Talk to us
by DarktraceTechBag Intel Page

Darktrace Forensic Acquisition & Investigation

Your compromised container was gone before anyone looked. Its evidence does not have to be — Darktrace Forensic Acquisition & Investigation captures full volumes or triage collections from cloud workloads, storage and logs, and runs in your own AWS, Azure or GCP account or as Darktrace SaaS.

Full volume or triage captureSelf-host in AWS, Azure or GCPSaaS in North America and Europe

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
Darktrace prints no price for forensics; its only public tiers are for the network product
Quote
Hosting
Self-host in AWS, Azure or GCP, or use Darktrace’s SaaS in North America or Europe
Your cloud or SaaS
Analysts
No analyst placement covers forensics; Darktrace’s Leader positions sit in Gartner’s NDR and email MQs
None for DFIR
India
No India SaaS region; evidence stays in India only if your own cloud account is there
Own account

Quick answer

Darktrace Forensic Acquisition & Investigation, the former Cado Security product, captures and analyses evidence from cloud compute, containers, serverless functions, object storage and logs, taking a full volume or a lighter triage collection. It reaches on-premises systems through detection and XDR integrations. Run it in your own AWS, Azure or GCP account, or as Darktrace SaaS in North America or Europe. Quote-only. Read more ↓ Show less ↑
Part 01 · Orient

The Darktrace platform family

This page covers Darktrace Forensic Acquisition & Investigation — cloud forensics, formerly Cado Security. The rest:

Quick facts

30-second orientation
Product
Automated forensic capture and investigation for cloud workloads, storage and logs
Maker
Darktrace Holdings, Cambridge, UK; owned by Thoma Bravo since 2024, CEO Ed Jennings
Origin
Built by Cado Security; Darktrace’s contract notes the product was previously named CADO
Price
Not published; quoted under its own specification in Darktrace’s offering document
Capture
A full-volume image for deep work, or a lightweight triage collection for speed
Sources
Cloud compute, containers, serverless, object storage and logs; on-premises via XDR integrations
Hosting
Customer-hosted in your AWS, Azure or GCP account, or SaaS in Darktrace’s AWS environment
SaaS regions
North America and Europe only; Darktrace says other regions will be added later
India
No India SaaS region; the customer-hosted edition keeps evidence in your own cloud account
In India via
TechBag — hosting choice, quote in INR with GST, first capture drill
Part 02 · Learn

Understand cloud forensics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is cloud forensic acquisition?

It captures evidence from cloud workloads, storage and logs, then analyses it so responders can see what happened.

Hand-made snapshots after the fact vs automated cloud capture — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionHand-made snapshots, after the factDarktrace Forensic Acquisition & Investigation
Starting a captureSomeone snapshots the disk by handAutomated capture, full volume or triage
Short-lived workloadsGone before anyone looksContainers and serverless are in scope
Storage and log evidencePulled separately, tool by toolCollected alongside the host evidence
Where evidence is keptWherever the responder copied itYour own cloud account, or Darktrace SaaS
Data-centre serversA separate forensic toolkitReached through XDR and detection integrations
What it is NOT—An EDR, a SIEM, or a SaaS hosted in India

The cheapest test is a drill: take a triage and a full-volume capture from one test workload and time how long each takes.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
How evidence is collected

Acquire

Full-volume and triage capture

It images a whole volume when an investigation needs everything, or takes a lighter triage collection when speed matters, from cloud compute, containers and serverless functions.

02
What sits beside the host evidence

Sources

Object storage and log collection

Object storage and logs are capture sources too, so a record of what an attacker read or changed in the cloud sits next to what actually ran on the compromised workload.

03
What starts a capture and widens reach

Hand-offs

Darktrace Cloud and XDR integrations

Darktrace Cloud integrates with it for automated cloud forensics, and integrations with cloud-native detection providers and XDR platforms extend it to on-premises systems.

04
Where captured evidence is kept

Hosting

Customer-hosted or Darktrace SaaS

Install it inside your own AWS, Azure or GCP account, or use the SaaS Darktrace runs on AWS in North America and Europe; that single choice settles where the evidence is stored.

Full volumes or triage from cloud workloads, storage and logs — kept in your own cloud account or in Darktrace SaaS.

Part 03 · Evaluate

Nine capabilities. Capture, investigate, run.

Darktrace Forensic Acquisition & Investigation captures cloud evidence automatically, before the workload that held it is gone.

Capture
Full volume

Whole-disk images

When an incident needs everything, it acquires the full volume of a cloud workload, preserving the disk for deeper work later.

Capture
Triage

Lightweight collection first

A smaller triage capture gathers the key evidence quickly, so responders can start on the essentials without a full disk.

Capture
Ephemeral

Containers and serverless

Capture covers containers and serverless functions as well as virtual machines, the workloads most likely to vanish first.

Investigate
Storage

Object storage in scope

Object storage is a listed source, so the buckets and blobs an intruder touched join the same investigation as the hosts.

Investigate
Logs

Logs beside the disk

Log collection sits next to host evidence, so an analyst can line cloud activity up against what happened on the workload.

Investigate
Analysis

Analysis, not just storage

Darktrace pairs acquisition with automated analysis, so captured evidence reaches investigators processed rather than raw.

Run
Your account

Customer-hosted edition

Run it inside your own AWS, Azure or GCP account, so captured evidence never has to leave infrastructure you control.

Run
SaaS

Darktrace-run service

Or let Darktrace host it in its AWS environment, offered in North America and Europe, with more regions promised later.

Run
On-premises

Data-centre reach by integration

Integrations with cloud-native detection tools and XDR platforms carry it to on-premises systems, not only cloud workloads.

See it, don’t just read it

Watch Darktrace talk cloud incident response

No product demo is on YouTube; Darktrace hosts those on its own site. This 2026 AWS Security LIVE! talk covers Darktrace’s approach to automated cloud incident response.

Darktrace (official)·Conference talk, 2026

Automated Incident Response in the Cloud - Darktrace at AWS

An AWS Security LIVE! session in which Darktrace’s SVP of Cloud Strategy explains its approach to automated cloud incident response. It is a talk, not a product demo.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Darktrace Forensic Acquisition & Investigation

Cloud evidence disappears with the workload. Forensic Acquisition & Investigation captures it first.

Here’s what genuinely sets it apart — and exactly where it stops.

01

Evidence captured before the workload is gone

Cloud workloads scale in, restart and get replaced, and whatever was on them goes too. This product automates capture across compute, containers, serverless functions, object storage and logs, taking either a full volume or a lighter triage collection, so the record outlives the workload it came from.

02

Evidence that stays in your own cloud account

The customer-hosted edition deploys inside your AWS, Azure or GCP account, so captured disks and triage data sit in infrastructure you control. It is the route to take if evidence must remain in India, because the SaaS edition Darktrace operates runs only in North America and Europe today.

03

Linked to Darktrace detection, open to other tools

Darktrace Cloud integrates with it for automated cloud forensics, so a cloud detection can lead straight to collected evidence. Integrations with cloud-native detection providers and XDR platforms reach beyond Darktrace’s own sensors, and that is also how on-premises systems come into scope.

04

Where it stops

There is no public price, and the SaaS edition runs only in North America and Europe. On-premises reach depends on detection and XDR integrations, so check yours is supported. Darktrace’s website files forensics under Darktrace Hybrid Network, so confirm the quote names it as a line; demos sit on darktrace.com, not YouTube.

The idea
Capture cloud evidence before it is gone
The residency
Self-host it in your own cloud account
The price
Quote-only, under its own specification
Proof, not promises

The numbers behind the platform

3 clouds
AWS, Azure and GCP: the accounts the customer-hosted edition can be deployed into
— Vendor
2 SaaS regions
North America and Europe, the only places Darktrace hosts the service for now
— Vendor
5 source types
cloud compute, containers, serverless functions, object storage and logs
— Vendor
2 capture modes
a full-volume image or a lightweight triage collection, picked per incident
— Vendor
~10000
customers across the Darktrace platform, by the company’s 2026 description of itself
— Vendor
2400+
Darktrace employees, at a company Thoma Bravo took private in 2024 for about $5.3 billion
— Vendor

What your Darktrace forensics rollout looks like

Week 1Model

Choose where evidence lives

Pick customer-hosted in your AWS, Azure or GCP account or Darktrace’s SaaS, knowing SaaS runs only in North America and Europe.

Week 2Decide

Map the sources

List the compute, containers, serverless functions, buckets and logs in scope, and which on-premises systems need an XDR link.

Week 3Pilot

Deploy and connect

Install the customer-hosted edition or open the SaaS tenant, grant cloud access, and connect Darktrace Cloud if you run it.

Month 2Prove

Run a capture drill

Take a triage and a full-volume capture from a test workload, then time how fast investigators reach findings they can use.

Month 3Commit

Write it into the IR plan

Record when a triage is enough and when a full volume is needed, who approves captures, and how long evidence is kept.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4
26+ reviews*
78% would recommend
Capture speed4.2
Cloud coverage4.2
Hosting choice4.3
Ease of setup3.8
Value for money3.6
5★
38%
4★
40%
3★
15%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Fintech
“An autoscaled node was terminated minutes after the alert, but the triage capture had already run, so its evidence survived.”
Cloud Security Engineer
Fintech
BFSI
“We self-host it in our own AWS account. Legal wanted evidence in storage we control, and that ended the hosting debate.”
Head of Security Operations
BFSI
SaaS
“Container coverage is why we bought it. Our old runbook assumed a VM disk someone could snapshot by hand on the night.”
DevSecOps Lead
SaaS
Manufacturing
“Plan the data-centre side early: our servers come in through the XDR integration, and that took longer than the cloud part.”
Incident Response Manager
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the cloud forensics and incident response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Cloud Forensics Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Darktrace Forensic Acquisition & InvestigationThis page

Quote-only, under its own specification in Darktrace’s contract.

Grid 02 · The architecture

Evidence Control × Capture Depth

The grid nobody publishes — how much control you keep over where evidence is stored vs how deep and wide the capture goes.

Deep capture, vendor cloudDeep capture, your cloudLogs and alerts onlyYour account, lighter capture
Darktrace Forensic Acquisition & InvestigationThis page

Your account or SaaS; full volume or triage across five source types.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Darktrace Forensic Acquisition & Investigation vs the forensics and response field

Against CrowdStrike Falcon Forensics, Palo Alto Cortex Forensics, Wiz Defend, Microsoft Sentinel and Mimecast Email Incident Response — on capture depth, sources, hosting, price, scale, India and exit.

DimensionDarktrace Forensic Acquisition & InvestigationCrowdStrike Falcon ForensicsPalo Alto Cortex ForensicsWiz DefendMicrosoft SentinelMimecast Email Incident Response
What it isCloud forensics, ex-CadoEndpoint triage toolAdd-on to CortexCDR with forensicsSIEM, not captureEmail IR service
DeploymentYour cloud or SaaSDissolvable executableAgent or offline kitAgentless + SensorSaaS on Azure onlyRun by Mimecast
Sources coveredCompute to storageWindows, macOS, LinuxLogs, registry, filesCloud workloadsLogs from the estateEmail only
Capture depthFull volume or triageTriage, not disk imagesTriage packagesVolume copiesLog records onlyMessage-level
How capture startsAutomated, CLOUD-linkedVia Real Time ResponseAnalyst-run triageOne-click volume copyAnalytics rulesUser reports
On-premises reachThrough integrationsAny Falcon endpointOffline hosts tooCloud-firstLogs, not hostsNot applicable
Pricing modelQuoted contractQuoted Falcon modulePaid add-onQuote-only, premiumPer GB ingestedRetainer or per user
Published entry priceNot publishedTrial, no priceNo list priceQuote~$4.30 per GBRate not printed
How it is boughtOwn spec, own lineFalcon platform moduleNeeds Cortex firstSensor costs extraAzure subscriptionMimecast customers
Scale limitsNot publishedTen to 100,000sTen per triageNot statedVolume drives costEvery mailbox
Analysis outputAutomated analysisDashboards, timelinesForensics tablesGraph contextKQL huntingAnalyst verdicts
India storageYour account onlyNot documentedNo India region statedIn a forensic accountStored in IndiaNot stated
Lock-in and exitEvidence you holdExport via FDRTied to CortexGoogle-owned nowPortal move by 2027Mimecast mail only
Best fitCloud-heavy IR teamsFalcon endpoint estatesCortex-run SOCsWiz posture customersMicrosoft-first SOCsMimecast mail estates
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Darktrace Forensic Acquisition & Investigation if…

  • ✓Your incidents happen in AWS, Azure or GCP, and evidence on short-lived containers or serverless functions keeps disappearing
  • ✓Evidence has to stay in infrastructure you control, so a customer-hosted deployment in your own cloud account matters
  • ✓You already run Darktrace Cloud and want its detections to lead straight on to captured evidence

Compare alternatives if…

  • ✓Most incidents start on laptops and servers — CrowdStrike Falcon Forensics and Cortex Forensics collect from endpoints directly
  • ✓You investigate from logs more than from disks — Microsoft Sentinel stores its data in Indian Azure regions
  • ✓Your cloud security already runs on Wiz — Wiz Defend copies volumes to a forensic account without a second vendor

Do not expect…

  • ✓A published price, or a Darktrace-hosted SaaS region in India
  • ✓Data-centre coverage without an integration — on-premises servers come in through detection and XDR platforms
  • ✓A YouTube product demo — Darktrace keeps its forensics demos on its own website

TechBag has no digital forensics guide yet, so Darktrace Forensic Acquisition & Investigation sits outside the category guides. Browse all products to compare it with the rest of the catalogue. →

Do the math

What does hand-run evidence collection cost you?

Drag the sliders (cloud workloads in scope; responder-hour cost). Estimates model responder time spent snapshotting disks by hand, copying evidence out and pulling logs tool by tool at an assumed 1.5 hours per workload a year, with 70% of it removed by automated capture and analysis. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual evidence-collection cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Darktrace prints no price for Forensic Acquisition & Investigation. It carries its own product specification in Darktrace’s contract and is quoted per customer, in either the customer-hosted or the SaaS edition. Darktrace’s only public prices are AWS Marketplace offers for its network product. TechBag gets forensics quoted as its own line, then bills in INR with GST.

Customer-hosted

Best when evidence must stay in your account

  • Quoted; no public rate
  • Runs in your AWS, Azure or GCP account
  • Full-volume and triage capture

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Darktrace SaaS

Best when you want nothing to operate

  • Quoted; no public rate
  • Hosted in Darktrace’s AWS environment
  • North America and Europe regions only

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Hosting

Will it run customer-hosted in your own cloud account, or as SaaS in North America or Europe? Your data rules decide.

2
Clouds

Are the workloads you need to investigate on AWS, Azure or GCP, the clouds the customer-hosted edition supports?

3
Workloads

Which containers and serverless functions must be covered, and how long do they actually live in production?

4
Storage and logs

Which object stores and log sources hold evidence you would want after an incident, and who owns them?

5
On-premises

Which data-centre servers need coverage, and does your XDR or detection platform integrate with the product?

6
Capture policy

When does an incident justify a full volume, and when is a triage collection enough to make a decision?

7
Darktrace stack

Do you run Darktrace Cloud already? Its integration is what links cloud detections to automated capture.

8
Licence

Is it quoted as its own line, not folded into Darktrace Hybrid Network? Ask for INR with GST and the contract term.

FAQ

Questions buyers ask

It is Darktrace’s cloud forensics product. It automates the capture of evidence from cloud compute, containers, serverless functions, object storage and logs, taking a full volume or a lightweight triage collection, then analyses what it collected so investigators work from findings rather than raw disk images.

Ready to evaluate Darktrace Forensic Acquisition & Investigation?

List the cloud workloads you would need evidence from first, or let a TechBag advisor weigh the customer-hosted edition against SaaS for your data rules.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.