Darktrace
Also known as: Darktrace ActiveAI Security Platform, ActiveAI, Cyber AI Analyst, Antigena, Darktrace PREVENT, Darktrace DETECT, Darktrace RESPOND, Darktrace HEAL, Enterprise Immune System, Cado Security, Cybersprint
Self-learning AI that models each customer's normal and flags deviation, with Cyber AI Analyst investigating every alert into a written summary and Autonomous Response acting in Human Confirmation or autonomous mode; cloud regions chosen by the customer.
Darktrace builds self-learning AI that models the patterns of life of each customer's environment and treats deviation from that learned normal as the signal, across network, email, cloud, operational technology, identity, SaaS and endpoint.
Cyber AI Analyst investigates every alert, including custom and third-party alerts, by questioning data, testing hypotheses and reaching conclusions with its own machine-learning models (DEMIST-2 for attacker behavior and DIGEST for escalation risk), deliberately without prompt-based generative AI, and produces a natural-language summary with its decision logic and recommended actions for each incident.
Autonomous Response acts on threats by blocking matching connections, isolating devices or enforcing a device's normal pattern of life, natively or through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike; it can run in Human Confirmation mode, where the team confirms each action, or autonomously within guiderails set by time window, device group and event type. The platform integrates with 40+ SIEM, SOAR, EDR, firewall, cloud and collaboration tools.
Darktrace runs cloud infrastructure in customer-chosen regions across AWS, Azure and Google Cloud and publishes appliance specifications for on-network deployment. It holds ISO 27001, ISO 42001, ISO 27018, Cyber Essentials and IRAP. OpenAI Daybreak models for incident context and a SECURE AI product for monitoring enterprise AI agents are in development.
Vendor details
Canonical URL
https://www.darktrace.com
Category
Security / SOC agent
Subcategory
Self learning autonomous detection and response
Funding status
Private, owned by Thoma Bravo since a take-private completed in October 2024.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
40+ integrations across SIEMs (Microsoft Sentinel, Elastic, LogRhythm, InsightIDR), SOAR (Cortex XSOAR, FortiSOAR, InsightConnect), EDR (CrowdStrike Falcon, Carbon Black, Cybereason, Microsoft), firewalls (Check Point, Cisco, Fortigate, Juniper), AWS, Azure, Google Cloud, Microsoft 365, Google Workspace, Jira and Teams. Autonomous Response acts through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike, and Cyber AI Analyst ingests third-party alerts and common log formats.
In practice
A security team faces a threat with no known signature, and the platform acts on it anyway because it deviates from that organization's own learned normal rather than matching a global indicator.
An analyst opens Cyber AI Analyst to find alerts already correlated across network, cloud and email into a written incident narrative with a priority attached.
An industrial operator extends the same anomaly detection into operational technology environments where signature based tooling has poor coverage.
Sources & related URLs
Research sources
Agentic Index coverage score
7.5 / 14 capabilities · 54%
| Integrations & Tool Calling | Full |
|---|---|
|
40+ named integrations across SIEMs (Sentinel, Elastic, LogRhythm, InsightIDR), SOAR (Cortex XSOAR, FortiSOAR, InsightConnect), EDR (CrowdStrike Falcon, Carbon Black, Cybereason, Microsoft), firewalls (Check Point, Cisco, Fortigate, Juniper), clouds, Jira and Teams; Autonomous Response acts through third-party firewalls, Microsoft Defender for Endpoint and CrowdStrike, and Cyber AI Analyst ingests third-party alerts. Sourcedarktrace.com/integrationsread 2026-09-28 |
|
| Workflow Orchestration | Partial |
|
Detection and Cyber AI Analyst investigation lead into Autonomous Response and then recovery, a fixed product pipeline. Cyber AI Analyst is a single investigating agent, and Autonomous Response is configured by time window, device group and event type rather than through a flow the buyer builds. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Knowledge Grounding & RAG | Partial |
|
Darktrace's self-learning AI models each customer's patterns of life and flags deviation, and Cyber AI Analyst runs ML models (DEMIST-2, DIGEST) over the customer's telemetry. The knowledge lives in learned models whose runs return predictions, not in a structure the customer can add knowledge to without retraining. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Human Oversight & Guardrails | Full |
|
Autonomous Response can run in Human Confirmation mode, where the team confirms actions before they execute, or entirely on its own within guiderails set by time window, device group and event type. Teams typically start in Human Confirmation mode. Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28 |
|
| Security, Identity & Governance | Partial |
|
Darktrace's trust center at trust.darktrace.com lists ISO 27001:2022, ISO 42001:2023 and ISO 27018, along with Cyber Essentials and IRAP. Its only SSO statement covers Darktrace's own employees, and nothing describes SSO, a role model or permissions for the customer console. Sourcetrust.darktrace.comread 2026-09-28 |
|
| Observability & Auditability | Partial |
|
Each Cyber AI Analyst investigation produces a natural language summary with its decision logic and recommended actions, and re-investigates as new data arrives. That is a write-up and decision record for each investigation; no log of each step or action is described, for the analyst or for Autonomous Response. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Memory & State Persistence | Not documented |
|
The learned pattern of life model is a detection model, not agent memory, and no memory with a scope and lifetime is described. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Deployment & Data Residency | Full |
|
Cloud infrastructure on AWS (US, Canada, UK, Ireland, Netherlands, Australia, Singapore), Azure (US, UK, Canada, UAE, Netherlands, Ireland, Singapore, Australia, South Africa) and Google Cloud (US, Netherlands), with "location based upon customer's choice": a named region list with selection. Darktrace also publishes appliance specifications for on-network deployment. Sourcetrust.darktrace.comread 2026-09-28 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Separate products cover network, email and cloud, as well as OT, identity and endpoint, and each runs the self-learning AI and Cyber AI Analyst on its own domain, so removing one leaves the others whole. Native Autonomous Response actions need no scripting. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Triggers & Channel Coverage | Full |
|
Cyber AI Analyst investigates every alert, including custom alerts and third-party triggers and log feeds from SIEM and SOAR, and Autonomous Response acts on detections by event type and time window: alert-arrival wakes. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| Model Flexibility & Routing | Not documented |
|
Cyber AI Analyst runs Darktrace's own ML models (DEMIST-2, DIGEST) and deliberately avoids prompt based generative AI; OpenAI Daybreak models are being added in development (September 2026). The models are Darktrace's own, and the customer has no choice among them. Sourcedarktrace.com/cyber-ai-analystread 2026-09-28 |
|
| APIs, SDKs & MCP Extensibility | Partial |
|
SOAR integrations such as Cortex XSOAR, FortiSOAR and InsightConnect imply a programmable interface into Darktrace, but no API reference, SDK or MCP server is published. Sourcedarktrace.com/integrationsread 2026-09-28 |
|
| Testing, Debugging & Optimization | Not documented |
|
Attack path simulation and readiness exercises test the customer's estate and response plan, not the AI, and Human Confirmation mode is oversight rather than evaluation. Nothing is offered for evaluating Cyber AI Analyst or Autonomous Response themselves. Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28 |
|
| Browser & Computer Use | Not documented |
|
Darktrace works on telemetry and acts through native controls and integrations; no browser or computer use by an agent is documented. Sourcedarktrace.com/darktrace-autonomous-responseread 2026-09-28 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Contact sales
not disclosed
What is public
Nothing on price.
Billing mechanics
Not publicly disclosed; sold through sales and partners.
Cost watchouts
Inference, not stated by the vendor: coverage is sold by domain product, so extending to more of the estate adds cost.
Variable cost rationale
Inference, not stated by the vendor: with no billing unit published, cost depends on which domain products and how much of the estate are covered.
Additional watchouts
Scope the domain products deliberately, since cross-domain correlation is part of the value case.
Sales call required
Yes, required for paid access
Free / trial
Not published
Commercial notes
Private, owned by Thoma Bravo.
Key ambiguities
No rate card or billing unit is published.
Missing data
All pricing and packaging.
Related vendors
- 7AI — Agentic SOC from the Cybereason founders: domain specialized agents…
- Abnormal AI — Behavioral AI email security with three named autonomous agents: a…
- AirMDR — AI-native MDR whose AI analyst investigates every alert and writes…
- Airrived — Agentic OS that unifies SOC, GRC, IAM, vulnerability management, IT,…
- Andesite — Human-AI SOC platform where customers build their own agents and…
- Anvilogic — Agentic security operations platform that works on top of existing…
Alternatives to Darktrace
The closest documented capability profiles to Darktrace among security and SOC agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Radiant Security6.0 / 14A lighter documented profile than Darktrace
- Sprinto9.0 / 14Fuller documented coverage on Workflow Orchestration and Security, Identity & Governance
- Anvilogic8.5 / 14Fuller documented coverage on Workflow Orchestration and Knowledge Grounding & RAG
- DeepKeep8.5 / 14Adds documented Testing, Debugging & Optimization
- Okta8.5 / 14Fuller documented coverage on Security, Identity & Governance and Observability & Auditability
- Operant AI7.5 / 14Fuller documented coverage on Security, Identity & Governance and Observability & Auditability
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded