Darktrace / NETWORK
Internal and perimeter traffic compared with the usual behaviour of every device: scanning, beaconing, lateral movement and exfiltration surface as deviations.
For teams running Darktrace with nobody to approve an autonomous action at two in the morning, or letting it act without knowing what it blocks. The Fortgale MDR service reads Darktrace detections together with endpoint and identity and contains at a median TTC of <30 minutes.
The Darktrace products the SOC takes on. If Darktrace is not in place yet, licensing and sensors are part of the service.
Internal and perimeter traffic compared with the usual behaviour of every device: scanning, beaconing, lateral movement and exfiltration surface as deviations.
SaaS accounts and identity providers: anomalous sign-ins and out-of-profile use, with actions such as disabling the account and forcing logout.
Email assessed on the behaviour of senders and recipients, with actions on the message and its links.
Cloud workloads and endpoint telemetry in the same view; endpoint isolation goes through the EDR integration.
Hunting in Advanced Search led by Fortgale analysts, starting from the incidents the Darktrace AI Analyst groups together.
Fortgale indicators loaded as Watched Domains and custom models in the Model Editor for the behaviour that matters in your environment.
A network detection tells you something is moving; it does not tell you who it is or what to do. Fortgale adds the missing part: every network detection is read by an analyst against 287 tracked adversary groups and attack tools and correlated with endpoint and identity activity, so lateral movement becomes an attribution and a decision. Noise drops by more than 90% by day 30, and containment runs through the controls your environment already has: median TTD <15 minutes, median TTC <30 minutes.
On Darktrace the response is Autonomous Response, the current name of Antigena: blocking connections that match the anomaly, enforcing the device's pattern of life, blocking incoming or outgoing traffic, quarantining the device. On identities it disables the account or forces logout; on email it moves the message and locks links.
Each model can act autonomously or in Human Confirmation mode, with the action pending approval, and a weekly schedule decides when each applies. That is where Fortgale works: which models act alone, which production assets always need an analyst, who approves out of hours. Isolating an endpoint or killing a process are not network actions: they go through the integrated EDR.
Fortgale CTI indicators, 34,000 IOCs a week, arrive as Watched Domains. Behaviour says a device is anomalous, the indicator says who owns the infrastructure it contacts: together they move the decision from “odd” to “contain”.
On a Darktrace instance already in production, the behavioural model of the environment already exists: takeover does not start from scratch and does not touch sensors or configuration.
Technical onboarding closes in one week: users, Autonomous Response mode per model, the confirmation schedule and integrations with EDR and firewalls.
On a new deployment the initial learning follows Darktrace's own timing, and Autonomous Response stays in confirmation mode until the model settles. On your side: the assets to keep out of autonomous actions, who approves out of hours and the escalation list.
In February 2026 the Fortgale incident response team contained Operation Storming Tide at a European logistics and transport company. Access dated back months, through a vulnerable Fortinet firewall with a persistent VPN tunnel; after a long dormant period the attacker, attributed to Mora_001, moved from unmanaged assets into the internal network with Matanbuchus 3.0, Astarion, SystemBC and RClone. The investigation started from anomalous internal network scanning, and neither exfiltration nor ransomware happened.
The article is not about Darktrace, but the starting point of the investigation is a network detection: unmanaged assets have no agent, while the scan travels across the network. A scan from a device that has never scanned before, the traffic of a proxy such as SystemBC and the outbound volumes of RClone are the kind of deviation a network behaviour model is built to see; with Autonomous Response the analyst can block the device's connections while the EDR isolates the covered hosts.
No. Darktrace Managed Detection & Response is the vendor's own service. Fortgale works independently on the Darktrace instance you already have, from a SOC in Milan, with analysts who decide with you which actions to leave to automation.
A network anomaly says a device behaves differently. The Fortgale analyst checks on the EDR which process generates the traffic and in identity logs which account uses it: when both sides agree, the anomaly becomes an incident with attribution and a containment decision.
Where you have decided so. Each model can act autonomously or wait for confirmation, on different schedules: at onboarding we agree which actions are autonomous, which production assets always need an analyst and who approves out of hours. Critical decisions on production always involve a person.
Sensors and the behavioural model stay on the instance: only users, response modes and contacts change. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.
Both models work: Fortgale operates the Darktrace instance you already own, or provides licensing and sensors as part of the service. Autonomous Response has its own licence: without it, Darktrace detects but does not act, and response goes through EDR and firewalls.
We walk through a network anomaly step by step: the model that flagged it, the check on the EDR, the Autonomous Response action approved by the analyst and the containment of the host. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.