# Darktrace is a learn-then-breach factory. Probe, baseline, then Antigena.

Source: https://ai.techclick.in/blog_darktrace_session_factory
Markdown: https://ai.techclick.in/blog_darktrace_session_factory.md
Publisher: Techclick Infosec Pvt Ltd

Darktrace is a learn-then-breach factory: probe coverage → device baseline → model breach → Antigena. Prove the ticket in Threat Visualizer, not Slack.

Quick answer

   Darktrace / NETWORK is a  learn-then-breach factory . A physical probe,  vSensor , or  osSensor  must see the packets. Self-Learning AI then builds a  pattern of life  for the device, its peer group, and the organisation. A  model  is a set of conditions; a match is a  model breach  with a score — unusual, not a family name.  Cyber AI Analyst  may write an incident.  Antigena  (Darktrace RESPOND) may act only if the group is Fully Autonomous. Success is a named Threat Visualizer field, not “Darktrace says malware.”

   Say this out loud

   I do not start with VirusTotal. I ask whether the probe saw the VLAN, whether Device Summary has First Seen / Last Seen, which model breached at what score against which peer group, and whether Antigena is Human Confirmation or Fully Autonomous. Score is unusual. No IOC is not a close. Coverage first — you cannot score what the SPAN never sent.

## 1. Why a score is not a factory

 SOC chat at 10:41Z: finance laptop  10.10.8.22  opened RDP to  203.0.113.88 . DETECT raised a model at score  82 . The L1 comment is “Darktrace says it is ransomware.” Leadership then asks why it was allowed. Both sentences skip the product. They treat the factory as a signature engine that prints convictions.

 Official Darktrace threat-detection language is the opposite. Self-Learning AI is trained  per deployment . It continuously ingests live data, builds a pattern of life for assets, peer groups, and the organisation, and flags behaviour that is both anomalous and unlikely to be benign — without relying on signatures, rules, or threat intelligence. A high score means rare versus that learned self. It does not name a malware family. It does not prove a hash. It does not prove Antigena acted.

   Hero · the factory floor

   Notice: the laptop is scored, not convicted. The factory must see the packets before it can learn, and it must learn before it can breach a model.

#### What the ticket asked

 “Darktrace says ransomware.” That sentence is a hypothesis. The factory may have printed an unusual-RDP ticket on a host the SPAN barely knows, with Antigena still in Human Confirmation.

#### What you prove first

 Probe / vSensor health, then Device Summary First Seen / Last Seen, then the Model Breach Event Log, then Antigena mode. The evidence desk is the night-shift version of this order.

   The lie every L1 repeats

   “Score 82 means malware, and we bought Darktrace so it should have blocked.” An 82 is how unusual the behaviour is versus pattern of life. DETECT is not RESPOND. Human Confirmation (Passive) will not block. A host First Seen tonight will score almost everything. Widening a model or flipping Fully Autonomous at 02:00 does not fix a dead SPAN.

 Concept first: the object is the  device in the model , not the Slack paraphrase. Path second: official Threat Visualizer surfaces in a fixed order. Do third: Side A builds the floor (probes), Side B reads the apprenticeship and the printed ticket (baseline + breach), Side C reads the action stamp (Antigena). Miss a stamp and you troubleshoot the wrong layer.

## 2. Mental model — four stamps on one ticket

 Hold four parts. Interviews fail when people mix them. Darktrace publishes these as separate products and UI surfaces. You do not buy four factories. One appliance chain writes four stamps, in this order, only if the previous stamp exists.

#### 1. Probe coverage is the floor

     Physical probe,  vSensor  (SPAN from a virtual switch to the master), or  osSensor  when you cannot SPAN. No packets on the wire = no pattern of life = no honest model breach.

#### 2. Device baseline is the apprenticeship

     Self-Learning AI learns normal for that host, its peer group, and the estate. Device Summary  First Seen  /  Last Seen  prove the host is in the model. A brand-new device has almost no self.

#### 3. Model breach is the ticket

     A model is a set of conditions. A match is a  model breach  with a score / priority. Quote the published name —  Compromise / Ransomware / Suspicious SMB Activity , not “Darktrace alert.”

#### 4. Antigena is the action stamp

     Official RESPOND language:  Human Confirmation  versus  Fully Autonomous . Actions include enforce pattern of life, block matching connections, quarantine, or a third-party integration. Would-have is not a live block.

   Flow 1 · one ticket, four stamps, one order

       Darktrace learn-then-breach factory: probe, device baseline, model breach, Antigena

- MB-1042 · four stamps, one device · 10.10.8.22 Device 10.10.8.22 VLAN20 New peer 203.0.113.88 RDP packets on SPAN → vSensor → master no SPAN = no Event Log = no honest score 1 Probe stamp did the wire arrive? vSensor · SPAN · PPS 2 Baseline stamp whose pattern of life First Seen · peers 3 Breach stamp which model · score unusual ≠ family 4 Antigena stamp allowed to act? HC vs Autonomous Cyber AI Analyst may write an incident. IOC / STIX is extra. Ack assigns an owner — it does not contain the host. Threat Visualizer is where you read the finished ticket. Slack is not a Model Breach Event Log. Read left → right. If stamp 1 is missing, stamps 2–4 are fiction. If stamp 4 is Human Confirmation, leadership’s “why didn’t it block?” already has an answer. Pre-train the vocabulary before the runbook. A model defines conditions; when they are met, Darktrace raises a model breach . Official DETECT blogs publish names in Category / Behaviour form — Device / Reverse DNS Sweep , Compromise / Ransomware / Suspicious SMB Activity , Compromise / Beaconing Activity To External Rare . Enhanced Monitoring models are higher-fidelity DETECT models, still not malware proof. Would-have is what RESPOND would do in Fully Autonomous. Acknowledge assigns an owner in Threat Visualizer — it does not isolate the host. vSensor is the virtual probe that needs a working SPAN (or osSensor feed) and a master appliance. Official Self-Learning AI stack (Darktrace threat-detection glossary): live training data unique to the deployment; Bayesian models that update with new evidence; clustering so a peer group can stop the AI from mis-learning malice as normal; anomaly scores plus a meta-classifier that ranks rarity. That is why a CEO laptop in a peer set of one scores like an incident on every new SaaS. The comparison set is the apprenticeship, not a bug in the model. ## 3. Learn, then breach The factory is sequential on purpose. Packets hit a SPAN / TAP / ERSPAN, a vSensor or physical probe, then the master. Pattern of life updates. A model’s conditions match — then, and only then, you have a breach. Later packets on a healthy sensor keep teaching the same device. That is why “we just installed Darktrace yesterday” and “the core change at 01:00 killed the SPAN” are different tickets that look the same in Slack: a red number, or no number at all. Path · coverage diamond before DETECT Notice: the first diamond is not “malware or not.” It is “did the probe see this host?” Path A is hunt and contain. Path B is coverage, peer-set, or a time-boxed exception. Flow 2 · official order at the breach (student labels) Darktrace first-minute path: probe coverage, device baseline, model breach, Antigena Ingress → coverage? → baseline → breach → Antigena? 1 Ticket MB-1042 · 82 Probe / SPAN seeing host? yes LEARN PATH — Device Summary then Event Log First Seen · Last Seen · peers · connections no → coverage ticket · do not open Model Editor First Seen in the model? Peer group honest set? Model + score Event Log AI Analyst lead, not close Antigena mode last action · would-have NEW PEER + HIGH SCORE + HUMAN CONFIRMATION isolate / block that connection now · Fully Autonomous is change-control, not a 02:00 toggle Official facts students invert 1. Encrypted payloads still update pattern of life — dest, volume, timing, peers. Empty Event Log is a tap miss, not “TLS so Darktrace is blind.” 2. Cyber AI Analyst investigates model breaches and writes an incident. It is not a malware family and it is not containment. 3. Published ransomware cases needed Antigena in Active / Fully Autonomous to stop encryption in seconds — with no public IOC. Read left → right, then the green bar. Decision diamond = “does the probe see this host?” DoS-style panic (“flip Active”) sits after you quote the mode, on purpose. #1 student trap — score without a floor A host that just appeared, or a VLAN whose PPS collapsed after a core change, will either scream or go mute. That is not a Model Editor problem. Official Customer Portal path is System Config → Probes (some builds: Admin → System Config), then Device Event Log for the same UTC window. You cannot exception a model for traffic you never captured. Confirm live labels on your version via customerportal.darktrace.com before you click in production. ## 4. How to choose the next stamp You are not choosing a product. You are choosing which stamp the factory is allowed to write — and which ticket you open when a stamp is missing. You see Choose Do not use when Proof you were right New external peer + unusual RDP + Human Confirmation Isolate / block that destination now (firewall, NAC, EDR, or a targeted Antigena action if Fully Autonomous is already on that model). You wait for a hash, or you flip Fully Autonomous from the P1 chat with no change ticket. Mode + last action none + would-have pasted. Connection blocked on the control you own. High score vs a peer group of one (CEO laptop) Fix tags / Device Groups so the comparison set is honest. Re-read the same breach. You disable the model because the executive is unique. Peer n is a real finance / server / backup set. Score re-evaluated against that set. Nightly SMB spike, same dest, same window, known backup Model exception in Model Editor with owner + expiry. Tag the backup group. You turn Compromise / Ransomware / Suspicious SMB Activity off forever. Exception has an owner, a reason, and a date. Ack has an owner. Host missing, or Event Log empty on a busy VLAN Coverage ticket: vSensor, SPAN / TAP / ERSPAN, osSensor, subnet, off-VPN. You tune models or enable Enhanced Monitoring in the dark. Probe status + PPS + Event Log rows after the mirror returns. Leadership: “why didn’t it block?” Quote Human Confirmation / Passive and the would-have action. DETECT is not RESPOND. You answer “Darktrace failed” or promise Active without change-control. System Config → Antigena shows the group mode. Last action is none. IOC = none, AI Analyst says Word → new RDP Hunt the story. Keep the case open. Assign an owner on the ack. You close as benign because VirusTotal is empty. Official ransomware cases often had no public IOC. New peer quoted. Related model named. Case still open. Official Autonomous Response can run fully autonomously or inside guiderails — certain times, certain devices, certain events. Darktrace’s own wording: many organisations start in Human Confirmation and switch to fully autonomous within weeks. That switch is policy, not a night-shift reflex. Source: Darktrace Autonomous Response product page. DETECT vs RESPOND is a buying and a policy fact You can own Darktrace / NETWORK DETECT and still have Antigena off, Human Confirmation only, or Fully Autonomous on a subset of models and subnets. “We bought Darktrace” is not “it will block RDP.” Quote the mode on the device or group. Confirm the live label (Antigena / Autonomous Response / RESPOND) on your build in the Customer Portal. ## 5. Runbook Side A → B → C Lab values only. Master DT-MASTER-LAB-01 , vSensor SENSOR-LAB-17 , device finance-lap / 10.10.8.22 , new peer 203.0.113.88 (RFC 5737), breach MB-1042 . Nothing here is a live tenant. Confirm every click path on customerportal.darktrace.com for your Threat Visualizer version before production. ### Side A — probe coverage (building the factory floor) Primary source: Darktrace Customer Portal — System Config (Probes, Push Probe Tokens) + vSensor deployment notes. Official objects: physical probe, vSensor, osSensor. #### Name the probe that should see this VLAN System Config → Probes (some builds: Admin → System Config). Find SENSOR-LAB-17 . Type = vSensor. Master = DT-MASTER-LAB-01 . A green Threat Visualizer homepage is not probe health. Quote connected / disconnected and last check-in.

- #### Prove the SPAN, not only the VM Official: a vSensor spans traffic from a virtual switch and sends data to the master appliance. If you cannot SPAN, osSensors on the guests feed the vSensor. A connected vSensor with collapsed packets/s after a core or vMotion change is a monitor-session / promiscuous-port / ERSPAN ticket. Quiet PPS on a busy VLAN is a tap story, not a tuning story.

- #### If the floor is dead, stop DETECT talk Open a coverage ticket with the network owner. Do not write a model exception for traffic you never captured. Darktrace is explicit: you cannot detect what is not on the wire. Source: Darktrace / NETWORK coverage + Customer Portal System Config.

     https://lab.cloud.darktrace.com · System Config › Probes › SENSOR-LAB-17

     Training mock · not live

       System Config &nbsp;›&nbsp; Probes &nbsp;›&nbsp; SENSOR-LAB-17

### vSensor · SENSOR-LAB-17

         Health  SPAN / capture  Tokens

          Type  Probe   vSensor · VLAN20 SPAN

          Master  DT-MASTER-LAB-01

          Status  Connected

          SPAN / capture  OK · pps=12.4k

 10:00Z  status=connected  pps=12.4k  span=ok

 10:40Z  finance-lap 10.10.8.22 still in Device Event Log

 If pps collapses after a core change → coverage ticket, not Model Editor

       Connected is not a healthy SPAN. Sample Event Log on two other VLAN20 hosts before you argue DETECT.

         Push Probe Tokens
         Open Device Event Log

    Source:  Darktrace Customer Portal — System Config (Probes, Push Probe Tokens). vSensor as official virtual probe that receives a SPAN and reports to a master. Dummy values only. Confirm labels on your version.

### Side B — device baseline, then the model breach (learning, then printing the ticket)

 Primary source: Darktrace Customer Portal — Threat Visualizer User Guide (Device Summary, Device Event Log, Model Breaches / Model Breach Event Log) + darktrace.com/cyber-ai-analyst.

- #### Search the host before you argue the score Threat Visualizer search: hostname, IP, or MAC. Open Device Summary . Official fields: First Seen , Last Seen , Operating System, subnet, tags. If search returns nothing, stop. There is no model breach to chase. A host First Seen tonight has almost no pattern of life — that is a new-device baseline, not ransomware.

- #### Read the Event Log, then the peers Select the device → Device Event Log . Official TV workflow: review connections over time in the ticket UTC window. Quote dest / proto / first-seen of the new peer — or quote “no connections in window.” Peer group of finance laptops with n=3 tagged wrong is a noisy score, not a broken model. Encrypted payloads still leave dest, volume, timing, and peers.

- #### Open the Model Breach Event Log, not Slack Threat Visualizer → Model Breaches (Threat Tray) → the breach → Model Breach Event Log . Quote the full published name, the score / priority, the timestamp, and acknowledged vs unacknowledged. Lab ticket: Compromise / RDP / Unusual External Destination , score 82, unacknowledged. Say “high score unusual external RDP,” not “ransomware.”

- #### Use Cyber AI Analyst as a lead Path: Threat Visualizer → Cyber AI Analyst . Official product: it autonomously investigates relevant model alerts, forms hypotheses, and writes a natural-language incident. Quote the incident title and the related model breaches. It is not a malware family name and it is not containment. Fewer than 4% of investigations requiring human review is a Darktrace claim about scale — it is not permission to close without reading the models.

     https://lab.cloud.darktrace.com · Threat Visualizer › Model Breaches › MB-1042

     Training mock · not live

       Threat Visualizer &nbsp;›&nbsp; Model Breaches &nbsp;›&nbsp; MB-1042

### Model Breach Event Log

          Device  Baseline   10.10.8.22 · finance-lap · VLAN20

          First Seen / Last Seen  2025-11-02 08:14Z · 10:41Z

          Model  Breach   Compromise / RDP / Unusual External Destination

          Score / status  82 · unacknowledged

         device:10.10.8.22  window:last 60m

         Apply Filter

               Time (UTC)
               Model
               Score
               Status
               Antigena

               10:12:08
               Device / Reverse DNS Sweep
               41
               Ack
               None

               10:41:06
               Compromise / RDP / Unusual External Destination
               82
               Unack
               Would-have

       Peer group Finance laptops · n=3 (too small). New dest 203.0.113.88 proto RDP. Cyber AI Analyst incident is a lead — Word → new public RDP — not a close.

         Acknowledge
         Open Event Log

    Source:  Darktrace Customer Portal — Threat Visualizer User Guide (Device Summary: First Seen, Last Seen; Model Breaches, Model Breach Event Log). Model name style as published on darktrace.com blogs (Category / Behaviour). Dummy values only.

  Side B fields you write in the ticket — dummy lab
 Path:            Threat Visualizer → Devices → 10.10.8.22
                 → Model Breaches → MB-1042 → Event Log
Device:          finance-lap · 10.10.8.22 · VLAN20
First Seen:      2025-11-02 08:14Z
Last Seen:       2026-08-16 10:41Z
Peer group:      Finance laptops · n=3 (re-tag before you trust 82)
Model:           Compromise / RDP / Unusual External Destination
Score / status:  82 · unacknowledged
New peer:        203.0.113.88 proto RDP first-seen 10:41Z
AI Analyst:      Word → never-before-seen public RDP · lead only
IOC:             none · not a close
Do not:          say “ransomware” or open Model Editor from an empty log

### Side C — Antigena / RESPOND (the action stamp)

 Primary source: Darktrace Autonomous Response product page + Customer Portal System Config → Antigena + “How RESPOND Neutralizes Zero-Day Ransomware.”

- #### Quote the mode before anyone asks “why” Device Summary shows Antigena state for that host / group. Estate-wide switch lives at System Config → Antigena (Autonomous Response / Antigena Network). Official modes: Human Confirmation versus Fully Autonomous . Human Confirmation will not block. Confirm the live wording on your version — UI may say Passive / Active, Human Confirmation / Fully Autonomous, or RESPOND.

- #### Read last action, then would-have Official out-of-the-box actions (no scripting): Automatic (best option from the alert), Block matching connections, Enforce device or group pattern of life, Block all incoming / outgoing or quarantine, third-party integration (firewall, Microsoft Defender for Endpoint, CrowdStrike). Published Antigena model names look like Antigena Ransomware Block and Antigena / Network / Significant Anomaly / … . If last action is none and mode is Human Confirmation, the proof field is would-have — for example “block RDP to 203.0.113.88” or “enforce pattern of life.” That sentence is what you tell the CISO.

- #### Isolate now; Fully Autonomous later Blocking this RDP (firewall, NAC, EDR, or a targeted Antigena action if you already have Fully Autonomous on that model) is incident response. Flipping the group to Fully Autonomous is change-control — owner, model list, rollback. Official Active-mode story: RESPOND stopped never-before-seen ransomware with no public IOC, enforced pattern of life in seconds, then quarantined patient zero for 24 hours — only because it was actually on. Source: darktrace.com — How RESPOND Neutralizes Zero-Day Ransomware.

- #### If it is a known backup, exception with a leash Model Editor / model exception: owner, reason, expiry. Never disable Compromise / Ransomware / Suspicious SMB Activity forever. Ack the breach with a note. Ack is not remediation.

     https://lab.cloud.darktrace.com · System Config › Antigena › VLAN20 Finance

     Training mock · not live

       System Config &nbsp;›&nbsp; Antigena / Autonomous Response &nbsp;›&nbsp; VLAN20

### Antigena Network · VLAN20 Finance

          Deployment mode  Antigena   Human Confirmation

          Scope  Device group · VLAN20

          Last action  none

          Would-have (Fully Autonomous)  Block matching connections · RDP to 203.0.113.88

        Guiderails (official product)  Certain times · certain devices · certain events — change ticket required

       Human Confirmation will not block. Would-have is Darktrace language. Dummy lab only. Do not flip Fully Autonomous from a P1 chat.

         Cancel
         Open change-control

    Click next:  isolate the RDP on a control you already own, then open change-control if the business wants Fully Autonomous.  Source:  Darktrace Autonomous Response (Human Confirmation vs fully autonomous; enforce pattern of life; block matching connections) + Customer Portal System Config.

   Proof · named field, then Closed

   Notice: juniors stare at a red 82. Seniors stare at probe health, First Seen, the model name, and Antigena mode.

   Green success on this runbook

   Probe that owns the VLAN is connected and PPS is honest. Device Summary returns the IP with  First Seen  /  Last Seen  in the ticket window. Model Breach Event Log names the model + score + unacknowledged/acknowledged. Antigena mode quoted; last action or would-have pasted. New peer (or empty Event Log) written in UTC. Owner on the ack. Isolate vs Fully Autonomous called out as two tickets. That is working. A screenshot of Slack saying “malware” is not.

## 6. Runtime — AI Analyst, exceptions, old baselines

 Once the sensor is healthy, every interesting minute looks the same. Packets hit SPAN / TAP → vSensor or physical probe → master. Self-Learning AI updates pattern of life for the device and its peer group. A model’s conditions match → model breach with score / priority. Cyber AI Analyst may attach a written incident, re-investigate as new evidence arrives, and recommend actions. If Antigena is Fully Autonomous for that model and group, a proportionate action fires. If Human Confirmation, you get would-have only. Analyst acknowledges, hunts, isolates, or files a time-boxed exception.

 Official RESPOND actions are surgical on purpose.  Enforce pattern of life  only allows what Darktrace already considers normal for that device or its auto-identified peer group.  Block matching connections  stops this connection and future matches (the published ransomware case blocked anomalous SMB, then quarantined patient zero for 24 hours while normal business continued). That is why “just quarantine the VLAN” is the wrong student reflex — and why Fully Autonomous on a mis-tagged CEO laptop is also wrong.

 Secondary STIX/TAXII intelligence can be ingested to detect known threats or create custom detections based on existing IoCs. Official product still leads with behavioural detection. Closing a high-score new-peer breach because external intel is “unrated” is the opposite of the published zero-day ransomware story.

 Exceptions live in  Model Editor . They are how you tell the factory “this backup window is normal for this tag.” They need an owner and an expiry. An open-ended suppress is how ransomware hides in the backup window. Enhanced Monitoring is how you raise fidelity on a crown-jewel subnet after the peer group is honest — not how you compensate for a dead SPAN.

 A host that joined tonight will keep scoring. That is the apprenticeship. Quote First Seen. Do not disable models. Do not treat every new-device breach as confirmed ransomware. After a few days of honest traffic, the same model gets quieter. If it does not, check tags and the probe before you touch thresholds.

   Encrypted traffic is not a blind spot

   Darktrace / NETWORK models connections even when the payload is encrypted — destination, volume, timing, and peers still update pattern of life. An empty Device Event Log is not “TLS so Darktrace is blind.” Empty log on a busy subnet is a SPAN / vSensor / mirror miss. Confirm probe health, then the Event Log, then talk about models.

## 7. Traps + Threat Visualizer proof

        Symptom  Looks like  Actually  First move

         Score 82 in Slack
         Confirmed ransomware
         Unusual vs pattern of life
         Quote model + score + peers

         “Why did Darktrace allow it?”
         DETECT failed
         Human Confirmation / Passive
         Mode + last action + would-have

         Every CEO action is P1
         Model is broken
         Peer group of one
         Fix tags / Device Groups

         Unrated IP, empty VT
         Safe to close
         No public IOC (official ransomware cases too)
         Hunt the new peer; keep case open

         “I acknowledged it”
         Ticket done
         Ack assigns owner only
         Containment is a different action

         Nightly backup SMB
         Turn the model off
         Known window, wrong leash
         Exception + owner + expiry

         Models went quiet after a core change
         Need lower thresholds
         SPAN / vSensor / PPS collapsed
         System Config → Probes, then Event Log

         Device not found
         Darktrace is down
         Host never modeled
         Quote search miss; fix subnet / SPAN / osSensor

         First Seen tonight, high scores
         Patient zero
         New baseline
         Quote First Seen; hunt peers; do not disable

         Empty Threat Tray
         DETECT failed
         Not unusual, excepted, or no packets
         Event Log in the same minute

         Flip Fully Autonomous at 02:00
         We paid for AI
         Change-control, not IR
         Isolate now; Active later with rollback

         Encrypted SMB, “blind”
         Need a decrypt box
         Connections still model
         Empty log = tap miss, not TLS

   Proof checklist — the factory actually printed this ticket

- UTC window written next to the tool you opened.

- System Config → Probes : the vSensor / probe that owns this VLAN is the one you think it is; SPAN / PPS honest.

- Device Summary returns this hostname / IP with First Seen / Last Seen (or you quoted device not found and stopped).

- Device Event Log shows the new peer in the window — or proves the log is empty (coverage, not Model Editor).

- Model Breach Event Log names the model + score + status — not “Darktrace alert.”

- Peer group is an honest set, or you said the set is too small before you treated 82 as high-fidelity.

- Cyber AI Analyst incident quoted as a lead, or explicitly empty.

- Antigena mode + last action + would-have pasted. Human Confirmation will not block.

- IOC / intel stated as extra, not as close.

- Owner on the ack. Exception has expiry if you tuned. Isolate vs Fully Autonomous are two tickets.

   Interview close you can steal

   Darktrace / NETWORK is a learn-then-breach factory. The probe has to see the VLAN. Self-Learning AI builds a pattern of life for the device and its peer group. A model breach is unusual behaviour, not a malware conviction. I prove the ticket in Threat Visualizer: First Seen / Last Seen, the Model Breach Event Log, Antigena mode and would-have. If Antigena is Human Confirmation I isolate the new peer myself. I do not close on an empty IOC. I do not flip Fully Autonomous at 02:00.

 Next: take the same dummy fields as full night-shift tickets on the  Darktrace evidence desk . Practice them on the  Darktrace dummy lab .

## Knowledge check

   Six judgment questions. Map each miss back to the section named in the reason.

       Q1
       Threat Visualizer shows Compromise / RDP / Unusual External Destination, score 82, on finance-lap. What is the factory’s first honest question?

           Which malware family did Darktrace confirm?
           Did the probe / SPAN see this host, then what is First Seen, the model, the peer group, and Antigena mode?
           Has Antigena already blocked it because the score is high?
           Close the ticket — 82 is a false positive until a hash lands

       Correct:  b . Learn-then-breach: coverage → baseline → model → Antigena. Score is unusual, not a family name. Re-read Quick answer and Mental model.

       Q2
       Device Summary shows First Seen 01:40Z tonight and three high-score breaches. First move?

           Quote First Seen — this is a new-device baseline, hunt peers, do not disable models
           Declare patient-zero ransomware and isolate the whole VLAN
           Turn off Enhanced Monitoring so the new host can finish learning in silence
           Flip Fully Autonomous immediately so Antigena can teach the baseline

       Correct:  a . A host the factory just met will score almost everything. That is the apprenticeship, not a conviction. Re-read Side B and the traps table.

       Q3
       What is a Darktrace model breach on / NETWORK?

           A signature match against a global malware lake
           Proof that Antigena quarantined the host
           A Cyber AI Analyst family name you can close on
           A model’s conditions matched — unusual behaviour versus the learned pattern of life, with a score, not a courtroom verdict

       Correct:  d . Official: a model defines conditions; a match is a model breach. Self-Learning AI does not rely on signatures. Re-read Mental model and Learn, then breach.

       Q4
       Leadership asks why Darktrace allowed the RDP. Device shows Human Confirmation and would-have-blocked that destination. What do you say?

           The sensor missed the packets so DETECT never fired
           Score 82 is too low for RESPOND
           DETECT worked; Antigena is Human Confirmation on this group so nothing was blocked — would-have is block that RDP
           Flip Fully Autonomous immediately from the P1 chat with no change ticket

       Correct:  c . Quote the mode. Fully Autonomous is change-control. Official ransomware stops needed Active / Fully Autonomous. Re-read Side C and How to choose.

       Q5
       Models on VLAN20 went quiet after a core change. First check?

           Lower every model threshold in Model Editor
           System Config → Probes: vSensor / SPAN health and PPS, then Device Event Log — coverage before tuning
           Enable Antigena Fully Autonomous org-wide
           Acknowledge all historic breaches so the tray looks clean

       Correct:  b . Quiet models can be a visibility outage. Connected is not a healthy SPAN. Re-read Side A and Learn, then breach.

       Q6
       Nightly backup SMB is scoring on Compromise / Ransomware / Suspicious SMB Activity. Correct action?

           Disable the model permanently
           Isolate the backup server as ransomware
           Time-boxed Model Editor exception with an owner and expiry; tag the backup group
           Leave it unacked so the SOC stays alert

       Correct:  c . Exceptions need a leash. Open-ended suppress is how ransomware hides in the backup window. Re-read How to choose and Side C.

       Check answers
       Reset

## Sources

- Darktrace Customer Portal — confirm live Threat Visualizer paths, Device Summary, Model Breach Event Log, Model Editor, System Config → Probes / Antigena on your version before you click in production

- Darktrace / NETWORK — Self-Learning AI on your data, Cyber AI Analyst, autonomous response, encrypted + decrypted traffic analysis

- Darktrace threat detection glossary — pattern of life for assets, peer groups, and the organisation; Bayesian + clustering; no signatures required

- Cyber AI Analyst — autonomously investigates relevant model alerts, hypotheses, natural-language incidents

- Autonomous Response — Human Confirmation vs fully autonomous; enforce pattern of life; block matching connections; quarantine; guiderails

- How RESPOND (formerly Antigena) neutralized zero-day ransomware — Active / Fully Autonomous, no public IOC, Compromise / Ransomware / Suspicious SMB Activity , Antigena Ransomware Block , Device / Reverse DNS Sweep

- Customer Portal · syslog JSON schema — Model Breach Alert vs AI Analyst Alert; a model is a set of conditions (confirm path on your portal build)

 Related:  Blog 2 · Evidence desk  ·  Darktrace interview hub  ·  Dummy lab  ·  Models &amp; breaches  ·  Autonomous response

 Dummy lab data only. No live tenant IDs. Confirm syntax, menu labels, and change-control on the production release via the Customer Portal.

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
