Talk to us
by DarktraceTechBag Intel Page

Darktrace Cloud

A cloud role nobody remembers just listed every bucket at 3 a.m. Your posture scan said it was compliant — Darktrace Cloud learns how each identity and workload in your AWS, Azure and GCP accounts normally behaves, then contains what breaks the pattern through the cloud provider’s own controls.

Behaviour baseline per cloud identityAgentless start, sensors optionalQuoted per Identity Workload count

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Darktrace prints no CLOUD price; the order form sets the Identity Workload count
Quote
Analysts
No CNAPP or CDR placement is verified; Darktrace’s Gartner Leader spots are for NDR and email
None for cloud
Agent
Agentless discovery first; sensors add process and traffic depth where you install them
Optional
India
Hosted infrastructure runs in AWS outside India, with Singapore the closest region
No region

Quick answer

Darktrace Cloud is cloud detection and response for AWS, Azure, GCP and SaaS. It learns how your workloads, containers, APIs and identities normally behave and answers deviations through the cloud platform’s own controls. Accounts are enumerated agentlessly, with optional sensors for depth, and it is quoted on an Identity Workload count. Darktrace lists no India hosting region; Singapore is the nearest. Read more ↓ Show less ↑
Part 01 · Orient

The Darktrace platform family

This page covers Darktrace Cloud — detection and response for public cloud and SaaS. The rest:

Quick facts

30-second orientation
Product
Behavioural cloud detection and response across AWS, Azure, GCP and SaaS
Maker
Darktrace, Cambridge, UK; taken private by Thoma Bravo in 2024 (about $5.3 billion); CEO Ed Jennings
Covers
Workloads, containers, APIs and identities, including excessive cloud permissions
Deploys
Agentless through cloud APIs and logs; vSensors, osSensors and containerSensors optional
Meter
Identity Workload count: cloud identities plus weighted workloads such as VMs and functions
Price
Quote-only; no public CLOUD list price
Exposure
A limited-feature edition of Darktrace’s exposure management is included
Hosting
Darktrace-run AWS regions in the EU, US, Canada, Singapore and Australia; Azure adds Japan East
India
No India hosting region listed; billing components always sit in AWS us-east-1
In India via
TechBag — account scoping, INR quote with GST, pilot on one cloud account
Part 02 · Learn

Understand cloud detection and response before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is cloud detection and response?

CDR watches running cloud activity for attacks in progress, where posture tools check settings before an attack.

Rules and quarterly reviews vs a learned cloud baseline — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionRules and periodic reviewsDarktrace Cloud
How a threat is spottedA rule someone wrote for a known patternA break from each identity’s learned behaviour
First visibilityWeeks spent rolling agents to every VMAgentless inventory, sensors added later
Cloud and network alertsTwo consoles, two timelinesOne Darktrace platform, one incident
Over-privileged rolesFound in an annual access reviewFlagged from observed permission use
ContainmentA ticket to the cloud teamAction through the provider’s own controls
What it is NOT—A full CNAPP, an IaC scanner, or India-hosted

The lowest-risk test is read-only: connect one account, let the baseline settle for a few weeks, and judge the alerts it raises.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How the estate is mapped

Enumerate

Agentless cloud connection

Read-only access to cloud APIs and logs lists accounts, workloads, storage, functions and identities across AWS, Azure and GCP, with nothing installed on the workloads themselves.

02
Where extra depth comes from

Sense

Optional sensors and mirroring

vSensors read mirrored VPC or GCP packet traffic, osSensors sit on hosts and containerSensors watch containers; each one is optional and adds evidence the API view cannot see.

03
What counts as unusual

Model

Behavioural baseline per estate

Darktrace’s Adaptive AI learns the normal pattern of each identity and workload in your accounts, so an alert reflects a break from your baseline, backed by custom models you can add.

04
How a threat is contained

Act

Platform-native response

Responses run through the cloud provider’s own controls rather than an inline device, and investigations can hand off to Forensic Acquisition & Investigation, a separately contracted product.

Agentless API enumeration plus optional sensors — a learned baseline per identity, answered through the cloud’s own controls.

Part 03 · Evaluate

Nine capabilities. Discover, detect, respond.

Darktrace Cloud watches what your cloud identities and workloads actually do — and acts when it stops looking normal.

Discover
Inventory

A live map of three clouds

Agentless enumeration lists accounts, VMs, functions, storage and identities across AWS, Azure and GCP in one view.

Discover
Permissions

Who can do too much

Identity and permission views flag roles and users holding more rights than their behaviour shows they need.

Discover
Exposure

Risk before an attack

A limited-feature edition of Darktrace’s exposure management ranks the cloud weaknesses most likely to be used.

Detect
Baseline

Normal for your accounts

Each identity and workload gets a behavioural profile, so a new API pattern or login stands out from routine work.

Detect
Containers

Inside pods and hosts

containerSensors and osSensors add process and connection detail from running containers and cloud hosts.

Detect
Traffic

Packets, not only logs

vSensors fed by VPC or GCP traffic mirroring read east-west flows that audit logs alone never record.

Respond
Response

Contain with cloud controls

Actions go through the provider’s own controls, so a misbehaving identity or workload is curbed without an inline box.

Respond
Forensics

Evidence while it is fresh

Automated cloud forensics link to Darktrace’s Forensic Acquisition & Investigation product, licensed on its own.

Respond
One platform

Joined to network and email

Cloud alerts sit in the Behavioral Defense Platform beside Darktrace network and email coverage, under one console.

See it, don’t just read it

Watch Darktrace Cloud in action

The current launch spot for Darktrace Cloud, a 2023 walk-through of real-time cloud visibility, and a short 2025 brand spot.

Darktrace (official)·Short, 2026

Stop emerging cloud threats instantly with Darktrace Cloud™

A 30-second launch spot for the current product, framed around stopping new cloud threats in real time.

Darktrace (official)·Explainer, 2023

Darktrace/Cloud: Secure Your Cloud in Real Time

A 90-second walk-through from 2023 of real-time cloud visibility; product naming on screen predates today’s.

Darktrace (official)·Short, 2025

Defend Beyond™ with Elevated AI Cloud Security

A 15-second brand spot for Darktrace’s cloud security message; watch it for tone, not detail.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Darktrace Cloud

Cloud attacks use valid identities. Darktrace Cloud watches how they behave.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Detection that starts from your own baseline

Most cloud tools begin with a rulebook of bad configurations. Darktrace Cloud begins by learning how each identity and workload in your accounts usually behaves, then flags what breaks that pattern, such as an unfamiliar API call sequence. Custom models can be added, so it is not rule-free, but the baseline does most of the work.

02

Nothing to install before the first finding

The connection is agentless: cloud APIs and logs give the inventory of accounts, workloads, storage, functions and identities from day one. Sensors come later and only where they add value, vSensors on mirrored VPC or GCP traffic, osSensors on hosts and containerSensors in clusters. You decide how deep to go, account by account.

03

Cloud alerts in the same place as network and email

For estates already running Darktrace network or email coverage, cloud detections join the same Behavioral Defense Platform, so an account takeover seen in email and odd activity in an AWS account can be read as one incident. Forensic capture links to Forensic Acquisition & Investigation, which is contracted separately.

04

Where it stops

It is detection and response first. Posture is a limited edition of Darktrace’s exposure management and no IaC or pipeline scanning is documented, so it is no CNAPP. No analyst has placed it in a cloud category. Packet depth needs complete traffic mirroring. It is quote-only, and no Darktrace-hosted region sits in India.

The idea
Behaviour baseline for every cloud identity
The start
Agentless first, sensors where depth pays
The price
Quoted per Identity Workload count
Proof, not promises

The numbers behind the platform

3 clouds
public clouds covered, AWS, Azure and GCP, with SaaS activity on top
— Vendor
3 sensor types
optional add-ons for depth: vSensors, osSensors and containerSensors
— Vendor
5 AWS regions
hosting choices for the Darktrace side: EU, US, Canada, Singapore, Australia
— Spec
0 India regions
Darktrace-hosted CLOUD regions in India; Singapore is the closest offered
— Spec
~10000
customers Darktrace reports across its whole platform, not CLOUD alone
— Vendor
2400+
employees, by Darktrace’s own 2026 company description
— Vendor

What your Darktrace Cloud rollout looks like

Week 1Model

Choose the accounts that matter

List the AWS, Azure and GCP accounts holding production data and count their identities and workloads for the quote.

Week 2Pilot

Connect read-only, agentless

Grant API and log access to a pilot account, review the inventory and pick a Darktrace hosting region outside India.

Week 3Decide

Let the baseline settle

Watch alerts while the model learns normal behaviour; tune noisy ones and add custom models for known internal jobs.

Month 2Prove

Add sensors where depth pays

Mirror VPC traffic to vSensors or place containerSensors in key clusters, then compare what the extra view reveals.

Month 3Commit

Agree response and scale out

Decide which actions run autonomously and which need approval, then extend to the remaining accounts and clouds.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.2
38+ reviews*
82% would recommend
Threat detection4.4
Ease of onboarding4.2
Response actions4.1
Posture depth3.5
Value for money3.7
5★
42%
4★
38%
3★
14%
2★
4%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Fintech
“A service account began listing buckets it had never touched at 3 a.m. Darktrace flagged it before our nightly review did.”
Cloud Security Engineer
Fintech
SaaS
“We connected three AWS accounts read-only on a Monday and had the identity inventory by Tuesday, with no agents yet.”
Head of Infrastructure
SaaS
BFSI
“Having cloud alerts next to our Darktrace email detections made one phishing-to-console takeover easy to trace.”
SOC Lead
BFSI
Healthcare
“The excessive-permission view found admin roles nobody had used in months. Removing them was the quick win.”
IAM Architect
Healthcare
E-commerce
“Mirroring VPC traffic to the vSensors took planning and cost; without it we saw less inside our clusters.”
Platform Engineer
E-commerce
Manufacturing
“Good detection, but we still run a separate CSPM for compliance reports and IaC checks. Budget for both.”
CISO
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud detection and response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Cloud Detection & Response Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Darktrace CloudThis page

Quote on an Identity Workload count; no cloud analyst placement.

Grid 02 · The architecture

Agentless Reach × Runtime Response

The grid nobody publishes — how much it sees with nothing installed vs how deeply it can act on a live cloud threat.

Sensor-first respondersAgentless and responsiveAgent-bound protectionLight-touch watchers
Darktrace CloudThis page

Agentless first; behavioural response through cloud controls.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Darktrace Cloud vs the cloud detection and response field

Against CrowdStrike Falcon Cloud Security, SentinelOne Singularity Cloud Security, Wiz Defend, Fortinet FortiCNAPP and Sophos Cloud Native Security — on deployment, detection, response, posture, price and India.

DimensionDarktrace CloudCrowdStrike Falcon Cloud SecuritySentinelOne Singularity Cloud SecurityWiz DefendFortinet FortiCNAPPSophos Cloud Native Security
What it isBehavioural CDRFull CNAPP on FalconCNAPP with runtimeRuntime CDR moduleCNAPP, Lacework rootsPosture + server runtime
DeploymentAgentless, sensors opt.Sensor + agentlessAgentless + agentNeeds the Wiz SensorAgentless + agentAgent + agentless
Clouds and workloadsAWS, Azure, GCP, SaaSMulti-cloud + on-premAWS, Azure, GCPCloud + KubernetesThree clouds + privateFour clouds + on-prem
Detection methodLearned baselineThreat Graph contextAutonomous runtimeeBPF + graph contextAnomaly, no rulesHost agent + XDR
Response actionsPlatform-nativeSensor + automationStop and containPlaybooks, WorkflowsDetect and mitigateHost agent + MDR
Posture and exposureLimited editionCSPM includedCSPM includedSeparate Wiz SKUCSPM + complianceCloud Optix CSPM
Identities and permissionsExcess rights flaggedCIEM includedCIEM includedWiz CIEM is separateNet-effective rightsIAM visualisation
Code and pipelineNot documentedIaC to runtimeIaC scanningWiz Code is separateSAST, SCA, IaC, SBOMIaC templates
Pricing modelIdentity Workload countModular, via FlexModular, consumptionAdd-on + SensorStarter pack, then quotePAYG per user, server
Published entry priceNot publishedNot publishedNot published~$18,000/yr reported~$25,000/yr starterMarketplace PAYG
Included vs add-onForensics extraOne CNAPP productBundled layersStacked modulesBroad in one platformMDR sold apart
India data regionNone; Singapore nearestAnnounced, not liveMumbai regionNot documentedNot documentedSophos Central Mumbai
Lock-in and exitBest with DarktraceFalcon-centredSingularity-centredWiz platform firstFabric-centredCentral-centred
Best fitDarktrace-led SOCsFalcon estatesS1 + India regionWiz posture customersFortinet + behaviourSophos Central shops
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Darktrace Cloud if…

  • ✓You already run Darktrace on the network or email and want cloud activity read by the same behavioural model
  • ✓You want cloud detection live within days through agentless API access, adding sensors only where depth pays
  • ✓Your worry is a compromised identity or workload acting oddly, more than a misconfiguration backlog

Compare alternatives if…

  • ✓You need a full CNAPP with IaC and code scanning — CrowdStrike, SentinelOne, FortiCNAPP and Sophos document it
  • ✓Cloud security data must be hosted in India — SentinelOne and Sophos list a Mumbai region
  • ✓You want a figure before talking to sales — FortiCNAPP’s starter pack and Sophos PAYG give a starting point

Do not expect…

  • ✓Posture management deep enough to retire a dedicated CSPM or compliance-reporting tool
  • ✓A Gartner or other analyst placement for Darktrace in a cloud security category
  • ✓A Darktrace-hosted region in India, or the AWS Marketplace network tiers to apply to CLOUD

Darktrace Cloud is one of 19 cloud & workload security products TechBag carries. The Cloud & Workload Security guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does manual cloud-alert triage cost you?

Drag the sliders (cloud identities and workloads in scope; analyst-hour cost). Estimates model analyst time spent triaging and investigating cloud alerts at an assumed 1.5 hours per identity or workload a year, with 70% of it removed by behavioural triage and autonomous response. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual cloud-triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Quote-only: Darktrace publishes no CLOUD price. It is metered on an Identity Workload count — cloud identities plus weighted workloads such as VMs, functions and storage — set in the order form. Darktrace’s public AWS Marketplace tiers ($30,000 to $100,000 a year) are metered on bandwidth and hosts for the network product and do not price CLOUD. TechBag counts your identities and workloads first, then quotes in INR with GST.

Darktrace Cloud

Best for behavioural cloud detection

  • Quoted per Identity Workload count
  • Agentless start; sensors optional
  • Limited exposure management included

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

With Forensic Acquisition

Best for evidence-led response

  • Forensic Acquisition & Investigation quoted apart
  • Automated capture of cloud evidence
  • Customer-hosted option in your account

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Scope

How many cloud identities and weighted workloads will count toward the Identity Workload meter in year one and year three?

2
Clouds

Are all your accounts on AWS, Azure or GCP, and which SaaS applications do you want in the same baseline?

3
Hosting

Which Darktrace region will hold your data, given none is in India and billing parts always run in us-east-1?

4
Sensors

Will you mirror VPC or GCP traffic to vSensors, and have you costed the mirroring and the sensor compute?

5
Posture gap

Which CSPM, compliance or IaC scanner will cover what CLOUD’s limited exposure edition does not?

6
Response

Which platform-native actions may run without approval, and who signs off on those that need a person?

7
Forensics

Do you need Forensic Acquisition & Investigation as well, and is it on the same order form or a separate one?

8
Contract

Does the quote spell out the Identity Workload count, overage terms, term length and an INR total with GST?

FAQ

Questions buyers ask

It is Darktrace’s cloud detection and response product for AWS, Azure, GCP and SaaS. It connects to your cloud accounts through APIs and logs, learns how each identity and workload normally behaves, and responds through the cloud provider’s own controls when activity breaks that pattern.

Ready to evaluate Darktrace Cloud?

Count the identities and workloads that drive the quote first, or let a TechBag advisor scope an agentless pilot on one production cloud account.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.