox is the ability to centralize brand monitoring across multiple sources, which greatly facilitates the identification of potential threats without having to constantly perform manual searches. I also highlight the quality of some findings, especially in matters of brand impersonation and suspicious domains. Additionally, the initial setup of ZeroFox was very easy. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

I have noticed that on certain occasions the detection and notification of findings is not as timely as expected, which can affect response capability. You could improve by optimizing the frequency of scans on critical sources and perhaps incorporating near real-time alerts or lower latency for certain types of high-priority findings. Review collected by and hosted on G2.com.

KJ
Kyle J.
IT Security Officer Assistant
Mid-Market (51-1000 emp.)
"Effective Dark Web Monitoring with User-Friendly Interface"
4/5
What do you like best about ZeroFox?

I like ZeroFox because of its ease of use, which makes it very user-friendly. One of my favorite features is the alerts tab, providing very detailed information on potential threats we observe. This feature keeps us aware of threats aimed at our institution and makes investigating or elevating alerts quite straightforward. Review collected by and hosted on G2.com.

What do you dislike about ZeroFox?

I have issues with the AI aspect of ZeroFox, especially in determining the legitimacy of some alerts, like domain analysis. I've noticed these are mainly false positives. I think they rely too much on potential typosquat or substring aspects without accurately comparing potential reported sites to our institution's own. Review collected by and hosted on G2.com.