Darktrace · Darktrace / HYBRID NETWORK

Autonomous Response — AI-selected network threat response

Darktrace Autonomous Response uses information gathered from a threat alert to select a network response from multiple documented interventions — from restricting a specific connection or port, through enforcing learned device or peer-group pattern of life, to blocking device traffic or quarantining a device, or invoking third-party containment — and can execute it without individual human approval when fully autonomous operation is permitted. Human Confirmation mode is also available. It is not a generic endpoint-isolation or generic Darktrace autonomous-security record.

Recorded characteristics

Function
Darktrace states that its Autonomous Response "natively and autonomously responds to anomalous network activity" with out-of-the-box actions requiring "no scripting". Its "Automatic" option "Automatically chooses the best option using information gathered from the alert. For example, if the alert concerns suspicious behavior to an SMB share on port 445, it may block connections just to that port." Other documented responses: block matching connections (the specific connection and future matching connections); enforce [group] pattern of life ("Only allows actions Darktrace considers normal… depending on severity of perceived threat"); block all incoming/outgoing traffic from a device or quarantine it entirely "depending on nature and severity of the threat"; and third-party integration actions (for example a third-party firewall blocking specific IPs, or Microsoft Defender for Endpoint or CrowdStrike quarantining, isolating or containing devices). Controlled object: network traffic permissions associated with an identified device or connection. Causal boundary: behavioural/contextual analysis → threatening/anomalous activity → Darktrace selects a response using alert/threat information → customer guardrails determine whether autonomous intervention is permitted → the selected response executes against live network activity. Documented action range runs from a narrow connection/port restriction to broader traffic blocking and device quarantine.
Data access
Darktrace / HYBRID NETWORK analyses "encrypted and decrypted traffic across network, cloud, and OT" to surface activity that does not fit the environment. Response selection uses information gathered from the alert.
Actions
Can take actions
External actions
Yes
Human confirmation
Conditional
Permission basis
Not established
Administrative control
Customer defines the autonomy envelope; Darktrace retains documented runtime discretion over response selection within that envelope. Darktrace states its response "can run fully autonomously, or operate within guiderails set by your team. It can, for example, be set to operate only at certain times, on certain devices, or in response to certain events." Darktrace also describes "Fully configurable policies" controlling "how and when Darktrace intervenes". Human Confirmation mode exists alongside fully autonomous mode; in autonomous mode individual responses do not require approval, in Human Confirmation mode they do. Darktrace notes "Many organizations start in Human Confirmation mode" — this describes customer practice, not a software default.
Default state
Not established
Availability
Current Darktrace product and capability pages (accessed 2026-10-03) present Darktrace / HYBRID NETWORK and Autonomous Response as current. The former product name Darktrace / NETWORK redirects to HYBRID NETWORK. Historical Antigena/RESPOND naming is outside this record.
Licensing
Not publicly established from the controlled sources.
External model or provider
Darktrace proprietary AI. Model type, family and version not publicly established.
Limitations and uncertainty
Not publicly established: (1) exact response-selection algorithm; (2) response-selection model type; (3) model version; (4) complete feature set; (5) feature weights; (6) exact anomaly-to-response mapping; (7) numerical confidence mechanism; (8) complete escalation/de-escalation logic; (9) whether every response type is dynamically selected; (10) whether customer policy overrides Darktrace's response choice; (11) exact runtime execution account/principal; (12) universal maximum blast radius — Universal maximum automated blast radius: Not Publicly Established; (13) retry semantics; (14) integration-failure behaviour; (15) fail-open/fail-closed behaviour; (16) automatic expiry semantics; (17) manual release semantics; (18) AI-decided reversal; (19) complete audit trail; (20) complete model-to-action provenance. Default state not established. Excluded: Darktrace / EMAIL, Darktrace / CLOUD, Darktrace OT as a separate capability, Cyber AI Analyst investigation, anomaly detection or alerts by themselves, human-confirmed responses as autonomous actions, generic SOAR playbooks, customer-authored fixed IF/THEN mappings, ordinary firewall administration, manual containment, generic endpoint isolation, and historical Antigena capabilities. Monitoring: one monitor on the Darktrace Autonomous Response page; the HYBRID NETWORK page is not monitored because it carries none of the classification-sensitive wording.

Evidence