Blog
/
Proactive Security
/
February 22, 2023

Find High-Impact Attack Paths with Darktrace / Proactive Exposure Management

Understand high-impact attack paths with Darktrace / Proactive Exposure Management. Learn from detailed use cases and improve your cybersecurity measures effectively.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Elliot Stocker
Product SME
Default blog image
22
Feb 2023

What are the people, process, and technology assets that would do the most harm, if compromised by an attacker?

Attack path modeling provides a detailed map of all the roads that lead to an organization's crown jewels, prioritized in order of likelihood and potential impact. CISO's are increasingly looking to this kind of solution to complement their security stack because it highlights risks that are specific to this organization's structure, as well as potentially unexpected relationships between devices or users that would prove catastrophic if they were exploited.  

What makes Darktrace's Attack Path Modeling solution stand out?

  • Data sources are varied and information from the entire digital estate is considered
  • Modeling is real-time and continuously re-evaluated
  • Output does not require expert technical knowledge to be leveraged
  • Valuable as a standalone for vulnerability prioritization
  • As a component of the Darktrace ActiveAI Security Platform, the solution provides immediate value by feeding back into detection and response engines (e.g. tag critical assets for detection) but also provides long term systemic improvements as outcomes are followed up.

Thinking like an attacker

It is anticipated that CISOs will soon move beyond just insurance and checkbox compliance, as underwriters include more and more exclusions for certain types of cyber-attacks and the limits of compliance ticking the protection box rather than bolstering operational assurance become more apparent. They will push their teams to opt for more proactive cyber security measures to maximize ROI in the face of budget cuts, shifting investment into tools and capabilities that continuously improve their cyber resilience and demonstrate cyber risk reduction.

While red teams can provide insight into where effort and resource should be most immediately applied, the exercises themselves are often costly, non-exhaustive and infrequently run.

Hackers are constantly seeking pathways, preferably those of least resistance, to compromise a system by exploiting its vulnerabilities. Attack path modeling enables security teams to look at their environment from the perspective of the attacker. In turn, this helps them eliminate attack paths progressively, reducing the options an attacker would have, should they breach the walls.

A deeper dive into Attack Path Modeling

An attack path is a visual representation of the path that an attacker takes to exploit a weakness in the system. It highlights the series of steps (attack vectors) that a threat actor might take from one of the doors into the organization (attack surface) to access valuable assets.

It is typically unusual for an attacker to have a boulevard straight down to the crown jewels. They will most likely leverage a couple of loopholes, unexpected relationships and blind spots in the security stack to piece together a path to these confidential assets. Attack path modeling can help to highlight the attack vectors that connect, to form this path to compromise.  

Figure 1: The Darktrace / Proactive Exposure Management user interface.

How to model attack paths

Darktrace's proprietary Self-Learning AI models relationships, and graph theory is incorporated to understand the importance of users, documents and relationships between these.

Darktrace's Attack Path Modeling component identifies target nodes (users, accounts, devices), it then calculates the shortest paths to these target nodes and weights the results according to the likelihood of this attack path and the damage caused if the target asset was compromised. This is exactly what an attacker would do when planning an attack, albeit with a significant advantage to Darktrace's AI Engine, which has access to more information than the attacker. For the first time, defenders have the upper hand against attackers.

Avoiding siloed efforts

According to a Gartner survey, 75% of organizations are looking at consolidating security tools, not primarily because of cost, but because it helps drive cyber risk reduction. Ensuring that security efforts are part of a wider security ecosystem, rather than siloed efforts, is crucial to maximize the return on these investments.

Darktrace / Proactive Exposure Management integrates with Darktrace's detection and response to ensure that the organization's security posture is hardened, even if the team doesn't have time to eliminate the attack path.

Defensive superiority is key, and Attack Path Modeling is one way to help security teams gain back an advantage. Find out how you can test it in your own environment.

Attack Path Modeling is an objective, however, and there are a few important questions to consider when assessing the different methods of creating these models.

Are we considering all the relevant data when building my attack paths map?

Consider the case where one of your marketing executives has a close friendship with someone in your development team. How do you model that into your attack paths cartography? Attack paths encompass the full digital estate, so the attack path modeling solution should consider information from various parts, internal and external. This may include data from the Email environment, the Network, Endpoints, SaaS & Cloud, Active Directory, Vulnerability Scanners, etc.  

Cross-data analysis is the only way to understand holistic attack paths.

Are we looking at the most up to date map of attack paths?

Relationships between users, devices and other sensitive assets can evolve on a daily basis, this implies attack paths evolve on a daily basis. Ensuring that the methods or solutions used update their understanding continuously and in real-time is vital if security teams want the most up to date understanding of their organization's risk posture.

To improve our security posture, how do we know which attack paths to start with?

One thing is to map the sum-total of attack paths, another is to prioritize them. Attack path modeling gives you the map but adding a risk-assessment (explored in more depth below) layer on top is how you prioritize. This is where graph theory can be very useful to identify choke points that you may want to strengthen.  

Does this output yield actionable insights?

The prime objective of this solution is not simply to provide an assessment of cyber risk posture, but rather to help drive security efforts in the right direction. To that end, the output needs to be accessible to team members that may not have expert cyber skills. Lowering barriers to entry with usable insights and mitigation advice is key to successfully improve the organization's security posture.

Assessing risk to prioritize attack paths

Darktrace Attack Path Modeling (APM) is a risk-based approach to assessing cyber-attack pathways, thinking like an attacker, and probing the path of least resistance. 'Risk' in this case is defined as the product of two factors: Probability and Impact. By using this information to categorize possible attack paths in the risk matrix below, Darktrace's APM can prioritize attack paths to ensure security team efforts are spent on controlling for the most relevant risks for their organization.

Figure 2: Risk matrix for attack path prioritization

A: Defining Probability

There are two types of probability to consider:

The likelihood of one particular door being chosen by an attacker to infiltrate the organization (among the assets at the attack surface - this could be an internet-facing server, an inbox, a SaaS/Cloud account, etc). And,

The likelihood of one particular node (defined as a device or user account) being compromised next, via lateral movement.

Figure 3: Simplified example of calculating probability of lateral movement from a compromised agent to one of two servers

B: Defining Impact

Impact refers to the overall impact of an asset being compromised and unusable. In the case of an asset (e.g.: a key server), the bigger the disruption if this asset goes down, the higher the impact score. If considering a particular document, restricted access and sensitivity score of users accessing it are some of the variables used to estimate impact.

Figure 4: Diagram showing a simplified example of mapping access volume and sensitivity to estimate document value.

Both variables are calculated by the AI autonomously, without requiring human input. Security teams can of course reinforce the AI's understanding of the organization with their business expertise (by tagging additional sensitive devices for example).

A more in-depth description of how impact is propagated to identify key servers or sensitive documents, as well as other components that comprise the Darktrace Attack Path Modeling module can be found in this white paper.

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Elliot Stocker
Product SME

More in this series

No items found.

Blog

/

Email

/

May 26, 2026

Journey of a Threat: How Multi-Layered AI Works in Darktrace / EMAIL

Man at a computerDefault blog imageDefault blog image

Darktrace / EMAIL is an implementation of the Darktrace methodology – a multi-layered AI system built into a single product. As with other Darktrace products, Darktrace / EMAIL learns the expected behaviours of an organization and its employees to identify novel threats and anomalous activity.

The diagram below represents the architecture of Darktrace / EMAIL’s multi-layered AI: a structured visualization of how intelligence is built, step by step, from raw data to actionable insight. Each layer plays a distinct role, feeding into the next: collecting data, understanding behaviour, analysing intent, making decisions, and presenting clear outcomes.

It all starts with an email

In this blog, we’ll follow a malicious email as it passes through the Darktrace / EMAIL system, showing exactly what happens as it travels through each layer of the pyramid, from basic data extraction to AI-powered metric creation, and finally deciding on any autonomous actions.

Let’s take this example email. As an end-user, you can see that this is an obvious extortion attempt where an adversary is threatening legal action if money isn’t paid within 24 hours, but how does Darktrace figure that out?

Part 1: Data Gathering

Processing of an email begins on point-of-transit for all inbound, outbound, or lateral emails. The first step is to extract information directly. This includes taking information from the headers (such as sending and receiving addresses, sender IP address, routing, and authentication protocols), as well as extraction of raw HTML and CSS data from the email itself.

This directly extracted information only allows for immediate surface level analysis, such as identifying signature-based attacks (known malicious addresses / domains), but is insufficient for identifying novel threats, complex attacks, or potential email or vendor compromise. This is where Darktrace’s AI analysis shines.

In this example, the SPF, DKIM, and DMARC authentication all passed successfully, showing that even malicious emails can still bypass these signature-based checks. Even with this success, Darktrace will continue to analyse the email.

Diving deeper into the technical information, we can see further information extracted from the headers, including aggregations from the header information, historical calculations such as the frequency and volume of emails to and from a particular domain, and much more.

Part 2: Social Graphing

Social Graphing involves the analysis of sending and receiving behaviours of different mailboxes to create peer-groups. Mailboxes who often send and receive to and from the same mailboxes, or exhibit other correlated behaviours, will be clustered together using a collection of unsupervised AI clustering systems. These groups may represent uses in the same teams who perform similar activity, groups of external facing mailboxes which often receive unsolicited emails, or groups of VIP users (such as C-suite or executives).

Social graphing is an essential component of Darktrace’s pattern of life analysis. This clustering allows Darktrace to understand the responsibilities of individuals – for example, behaviours which are anomalous for one group of users may be completely expected of another group.

In our example, the email was sent to 3 different users within the organization. As part of the social graphing, an “Association Anomaly” is calculated which indicates the likelihood that these users would receive emails from this user or domain, based on historical patterns.

Part 3: Metric Calculation

Metrics are calculated for every email, representing more complex characteristics of an email which can’t be directly extracted. Darktrace / EMAIL features over 1000 unique metrics, calculated both algorithmically and using an ensemble of AI systems.

Algorithmically calculated (non-AI) metrics include further historical calculations, and counts of features such as code blocks, and hidden text, to name a few.

AI-driven metrics include Inducement Classification which uses Natural Language Processing to identify potential phishing, solicitation, or extortion attempts; Named Entity Recognition to identify PII and other sensitive data within an email to support Data Loss Prevention; and many more.

We can follow our example email through this process and view the outcome of these metric calculations. Looking at the language metrics for this email, we can see that our email has reported a high extortion inducement, along with identification of banking information and language indicating urgency.

Part 4: Evaluation and Combination Engine (models)

Once all metrics have been calculated for an email, it gets sent to an evaluation and combination engine where the metrics are compared against blocks of logic to determine if an email contains a threat. One key model which alerted for this example message was a model to tag and block extortion attempts.

Since our example email has a high inducement score for extortion, along the presence of a bitcoin wallet address in the message, this model alerts. When a model in the engine is activated, actions are taken – in this case adding a tag to the email to flag it as extortion in the console and hold the email to prevent it from reaching the end-user mailbox.

Part 5: Meta-Modelling and Actions

Once the models have been run, the actions are taken against the email. If the email hasn’t been blocked or held, this is the point where it will reach the end-user's mailbox.

In the Darktrace / EMAIL UI, all actions models which alerted for an email and actions taken as a result can be seen. At the top of this page, you can see the alert indicating an extortion attempt along with the action to hold the message.

Alongside this, a meta-classifier is used to calculate an overall anomaly score for each email, based on how much the email differs from the pattern of life for the user. The score of the email is boosted by any actions that have taken place.

Part 6: Campaign Clustering

All emails are passed through the Darktrace / EMAIL campaign clustering system. This system creates clusters based on related features within the emails to identify groups of emails with the same sender or intent.

In our case, the email was identified as part of a campaign, alongside other emails which were also identified as extortion attempts against a small group of recipients.

Email campaigns may have additional actions applied to them if the campaign is deemed malicious, and in this case, you can see that the autonomous response was to hold all emails in the campaign. This means that if an email manages to avoid being blocked in the evaluation and combination engine but gets identified as part of the campaign, the hold action will be applied to it retroactively.

Part 7: Cyber AI Analyst

Darktrace’s Cyber AI Analyst presents key information and anomaly indicators for each email, such as further information about authentication, specific metrics, or other identified anomalies and mismatches.

Cyber AI Analyst can also utilize data from Darktrace / EMAIL to enhance its investigation of incidents from other Darktrace products, correlating relevant information to build a fuller picture. More information about the Cyber AI Analyst is available in the Darktrace AI Arsenal.

Part 8: Data Presentation (UI)

Once all processing has taken place against the email, it is presented in the Darktrace / EMAIL UI. Here, members of the SOC team can investigate incidents and anomalies, interact with malicious emails to see why they were blocked, and much more.

Our email stands out here with its 100 anomaly score. Every email which passes through a Darktrace / EMAIL will undergo the same thorough and rigorous analysis to identify potential risks, apply autonomous actions where required, and will ultimately be assigned a score to be displayed here. By providing a single overall score in the UI, rather than presenting emails in full, Darktrace / EMAIL allows SOC teams to more easily identify which emails are most important to investigate, increasing efficiency and reducing alert fatigue.

Take the next step

Many email security tools on the market that claim to be AI-driven are in fact bolting AI onto attack-centric approaches, which rely on automating the identification of known threats. These approaches struggle, and will continue to struggle, with adapting to novel, AI-generated threats.

By analyzing every email within its deeply integrated, multi-layered AI system, Darktrace / EMAIL is able to identify the subtle threats that others miss. This depth not only improves detection accuracy, but enables confident, autonomous action, giving security teams clearer insight into AI outcomes and greater control while supporting users.

For a full deep dive into each stage of the AI system, check out the white paper: A Guide to the Multi-Layered AI in Darktrace / EMAIL

Learn more about securing AI in your enterprise.

[related-resource]

Continue reading
About the author
Jamie Bali
Technical Author (AI) Developer

Blog

/

Network

/

May 26, 2026

Darktrace named a Leader in the 2026 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) For the Second Consecutive Year

garnter ndr magic quadrantDefault blog imageDefault blog image

Continued recognition in NDR  

Darktrace has been recognized as a Leader in the 2026 Gartner® Magic Quadrant™ for Network Detection and Response (NDR), marking the second consecutive year in the Leaders quadrant.

We believe this consistency reflects sustained ability to execute, adapt, and deliver outcomes as the market evolves.

While we are immensely proud to be recognized by industry analysts as a Leader in NDR, that's just part of the story. Darktrace was also Named the Only 2025 Gartner® Peer Insights™ Customers’ Choice for Network Detection and Response based on direct customer feedback and real-world experience.

We believe the combination of these two signals is important. One reflects how the market is evaluated. The other reflects how technology performs in practice.

Why Darktrace continues to be recognized as a leader

We believe our position as a Leader for the second consecutive year reflects a combination of our sustained ability to execute in NDR, continued AI innovation, and proven delivery of security outcomes for customers and partners worldwide.

We also feel that our leadership in the NDR market is a testament to our unique and multi-layered AI approach, for which we were recognized as No.7 on Fast Company’s Most Innovative AI Companies of 2026 list, plus one of the hottest AI cybersecurity companies in CRN's AI 100.

Adapting to complex, real-world environments

Organizations are no longer protecting a single network perimeter. They are securing a mix of users, devices, applications, and data that move across hybrid environments.

Darktrace has focused on maintaining visibility and detection across these conditions, allowing security teams to understand activity as it scales.

Supporting organizations globally, not just technically

Security outcomes are shaped as much by deployment and support as they are by detection capability.

Darktrace continues to invest in regional presence across 29 countries around the world, helping organizations operationalize NDR in ways that align with local requirements, internal processes, and team structures.

Continuing to push AI beyond detection

AI in cybersecurity is often positioned as a way to improve detection accuracy. But the more important shift is how AI can influence decision-making and response.

Darktrace continues to develop models that learn from both live environments and historical incident data, combining real-time behavioral analysis with insights derived from prior attack patterns.

Using technologies such as the Incident Graph and DIGEST (Darktrace Incident Graph Evaluation for Security Threats), activity is not analyzed in isolation. Instead, relationships between users, devices, connections, and events are mapped over time, allowing the system to reconstruct how an incident is unfolding and how similar incidents have progressed in the past.

By evaluating these patterns, Darktrace can assess the likelihood that an incident will escalate, prioritizing the activity that poses the greatest risk and surfacing the most relevant context for investigation.

This shifts security operations from simply identifying anomalies to understanding their trajectory, helping teams anticipate potential impact and respond earlier with greater precision.

Why NDR is shifting from reactive detection to proactive, AI-driven security

Traditional approaches to NDR have been built around reactively identifying threats once they become clearly visible. That model is increasingly difficult to rely on.

Attackers are no longer operating in ways that stand out. They use valid credentials, trusted tools, and low-and-slow techniques that blend into everyday activity. By the time something looks obviously malicious, the impact is often already underway.

This is the core limitation of reactive detection. It depends on recognizing something that already looks like a threat.

As a result, many of the most consequential incidents today fall into a gap.

Insider activity, compromised credentials, and novel attacks rarely trigger traditional alerts because they do not follow known patterns. On the surface, they often appear legitimate, making them difficult to distinguish from normal behavior without deeper context.

This is why we believe this Gartner recognition reflects a broader shift in NDR toward autonomous, proactive and pre‑emptive security operations.

By understanding normal behavior within an environment, it is possible to identify subtle deviations rather than waiting for confirmation of threats as they are taking place.

Darktrace’s Self-Learning AI is designed for behavioral understanding. By continuously learning each organization’s normal patterns, it can detect deviations in real time, enabling a proactive and pre-emptive model of NDR where security teams can respond to early signs of risk as they emerge, reducing the window in which attacks can develop.

In multiple cases, this behavioral approach has led to early threat detection where Darktrace identified completely unknown threats, including pre-CVE zero-day activity. By detecting subtle behavioral changes before vulnerabilities were publicly disclosed or widely understood, organizations can mitigate threats before they do damage.

This shift is subtle but important. Modern NDR solutions must shift from a system that explains what happened to one that helps prevent threats from developing in the first place, and Darktrace is proud to be at the forefront of this shift - helping organizations build and maintain a state of proactive network resilience.

Continuing to innovate at the forefront of NDR

In our view, recognition as a Leader reflects where the market is today. Continuing to innovate defines what comes next.

As businesses evolve, new technologies like AI tools and agents introduce new security risks and challenges; security teams need more than simple detection. They need a complete understanding of risk as it develops, the ability to investigate it in context, and to contain threats at machine speed.  

Darktrace / NETWORK is built to deliver across that full spectrum. Its Self-Learning AI continuously adapts to each organization’s environment, identifying subtle behavioral changes that signal emerging threats. Integrated investigation and autonomous response reduce the time between detection and action, allowing teams to move with greater speed and confidence.

This combination enables organizations to detect and contain known, unknown, and insider threats as they develop, while also strengthening resilience over time.

As a two-time Leader in the Gartner® Magic Quadrant™ for NDR and the only 2025 Gartner® Peer Insights™ Customers’ Choice, we feel Darktrace continues to evolve its platform to meet the demands of modern environments, delivering a more complete and adaptive approach to network security.

[related-resource]

Disclaimer: The 2026 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) ,The 2026 Gartner® Magic Quadrant™ for Network Detection and Response (NDR), Thomas Lintemuth, Charanpal Bhogal, Nahim Fazal, 18 May 2026.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Magic Quadrant is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved.

Continue reading
About the author
Mikey Anderson
Product Marketing Manager, Network Detection & Response
Your data. Our AI.
Elevate your network security with Darktrace AI