MDR partner · Darktrace

MDR for Darktrace: the AI sees the anomaly, an analyst makes the decision.

For teams running Darktrace with nobody to approve an autonomous action at two in the morning, or letting it act without knowing what it blocks. The Fortgale MDR service reads Darktrace detections together with endpoint and identity and contains at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Darktrace
MDR · live
Darktrace sensor activeEndpoint · cloud · identity telemetry
Darktrace
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Darktrace responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Darktrace + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Darktrace
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Darktrace.

The Darktrace products the SOC takes on. If Darktrace is not in place yet, licensing and sensors are part of the service.

01

Darktrace / NETWORK

Internal and perimeter traffic compared with the usual behaviour of every device: scanning, beaconing, lateral movement and exfiltration surface as deviations.

02

Darktrace / IDENTITY

SaaS accounts and identity providers: anomalous sign-ins and out-of-profile use, with actions such as disabling the account and forcing logout.

03

Darktrace / EMAIL

Email assessed on the behaviour of senders and recipients, with actions on the message and its links.

04

Darktrace / CLOUD and / ENDPOINT

Cloud workloads and endpoint telemetry in the same view; endpoint isolation goes through the EDR integration.

05

Hunting and investigation

Hunting in Advanced Search led by Fortgale analysts, starting from the incidents the Darktrace AI Analyst groups together.

06

Watched Domains and custom models

Fortgale indicators loaded as Watched Domains and custom models in the Model Editor for the behaviour that matters in your environment.

What we add

What Fortgale adds on top of Darktrace.

A network detection tells you something is moving; it does not tell you who it is or what to do. Fortgale adds the missing part: every network detection is read by an analyst against 287 tracked adversary groups and attack tools and correlated with endpoint and identity activity, so lateral movement becomes an attribution and a decision. Noise drops by more than 90% by day 30, and containment runs through the controls your environment already has: median TTD <15 minutes, median TTC <30 minutes.

On Darktrace the response is Autonomous Response, the current name of Antigena: blocking connections that match the anomaly, enforcing the device's pattern of life, blocking incoming or outgoing traffic, quarantining the device. On identities it disables the account or forces logout; on email it moves the message and locks links.

Each model can act autonomously or in Human Confirmation mode, with the action pending approval, and a weekly schedule decides when each applies. That is where Fortgale works: which models act alone, which production assets always need an analyst, who approves out of hours. Isolating an endpoint or killing a process are not network actions: they go through the integrated EDR.

Fortgale CTI indicators, 34,000 IOCs a week, arrive as Watched Domains. Behaviour says a device is anomalous, the indicator says who owns the infrastructure it contacts: together they move the decision from “odd” to “contain”.

Takeover

How we take over your Darktrace environment.

On a Darktrace instance already in production, the behavioural model of the environment already exists: takeover does not start from scratch and does not touch sensors or configuration.

Technical onboarding closes in one week: users, Autonomous Response mode per model, the confirmation schedule and integrations with EDR and firewalls.

On a new deployment the initial learning follows Darktrace's own timing, and Autonomous Response stays in confirmation mode until the model settles. On your side: the assets to keep out of autonomous actions, who approves out of hours and the escalation list.

From the field

Storming Tide: the signal was the internal network.

In February 2026 the Fortgale incident response team contained Operation Storming Tide at a European logistics and transport company. Access dated back months, through a vulnerable Fortinet firewall with a persistent VPN tunnel; after a long dormant period the attacker, attributed to Mora_001, moved from unmanaged assets into the internal network with Matanbuchus 3.0, Astarion, SystemBC and RClone. The investigation started from anomalous internal network scanning, and neither exfiltration nor ransomware happened.

The article is not about Darktrace, but the starting point of the investigation is a network detection: unmanaged assets have no agent, while the scan travels across the network. A scan from a device that has never scanned before, the traffic of a proxy such as SystemBC and the outbound volumes of RClone are the kind of deviation a network behaviour model is built to see; with Autonomous Response the analyst can block the device's connections while the EDR isolates the covered hosts.

FAQ

What buyers running Darktrace actually ask.

Do we need Darktrace's MDR service to work with Fortgale?

No. Darktrace Managed Detection & Response is the vendor's own service. Fortgale works independently on the Darktrace instance you already have, from a SOC in Milan, with analysts who decide with you which actions to leave to automation.

How do you correlate Darktrace anomalies with endpoint and identity?

A network anomaly says a device behaves differently. The Fortgale analyst checks on the EDR which process generates the traffic and in identity logs which account uses it: when both sides agree, the anomaly becomes an incident with attribution and a containment decision.

Do you let Autonomous Response act on its own?

Where you have decided so. Each model can act autonomously or wait for confirmation, on different schedules: at onboarding we agree which actions are autonomous, which production assets always need an analyst and who approves out of hours. Critical decisions on production always involve a person.

How do we move from another provider without a gap in coverage?

Sensors and the behavioural model stay on the instance: only users, response modes and contacts change. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Darktrace licences, or do you?

Both models work: Fortgale operates the Darktrace instance you already own, or provides licensing and sensors as part of the service. Autonomous Response has its own licence: without it, Darktrace detects but does not act, and response goes through EDR and firewalls.

See a real runbook

A real runbook on your Darktrace instance.

We walk through a network anomaly step by step: the model that flagged it, the check on the EDR, the Autonomous Response action approved by the analyst and the containment of the host. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.