Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.
Separated marks connect to their exact positions. Separation does not change scores.
Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.
Missing evidence for this view
Unknown is not a low score. Select an offering above to inspect its evidence.
A position is only half the story
Momentum
Building history
Baseline recorded 2026-09-21. A second comparable review is needed to show movement.
Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.
Vectra AI Platform (Network)· movement by dimension
Dimension
Own movement
Against peers
Operational maturity
Building history
Not available yetNo direction inferred
Shipped innovation
Building history
Not available yetNo direction inferred
Capability breadth
Building history
Not available yetNo direction inferred
Ecosystem & integration
Building history
Not available yetNo direction inferred
Governance & control
Building history
Not available yetNo direction inferred
Operator enablement
Building history
Not available yetNo direction inferred
History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.
Review history & what changed
The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.
2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
Vectra AI Platform (Network) (medium confidence) has the highest documented score (3.3) for Operational maturity among assessed offerings in this comparison group.
Vectra AI Platform (Network) (medium confidence) has the highest documented score (4.0) for Shipped innovation among assessed offerings in this comparison group.
Unknowns and gaps
Unknown is not low quality. Marks are omitted where a required score is unknown.
Vectra AI Platform (Network): no unknown dimensions.
RevealX NDR: Governance & control
Open NDR with Investigator: Governance & control
Cisco Secure Network Analytics: Governance & control
Scenario lens
A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.
Selected evidence
Vectra AI Platform (Network) · Vectra AI
Vectra AI Platform Network detections in Respond UX; optional Match/Stream, cloud-log and identity detection surfaces, MDR and extra search entitlements excluded · Assessed 2026-09-21 · Research preview
Operational maturity
How complete is the documented collection-to-investigation operating model?
Completeness of the publicly documented operating model, not measured reliability, installed base or vendor size. Anchors are cumulative; missing evidence is unknown, never zero.
Public triage and API documentation supports an explainable operating workflow. AI-Triage is evaluated as a documented mechanism, not as proof of superior detection quality.
Score3.3 / 5.0medium confidence
Comparison:
Rationale and sources
Network collection and detections connect to scoped triage controls, disposition and tuning, satisfying stage 3. The appliance-health procedure adds 0.3. A complete Respond UX operational role matrix and action-audit procedure were not verified, so their credits are withheld.
How this score is built
3.0 anchor + 0.3 credited progress = 3.3
Next anchor: 4 — Stage 3 plus documented role permissions, audit of analyst or administrative actions, and collection-health monitoring.
Not credited: 0.3 · Documented operational role permissions
Not established by this assessment; no credit. This does not establish absence.
Not credited: 0.4 · Documented audit of analyst or administrative actions
Not established by this assessment; no credit. This does not establish absence.
+0.3 · Documented collection or sensor health monitoring procedure
The appliance-health guide provides operational monitoring of Brain and Sensor health.
Weights are shared editorial rules for this dimension and anchor interval. They are not measured performance differences.
Constraints
Respond UX and Quadrant UX have different APIs and operational behavior; procedures are not interchangeable.
Filtered detections and whitelist-hidden detections have different visibility consequences.
Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership.
AI-Triage cannot be disabled in Respond UX. Do not apply Quadrant UX toggle instructions to RUX.
This first review is a dated baseline. Momentum begins only after a second comparable review; no trend is inferred from naming or scoring changes.
Scores reflect publicly evidenced stages, not observed efficacy, market share or maturity inferred from company age. Public documentation confidence is at most medium.
Ordinary network baselines include rules or behavioral detections, context and investigation. Additional innovation credit needs inspectable output, operator controls and explicit limits.
Equivalent scores are acceptable. Decimal credits apply shared criteria totaling ten tenths and are not graph jitter.
Zeek is an educational telemetry alternative, not a scored commercial platform. Darktrace, Fortinet and Arista remain substantive catalog profiles awaiting equivalent scoped assessments.
Some operator and audit sources could not be retrieved; unverified controls remain unknown instead of being scored as absent.
Packet- and flow-based architectures differ. A comparison must retain collection, encryption, sampling and licensing constraints.
How to read these scores
Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.
What this edition covers.
First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.
This first review is a dated baseline. Momentum begins only after a second comparable review; no trend is inferred from naming or scoring changes.
Scores reflect publicly evidenced stages, not observed efficacy, market share or maturity inferred from company age. Public documentation confidence is at most medium.
Ordinary network baselines include rules or behavioral detections, context and investigation. Additional innovation credit needs inspectable output, operator controls and explicit limits.
Equivalent scores are acceptable. Decimal credits apply shared criteria totaling ten tenths and are not graph jitter.
Zeek is an educational telemetry alternative, not a scored commercial platform. Darktrace, Fortinet and Arista remain substantive catalog profiles awaiting equivalent scoped assessments.
Some operator and audit sources could not be retrieved; unverified controls remain unknown instead of being scored as absent.
Packet- and flow-based architectures differ. A comparison must retain collection, encryption, sampling and licensing constraints.
Network detection & investigation platforms
Commercial platforms that collect network-derived evidence, generate detections and support analyst investigation. Packet and flow architectures remain visible constraints. Open-source telemetry engines, standalone packet brokers, managed-service staffing and unrelated cloud/identity/email bundles are excluded.