T Techclick ← Darktrace hub
Darktrace · / NETWORK · Learn-then-breach factory · Interactive lesson

Darktrace is a learn-then-breach factory. Probe, baseline, then Antigena.

The ticket says “Darktrace says ransomware — score 82.” That sentence is already wrong. The factory does not convict. It learns a pattern of life, then it breaches a model when behaviour is unusual. Probe coverage is the factory floor. The device baseline is the apprenticeship. The model breach is the ticket. Antigena / RESPOND is a later stamp — Human Confirmation will not block. This lesson is the official order, and the Threat Visualizer fields that close the ticket.

20 min read · L2 primary · Quiz at end · Dummy lab only

⚡ Quick Answer

Darktrace is a learn-then-breach factory: probe coverage → device baseline → model breach → Antigena. Prove the ticket in Threat Visualizer, not Slack.

After this page you can

Quick answer

Darktrace / NETWORK is a learn-then-breach factory. A physical probe, vSensor, or osSensor must see the packets. Self-Learning AI then builds a pattern of life for the device, its peer group, and the organisation. A model is a set of conditions; a match is a model breach with a score — unusual, not a family name. Cyber AI Analyst may write an incident. Antigena (Darktrace RESPOND) may act only if the group is Fully Autonomous. Success is a named Threat Visualizer field, not “Darktrace says malware.”

Say this out loud

I do not start with VirusTotal. I ask whether the probe saw the VLAN, whether Device Summary has First Seen / Last Seen, which model breached at what score against which peer group, and whether Antigena is Human Confirmation or Fully Autonomous. Score is unusual. No IOC is not a close. Coverage first — you cannot score what the SPAN never sent.

1. Why a score is not a factory

SOC chat at 10:41Z: finance laptop 10.10.8.22 opened RDP to 203.0.113.88. DETECT raised a model at score 82. The L1 comment is “Darktrace says it is ransomware.” Leadership then asks why it was allowed. Both sentences skip the product. They treat the factory as a signature engine that prints convictions.

Official Darktrace threat-detection language is the opposite. Self-Learning AI is trained per deployment. It continuously ingests live data, builds a pattern of life for assets, peer groups, and the organisation, and flags behaviour that is both anomalous and unlikely to be benign — without relying on signatures, rules, or threat intelligence. A high score means rare versus that learned self. It does not name a malware family. It does not prove a hash. It does not prove Antigena acted.

Hero · the factory floor
Teaches: device traffic is scored as unusual after a probe sees it, then DETECT and RESPOND are separate gates
Notice: the laptop is scored, not convicted. The factory must see the packets before it can learn, and it must learn before it can breach a model.

What the ticket asked

“Darktrace says ransomware.” That sentence is a hypothesis. The factory may have printed an unusual-RDP ticket on a host the SPAN barely knows, with Antigena still in Human Confirmation.

What you prove first

Probe / vSensor health, then Device Summary First Seen / Last Seen, then the Model Breach Event Log, then Antigena mode. The evidence desk is the night-shift version of this order.

The lie every L1 repeats

“Score 82 means malware, and we bought Darktrace so it should have blocked.” An 82 is how unusual the behaviour is versus pattern of life. DETECT is not RESPOND. Human Confirmation (Passive) will not block. A host First Seen tonight will score almost everything. Widening a model or flipping Fully Autonomous at 02:00 does not fix a dead SPAN.

Concept first: the object is the device in the model, not the Slack paraphrase. Path second: official Threat Visualizer surfaces in a fixed order. Do third: Side A builds the floor (probes), Side B reads the apprenticeship and the printed ticket (baseline + breach), Side C reads the action stamp (Antigena). Miss a stamp and you troubleshoot the wrong layer.

2. Mental model — four stamps on one ticket

Hold four parts. Interviews fail when people mix them. Darktrace publishes these as separate products and UI surfaces. You do not buy four factories. One appliance chain writes four stamps, in this order, only if the previous stamp exists.

1. Probe coverage is the floor

Physical probe, vSensor (SPAN from a virtual switch to the master), or osSensor when you cannot SPAN. No packets on the wire = no pattern of life = no honest model breach.

2. Device baseline is the apprenticeship

Self-Learning AI learns normal for that host, its peer group, and the estate. Device Summary First Seen / Last Seen prove the host is in the model. A brand-new device has almost no self.

3. Model breach is the ticket

A model is a set of conditions. A match is a model breach with a score / priority. Quote the published name — Compromise / Ransomware / Suspicious SMB Activity, not “Darktrace alert.”

4. Antigena is the action stamp

Official RESPOND language: Human Confirmation versus Fully Autonomous. Actions include enforce pattern of life, block matching connections, quarantine, or a third-party integration. Would-have is not a live block.

Flow 1 · one ticket, four stamps, one order
MB-1042 · four stamps, one device · 10.10.8.22 Device 10.10.8.22 VLAN20 New peer 203.0.113.88 RDP packets on SPAN → vSensor → master no SPAN = no Event Log = no honest score 1 Probe stamp did the wire arrive? vSensor · SPAN · PPS 2 Baseline stamp whose pattern of life First Seen · peers 3 Breach stamp which model · score unusual ≠ family 4 Antigena stamp allowed to act? HC vs Autonomous Cyber AI Analyst may write an incident. IOC / STIX is extra. Ack assigns an owner — it does not contain the host. Threat Visualizer is where you read the finished ticket. Slack is not a Model Breach Event Log.

Read left → right. If stamp 1 is missing, stamps 2–4 are fiction. If stamp 4 is Human Confirmation, leadership’s “why didn’t it block?” already has an answer.

Pre-train the vocabulary before the runbook. A model defines conditions; when they are met, Darktrace raises a model breach. Official DETECT blogs publish names in Category / Behaviour form — Device / Reverse DNS Sweep, Compromise / Ransomware / Suspicious SMB Activity, Compromise / Beaconing Activity To External Rare. Enhanced Monitoring models are higher-fidelity DETECT models, still not malware proof. Would-have is what RESPOND would do in Fully Autonomous. Acknowledge assigns an owner in Threat Visualizer — it does not isolate the host. vSensor is the virtual probe that needs a working SPAN (or osSensor feed) and a master appliance.

Official Self-Learning AI stack (Darktrace threat-detection glossary): live training data unique to the deployment; Bayesian models that update with new evidence; clustering so a peer group can stop the AI from mis-learning malice as normal; anomaly scores plus a meta-classifier that ranks rarity. That is why a CEO laptop in a peer set of one scores like an incident on every new SaaS. The comparison set is the apprenticeship, not a bug in the model.

3. Learn, then breach

The factory is sequential on purpose. Packets hit a SPAN / TAP / ERSPAN, a vSensor or physical probe, then the master. Pattern of life updates. A model’s conditions match — then, and only then, you have a breach. Later packets on a healthy sensor keep teaching the same device. That is why “we just installed Darktrace yesterday” and “the core change at 01:00 killed the SPAN” are different tickets that look the same in Slack: a red number, or no number at all.

Path · coverage diamond before DETECT
Teaches: after a high score you fork between investigate/isolate and coverage/exception
Notice: the first diamond is not “malware or not.” It is “did the probe see this host?” Path A is hunt and contain. Path B is coverage, peer-set, or a time-boxed exception.
Flow 2 · official order at the breach (student labels)
Ingress → coverage? → baseline → breach → Antigena? 1 Ticket MB-1042 · 82 Probe / SPAN seeing host? yes LEARN PATH — Device Summary then Event Log First Seen · Last Seen · peers · connections no → coverage ticket · do not open Model Editor First Seen in the model? Peer group honest set? Model + score Event Log AI Analyst lead, not close Antigena mode last action · would-have NEW PEER + HIGH SCORE + HUMAN CONFIRMATION isolate / block that connection now · Fully Autonomous is change-control, not a 02:00 toggle Official facts students invert 1. Encrypted payloads still update pattern of life — dest, volume, timing, peers. Empty Event Log is a tap miss, not “TLS so Darktrace is blind.” 2. Cyber AI Analyst investigates model breaches and writes an incident. It is not a malware family and it is not containment. 3. Published ransomware cases needed Antigena in Active / Fully Autonomous to stop encryption in seconds — with no public IOC.

Read left → right, then the green bar. Decision diamond = “does the probe see this host?” DoS-style panic (“flip Active”) sits after you quote the mode, on purpose.

#1 student trap — score without a floor

A host that just appeared, or a VLAN whose PPS collapsed after a core change, will either scream or go mute. That is not a Model Editor problem. Official Customer Portal path is System Config → Probes (some builds: Admin → System Config), then Device Event Log for the same UTC window. You cannot exception a model for traffic you never captured. Confirm live labels on your version via customerportal.darktrace.com before you click in production.

4. How to choose the next stamp

You are not choosing a product. You are choosing which stamp the factory is allowed to write — and which ticket you open when a stamp is missing.

You seeChooseDo not use whenProof you were right
New external peer + unusual RDP + Human Confirmation Isolate / block that destination now (firewall, NAC, EDR, or a targeted Antigena action if Fully Autonomous is already on that model). You wait for a hash, or you flip Fully Autonomous from the P1 chat with no change ticket. Mode + last action none + would-have pasted. Connection blocked on the control you own.
High score vs a peer group of one (CEO laptop) Fix tags / Device Groups so the comparison set is honest. Re-read the same breach. You disable the model because the executive is unique. Peer n is a real finance / server / backup set. Score re-evaluated against that set.
Nightly SMB spike, same dest, same window, known backup Model exception in Model Editor with owner + expiry. Tag the backup group. You turn Compromise / Ransomware / Suspicious SMB Activity off forever. Exception has an owner, a reason, and a date. Ack has an owner.
Host missing, or Event Log empty on a busy VLAN Coverage ticket: vSensor, SPAN / TAP / ERSPAN, osSensor, subnet, off-VPN. You tune models or enable Enhanced Monitoring in the dark. Probe status + PPS + Event Log rows after the mirror returns.
Leadership: “why didn’t it block?” Quote Human Confirmation / Passive and the would-have action. DETECT is not RESPOND. You answer “Darktrace failed” or promise Active without change-control. System Config → Antigena shows the group mode. Last action is none.
IOC = none, AI Analyst says Word → new RDP Hunt the story. Keep the case open. Assign an owner on the ack. You close as benign because VirusTotal is empty. Official ransomware cases often had no public IOC. New peer quoted. Related model named. Case still open.

Official Autonomous Response can run fully autonomously or inside guiderails — certain times, certain devices, certain events. Darktrace’s own wording: many organisations start in Human Confirmation and switch to fully autonomous within weeks. That switch is policy, not a night-shift reflex. Source: Darktrace Autonomous Response product page.

DETECT vs RESPOND is a buying and a policy fact

You can own Darktrace / NETWORK DETECT and still have Antigena off, Human Confirmation only, or Fully Autonomous on a subset of models and subnets. “We bought Darktrace” is not “it will block RDP.” Quote the mode on the device or group. Confirm the live label (Antigena / Autonomous Response / RESPOND) on your build in the Customer Portal.

5. Runbook Side A → B → C

Lab values only. Master DT-MASTER-LAB-01, vSensor SENSOR-LAB-17, device finance-lap / 10.10.8.22, new peer 203.0.113.88 (RFC 5737), breach MB-1042. Nothing here is a live tenant. Confirm every click path on customerportal.darktrace.com for your Threat Visualizer version before production.

Side A — probe coverage (building the factory floor)

Primary source: Darktrace Customer Portal — System Config (Probes, Push Probe Tokens) + vSensor deployment notes. Official objects: physical probe, vSensor, osSensor.

  1. Name the probe that should see this VLAN

    System Config → Probes (some builds: Admin → System Config). Find SENSOR-LAB-17. Type = vSensor. Master = DT-MASTER-LAB-01. A green Threat Visualizer homepage is not probe health. Quote connected / disconnected and last check-in.

  2. Prove the SPAN, not only the VM

    Official: a vSensor spans traffic from a virtual switch and sends data to the master appliance. If you cannot SPAN, osSensors on the guests feed the vSensor. A connected vSensor with collapsed packets/s after a core or vMotion change is a monitor-session / promiscuous-port / ERSPAN ticket. Quiet PPS on a busy VLAN is a tap story, not a tuning story.

  3. If the floor is dead, stop DETECT talk

    Open a coverage ticket with the network owner. Do not write a model exception for traffic you never captured. Darktrace is explicit: you cannot detect what is not on the wire. Source: Darktrace / NETWORK coverage + Customer Portal System Config.

Side B — device baseline, then the model breach (learning, then printing the ticket)

Primary source: Darktrace Customer Portal — Threat Visualizer User Guide (Device Summary, Device Event Log, Model Breaches / Model Breach Event Log) + darktrace.com/cyber-ai-analyst.

  1. Search the host before you argue the score

    Threat Visualizer search: hostname, IP, or MAC. Open Device Summary. Official fields: First Seen, Last Seen, Operating System, subnet, tags. If search returns nothing, stop. There is no model breach to chase. A host First Seen tonight has almost no pattern of life — that is a new-device baseline, not ransomware.

  2. Read the Event Log, then the peers

    Select the device → Device Event Log. Official TV workflow: review connections over time in the ticket UTC window. Quote dest / proto / first-seen of the new peer — or quote “no connections in window.” Peer group of finance laptops with n=3 tagged wrong is a noisy score, not a broken model. Encrypted payloads still leave dest, volume, timing, and peers.

  3. Open the Model Breach Event Log, not Slack

    Threat Visualizer → Model Breaches (Threat Tray) → the breach → Model Breach Event Log. Quote the full published name, the score / priority, the timestamp, and acknowledged vs unacknowledged. Lab ticket: Compromise / RDP / Unusual External Destination, score 82, unacknowledged. Say “high score unusual external RDP,” not “ransomware.”

  4. Use Cyber AI Analyst as a lead

    Path: Threat Visualizer → Cyber AI Analyst. Official product: it autonomously investigates relevant model alerts, forms hypotheses, and writes a natural-language incident. Quote the incident title and the related model breaches. It is not a malware family name and it is not containment. Fewer than 4% of investigations requiring human review is a Darktrace claim about scale — it is not permission to close without reading the models.

Side B fields you write in the ticket — dummy lab
Path:            Threat Visualizer → Devices → 10.10.8.22
                 → Model Breaches → MB-1042 → Event Log
Device:          finance-lap · 10.10.8.22 · VLAN20
First Seen:      2025-11-02 08:14Z
Last Seen:       2026-08-16 10:41Z
Peer group:      Finance laptops · n=3 (re-tag before you trust 82)
Model:           Compromise / RDP / Unusual External Destination
Score / status:  82 · unacknowledged
New peer:        203.0.113.88 proto RDP first-seen 10:41Z
AI Analyst:      Word → never-before-seen public RDP · lead only
IOC:             none · not a close
Do not:          say “ransomware” or open Model Editor from an empty log

Side C — Antigena / RESPOND (the action stamp)

Primary source: Darktrace Autonomous Response product page + Customer Portal System Config → Antigena + “How RESPOND Neutralizes Zero-Day Ransomware.”

  1. Quote the mode before anyone asks “why”

    Device Summary shows Antigena state for that host / group. Estate-wide switch lives at System Config → Antigena (Autonomous Response / Antigena Network). Official modes: Human Confirmation versus Fully Autonomous. Human Confirmation will not block. Confirm the live wording on your version — UI may say Passive / Active, Human Confirmation / Fully Autonomous, or RESPOND.

  2. Read last action, then would-have

    Official out-of-the-box actions (no scripting): Automatic (best option from the alert), Block matching connections, Enforce device or group pattern of life, Block all incoming / outgoing or quarantine, third-party integration (firewall, Microsoft Defender for Endpoint, CrowdStrike). Published Antigena model names look like Antigena Ransomware Block and Antigena / Network / Significant Anomaly / …. If last action is none and mode is Human Confirmation, the proof field is would-have — for example “block RDP to 203.0.113.88” or “enforce pattern of life.” That sentence is what you tell the CISO.

  3. Isolate now; Fully Autonomous later

    Blocking this RDP (firewall, NAC, EDR, or a targeted Antigena action if you already have Fully Autonomous on that model) is incident response. Flipping the group to Fully Autonomous is change-control — owner, model list, rollback. Official Active-mode story: RESPOND stopped never-before-seen ransomware with no public IOC, enforced pattern of life in seconds, then quarantined patient zero for 24 hours — only because it was actually on. Source: darktrace.com — How RESPOND Neutralizes Zero-Day Ransomware.

  4. If it is a known backup, exception with a leash

    Model Editor / model exception: owner, reason, expiry. Never disable Compromise / Ransomware / Suspicious SMB Activity forever. Ack the breach with a note. Ack is not remediation.

Proof · named field, then Closed
Teaches: operators prove a Darktrace ticket from named Threat Visualizer fields, not from a Slack paraphrase
Notice: juniors stare at a red 82. Seniors stare at probe health, First Seen, the model name, and Antigena mode.
Green success on this runbook

Probe that owns the VLAN is connected and PPS is honest. Device Summary returns the IP with First Seen / Last Seen in the ticket window. Model Breach Event Log names the model + score + unacknowledged/acknowledged. Antigena mode quoted; last action or would-have pasted. New peer (or empty Event Log) written in UTC. Owner on the ack. Isolate vs Fully Autonomous called out as two tickets. That is working. A screenshot of Slack saying “malware” is not.

6. Runtime — AI Analyst, exceptions, old baselines

Once the sensor is healthy, every interesting minute looks the same. Packets hit SPAN / TAP → vSensor or physical probe → master. Self-Learning AI updates pattern of life for the device and its peer group. A model’s conditions match → model breach with score / priority. Cyber AI Analyst may attach a written incident, re-investigate as new evidence arrives, and recommend actions. If Antigena is Fully Autonomous for that model and group, a proportionate action fires. If Human Confirmation, you get would-have only. Analyst acknowledges, hunts, isolates, or files a time-boxed exception.

Official RESPOND actions are surgical on purpose. Enforce pattern of life only allows what Darktrace already considers normal for that device or its auto-identified peer group. Block matching connections stops this connection and future matches (the published ransomware case blocked anomalous SMB, then quarantined patient zero for 24 hours while normal business continued). That is why “just quarantine the VLAN” is the wrong student reflex — and why Fully Autonomous on a mis-tagged CEO laptop is also wrong.

Secondary STIX/TAXII intelligence can be ingested to detect known threats or create custom detections based on existing IoCs. Official product still leads with behavioural detection. Closing a high-score new-peer breach because external intel is “unrated” is the opposite of the published zero-day ransomware story.

Exceptions live in Model Editor. They are how you tell the factory “this backup window is normal for this tag.” They need an owner and an expiry. An open-ended suppress is how ransomware hides in the backup window. Enhanced Monitoring is how you raise fidelity on a crown-jewel subnet after the peer group is honest — not how you compensate for a dead SPAN.

A host that joined tonight will keep scoring. That is the apprenticeship. Quote First Seen. Do not disable models. Do not treat every new-device breach as confirmed ransomware. After a few days of honest traffic, the same model gets quieter. If it does not, check tags and the probe before you touch thresholds.

Encrypted traffic is not a blind spot

Darktrace / NETWORK models connections even when the payload is encrypted — destination, volume, timing, and peers still update pattern of life. An empty Device Event Log is not “TLS so Darktrace is blind.” Empty log on a busy subnet is a SPAN / vSensor / mirror miss. Confirm probe health, then the Event Log, then talk about models.

7. Traps + Threat Visualizer proof

SymptomLooks likeActuallyFirst move
Score 82 in Slack Confirmed ransomware Unusual vs pattern of life Quote model + score + peers
“Why did Darktrace allow it?” DETECT failed Human Confirmation / Passive Mode + last action + would-have
Every CEO action is P1 Model is broken Peer group of one Fix tags / Device Groups
Unrated IP, empty VT Safe to close No public IOC (official ransomware cases too) Hunt the new peer; keep case open
“I acknowledged it” Ticket done Ack assigns owner only Containment is a different action
Nightly backup SMB Turn the model off Known window, wrong leash Exception + owner + expiry
Models went quiet after a core change Need lower thresholds SPAN / vSensor / PPS collapsed System Config → Probes, then Event Log
Device not found Darktrace is down Host never modeled Quote search miss; fix subnet / SPAN / osSensor
First Seen tonight, high scores Patient zero New baseline Quote First Seen; hunt peers; do not disable
Empty Threat Tray DETECT failed Not unusual, excepted, or no packets Event Log in the same minute
Flip Fully Autonomous at 02:00 We paid for AI Change-control, not IR Isolate now; Active later with rollback
Encrypted SMB, “blind” Need a decrypt box Connections still model Empty log = tap miss, not TLS
Proof checklist — the factory actually printed this ticket
Interview close you can steal

Darktrace / NETWORK is a learn-then-breach factory. The probe has to see the VLAN. Self-Learning AI builds a pattern of life for the device and its peer group. A model breach is unusual behaviour, not a malware conviction. I prove the ticket in Threat Visualizer: First Seen / Last Seen, the Model Breach Event Log, Antigena mode and would-have. If Antigena is Human Confirmation I isolate the new peer myself. I do not close on an empty IOC. I do not flip Fully Autonomous at 02:00.

Next: take the same dummy fields as full night-shift tickets on the Darktrace evidence desk. Practice them on the Darktrace dummy lab.

Knowledge check

Six judgment questions. Map each miss back to the section named in the reason.

Q1

Threat Visualizer shows Compromise / RDP / Unusual External Destination, score 82, on finance-lap. What is the factory’s first honest question?

Correct: b. Learn-then-breach: coverage → baseline → model → Antigena. Score is unusual, not a family name. Re-read Quick answer and Mental model.
Q2

Device Summary shows First Seen 01:40Z tonight and three high-score breaches. First move?

Correct: a. A host the factory just met will score almost everything. That is the apprenticeship, not a conviction. Re-read Side B and the traps table.
Q3

What is a Darktrace model breach on / NETWORK?

Correct: d. Official: a model defines conditions; a match is a model breach. Self-Learning AI does not rely on signatures. Re-read Mental model and Learn, then breach.
Q4

Leadership asks why Darktrace allowed the RDP. Device shows Human Confirmation and would-have-blocked that destination. What do you say?

Correct: c. Quote the mode. Fully Autonomous is change-control. Official ransomware stops needed Active / Fully Autonomous. Re-read Side C and How to choose.
Q5

Models on VLAN20 went quiet after a core change. First check?

Correct: b. Quiet models can be a visibility outage. Connected is not a healthy SPAN. Re-read Side A and Learn, then breach.
Q6

Nightly backup SMB is scoring on Compromise / Ransomware / Suspicious SMB Activity. Correct action?

Correct: c. Exceptions need a leash. Open-ended suppress is how ransomware hides in the backup window. Re-read How to choose and Side C.

Sources

Related: Blog 2 · Evidence desk · Darktrace interview hub · Dummy lab · Models & breaches · Autonomous response

Dummy lab data only. No live tenant IDs. Confirm syntax, menu labels, and change-control on the production release via the Customer Portal.