Darktrace ActiveAI · Self-Learning
Pattern of life per device, network, user. Native NDR + email (Antigena Email) + cloud + endpoint. Detection of unknown unknowns via behavioural anomalies, no signatures.
The Fortgale European SOC 24·7·365 governing the Darktrace AI. Antigena autonomous response validated by L2/L3 analysts to avoid false positives, ~11 min median containment on incident escalation.
Darktrace ActiveAI builds a 'pattern of life' for every device. Powerful for unknown threats but prone to false positives on heterogeneous environments. Fortgale governs the Antigena AI with European analysts who know the operational context of European enterprises.
Pattern of life per device, network, user. Native NDR + email (Antigena Email) + cloud + endpoint. Detection of unknown unknowns via behavioural anomalies, no signatures.
L2/L3 analysts specialised on Darktrace. Antigena tuning, false positive reduction, contextualisation on European environments. Triage <15 min on Darktrace AI alerts.
Validation of autonomous response: which traffic to block, which to slow. Custom rules for business-critical processes. Direct escalation to Fortgale IR. Full NIS2 national CSIRT notification support.
From self-learning baseline to validated Antigena response — all governed by Fortgale with European analysts who know operational context.
7-14 days of learning to build the per-device pattern of life. Sensors on network (NDR), email (Antigena Email), cloud, endpoint. Continuous baseline updates.
Detection of behavioural anomalies via Self-Learning AI. Fortgale tunes thresholds and exclusions on European context, reducing false positives by 60-80%.
European SOC validates every Darktrace AI decision before Antigena fires. Critical decisions never fully autonomous on production assets. Direct interaction in your business language.
Antigena governed: autonomous traffic block, anomalous device isolation, email quarantine. Direct escalation to Fortgale IR for critical incidents requiring forensic and recovery support.
Metrics measured on real customer telemetry — Q1 2026, updated quarterly.
Every component designed to leverage Darktrace AI with European SOC governance, avoiding false positives on production environments.
Darktrace licensing (or existing instance). Network, email, cloud, endpoint sensors managed by Fortgale. Continuous baseline tuning. Per-environment adaptation.
Validation of autonomous response: rules for business-critical processes, exclusions, response thresholds. Avoids unwanted blocks on legitimate workloads.
34,000+ IoCs per week from Fortgale OpenCTI integrated as Darktrace Custom Watchlists. Behavioural detection enriched with proprietary intelligence.
Monthly hunting via Darktrace Investigate using pattern of life + proprietary CTI. Focus on lateral movement, data staging, persistence not covered by automatic detections.
Executive reports with MTTD, MTTR, Antigena interventions, FP rate. Per-incident technical reports. NIS2/ISO 27001/GDPR audit documentation.
Darktrace PREVENT + DETECT + RESPOND + HEAL integration. Attack Path Modelling for proactive risk assessment. Fortgale orchestrates the entire AI Loop.
The CISO decides on risk. The IT lead decides on the runbook. Fortgale MDR produces evidence for both.
Each month the CISO receives the profile of the 3 most likely actors against their sector, with the Fortgale MDR runbook already mapped to the Darktrace ActiveAI telemetry.
When the Darktrace alert is real, decision time is containment time. Our L2/L3 analysts know the Darktrace ActiveAI console and have a mandate to decide.
Combines Darktrace ActiveAI (Self-Learning AI for network, email, cloud, endpoint) with the Fortgale European SOC 24·7·365. L2/L3 analysts govern Antigena AI, validate autonomous decisions and apply MITRE-mapped runbooks to avoid false positives on sensitive workloads.
Antigena is the Darktrace autonomous response: it blocks or slows anomalous traffic based on learned behaviour (Self-Learning AI). The Fortgale SOC governs Antigena to avoid unwanted blocks on business-critical processes and to orchestrate cross-domain response.
No. Fortgale handles the full cycle: licensing, sensor deployment (network, email, cloud, endpoint), self-learning model tuning, Antigena configuration. Available both on existing instance or as part of the service.
Yes. We support NIS2 transposition requirements: continuous monitoring, IoC collection for national CSIRT notification within 24 hours, technical documentation for 72-hour notifications.
Darktrace sensor deployment is fast (1-2 days), but the Self-Learning AI model requires 7-14 days to build the 'pattern of life' behavioural baseline. Full MDR service onboarding: 14-21 business days.
We bring you the Report on your sector with the most likely actors and a concrete MDR runbook on your Darktrace ActiveAI console.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.