{"id":4604,"date":"2024-05-24T10:50:15","date_gmt":"2024-05-23T22:50:15","guid":{"rendered":"https:\/\/ostermanresearch.com\/2024\/05\/24\/rsac2024-darktrace\/"},"modified":"2025-03-10T17:00:27","modified_gmt":"2025-03-10T04:00:27","slug":"rsac2024-darktrace","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2024\/05\/24\/rsac2024-darktrace\/","title":{"rendered":"Notes on our briefing with Darktrace &#8211; the RSAC2024 files"},"content":{"rendered":"\n<p><em>We attended RSAC 2024 in San Francisco from May 6-8. Our days at the conference were packed with back-to-back briefings.&nbsp;<\/em><\/p>\n\n\n\n<p>Here\u2019s some notes on our briefing with Mitchell Bezzina (VP, Product Marketing) and Madeline Wilson (Communications Manager) at Darktrace. The briefing was organized by Caroline Dobyns at <a href=\"https:\/\/luminapr.com\" target=\"_blank\" rel=\"noreferrer noopener\">ICR Lumina<\/a>.<\/p>\n\n\n\n<p>Our notes from the briefing (enriched with some additional research):<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Darktrace has built its security offerings as a single platform architecture with AI a fundamental design layer. Its three solution areas are detection and response (across cloud, email, endpoint, OT, identity, and network), prevention (e.g., attack surface management), and heal (with automated playbooks for recovery).<\/li>\n\n\n\n<li>UEBA (user and entity behavioral analytics) is a core part of Darktrace&#8217;s approach to assessing for security threats versus what normal behavior looks like. In its <a href=\"https:\/\/darktrace.com\/resources\/the-cisos-guide-to-cyber-ai\" target=\"_blank\" rel=\"noreferrer noopener\">CISO Guide to Cyber AI<\/a> white paper, the Darktrace team says this about their approach: &#8221; &#8230; <em>self-learning AI approaches learn what constitutes \u2018normal\u2019 by continuously analyzing every device, every user, and the millions of interactions between them, this type of AI can understand \u2018self\u2019 for an organization. Once it knows \u2018self,\u2019 it can piece together subtle deviations from \u2018self\u2019 and connect the dots of a cyber-attack. This way, it can adapt and evolve at the same rate as threats, identifying unfamiliar and novel attacks<\/em>.&#8221;<\/li>\n\n\n\n<li>Darktrace has grown significantly over the past year. It currently has over 2,300 employees spread across more than 110 countries. Annual recurring revenue in 2023 was $628.4 million.<\/li>\n\n\n\n<li>Darktrace offers a Cyber AI analyst for analyzing alerts from the customer&#8217;s SIEM. The AI analyst automatically triages new alerts and offers a suggested prioritization for a human analyst. Mitchell said their AI analyst is doing an initial run through of around 90% of alerts.<\/li>\n\n\n\n<li>One investment area for Darktrace is driving nuance for a compromised or threatened endpoint. While a common approach is to automatically take a compromised endpoint offline to isolate \/ quarantine it from other network elements, Darktrace is able to isolate the threats on the endpoint while allowing other connections to continue unhindered. This nuanced approach deals with the threat without stopping a user&#8217;s ability to work. See <a href=\"https:\/\/darktrace.com\/products\/endpoint\" target=\"_blank\" rel=\"noreferrer noopener\">Darktrace\/Endpoint<\/a> for more- although what we call &#8220;nuanced&#8221; is called &#8220;surgical&#8221; by Darktrace. Same concept, different word.<\/li>\n<\/ul>\n\n\n\n<p>For more, see <a href=\"https:\/\/darktrace.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Darktrace<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some notes on our briefing with Darktrace at RSAC2024. Their AI-driven platform focuses on detection, prevention, and healing of security threats. With UEBA as a core component, self-learning AI identifies deviations from &#8216;normal&#8217; behavior to combat cyber-attacks. Darktrace&#8217;s is growing rapidly and is investing on nuanced endpoint protection capabilities.<\/p>\n","protected":false},"author":384585,"featured_media":4730,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027319,712027168],"tags":[712027518],"class_list":["post-4604","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-cybersecurity","tag-notes-on-briefings"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2024\/05\/darktrace2024.jpg?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1cg","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=4604"}],"version-history":[{"count":1,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4604\/revisions"}],"predecessor-version":[{"id":4660,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/4604\/revisions\/4660"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/4730"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=4604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=4604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=4604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}