MDR partner · Darktrace ActiveAI

MDR on Darktrace ActiveAI: Self-Learning AI governed by senior analysts.

The Fortgale European SOC 24·7·365 governing the Darktrace AI. Antigena autonomous response validated by L2/L3 analysts to avoid false positives, ~11 min median containment on incident escalation.

~11 minMedian containment
24·7·365European SOC
Pattern of LifeSelf-Learning AI
Fortgale × Darktrace
MDR · live
Darktrace sensor activeEndpoint · cloud · identity telemetry
Darktrace
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced by 94%
Fortgale
Native Darktrace responseMedian host isolation ~8 s
Live
Proprietary intelligence34,000+ IoCs per week · European actors
Fortgale
MDR live — Darktrace + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Darktrace ActiveAI
MITRE ATT&CK aligned
OpenCTI
Why Fortgale + Darktrace

Self-Learning AI, governed by people who know European context.

Darktrace ActiveAI builds a 'pattern of life' for every device. Powerful for unknown threats but prone to false positives on heterogeneous environments. Fortgale governs the Antigena AI with European analysts who know the operational context of European enterprises.

01 ·

Darktrace ActiveAI · Self-Learning

Pattern of life per device, network, user. Native NDR + email (Antigena Email) + cloud + endpoint. Detection of unknown unknowns via behavioural anomalies, no signatures.

02 ·

European SOC 24·7·365

L2/L3 analysts specialised on Darktrace. Antigena tuning, false positive reduction, contextualisation on European environments. Triage <15 min on Darktrace AI alerts.

03 ·

Antigena governance + IR

Validation of autonomous response: which traffic to block, which to slow. Custom rules for business-critical processes. Direct escalation to Fortgale IR. Full NIS2 national CSIRT notification support.

How it works · architecture

Four blocks, one MDR cycle on Darktrace.

From self-learning baseline to validated Antigena response — all governed by Fortgale with European analysts who know operational context.

01 ·
01 · Learning

Pattern of life baseline

7-14 days of learning to build the per-device pattern of life. Sensors on network (NDR), email (Antigena Email), cloud, endpoint. Continuous baseline updates.

02 ·
02 · Tier-zero

Darktrace AI + custom tuning

Detection of behavioural anomalies via Self-Learning AI. Fortgale tunes thresholds and exclusions on European context, reducing false positives by 60-80%.

03 ·
03 · Analysts

Our L2/L3 govern AI

European SOC validates every Darktrace AI decision before Antigena fires. Critical decisions never fully autonomous on production assets. Direct interaction in your business language.

04 ·
04 · Response

Antigena + IR escalation

Antigena governed: autonomous traffic block, anomalous device isolation, email quarantine. Direct escalation to Fortgale IR for critical incidents requiring forensic and recovery support.

Proof · service metrics

Four numbers that hold MDR on Darktrace up.

Metrics measured on real customer telemetry — Q1 2026, updated quarterly.

~11 min
Median containment
from confirmed Darktrace alert
60-80 %
False positives
reduced by Fortgale tuning
Pattern
Per-device of Life
Self-Learning AI
21 days
Full onboarding
Darktrace + Antigena
What the service includes

MDR on Darktrace, in detail.

Every component designed to leverage Darktrace AI with European SOC governance, avoiding false positives on production environments.

01

Managed Darktrace ActiveAI

Darktrace licensing (or existing instance). Network, email, cloud, endpoint sensors managed by Fortgale. Continuous baseline tuning. Per-environment adaptation.

02

Antigena governance

Validation of autonomous response: rules for business-critical processes, exclusions, response thresholds. Avoids unwanted blocks on legitimate workloads.

03

Proprietary CTI integration

34,000+ IoCs per week from Fortgale OpenCTI integrated as Darktrace Custom Watchlists. Behavioural detection enriched with proprietary intelligence.

04

Cross-domain hunting

Monthly hunting via Darktrace Investigate using pattern of life + proprietary CTI. Focus on lateral movement, data staging, persistence not covered by automatic detections.

05

Reporting & governance

Executive reports with MTTD, MTTR, Antigena interventions, FP rate. Per-incident technical reports. NIS2/ISO 27001/GDPR audit documentation.

06

Cyber AI Loop

Darktrace PREVENT + DETECT + RESPOND + HEAL integration. Attack Path Modelling for proactive risk assessment. Fortgale orchestrates the entire AI Loop.

For whom · two angles

Same MDR on Darktrace, two angles.

The CISO decides on risk. The IT lead decides on the runbook. Fortgale MDR produces evidence for both.

For the CISO

A named runbook per actor, on the Darktrace stack.

Each month the CISO receives the profile of the 3 most likely actors against their sector, with the Fortgale MDR runbook already mapped to the Darktrace ActiveAI telemetry.

  • Monthly threat briefingActors, observed TTPs, campaigns in progress on your sector.
  • Darktrace runbookLive MITRE-mapped playbooks, executable on the Darktrace ActiveAI console.
  • Board-ready reportingRisk · impact · decision. No slideware technology.
Request the threat briefing →
For the IT lead

Zero translator handover. European analysts on your Darktrace console.

When the Darktrace alert is real, decision time is containment time. Our L2/L3 analysts know the Darktrace ActiveAI console and have a mandate to decide.

  • Median containment ~11 minFrom confirmed alert to remediation in production.
  • Native Darktrace responseProcess kill, host isolation, network containment via Darktrace ActiveAI API.
  • End-to-end integrationDarktrace telemetry ingested into our multi-domain data fabric.
See a real runbook →
FAQ · frequently asked

Everything to know before talking to our analysts.

What is the Fortgale MDR service on Darktrace?

Combines Darktrace ActiveAI (Self-Learning AI for network, email, cloud, endpoint) with the Fortgale European SOC 24·7·365. L2/L3 analysts govern Antigena AI, validate autonomous decisions and apply MITRE-mapped runbooks to avoid false positives on sensitive workloads.

What is Darktrace Antigena?

Antigena is the Darktrace autonomous response: it blocks or slows anomalous traffic based on learned behaviour (Self-Learning AI). The Fortgale SOC governs Antigena to avoid unwanted blocks on business-critical processes and to orchestrate cross-domain response.

Do I need to already have Darktrace?

No. Fortgale handles the full cycle: licensing, sensor deployment (network, email, cloud, endpoint), self-learning model tuning, Antigena configuration. Available both on existing instance or as part of the service.

Is the service NIS2-compliant?

Yes. We support NIS2 transposition requirements: continuous monitoring, IoC collection for national CSIRT notification within 24 hours, technical documentation for 72-hour notifications.

How long does Darktrace activation take?

Darktrace sensor deployment is fast (1-2 days), but the Self-Learning AI model requires 7-14 days to build the 'pattern of life' behavioural baseline. Full MDR service onboarding: 14-21 business days.

Talk to the outpost

One meeting. One NDA. One real runbook on Darktrace.

We bring you the Report on your sector with the most likely actors and a concrete MDR runbook on your Darktrace ActiveAI console.

Tempo di risposta: < 1 giorno lavorativo.

Questo sito è protetto da reCAPTCHA e si applicano la Privacy Policy e i Termini di servizio di Google.