Press Release
Updated statement regarding LockBit claims
We have completed a thorough security investigation following yesterday’s tweets by LockBit claiming they had compromised Darktrace’s internal systems. We can confirm that there has been no compromise of our systems or any of our affiliate systems. Our service to our customers remains uninterrupted and is operating as normal and no further action is required.
Press Release
Statement regarding LockBit claims
Earlier this morning we became aware of tweets from LockBit, the cyber-criminal gang, claiming that they had compromised Darktrace’s internal security systems and had accessed our data. Our security teams have run a full review of our internal systems and can see no evidence of compromise. None of the LockBit social media posts link to any compromised Darktrace data. We will continue to monitor the situation extremely closely, but based on our current investigations we are confident that our systems remain secure and all customer data is fully protected.
Press Release
Darktrace Delivers New Innovations in Network Detection and Response for Enhanced Detection, Scalability, and SOC Efficiency in the Modern Enterprise
- Darktrace / NETWORK detects and precisely responds to both known and novel threats. Approximately 70 percent of detections involve highly anomalous activity, including insider threats, compliance-related issues, or other malicious external threats.
Darktrace, a global leader in AI for cybersecurity, announced it has delivered significant new advancements in network detection and response (NDR) with multiple new innovations for Darktrace / NETWORK™. These updates help organizations address the challenges of the modern enterprise network, including managing distributed infrastructure and a hybrid workforce, detecting an increasing volume of novel, unknown, and AI-driven threats, and streamlining the time-intensive burden of investigation and response for security analysts.
Jack Stockdale, Chief Technology Officer, Darktrace, commented:
“For over a decade, Darktrace has pioneered the use of AI in network detection and response, achieving one-fifth of the global NDR market share and supporting nearly 10,000 organizations. Darktrace is proven to meet the needs of the increasingly complex modern enterprise IT network and currently supports customers in industries including critical infrastructure like healthcare and energy, financial services, telecommunications, retail, manufacturing, and many more. We regularly deliver new innovations to meet the core challenges in the NDR market, and advance beyond traditional requirements to help our customers secure their environments from a wide range of evolving threats.” [1]
Expanded Threat Detection Methods
Darktrace / NETWORK uses a unique Self-Learning AI engine that learns what is normal behavior for an organization’s entire network, continuously analyzing, mapping and modeling every connection to create a full picture of your devices, identities, connections, and potential attack paths. With its ability to uncover previously unknown threats as well as detect known threats via signatures and threat intelligence, Darktrace is an essential layer of the security stack that augments existing preventative measures. Darktrace has helped secure customers against attacks including Log4J, SolarWinds, novel phishing scams during COVID-19, and more.
An evaluation conducted in November 2024 of actionable detections across the global Darktrace / NETWORK customer base [2] found that most threats detected were novel or highly anomalous. These threats were not blocked by other security tools that rely heavily on pre-existing indicators of compromise, rules, and signatures, such as next-generation firewalls, secure service edge and zero trust network access, or intrusion prevention systems, due to how these components are managed.
- 30% of detections in this period were from known threats, half of which matched indicators of compromise from external threat intelligence and the other half were rules or signature-based (using machine learning to automatically manage their detection engineering properties).
- 70% were detections of highly anomalous activity, including insider threats, compliance risks, and novel or unknown external threat activity.
To further enhance these capabilities, Darktrace introduced new detection features over the last year including:
- Threat intelligence ingestion: Darktrace can ingest and manage secondary STIX and TAXII threat intelligence to proactively detect and autonomously respond to known threats based on indicators of compromise, facilitating additional threat hunting and creation of custom detections. Now, Darktrace Cyber AI Analyst™ can automatically investigate, correlate, and raise a critical incident for each intelligence-based detection if deemed important for the human investigation team.
- Decryption and encrypted traffic analysis: Darktrace supports decrypting TLS traffic and analyzing both encrypted and decrypted forms together, including Deep Packet Inspection for protocols inside encrypted connections such as HTTP/2.
- Support for NetFlow v9: Darktrace ingests NetFlow v9 records of traffic activity which enhances visibility over areas of networks that might otherwise go unmonitored.
- Tunneling detection improvements: Specialized scrutiny of commonly used tunneling services that can easily be repurposed for remote access and control of devices and have seen increasing use globally throughout 2024.
- Detection of generative AI misuse: Dedicated risk and compliance detection models help prevent data loss by allowing customers to monitor, and when necessary, respond to activity and connections to generative AI and large language model (LLM) tools such as AutoGPT, ChatGPT, Stable Diffusion, Claude, and more.
Enhancements to Support the Scale of Large, Modern Network Architectures
Darktrace / NETWORK is designed to scale with the needs of modern organizations, providing robust performance and visibility across large and complex networks.
Darktrace’s ability to handle this scale and complexity has been proven with customers throughout 2024. For example, one customer oversees their entire Darktrace / NETWORK deployment from a single central unified view that covers 50 large locations globally (many with their own security teams working locally) plus more than 15,000 Darktrace / ENDPOINT™ agents providing network visibility for traveling devices and smaller offices and locations.
Recent updates to further support large, global deployments include:
- Centralized, enterprise-wide network detection, investigation and response: Customers can extend visibility and control across the modern perimeter-less network, with support for Microsoft Azure and Amazon Web Services (AWS) environments with Darktrace / CLOUD™; remote or hybrid workers with integrations for leading Zero Trust Network Access providers or with Darktrace / ENDPOINT; cyber-physical systems and operational technology with Darktrace / OT™; and, a wide variety of enterprise SaaS applications and identities including Microsoft 365 and Salesforce with Darktrace / IDENTITY™ .
- Proactive network performance monitoring: Detailed status alerts for significant changes in bulk network activity, with proactive recommendations to identify and resolve potential security threats and network performance issues.
- Additional customization for distributed deployments: Darktrace offers a unified view to streamline the management of large deployments, which can now be used to centrally define a wider range of unique local settings. This increases flexibility and simplifies ongoing management for large, distributed, global deployments where different configurations are required across different locations with multiple physical, virtual, and cloud deployment types.
Innovations to Streamline Security Workflows
Darktrace / NETWORK can be used by security teams as the central place to manage and respond to threats, and it is uniquely designed to help streamline and improve SOC efficiency. Innovations including Darktrace’s industry-first Cyber AI Analyst™ provide a patented approach to automate the investigation of alerts and understand incidents at scale. Cyber AI Analyst performed 1.5 million investigations per week on average during 2023, and generally completes an investigation within just five minutes of an initial alert being raised [3].
Darktrace has continued to prioritize user experience, efficiency, and scale, with enhancements including:
- Automated detection engineering: External threat intelligence feeds and custom signatures are automatically investigated and an incident raised if there is a material impact. This helps minimize the amount of time and effort required by a security analyst to manage rules or continually assess incorrect or outdated intelligence and indicators of compromise.
- Explainable and automated AI-led triage and investigations for alerts: Cyber AI Analyst automatically investigates all relevant alerts to completion, including third party alerts, reducing alert fatigue by replacing the existing manual triage process with AI. It now provides detailed explanations of an investigation, its reasoning behind search queries, and significance of findings, even for those alerts that are not escalated to incidents. This frees up teams to focus on response actions, threat hunting, and proactive hardening.
- Increased customization of investigations: Customers can now specify how Cyber AI Analyst investigates alerts, providing increased flexibility for custom alerts.
- Upgraded incident interface: A new interface centralizes all components of an investigation and gathers all capabilities needed to follow up on incidents, including incident structure, key investigation details, Autonomous Response action summaries, third party alerts, and more.
- MITRE ATT&CK mapping: Darktrace tracks any relevant model alert to the MITRE ATT&CK framework and will display this is in any related Cyber AI Analyst investigations and reports.
- Autonomous Response enhancements: Cyber AI Analyst can initiate and further leverage Autonomous Response actions when it discovers a high importance or large-scale incident, even if the initial alerts were not threatening enough to justify immediate automated actions. The duration of Autonomous Response actions can also be adjusted at a global level, giving security teams the flexibility to enforce a minimum containment time aligned with their known or target time to follow up.
Darktrace was recently named a leader in the 2024 IDC MarketScape for Worldwide Network Detection and Response, and the KuppingerCole Leadership Compass: Network Detection and Response (2024).
For more information about Darktrace / NETWORK and how it is pushing beyond the definitions of traditional NDR technologies, please visit https://darktrace.com/products/ NETWORK
About Darktrace
Darktrace is a global leader in AI for cybersecurity that keeps organizations ahead of the changing threat landscape every day. Founded in 2013, Darktrace provides the essential cybersecurity platform protecting organizations from unknown threats using its proprietary AI that learns from the unique patterns of life for each customer in real-time. The Darktrace ActiveAI Security Platform™ delivers a proactive approach to cyber resilience with pre-emptive visibility into security posture, real-time threat detection, and autonomous response – securing the business across cloud, email, identities, operational technology, endpoints, and network. Breakthrough innovations from our R&D teams in Cambridge, UK, and The Hague, Netherlands have resulted in over 200 patent applications filed. Darktrace’s platform and services are supported by over 2,400 employees around the world who protect nearly 10,000 customers across all major industries globally. To learn more, visit http://www.darktrace.com.
NOTES
[1] IDC MarketScape: Worldwide Network Detection and Response 2024 Vendor Assessment (doc #US51752324, November 2024). The report notes, “Darktrace achieves roughly one-fifth of all global NDR revenue.”
[2] Based on a study conducted by Darktrace between November 1-30, 2024, of all actionable detections from Darktrace / NETWORK customers providing relevant telemetry.
[3] Based on an internal analysis of Darktrace Cyber AI Analyst fleet data collected from 1 January to 31 December 2023.
Darktrace Delivers New Innovations in Network Detection and Response for Enhanced Detection, Scalability, and SOC Efficiency in the Modern Enterprise
cv
Darktrace named a Challenger in first Gartner® Magic Quadrant™ for Email Security Platforms · Evaluated on Completeness of Vision and Ability to Execute Darktrace, a global leader in AI for cybersecurity,today announces that Darktrace / EMAIL™, has been recognized in thefirst ever Gartner Magic Quadrant™ for Email Security Platforms (ESP) as a Challenger. Chris Kozup, Chief Marketing Officer, Darktrace, said of therecognition: “We are extremely proud to have been recognized in the first MagicQuadrant for ESP. We believe the factthat wehave seen such wide scale adoption is testament to the unique way in which wedevelop products to keep our customers safe from even the most sophisticated emailcompromises. We believe our placement reaffirms our dedication to deliveringexceptional customer service, and innovations that safeguard against the emailchallenges of today—and tomorrow.” Darktrace customers consistently acknowledge its exceptional customersupport, delivered by an award-winning[1]service team. Darktrace has the highest percentage of 5-star ratings with a 4.8rating on Gartner® Peer Insights™ out of 249 reviews as on[MW1] 19th December. We feel this unwavering commitment to customersatisfaction is evident in strong renewal rates and accelerated growth inDarktrace / EMAIL over the past few years, gaining almost 5,000 customers sinceits launch in 2019. Darktrace / EMAIL, one of the fastest-growing emailsecurity products on the market, is built on Darktrace’s unique Self-LearningAI, a multi-layered AI engine that leverages different types of AI includingNLP and behavioral analysis to detect threats, instead of traditional securitymeasures such as signatures and sandboxing. This approach enables Darktrace todetect and stop threats like business email compromise attacks and noveltechniques, including some 56% of which passed through customers’ other emailsecurity layers. This pioneering approach has enabled Darktrace to introduce industry-leadingcapabilities such as QR code analysis and automated incident investigations, alongsidedifferentiated functionality to help teams add new depth to their emailsecurity, including: Account take over and Lateral mail account compromise protection. Contributing yet another layer to the AI behavioural profile for each user, security teams can now spot early symptoms of account compromise or malicious insiders before a link or attachment payload is sent, and exfiltration occur Microsoft Teams security with advanced messaging analysis: Advancing beyond simple text analysis to behavioral and natural language content analysis that tracks context across both email and instant messaging to identify the approximately 38% of phishing, sophisticated social engineering and novel insider threats other solutions fail to capture · Drastically improveend user reporting with Cyber AI Analyst narratives: Real-time awareness training capabilities reduce falsepositives in phishing investigations by up to 60% by providing context specificanalysis of each received email to each employee as they interact with their mail.· MailboxSecurity Assistant to increase security team operational efficiency: All forms ofsecondary investigations can now automatically perform advanced behavioralbrowser analysis and stop malicious links within webpages, reducing manualeffort of security analysts to detecting phishing links, and allowing them to remediateup to 70% more malicious phishing links than before.· AI based,autonomous data loss prevention: to immediately protect organizations from misdirected emails,insider threats, and data loss—both classified and unclassified – using userbehavior and dynamic content analysis to determine sensitivity, removing administrativeoverhead from manual expressions and labeling.Marco Cavallo, IT Manager at Darktrace / EMAIL customer Arpa Industries comments:“During the POV, Darktrace / EMAIL showed how specific attacks weresurgically blocked. We realized that other tools wouldn’t have detected thesethreats.” Darktrace / EMAIL is part of Darktrace’s ActiveAI Security Platform™,offering network, cloud, endpoint, identity and operational technologyprotection from a single shared architecture, all built on Darktrace’s uniqueAI engine – providing a strong, integrated approach to threat prevention,detection and response across an organization’s entire digital footprint. Darktrace’s global presence supports a diverse and varied customer base,and adapts proactively to customer pain points of all kinds. Darktrace’sadaptability across all market segments, from SMBs to large enterprisessupports both first time email security buyers and mature email securitystacks. It is able to meet varied security needs with lower setuprequirements, includes capability for advanced depth in configuration and,particularly for mature organizations, can augment existing security providerswith additional protections. Download the fullMagic Quadrant for Email Security Platforms here Resources:· Read more onthe Darktrace Blog· Read more abouthow business email compromise attacks are evolving on The Inference Gartner disclaimersGartner, Magic Quadrant for EmailSecurity Platforms, Max Taggett, Nikul Patel, Franz Hinner, Deepak Mishra, 16December 2024 GARTNER is a registered trademarkand service mark of Gartner and Magic Quadrant and Peer Insights are aregistered trademark, of Gartner, Inc. and/or its affiliates in the U.S. andinternationally and are used herein with permission. All rights reserved.
Gartner Peer Insights content consists of the opinions of individual endusers based on their own experiences with the vendors listed on the platform,should not be construed as statements of fact, nor do they represent the viewsof Gartner or its affiliates. Gartner does not endorse any vendor, product orservice depicted in this content nor makes any warranties, expressed orimplied, with respect to this content, about its accuracy or completeness,including any warranties of merchantability or fitness for a particularpurpose. Gartner does not endorse any vendor,product or service depicted in its research publications and does not advisetechnology users to select only those vendors with the highest ratings or otherdesignation. Gartner research publications consist of the opinions of Gartner’sresearch organization and should not be construed as statements of fact.Gartner disclaims all warranties, expressed or implied, with respect to thisresearch, including any warranties of merchantability or fitness for aparticular purpose. About DarktraceDarktrace is a global leader in AI for cybersecurity that keepsorganizations ahead of the changing threat landscape every day. Founded in2013, Darktrace provides the essential cybersecurity platform protectingorganizations from unknown threats using its proprietary AI that learns fromthe unique patterns of life for each customer in real-time. The DarktraceActiveAI Security Platform™ delivers a proactive approach to cyber resiliencewith pre-emptive visibility into security posture, real-time threat detection,and autonomous response – securing the business across cloud, email,identities, operational technology, endpoints, and network. Breakthroughinnovations from our R&D teams in Cambridge, UK, and The Hague, Netherlandshave resulted in over 200 patent applications filed. Darktrace’s platform andservices are supported by over 2,400 employees around the world who protectnearly 10,000 customers across all major industries globally. To learn more,visit http://www.darktrace.com. ----
[1] Darktrace wins two Globeeawards for excellent customer service [PressRelease] [MW1]shouldthis be 'of'