A cloud role nobody remembers just listed every bucket at 3 a.m. Your posture scan said it was compliant — Darktrace Cloud learns how each identity and workload in your AWS, Azure and GCP accounts normally behaves, then contains what breaks the pattern through the cloud provider’s own controls.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Cloud — detection and response for public cloud and SaaS. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
CDR watches running cloud activity for attacks in progress, where posture tools check settings before an attack.
What consolidation actually replaces, dimension by dimension.
| Dimension | Rules and periodic reviews | Darktrace Cloud |
|---|---|---|
| How a threat is spotted | A rule someone wrote for a known pattern | A break from each identity’s learned behaviour |
| First visibility | Weeks spent rolling agents to every VM | Agentless inventory, sensors added later |
| Cloud and network alerts | Two consoles, two timelines | One Darktrace platform, one incident |
| Over-privileged roles | Found in an annual access review | Flagged from observed permission use |
| Containment | A ticket to the cloud team | Action through the provider’s own controls |
| What it is NOT | — | A full CNAPP, an IaC scanner, or India-hosted |
The lowest-risk test is read-only: connect one account, let the baseline settle for a few weeks, and judge the alerts it raises.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Read-only access to cloud APIs and logs lists accounts, workloads, storage, functions and identities across AWS, Azure and GCP, with nothing installed on the workloads themselves.
vSensors read mirrored VPC or GCP packet traffic, osSensors sit on hosts and containerSensors watch containers; each one is optional and adds evidence the API view cannot see.
Darktrace’s Adaptive AI learns the normal pattern of each identity and workload in your accounts, so an alert reflects a break from your baseline, backed by custom models you can add.
Responses run through the cloud provider’s own controls rather than an inline device, and investigations can hand off to Forensic Acquisition & Investigation, a separately contracted product.
Agentless API enumeration plus optional sensors — a learned baseline per identity, answered through the cloud’s own controls.
Darktrace Cloud watches what your cloud identities and workloads actually do — and acts when it stops looking normal.
Agentless enumeration lists accounts, VMs, functions, storage and identities across AWS, Azure and GCP in one view.
Identity and permission views flag roles and users holding more rights than their behaviour shows they need.
A limited-feature edition of Darktrace’s exposure management ranks the cloud weaknesses most likely to be used.
Each identity and workload gets a behavioural profile, so a new API pattern or login stands out from routine work.
containerSensors and osSensors add process and connection detail from running containers and cloud hosts.
vSensors fed by VPC or GCP traffic mirroring read east-west flows that audit logs alone never record.
Actions go through the provider’s own controls, so a misbehaving identity or workload is curbed without an inline box.
Automated cloud forensics link to Darktrace’s Forensic Acquisition & Investigation product, licensed on its own.
Cloud alerts sit in the Behavioral Defense Platform beside Darktrace network and email coverage, under one console.
The current launch spot for Darktrace Cloud, a 2023 walk-through of real-time cloud visibility, and a short 2025 brand spot.
A 30-second launch spot for the current product, framed around stopping new cloud threats in real time.
A 90-second walk-through from 2023 of real-time cloud visibility; product naming on screen predates today’s.
A 15-second brand spot for Darktrace’s cloud security message; watch it for tone, not detail.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Most cloud tools begin with a rulebook of bad configurations. Darktrace Cloud begins by learning how each identity and workload in your accounts usually behaves, then flags what breaks that pattern, such as an unfamiliar API call sequence. Custom models can be added, so it is not rule-free, but the baseline does most of the work.
The connection is agentless: cloud APIs and logs give the inventory of accounts, workloads, storage, functions and identities from day one. Sensors come later and only where they add value, vSensors on mirrored VPC or GCP traffic, osSensors on hosts and containerSensors in clusters. You decide how deep to go, account by account.
For estates already running Darktrace network or email coverage, cloud detections join the same Behavioral Defense Platform, so an account takeover seen in email and odd activity in an AWS account can be read as one incident. Forensic capture links to Forensic Acquisition & Investigation, which is contracted separately.
It is detection and response first. Posture is a limited edition of Darktrace’s exposure management and no IaC or pipeline scanning is documented, so it is no CNAPP. No analyst has placed it in a cloud category. Packet depth needs complete traffic mirroring. It is quote-only, and no Darktrace-hosted region sits in India.
List the AWS, Azure and GCP accounts holding production data and count their identities and workloads for the quote.
Grant API and log access to a pilot account, review the inventory and pick a Darktrace hosting region outside India.
Watch alerts while the model learns normal behaviour; tune noisy ones and add custom models for known internal jobs.
Mirror VPC traffic to vSensors or place containerSensors in key clusters, then compare what the extra view reveals.
Decide which actions run autonomously and which need approval, then extend to the remaining accounts and clouds.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A service account began listing buckets it had never touched at 3 a.m. Darktrace flagged it before our nightly review did.”
“We connected three AWS accounts read-only on a Monday and had the identity inventory by Tuesday, with no agents yet.”
“Having cloud alerts next to our Darktrace email detections made one phishing-to-console takeover easy to trace.”
“The excessive-permission view found admin roles nobody had used in months. Removing them was the quick win.”
“Mirroring VPC traffic to the vSensors took planning and cost; without it we saw less inside our clusters.”
“Good detection, but we still run a separate CSPM for compliance reports and IaC checks. Budget for both.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote on an Identity Workload count; no cloud analyst placement.
The grid nobody publishes — how much it sees with nothing installed vs how deeply it can act on a live cloud threat.
Agentless first; behavioural response through cloud controls.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CrowdStrike Falcon Cloud Security, SentinelOne Singularity Cloud Security, Wiz Defend, Fortinet FortiCNAPP and Sophos Cloud Native Security — on deployment, detection, response, posture, price and India.
| Dimension | Darktrace Cloud | CrowdStrike Falcon Cloud Security | SentinelOne Singularity Cloud Security | Wiz Defend | Fortinet FortiCNAPP | Sophos Cloud Native Security |
|---|---|---|---|---|---|---|
| What it is | Behavioural CDR | Full CNAPP on Falcon | CNAPP with runtime | Runtime CDR module | CNAPP, Lacework roots | Posture + server runtime |
| Deployment | Agentless, sensors opt. | Sensor + agentless | Agentless + agent | Needs the Wiz Sensor | Agentless + agent | Agent + agentless |
| Clouds and workloads | AWS, Azure, GCP, SaaS | Multi-cloud + on-prem | AWS, Azure, GCP | Cloud + Kubernetes | Three clouds + private | Four clouds + on-prem |
| Detection method | Learned baseline | Threat Graph context | Autonomous runtime | eBPF + graph context | Anomaly, no rules | Host agent + XDR |
| Response actions | Platform-native | Sensor + automation | Stop and contain | Playbooks, Workflows | Detect and mitigate | Host agent + MDR |
| Posture and exposure | Limited edition | CSPM included | CSPM included | Separate Wiz SKU | CSPM + compliance | Cloud Optix CSPM |
| Identities and permissions | Excess rights flagged | CIEM included | CIEM included | Wiz CIEM is separate | Net-effective rights | IAM visualisation |
| Code and pipeline | Not documented | IaC to runtime | IaC scanning | Wiz Code is separate | SAST, SCA, IaC, SBOM | IaC templates |
| Pricing model | Identity Workload count | Modular, via Flex | Modular, consumption | Add-on + Sensor | Starter pack, then quote | PAYG per user, server |
| Published entry price | Not published | Not published | Not published | ~$18,000/yr reported | ~$25,000/yr starter | Marketplace PAYG |
| Included vs add-on | Forensics extra | One CNAPP product | Bundled layers | Stacked modules | Broad in one platform | MDR sold apart |
| India data region | None; Singapore nearest | Announced, not live | Mumbai region | Not documented | Not documented | Sophos Central Mumbai |
| Lock-in and exit | Best with Darktrace | Falcon-centred | Singularity-centred | Wiz platform first | Fabric-centred | Central-centred |
| Best fit | Darktrace-led SOCs | Falcon estates | S1 + India region | Wiz posture customers | Fortinet + behaviour | Sophos Central shops |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Darktrace Cloud is one of 19 cloud & workload security products TechBag carries. The Cloud & Workload Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (cloud identities and workloads in scope; analyst-hour cost). Estimates model analyst time spent triaging and investigating cloud alerts at an assumed 1.5 hours per identity or workload a year, with 70% of it removed by behavioural triage and autonomous response. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Quote-only: Darktrace publishes no CLOUD price. It is metered on an Identity Workload count — cloud identities plus weighted workloads such as VMs, functions and storage — set in the order form. Darktrace’s public AWS Marketplace tiers ($30,000 to $100,000 a year) are metered on bandwidth and hosts for the network product and do not price CLOUD. TechBag counts your identities and workloads first, then quotes in INR with GST.
Best for behavioural cloud detection
Best for a broader rollout
Best for evidence-led response
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
How many cloud identities and weighted workloads will count toward the Identity Workload meter in year one and year three?
Are all your accounts on AWS, Azure or GCP, and which SaaS applications do you want in the same baseline?
Which Darktrace region will hold your data, given none is in India and billing parts always run in us-east-1?
Will you mirror VPC or GCP traffic to vSensors, and have you costed the mirroring and the sensor compute?
Which CSPM, compliance or IaC scanner will cover what CLOUD’s limited exposure edition does not?
Which platform-native actions may run without approval, and who signs off on those that need a person?
Do you need Forensic Acquisition & Investigation as well, and is it on the same order form or a separate one?
Does the quote spell out the Identity Workload count, overage terms, term length and an INR total with GST?
Count the identities and workloads that drive the quote first, or let a TechBag advisor scope an agentless pilot on one production cloud account.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.