Autonomous Response — AI-selected network threat response
Darktrace Autonomous Response uses information gathered from a threat alert to select a network response from multiple documented interventions — from restricting a specific connection or port, through enforcing learned device or peer-group pattern of life, to blocking device traffic or quarantining a device, or invoking third-party containment — and can execute it without individual human approval when fully autonomous operation is permitted. Human Confirmation mode is also available. It is not a generic endpoint-isolation or generic Darktrace autonomous-security record.
Recorded characteristics
- Function
- Darktrace states that its Autonomous Response "natively and autonomously responds to anomalous network activity" with out-of-the-box actions requiring "no scripting". Its "Automatic" option "Automatically chooses the best option using information gathered from the alert. For example, if the alert concerns suspicious behavior to an SMB share on port 445, it may block connections just to that port." Other documented responses: block matching connections (the specific connection and future matching connections); enforce [group] pattern of life ("Only allows actions Darktrace considers normal… depending on severity of perceived threat"); block all incoming/outgoing traffic from a device or quarantine it entirely "depending on nature and severity of the threat"; and third-party integration actions (for example a third-party firewall blocking specific IPs, or Microsoft Defender for Endpoint or CrowdStrike quarantining, isolating or containing devices). Controlled object: network traffic permissions associated with an identified device or connection. Causal boundary: behavioural/contextual analysis → threatening/anomalous activity → Darktrace selects a response using alert/threat information → customer guardrails determine whether autonomous intervention is permitted → the selected response executes against live network activity. Documented action range runs from a narrow connection/port restriction to broader traffic blocking and device quarantine.
- Data access
- Darktrace / HYBRID NETWORK analyses "encrypted and decrypted traffic across network, cloud, and OT" to surface activity that does not fit the environment. Response selection uses information gathered from the alert.
- Actions
- Can take actions
- External actions
- Yes
- Human confirmation
- Conditional
- Permission basis
- Not established
- Administrative control
- Customer defines the autonomy envelope; Darktrace retains documented runtime discretion over response selection within that envelope. Darktrace states its response "can run fully autonomously, or operate within guiderails set by your team. It can, for example, be set to operate only at certain times, on certain devices, or in response to certain events." Darktrace also describes "Fully configurable policies" controlling "how and when Darktrace intervenes". Human Confirmation mode exists alongside fully autonomous mode; in autonomous mode individual responses do not require approval, in Human Confirmation mode they do. Darktrace notes "Many organizations start in Human Confirmation mode" — this describes customer practice, not a software default.
- Default state
- Not established
- Availability
- Current Darktrace product and capability pages (accessed 2026-10-03) present Darktrace / HYBRID NETWORK and Autonomous Response as current. The former product name Darktrace / NETWORK redirects to HYBRID NETWORK. Historical Antigena/RESPOND naming is outside this record.
- Licensing
- Not publicly established from the controlled sources.
- External model or provider
- Darktrace proprietary AI. Model type, family and version not publicly established.
- Limitations and uncertainty
- Not publicly established: (1) exact response-selection algorithm; (2) response-selection model type; (3) model version; (4) complete feature set; (5) feature weights; (6) exact anomaly-to-response mapping; (7) numerical confidence mechanism; (8) complete escalation/de-escalation logic; (9) whether every response type is dynamically selected; (10) whether customer policy overrides Darktrace's response choice; (11) exact runtime execution account/principal; (12) universal maximum blast radius — Universal maximum automated blast radius: Not Publicly Established; (13) retry semantics; (14) integration-failure behaviour; (15) fail-open/fail-closed behaviour; (16) automatic expiry semantics; (17) manual release semantics; (18) AI-decided reversal; (19) complete audit trail; (20) complete model-to-action provenance. Default state not established. Excluded: Darktrace / EMAIL, Darktrace / CLOUD, Darktrace OT as a separate capability, Cyber AI Analyst investigation, anomaly detection or alerts by themselves, human-confirmed responses as autonomous actions, generic SOAR playbooks, customer-authored fixed IF/THEN mappings, ordinary firewall administration, manual containment, generic endpoint isolation, and historical Antigena capabilities. Monitoring: one monitor on the Darktrace Autonomous Response page; the HYBRID NETWORK page is not monitored because it carries none of the classification-sensitive wording.
Evidence
- Darktrace — Autonomous Response
Supports: Function · Actions · External actions · Human confirmation · Admin controls · General · Primary source
"Automatically chooses the best option using information gathered from the alert" — SMB/port 445 example.
Documented responses: block matching connections, enforce [group] pattern of life, block device traffic, quarantine device.
Third-party integration actions: firewall IP blocking; Microsoft Defender for Endpoint or CrowdStrike containment.
Response "can run fully autonomously"; Human Confirmation mode also exists.
Guiderails: certain times, certain devices, certain events.
Autonomous Response natively and autonomously responds to anomalous network activity, out-of-the-box with no scripting.
- Darktrace / HYBRID NETWORK
Supports: General · Data access · Primary source
Current product name Darktrace / HYBRID NETWORK; responses taken natively or through firewalls, EDR, SOAR and ITSM tools; configurable policies.
Analyses encrypted and decrypted traffic across network, cloud and OT.