
Cybersecurity company Darktrace has upgraded its network detection and response (NDR) solution to better meet the demands of modern enterprise networks. The latest upgrade extends beyond traditional NDR solutions to offer deeper visibility, more precise autonomous response, new proactive risk management capabilities, and integrations to augment novel threat detection for secure access service edge and zero trust network access technologies. The upgrade follows improvements to Darktrace’s Cyber AI Analyst.
“We’re providing the visibility, real-time detection and autonomous response capabilities that customers need to defend against fast-moving and changing threats, whether they originate from a remote worker device, a misconfigured SaaS app, or a compromised internal server,” said Darktrace Product SVP Connie Stride. “These new features and integrations are designed to help organisations rebuild their security operations around AI and create proactive cyber resilience to protect their complex digital environments.”
The new NDR capabilities include:
-
Increased visibility of threats to remote workers with Netskope Cloud TAP: A new integration with Netskope enables Darktrace to ingest raw, decrypted network traffic to detect unknown, novel and active threats targeting remote workers using SASE environments.
-
The Netskope NewEdge Network enables fast performance for traffic packet capture between users and offices and the Netskope One platform across the globe with the ready-to-use Darktrace integration. This visibility reduces blind spots for customers even as network traffic flows shift further away from traditional network perimeters.
-
Enhanced autonomous response for Zscaler Private Access: Darktrace can now deliver response actions at machine speed for remote user devices by integrating with Zscaler’s Zero Trust Network Access service. After Darktrace detects an active threat allowed within existing policies, this new capability enables security teams to autonomously shut down access using ZPA and stop suspicious activity on remote devices at machine speed, buying valuable containment time for analysts to confirm investigation results and remediate.
-
Support for decrypted traffic via Mira: The new integration with Mira ETO allows organisations that choose to decrypt for compliance to analyse network traffic in its plaintext form. This integration maintains the encrypted traffic’s context while enabling more in-depth anomaly detection, adding to Darktrace’s leading Self-Learning AI, which can already detect novel threats without the need to decrypt traffic.
-
Custom routes for autonomous response in complex networks: A new module allows organisations to define custom pathways for autonomous response actions that stop the malicious action while maintaining production activity, allowing for more precise threat containment even in highly segmented network environments.
-
Attack path finder and new risk management reports: Darktrace is introducing a searchable risk visualisation dashboard that maps out all attack paths between assets and vulnerable users, not just the critical paths, helping teams prioritise and proactively build resilience. The solution includes three new automatically generated reports that are designed to highlight the impact and success of risk management activity and demonstrate ROI to stakeholders.
-
Expanded protocol analysis: With new support for WebSocket, Darktrace extends detection coverage into real-time communication channels often used in live chat and streaming applications, which can be targeted by attackers.
Darktrace says its self-learning AI is the backbone of its NDR solution, uniquely learning the normal pattern of life for every network entity and user. Unlike traditional approaches that rely on threat signatures or manual rule-setting, Darktrace uses its knowledge of the organisation to identify and contain known and unknown threats in real-time, utilising that data to not only investigate all relevant alerts with Cyber AI Analyst, but also provide recommendations for security improvements ensuring organisations stay ahead even as adversaries evolve.