An intruder is already moving between your servers. Your perimeter firewall never sees that traffic — Darktrace Hybrid Network learns how every device on your network normally behaves from mirrored traffic, and Autonomous Response contains what departs from it — through its own sensors or your firewall.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Hybrid Network — the NDR product, with the osSensor and NEXT endpoint telemetry folded in. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
NDR watches traffic inside the network, between your own hosts, and flags behaviour a perimeter firewall never sees.
What consolidation actually replaces, dimension by dimension.
| Dimension | Perimeter firewall and signature IDS | Darktrace Hybrid Network |
|---|---|---|
| What gets seen | Traffic crossing the perimeter | East-west traffic between internal hosts too |
| How a threat is found | Signatures written after others were hit | Departures from each device’s learned behaviour |
| Encrypted sessions | Opaque unless someone decrypts them | Read for behaviour, encrypted or decrypted |
| First containment | An analyst, once the alert is read | Autonomous Response, via sensor or firewall |
| Knowing the price | A quote after a scoping call | Public marketplace tiers from $30,000 a year |
| What it is NOT | — | An inline firewall, an EDR or an India-hosted cloud |
The cheapest test is the free 30-day Proof of Value: mirror one busy segment, let the models learn, and count the findings that were real.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The Master runs the behavioural models and hosts the Threat Visualizer console. It is either a physical appliance in your data centre or a cloud master that Darktrace hosts.
Probes take SPAN or TAP feeds at other sites, vSensors read virtual and cloud traffic mirrors, and osSensor agents on Windows or Linux hosts report to a vSensor, up to 255 each.
Adaptive AI builds a behavioural profile of each device and user from its traffic and raises a model breach when activity departs from it; you can add custom models as well.
Actions go out as spoofed TCP resets from an appliance or sensor, or through the firewall integrations bundled with the product. A Darktrace-hosted master cannot send resets alone.
Sensors on mirrored traffic and a Master on site or hosted — behaviour learned per device, threats cut by reset or firewall.
Darktrace Hybrid Network learns normal behaviour from mirrored traffic and contains what departs from it.
Darktrace analyses encrypted and decrypted traffic across network, cloud and OT, so odd behaviour still shows when payloads stay sealed.
Detection keys on departures from learned behaviour; Darktrace’s research says it flags novel threats eight days before disclosure on average.
The Master also ingests syslog, so events from other devices join the traffic picture the models and your analysts already work from.
Configurable actions stop a suspicious connection from the appliance or sensor that saw it, natively or through tools you already run.
A TCP reset cannot cross a stateful boundary, so the bundled firewall integrations push the block to the firewall that stands between segments.
Containment can also run through your EDR, SOAR and ITSM tools, so each action lands in the consoles and queues your team already uses.
osSensor and the NEXT agent add process-level root cause to network threats; Darktrace places them beside Defender for Endpoint, not as an EDR.
The product page groups NDR, CDR, OT security, identity detection, attack path modeling and forensics; several are contracted on their own.
Darktrace bought Mira Security in July 2025 for traffic visibility and in-line decryption, feeding new hardware with 100 Gbps interfaces.
A 2026 product spot, then two 2024 walk-throughs of threats caught on the network — an Ivanti exploitation and SmokeLoader malware. All from Darktrace’s official channel.
A 30-second spot for the network product, under the contract name it still carries.
How network behaviour exposed attackers exploiting an Ivanti flaw, in just over two minutes.
A SmokeLoader infection traced from its network activity and contained, step by step.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
Gartner placed Darktrace as a Leader in its NDR Magic Quadrant in 2025 and again in 2026. Most NDR hands a finding to another tool; Autonomous Response can stop the connection itself, with spoofed resets from its sensors or through firewall integrations bundled with the product.
NDR is usually quote-only. Darktrace’s AWS Marketplace public offer sets three 12-month tiers: Small (300 Mbps, 200 hosts) at $30,000, Medium (2 Gbps, 1,000 hosts) at $60,000 and Large (5 Gbps, 10,000 hosts) at $100,000, after a free 30-day Proof of Value.
The same product page reaches cloud, OT, identity and exposure work, while osSensor and the NEXT agent add host context Darktrace positions beside Defender for Endpoint. Buying Mira Security in 2025 brought in-line decryption for traffic that would stay opaque.
It sees only what you mirror; Darktrace’s specification warns an incomplete feed severely impacts analysis. Resets cannot cross stateful boundaries without a firewall integration, and a hosted master cannot send them. It is not an inline firewall or an EDR, and no hosted region is in India.
List core switches, data-centre segments and cloud VPCs, and confirm where SPAN, TAP or a cloud mirror can feed a sensor.
Pick a physical Master in your Indian data centre or a Darktrace-hosted master in Singapore or another listed region.
Use the 30-day POV on real mirrored traffic; let the models learn, then sort model breaches into real findings and noise.
Enable actions on lower-risk segments first, add a firewall integration where resets cannot cross, and log each action.
Measure hosts and average bandwidth against the Small, Medium and Large bands, then get the quote itemised in INR with GST.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A file server started talking to an unfamiliar host at 3 a.m.; Autonomous Response had cut the session before anyone woke.”
“Our first fortnight of thin detections traced back to SPAN gaps on two core switches, not to the product. Map mirroring first.”
“Seeing the Small tier price on AWS Marketplace let us budget the Proof of Value before procurement even asked for a quote.”
“Resets stopped at our internal firewall until we switched on the firewall integration. Segmented networks need that planned in.”
“Compliance asked where a hosted master would keep our metadata, so we chose an on-premises Master in our own data centre.”
“We outgrew the Medium band’s 1,000 hosts within a year. Count every host you will mirror before you pick a tier.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the network detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
NDR Leader in 2025 and 2026; public tiers from $30,000 a year.
The grid nobody publishes — how deep into the traffic a product reads vs how much it can contain without another vendor’s tool.
Encrypted and decrypted traffic; resets and firewall blocks built in.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Against LinkShadow Intelligent NDR, Sophos NDR, WatchGuard NDR, Vectra AI Platform and ExtraHop RevealX — on traffic depth, deployment, price, sizing, response, analyst standing, managed options and India.
| Dimension | Darktrace Hybrid Network | LinkShadow Intelligent NDR | Sophos NDR | WatchGuard NDR | Vectra AI Platform | ExtraHop RevealX |
|---|---|---|---|---|---|---|
| What it is | Behavioural NDR | DPI-led NDR flagship | Sensor for XDR and MDR | Flow-based cloud NDR | Hybrid attack signal | Wire-data NDR |
| Deployment | Appliances + sensors | Sensors and a Master | VM or certified kit | Cloud + site collector | On-site Brain, sensors | SaaS console, own kit |
| Traffic and coverage | Packets, cloud, OT | Mirrored packets | Packets, agentless kit | Flows and logs only | Metadata + identity | Full streams, hybrid |
| Pricing model | Bandwidth + host bands | Sensor + Master quote | Users and servers | Per user or Firebox | Standard or Complete | Quote via ExtraHop |
| Published entry price | $30,000 a year | Not published | Not published | Not published | $499/month listed | Not published |
| Included vs add-on | Firewall hooks included | DSPM, ITDR extra | Unlimited sensors | Tiers differ in reach | MDR in Complete | Packetstores apart |
| Sizing and limits | Up to 5 Gbps public | No figure published | 1 Gbps per VM sensor | 500k flows a minute | 14 to 90 days kept | Sized to traffic |
| Detection depth | Encrypted + decrypted | DPI plus baselines | Five engines | Flow behaviour | Correlated attack signal | TLS 1.3 decrypted |
| Response | Native containment | Detect only | Via Sophos Firewall | Firebox, endpoint, IdP | Through the Brain | SOAR and firewalls |
| Gartner NDR standing | Leader 2025 + 2026 | Visionary, 2026 | None cited | None cited | Leader 2026 | Leader 2026 |
| Who watches alerts | Darktrace MDR | Your SOC or a partner | Sophos MDR | Total MDR | Vectra MDR, MXDR | Partner MNDR, US |
| India data location | On-prem Master | Master in India | Mumbai; confirm NDR | No India region | Brain here, UI abroad | Sensors in India |
| Lock-in and exit | Appliance-based term | Data on your hardware | Tied to Sophos Central | Deleted after 7 days | Cases in the cloud | Cloud recordstore |
| Best fit | Self-acting NDR | Data stays on site | Sophos XDR shops | NetFlow-rich SMBs | Microsoft-heavy hybrid | Packet forensics SOCs |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Darktrace Hybrid Network is one of 17 firewall & network security products TechBag carries. The Firewall & Network Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (hosts you monitor; analyst-hour cost). Estimates model the analyst time spent triaging network alerts, tracing lateral movement and containing incidents by hand, at an assumed 1.5 hours per host a year, with 70% of it removed by behavioural detection and Autonomous Response. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Published: Darktrace’s AWS Marketplace public offer lists three 12-month tiers — Small (up to 300 Mbps average bandwidth, 200 hosts) at $30,000, Medium (2 Gbps, 1,000 hosts) at $60,000 and Large (5 Gbps, 10,000 hosts) at $100,000 — after a free 30-day Proof of Value. Direct contracts use usage-metric bands set in the order form, and estates beyond the public bands are quoted. OT, IDENTITY, CLOUD and managed detection are contracted separately. Darktrace publishes no rupee price; TechBag sizes your hosts and bandwidth first, then quotes in INR with GST.
Best for estates that fit a public band
Best for a broader rollout
Best for larger estates or an on-site Master
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Can every important segment be fed by SPAN, TAP or a cloud mirror? Darktrace warns gaps severely impact its analysis.
Will the Master be an appliance in your Indian data centre, or a hosted master in Singapore or another listed region?
What are your average bandwidth and host count? Public bands stop at 300 Mbps/200, 2 Gbps/1,000 and 5 Gbps/10,000.
Which segments may Autonomous Response act on alone, and who reviews each action it takes in the first month?
Must blocks cross stateful firewalls between segments? If so, which bundled firewall integration will carry them?
Will you add osSensor or NEXT? Treat them as context beside an EDR such as Defender, never a substitute for one.
Is the Threat Visualizer on a current build? CVE-2024-22854 affected version 6.1.27 (bundle 61050) and earlier.
Does the order form name the usage-metric band, the term, POV terms, and which modules such as OT or IDENTITY are extra?
Map which segments you can mirror first, or let a TechBag advisor plan the free Proof of Value, choose between an on-site and a hosted Master, and size your tier.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.