Dimension scores are derived from public data and fields; weighted into the composite. Reference only.
Endace is an enterprise-grade cybersecurity company from New Zealand, focused on Full Packet Capture and Network Recording solutions. Its core offering is the EndaceProbe hardware appliance series and accompanying software, which can continuously record every packet in network traffic at line rate and provide millisecond-level historical search and replay. For large organizations that need deep network forensics, threat hunting, and compliance auditing, Endace is widely recognized as a benchmark tool in the industry, and is especially adopted by high-security sectors such as finance, government, and telecommunications.
Founded in 2001 and headquartered in Hamilton, New Zealand, Endace also has offices in the United States, the United Kingdom, Australia, and other regions. It is not a consumer-facing brand, but a provider focused on enterprise cybersecurity infrastructure. Its core business is a “Full Packet Capture and Network Recording” platform, meaning that unlike traditional IDS/IPS tools that only analyze traffic summaries, it preserves raw network traffic in full for deep analysis at any later point in time. Endace’s customers mainly include large banks, securities exchanges, national security agencies, telecom operators, and major internet companies. In the industry, Endace is often associated with concepts such as “network forensics” and “zero-trust network visibility.” Its appliances are typically deployed at core network nodes and serve as the underlying data foundation for security operations centers (SOCs). The company’s product line is mainly hardware probes, with virtualized versions also available, but its overall positioning is high-end and beyond the reach of ordinary users.
Endace has a very clearly defined target audience: enterprise security teams, network operations teams, and forensic investigators. More specifically, it is suitable for the following scenarios: first, financial institutions or critical infrastructure organizations that must meet strict data retention and audit compliance requirements, such as PCI DSS or the NIST framework; second, large SOC teams that need to quickly look back at attack traffic from days or even months earlier to reconstruct the full attack chain; third, cybersecurity research organizations that need to retain raw traffic over the long term for threat hunting and machine-learning model training. Endace is not suitable for individual users, small startups, or teams with only basic monitoring needs, because its deployment cost, operational complexity, and hardware requirements are all quite high. If you only need temporary packet capture and analysis, Wireshark or open-source tools such as Moloch, now renamed Arkime, may be more practical.
Endace does not publish monthly or annual pricing. Its pricing model is the typical “contact sales for enterprise quote” approach. Based on industry experience, a single EndaceProbe hardware appliance, including a one-year license, usually costs from tens of thousands to hundreds of thousands of US dollars, depending on capture rate, storage capacity, and add-on features. This places it in the high-end and relatively expensive tier among comparable products. Compared with open-source solutions such as Arkime + Elasticsearch, Endace’s hardware cost plus annual maintenance fees can be a heavy burden for small and medium-sized businesses. For large organizations, however, the investment is often treated as security insurance, because one successful data recovery or litigation-related forensic investigation may prevent losses far exceeding the cost of the equipment. It is worth noting that Endace does not offer a monthly subscription model, nor are there “hidden fees,” but annual technical support and software update contracts usually need to be renewed. This typically costs around 15%-20% of the initial purchase price.
Endace’s usability in mainland China is somewhat complicated. First, its official website is accessible from mainland China, but product documentation and the download center require registration, and some pages may load slowly. Second, Endace hardware must be shipped from New Zealand or the United States, so customs clearance procedures and import duties need to be handled by the buyer. Most importantly, Endace’s cloud management platform or some online activation services may require circumvention tools, because its infrastructure is hosted in overseas AWS regions. For payment, Endace supports international credit cards and corporate bank transfers, but usually does not accept Alipay or WeChat Pay. For Chinese enterprise users that need invoices, Endace can issue pro forma or commercial invoices from its New Zealand or US entities, but cannot provide Chinese VAT special invoices. This means domestic companies may need to purchase through an agent with import/export qualifications to satisfy financial compliance requirements. There are no fully equivalent domestic products, though Huawei HiSec Insight and NSFOCUS traffic analysis appliances have some functional overlap. However, their packet capture depth and forensic accuracy are not on the same level as Endace.
Pros:
Cons:
Endace differentiates itself by focusing on the “recording” layer rather than analysis. It is more like a “video recorder” for security teams, while other products tend to be more like a “camera” plus an “alarm system.”
Endace is best suited for the following scenario: your organization has clear compliance-driven data retention requirements, such as a financial institution that needs to retain transaction logs for more than six months, and your security team frequently needs to look back at historical traffic for attack investigations. If you are building an enterprise-grade SOC and have a sufficient budget, Endace can serve as the underlying data infrastructure. It is not suitable for individual security enthusiasts, budget-constrained small and medium-sized businesses, or teams that only need real-time alerts rather than historical records. Since Endace does not offer a publicly available free trial, it is recommended to contact sales through the official website and request a PoC, or proof of concept, or a remote demo before purchasing to confirm whether its functionality meets your actual needs. For Chinese users, if invoice and network issues cannot be resolved, it may be better to first evaluate open-source alternatives such as Arkime, or purchase through an overseas subsidiary.
⚠ This review is compiled from public sources and does not constitute a purchase recommendation. Verify all facts on the vendor's official site. Verify on endace.com official site.
endace.com is an New Zealand Security provider. TG4G tracks its product information, an overall rating of 8.0/10, and a China-accessibility score of Workable. Click "Visit Official Site" to reach endace.com directly.