Contact sales
Details

Darktrace /NETWORK is a Network Detection and Response (NDR) offering.

Darktrace /NETWORK is a Network Detection and Response (NDR) offering. In Cisco XDR, we enable Darktrace users to leverage it in investigations and for response actions. In Investigate, Darktrace can respond with detection details for queried hostnames, IP and MAC addresses, and Darktrace DeviceIDs. The Darktrace Integration can also be used in Automation and from the pivot menu to quarantine and unquarantine devices by hostname, Darktrace DeviceID, and IP or MAC address.

Capabilities
Automation
Automatic target creation for Cisco XDR automation
Health
Validates that the integration is healthy
Observe
Provides sightings for an observable
Regions
North America
Europe
Asia-Pacific, Japan & China
Installable workflows

These are workflows that you can install in Cisco XDR automation and use with this integration. These are different from built-in workflows which are built into Cisco XDR by default for all customers.

Cisco Managed
This workflow appears in the pivot menu and allows a user to quarantine a device in Darktrace /NETWORK.
Cisco Managed
This workflow appears in the pivot menu and allows a user to unquarantine a device in Darktrace /NETWORK.
Built-in workflows

These workflows are built into Cisco XDR automation and can be used with this integration. These are different from installable workflows, which are optional workflows you can install from Cisco and its partners.

Configuration details