Your compromised container was gone before anyone looked. Its evidence does not have to be — Darktrace Forensic Acquisition & Investigation captures full volumes or triage collections from cloud workloads, storage and logs, and runs in your own AWS, Azure or GCP account or as Darktrace SaaS.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Forensic Acquisition & Investigation — cloud forensics, formerly Cado Security. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
It captures evidence from cloud workloads, storage and logs, then analyses it so responders can see what happened.
What consolidation actually replaces, dimension by dimension.
| Dimension | Hand-made snapshots, after the fact | Darktrace Forensic Acquisition & Investigation |
|---|---|---|
| Starting a capture | Someone snapshots the disk by hand | Automated capture, full volume or triage |
| Short-lived workloads | Gone before anyone looks | Containers and serverless are in scope |
| Storage and log evidence | Pulled separately, tool by tool | Collected alongside the host evidence |
| Where evidence is kept | Wherever the responder copied it | Your own cloud account, or Darktrace SaaS |
| Data-centre servers | A separate forensic toolkit | Reached through XDR and detection integrations |
| What it is NOT | — | An EDR, a SIEM, or a SaaS hosted in India |
The cheapest test is a drill: take a triage and a full-volume capture from one test workload and time how long each takes.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
It images a whole volume when an investigation needs everything, or takes a lighter triage collection when speed matters, from cloud compute, containers and serverless functions.
Object storage and logs are capture sources too, so a record of what an attacker read or changed in the cloud sits next to what actually ran on the compromised workload.
Darktrace Cloud integrates with it for automated cloud forensics, and integrations with cloud-native detection providers and XDR platforms extend it to on-premises systems.
Install it inside your own AWS, Azure or GCP account, or use the SaaS Darktrace runs on AWS in North America and Europe; that single choice settles where the evidence is stored.
Full volumes or triage from cloud workloads, storage and logs — kept in your own cloud account or in Darktrace SaaS.
Darktrace Forensic Acquisition & Investigation captures cloud evidence automatically, before the workload that held it is gone.
When an incident needs everything, it acquires the full volume of a cloud workload, preserving the disk for deeper work later.
A smaller triage capture gathers the key evidence quickly, so responders can start on the essentials without a full disk.
Capture covers containers and serverless functions as well as virtual machines, the workloads most likely to vanish first.
Object storage is a listed source, so the buckets and blobs an intruder touched join the same investigation as the hosts.
Log collection sits next to host evidence, so an analyst can line cloud activity up against what happened on the workload.
Darktrace pairs acquisition with automated analysis, so captured evidence reaches investigators processed rather than raw.
Run it inside your own AWS, Azure or GCP account, so captured evidence never has to leave infrastructure you control.
Or let Darktrace host it in its AWS environment, offered in North America and Europe, with more regions promised later.
Integrations with cloud-native detection tools and XDR platforms carry it to on-premises systems, not only cloud workloads.
No product demo is on YouTube; Darktrace hosts those on its own site. This 2026 AWS Security LIVE! talk covers Darktrace’s approach to automated cloud incident response.
An AWS Security LIVE! session in which Darktrace’s SVP of Cloud Strategy explains its approach to automated cloud incident response. It is a talk, not a product demo.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Cloud workloads scale in, restart and get replaced, and whatever was on them goes too. This product automates capture across compute, containers, serverless functions, object storage and logs, taking either a full volume or a lighter triage collection, so the record outlives the workload it came from.
The customer-hosted edition deploys inside your AWS, Azure or GCP account, so captured disks and triage data sit in infrastructure you control. It is the route to take if evidence must remain in India, because the SaaS edition Darktrace operates runs only in North America and Europe today.
Darktrace Cloud integrates with it for automated cloud forensics, so a cloud detection can lead straight to collected evidence. Integrations with cloud-native detection providers and XDR platforms reach beyond Darktrace’s own sensors, and that is also how on-premises systems come into scope.
There is no public price, and the SaaS edition runs only in North America and Europe. On-premises reach depends on detection and XDR integrations, so check yours is supported. Darktrace’s website files forensics under Darktrace Hybrid Network, so confirm the quote names it as a line; demos sit on darktrace.com, not YouTube.
Pick customer-hosted in your AWS, Azure or GCP account or Darktrace’s SaaS, knowing SaaS runs only in North America and Europe.
List the compute, containers, serverless functions, buckets and logs in scope, and which on-premises systems need an XDR link.
Install the customer-hosted edition or open the SaaS tenant, grant cloud access, and connect Darktrace Cloud if you run it.
Take a triage and a full-volume capture from a test workload, then time how fast investigators reach findings they can use.
Record when a triage is enough and when a full volume is needed, who approves captures, and how long evidence is kept.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“An autoscaled node was terminated minutes after the alert, but the triage capture had already run, so its evidence survived.”
“We self-host it in our own AWS account. Legal wanted evidence in storage we control, and that ended the hosting debate.”
“Container coverage is why we bought it. Our old runbook assumed a VM disk someone could snapshot by hand on the night.”
“Plan the data-centre side early: our servers come in through the XDR integration, and that took longer than the cloud part.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud forensics and incident response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Quote-only, under its own specification in Darktrace’s contract.
The grid nobody publishes — how much control you keep over where evidence is stored vs how deep and wide the capture goes.
Your account or SaaS; full volume or triage across five source types.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against CrowdStrike Falcon Forensics, Palo Alto Cortex Forensics, Wiz Defend, Microsoft Sentinel and Mimecast Email Incident Response — on capture depth, sources, hosting, price, scale, India and exit.
| Dimension | Darktrace Forensic Acquisition & Investigation | CrowdStrike Falcon Forensics | Palo Alto Cortex Forensics | Wiz Defend | Microsoft Sentinel | Mimecast Email Incident Response |
|---|---|---|---|---|---|---|
| What it is | Cloud forensics, ex-Cado | Endpoint triage tool | Add-on to Cortex | CDR with forensics | SIEM, not capture | Email IR service |
| Deployment | Your cloud or SaaS | Dissolvable executable | Agent or offline kit | Agentless + Sensor | SaaS on Azure only | Run by Mimecast |
| Sources covered | Compute to storage | Windows, macOS, Linux | Logs, registry, files | Cloud workloads | Logs from the estate | Email only |
| Capture depth | Full volume or triage | Triage, not disk images | Triage packages | Volume copies | Log records only | Message-level |
| How capture starts | Automated, CLOUD-linked | Via Real Time Response | Analyst-run triage | One-click volume copy | Analytics rules | User reports |
| On-premises reach | Through integrations | Any Falcon endpoint | Offline hosts too | Cloud-first | Logs, not hosts | Not applicable |
| Pricing model | Quoted contract | Quoted Falcon module | Paid add-on | Quote-only, premium | Per GB ingested | Retainer or per user |
| Published entry price | Not published | Trial, no price | No list price | Quote | ~$4.30 per GB | Rate not printed |
| How it is bought | Own spec, own line | Falcon platform module | Needs Cortex first | Sensor costs extra | Azure subscription | Mimecast customers |
| Scale limits | Not published | Ten to 100,000s | Ten per triage | Not stated | Volume drives cost | Every mailbox |
| Analysis output | Automated analysis | Dashboards, timelines | Forensics tables | Graph context | KQL hunting | Analyst verdicts |
| India storage | Your account only | Not documented | No India region stated | In a forensic account | Stored in India | Not stated |
| Lock-in and exit | Evidence you hold | Export via FDR | Tied to Cortex | Google-owned now | Portal move by 2027 | Mimecast mail only |
| Best fit | Cloud-heavy IR teams | Falcon endpoint estates | Cortex-run SOCs | Wiz posture customers | Microsoft-first SOCs | Mimecast mail estates |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
TechBag has no digital forensics guide yet, so Darktrace Forensic Acquisition & Investigation sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →
Drag the sliders (cloud workloads in scope; responder-hour cost). Estimates model responder time spent snapshotting disks by hand, copying evidence out and pulling logs tool by tool at an assumed 1.5 hours per workload a year, with 70% of it removed by automated capture and analysis. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Darktrace prints no price for Forensic Acquisition & Investigation. It carries its own product specification in Darktrace’s contract and is quoted per customer, in either the customer-hosted or the SaaS edition. Darktrace’s only public prices are AWS Marketplace offers for its network product. TechBag gets forensics quoted as its own line, then bills in INR with GST.
Best when evidence must stay in your account
Best for a broader rollout
Best when you want nothing to operate
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Will it run customer-hosted in your own cloud account, or as SaaS in North America or Europe? Your data rules decide.
Are the workloads you need to investigate on AWS, Azure or GCP, the clouds the customer-hosted edition supports?
Which containers and serverless functions must be covered, and how long do they actually live in production?
Which object stores and log sources hold evidence you would want after an incident, and who owns them?
Which data-centre servers need coverage, and does your XDR or detection platform integrate with the product?
When does an incident justify a full volume, and when is a triage collection enough to make a decision?
Do you run Darktrace Cloud already? Its integration is what links cloud detections to automated capture.
Is it quoted as its own line, not folded into Darktrace Hybrid Network? Ask for INR with GST and the contract term.
List the cloud workloads you would need evidence from first, or let a TechBag advisor weigh the customer-hosted edition against SaaS for your data rules.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.