What you are evaluating
Scope Network separately from email, cloud and other Darktrace products. Detection, autonomous response, retention and integration entitlements should be confirmed for the selected deployment; a behavioral alert alone does not authorize disruption.
A useful evaluation context
Teams evaluating behavioral network monitoring and carefully governed response workflows.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Network behavior analysis highlights activity for security investigation.
- Investigation context helps analysts examine affected devices and related communications.
- The published integration catalog identifies connections with other security and operational tools.
Where it fits in the work
- Document the learning period and traffic visibility for the pilot.
- Review an unusual connection against maintenance and business records.
- If response is in scope, test its approval mode and reversal on an expendable lab device.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
A finance batch job moves to a new server and triggers a lab anomaly. Compare the approved change with a superficially similar unexplained transfer.
Evidence to look for
Write a disposition for each observation using the destination, owner and timing. Explain why “unusual” and “malicious” are different judgments.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- How does the baseline handle new sites, seasonal jobs and major application changes?
- Which response actions are advisory, human-approved or automatic?
- Which integration fields remain available after export?