Blog
/
/
January 24, 2021

Darktrace Vers. 5: AI Transforming Enterprise Security

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
24
Jan 2021
Darktrace's Immune System Version 5 revolutionizes cybersecurity with AI, cloud service coverage, and seamless integrations.

Today’s workforce is more dispersed and mobile than ever before, with critical operations increasingly residing in a diverse patchwork of cloud services and endpoints. This architectural shift has been met by attacks that have scaled up to capitalize on insufficiently protected data and devices, emphasizing the need for enterprise security to be adaptive, autonomous, and ubiquitous.

Increasing demands placed on the SOC have stretched security teams to breaking point, and CISOs now progressively seek to streamline workflows by favoring self-learning enterprise-wide security platforms over disparate and siloed point solutions with limited visibility.

Version 5 offers a series of innovations across Darktrace’s Immune System platform, bringing critical value to security teams grappling with the new normal. This free upgrade for existing customers allows for on-demand automated investigations, supports one-click integrations with a wide range of technologies, and showcases an improved Model Editor that allows security teams to tailor Darktrace even further to their specific business risks.

Darktrace’s Immune System has been enhanced in three critical areas: in the augmentation of its core AI capabilities, in extended coverage to SaaS applications and zero-trust environments, and an open architecture which streamlines workflows across the cyber security stack.

AI augmentation

Last year saw the introduction of new technologies, services, data flows, and topologies. Static rules and signature-based defenses were unable to adapt to changing users and working practices, no matter how diligently and rapidly they were rewritten. We have seen an urgent need for augmentation, and to that end Version 5 enhances Darktrace’s self-learning capabilities across two core areas of the platform: Autonomous Response and AI Investigation.

By containing machine-speed threats like ransomware in seconds, Autonomous Response enables security teams to prioritize strategic work even as the volume and speed of attacks continues to rise. Darktrace Antigena can either take self-directed action or integrate with existing investments, informing third-party systems about in-progress cyber-attacks.

With Version 5, Antigena can now neutralize attacks in a wide variety of SaaS services like Zoom and Microsoft Teams, as well as cloud file storage applications like SharePoint and OneDrive. In cases of account takeover, Antigena can autonomously respond, protecting sensitive data in the cloud without any human intervention.

Cyber AI Analyst also now automates investigations beyond network events to SaaS applications, cloud infrastructure, and cyber-physical systems. Version 5 enables on-demand investigations into users and devices of interest, the ingestion of third-party alerts to trigger new investigations, and seamless integration with any SIEM, SOAR, or downstream ticketing system.

Customers have already found that the new capabilities in Cyber AI Analyst have added substantial value, especially in the ability to launch on-demand investigations and query SaaS data at any time.

Dynamic workforce protection

In addition to the extension of AI-enabled investigations and response, Darktrace Version 5 complements native cloud and SaaS defenses with a range of critical enhancements, including a dedicated SaaS Console, and integrations with Zoom, Okta, Microsoft Teams, Slack, Duo, and more. Equally, new ingestion capabilities for zero-trust technologies enable Darktrace to protect employees wherever they operate.

Figure 1: Dedicated SaaS Console

Customers can also now choose to purchase Client Sensors that extend the Immune System’s visibility of the dynamic workforce on and off the VPN. With Client Sensors, organizations can take Darktrace’s existing real-time analysis and tie it in with risky or malicious behavior that may be occurring off the VPN.

Antigena Email, the world’s first self-learning email security solution, has also been enhanced with Version 5. Not only does the technology detect the subtle deviations in threatening emails that other tools miss, but with text-based summarization, the story behind every email is automatically generated in plain English so that even a non-technical reader can fully understand why specific actions were taken.

Open architecture and interoperability

Flexibility and the ability to integrate with existing enterprise security investments lie at the core of the Darktrace Immune System, and Version 5 extends its open and extensible architecture to seamlessly integrate with your existing investments. New functionality enables customers to enhance and extend their Darktrace deployment via one-click integrations. This includes the ability to immediately extend coverage to new cloud services, and enrich the platform’s analysis with new sources of log ingestion.

Version 5 also sees the introduction of bespoke new interfaces that cover the different areas of the digital infrastructure – from the aforementioned SaaS Console to a specialized OT Engineer View. These inclusions represent an overarching design principle of unification, and the interfaces are harmonized accordingly to facilitate seamless investigations and simplified workflows.

Figure 2: An autonomous investigation into anomalous cloud activity

Our customers are increasingly using the Immune System protect their business across email, SaaS, and industrial systems as well as the corporate network, and Version 5 makes it easier than ever to defend these environments.

Version 5 not only expands the Darktrace Immune System to new areas of the business, but also ensures that this expansion delivers a seamless experience for customers, regardless of where they start their journey with the platform. Delivery and expansion are entirely flexible, with the option of 100% cloud-delivered deployments, or hybrid deployments that cover on-premise and cloud environments.

Enterprise security: Innovating through times of change

As organizations accelerate digital transformation and prepare for the future of work, the ability to quickly adapt and integrate their security defenses will be more critical than ever. And with the new AI augmentation and extended coverage of Darktrace’s core self-learning technology, Version 5 ensures that customers can detect, contain, and investigate threats wherever they arise, without placing any additional burden on security teams.

Find out more about Darktrace Version 5

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
No items found.
Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

OT

/

April 4, 2025

Darktrace Named as Market Leader in the 2025 Omdia Market Radar for OT Cybersecurity Platforms

Default blog imageDefault blog image

We are pleased to announce that Darktrace / OT has been named a Market Leader in Omdia’s  2025 Market Radar for OT Cybersecurity Platforms. We believe this highlights our unique capabilities in the OT security market and follows similar recognition from Gartner who recently named Darktrace / OT as the sole Visionary in in the Magic Quadrant for Cyber Physical Systems (CPS) Protection Platforms market.

Historically, IT and OT systems have been managed separately, creating challenges due to the differences of priorities between the two domains. While both value availability, IT emphasizes confidentiality and integrity whereas OT focuses on safety and reliability. Organizations are increasingly converging these systems to reap the benefits of automation, efficiency, and productivity (1).

Omdia’s research highlights that decision makers are increasingly prioritizing comprehensive security coverage, centralized management, and advanced cybersecurity capabilities when selecting OT security solutions (1).

Rising productivity demands have driven the convergence of OT, IT, and cloud-connected systems, expanding attack surfaces and exposing vulnerabilities. Darktrace / OT provides a comprehensive OT security solution, purpose-built for critical infrastructure, offering visibility across OT, IoT, and IT assets, bespoke risk management, and industry-leading threat detection and response powered by Self-Learning AITM.

Figure 1: Omdia vendor overview for OT cybersecurity platforms
Figure 1: Omdia vendor overview for OT cybersecurity platforms

An AI-first approach to OT security  

Many OT security vendors have integrated AI into their offerings, often leveraging machine learning for anomaly detection and threat response. However, only a few have a deep-rooted history in AI, with longstanding expertise shaping their approach beyond surface-level adoption.

The Omdia Market Radar recognizes that Darktrace has extensive background in the AI space:

“Darktrace has invested extensively in AI research to fuel its capabilities since 2013 with 200-plus patent applications, providing anomaly detection with a significant level of customization, helping with SOC productivity and efficiency, streamlining to show what matters for OT.” (1)

Unlike other security approaches that rely on existing threat data, Darktrace / OT achieves this through Self-Learning AI that understands normal business operations, detecting and containing known and unknown threats autonomously, thereby reducing Sec Ops workload and ensuring minimal downtime

This approach extends to incident investigations where an industry-first Cyber AI AnalystTM automatically investigates all relevant threats across IT and OT, prioritizes critical incidents, and then summarizes findings in an easily understandable view—bringing production engineers and security analysts together to communicate and quickly take appropriate action.

Balancing autonomous response with human oversight

In OT environments where uptime is essential, autonomous response technology can be approached with apprehension. However, Darktrace offers customizable response actions that can be set to “human confirmation mode.”

Omdia recognizes that our approach provides customizable options for autonomous response:

“Darktrace’s autonomous response functionality enforces normal, expected behavior. This can be automated but does not need to be from the beginning, and it can be fine-tuned. Alternative step-by-step mitigations are clearly laid out step-by-step and updated based on organizational risk posture and current level of progress.” (1)

This approach allows security and production to keep humans-in-the-loop with pre-defined actions for potential attacks, enforcing normal to contain a threat, and allowing production to continue without disruption.  

Bespoke vulnerability and risk management

In the realm of OT security, asset management takes precedent as one of the key focus points for organizations. With a large quantity of assets to manage, practitioners are overwhelmed with information with no real way to prioritize or apply them to their unique environment.

Darktrace / OT is recognized by Omdia as having:

“Advanced risk management capabilities that showcase metrics on impact, exploit difficulty, and estimated cost of an attack […] Given the nascency of this capability (April 2024), it is remarkably granular in depth and insight.” (1)

Enabling this is Darktrace’s unique approach to AI extends to risk management capabilities for OT. Darktrace / OT understands customers’ unique risks by building a comprehensive and contextualized picture that goes beyond isolated CVE scoring. It combines attack path modeling with MITRE ATT&CK  techniques to provide hardening recommendations regardless of patching availability and gives you a clearer view of the potential impact of an attack from APT groups.

Modular, scalable security for industrial environments

Organizations need flexibility when it comes to OT security, some want a fully integrated IT-OT security stack, while others prefer a segregated approach due to compliance or operational concerns. The Darktrace ActiveAI Security Platform offers integrated security across multiple domains, allowing flexibility and unification across IT and OT security. The platform combines telemetry from all areas of your digital estate to detect and respond to threats, including OT, network, cloud, email, and user identities.

Omdia recognizes Darktrace’s expansive coverage across multiple domains as a key reason why organizations should consider Darktrace / OT:

“Darktrace’s modular and platform, approach offer’s integrated security across multiple domains. It offers the option of Darktrace / OT as a separate platform product for those that want to segregate IT and OT cybersecurity or are not yet in a position to secure both domains in tandem. The deployment of Darktrace’s platform is flexible—with nine different deployment options, including physical on-premises, virtual, cloud, and hybrid.” (1)

With flexible deployment options, Darktrace offers security teams the ability to choose a model that works best for their organization, ensuring that security doesn’t have to be a “one-size-fits-all” approach.

Conclusion: Why Darktrace / OT stands out in Omdia’s evaluation

Omdia’s 2025 Market Radar for OT Cybersecurity Platforms provides a technical-first, vendor-agnostic evaluation, offering critical insights for organizations looking to strengthen their OT security posture. Darktrace’s recognition as a Market Leader reinforces its unique AI-driven approach, flexible deployment options, and advanced risk management capabilities as key differentiators in an evolving threat landscape.

By leveraging Self-Learning AI, autonomous response, and real-world risk analysis, Darktrace / OT enables organizations to detect, investigate, and mitigate threats before they escalate, without compromising operational uptime.

Read the full report here!

References

  1. www.darktrace.com/resources/darktrace-named-a-market-leader-in-the-2025-omdia-market-radar-for-ot-cybersecurity-platforms
Continue reading
About the author
Pallavi Singh
Product Marketing Manager, OT Security & Compliance

Blog

/

Cloud

/

April 2, 2025

Fusing Vulnerability and Threat Data: Enhancing the Depth of Attack Analysis

Default blog imageDefault blog image

Cado Security, recently acquired by Darktrace, is excited to announce a significant enhancement to its data collection capabilities, with the addition of a vulnerability discovery feature for Linux-based cloud resources. According to Darktrace’s Annual Threat Report 2024, the most significant campaigns observed in 2024 involved the ongoing exploitation of significant vulnerabilities in internet-facing systems. Cado’s new vulnerability discovery capability further deepens its ability to provide extensive context to security teams, enabling them to make informed decisions about threats, faster than ever.

Deep context to accelerate understanding and remediation

Context is critical when understanding the circumstances surrounding a threat. It can also take many forms – alert data, telemetry, file content, business context (for example asset criticality, core function of the resource), and risk context, such as open vulnerabilities.

When performing an investigation, it is common practice to understand the risk profile of the resource impacted, specifically determining open vulnerabilities and how they may relate to the threat. For example, if an analyst is triaging an alert related to an internet-facing Webserver running Apache, it would greatly benefit the analyst to understand open vulnerabilities in the Apache version that is running, if any of them are exploitable, whether a fix is available, etc. This dataset also serves as an invaluable source when developing a remediation plan, identifying specific vulnerabilities to be prioritised for patching.

Data acquisition in Cado

Cado is the only platform with the ability to perform full forensic captures as well as utilize instant triage collection methods, which is why fusing host-based artifact data with vulnerability data is such an exciting and compelling development.

The vulnerability discovery feature can be run as part of an acquisition – full or triage – as well as independently using a fast ‘Scan only’ mode.

Figure 1: A fast vulnerability scan being performed on the acquired evidence

Once the acquisition has completed, the user will have access to a ‘Vulnerabilities’ table within their investigation, where they are able to view and filter open vulnerabilities (by Severity, CVE ID, Resource, and other properties), as well as pivot to the full Event Timeline. In the Event Timeline, the user will be able to identify whether there is any malicious, suspicious or other interesting activity surrounding the vulnerable package, given the unified timeline presents a complete chronological dataset of all evidence and context collected.

Figure 2: Vulnerabilities discovered on the acquired evidence
Figure 3: Pivot from the Vulnerabilities table to the Event Timeline provides an in-depth view of file and process data associated with the vulnerable package selected. In this example, Apache2.

Future work

In the coming months, we’ll be releasing initial versions of highly anticipated integrations between Cado and Darktrace, including the ability to ingest Darktrace / CLOUD alerts which will automatically trigger a forensic capture (as well as a vulnerability discovery) of the impacted assets.

To learn more about how Cado and Darktrace will combine forces, request a demo today.

Continue reading
About the author
Paul Bottomley
Director of Product Management, Cado
Your data. Our AI.
Elevate your network security with Darktrace AI