Darktrace contains a threat at 3 a.m. and nobody reviews it until morning. Someone who knows the platform should be watching it — Darktrace Managed Detection & Response puts Darktrace’s own follow-the-sun SOC on the Darktrace deployment you already run, extending Autonomous Response overnight while remediation stays with your team.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Darktrace Managed Detection & Response — the service bundle, plus the lighter Managed Threat Detection and Security Operations Support services. The rest:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
The maker of your security platform staffs the SOC that watches it, around the clock, and escalates what is real.
What consolidation actually replaces, dimension by dimension.
| Dimension | Darktrace alerts unread overnight | Darktrace Managed Detection & Response |
|---|---|---|
| Darktrace alerts after hours | Queued until someone logs in | Picked up by a follow-the-sun SOC |
| An overnight containment | Expires before anyone reviews it | Extended by an analyst on eligible devices |
| Who gets called | Whoever picks up the shared phone | Named contacts set in readiness workshops |
| Wider response actions | Taken in a hurry, then justified | Recommended, then run on written approval |
| Reporting upward | Screenshots pasted into an email | A monthly SOC report on investigations |
| What it is NOT | — | Remediation, multi-vendor MDR, or India-hosted |
The cheapest first step is a scoping call: list your mirrored segments and cloud accounts, and see what the SOC could actually watch.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
The service rides on the platform you already license: appliances, vSensors and osSensors feed Darktrace’s models, and the Real-Time AI Analyst is the layer that investigates first.
Before go-live a readiness check sets the scope, and up to three workshops within 30 days settle named contacts, eligible devices and which model alerts reach the SOC.
Darktrace analysts working a follow-the-sun pattern pick up Enhanced Monitoring model alerts at any hour, investigate them, and raise the contacts you agreed in readiness.
On eligible devices the analysts can lengthen the Autonomous Response actions already running; anything wider goes to you as a recommendation that needs written approval.
Your Darktrace deployment raises the alerts — a follow-the-sun SOC investigates, extends containment and hands remediation back.
Darktrace Managed Detection & Response staffs the platform you already own — around the clock, on Darktrace telemetry only.
Darktrace staffs the service on a follow-the-sun pattern, so model alerts raised overnight in India meet an analyst on shift.
The SOC investigates alerts from Darktrace’s Enhanced Monitoring models, the set agreed for it during the readiness work.
Coverage follows what you license from Darktrace: network, cloud, SaaS and OT, judged against one behavioural model per estate.
On eligible devices an analyst can extend an Autonomous Response action, keeping a suspect device restricted while you decide.
Any action beyond extending Darktrace’s own response arrives as a recommendation; nothing wider runs without written approval.
Confirmed threats are raised with the people you name in readiness, so the call reaches someone who can act on the network.
Each month the service sends a SOC report summarising what the analysts investigated and what they escalated to your team.
The bundle carries up to three service readiness workshops inside 30 days, where scope, contacts and eligible devices are agreed.
Proactive Health Optimization, offered at Essentials, Standard and Premium levels, is defined as its own service beside MDR.
Darktrace’s service analysts containing and investigating a business email compromise, and the AI investigation layer that hands them incidents.
How Darktrace’s service analysts contained and then investigated a business email compromise, told from the SOC’s side.
The AI investigation layer that hands the SOC its incidents, shown under its older Cyber AI Analyst name.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets it apart — and exactly where it stops.
This is Darktrace’s own SOC working Darktrace’s own models, not a third party learning your tooling. Analysts start from Enhanced Monitoring model alerts on a platform they work on daily, so nobody has to learn your stack first.
Autonomous Response comes with the network licence, so the SOC needs no new agent to act. On eligible devices analysts can extend an action the platform started, holding a suspect device in check overnight, and everything wider comes to you as a recommendation you approve in writing.
A Service Readiness Check and up to three workshops in the first 30 days fix which devices are eligible, which models the SOC watches and whom it calls. Lighter options exist: Managed Threat Detection and Security Operations Support.
It watches Darktrace only; CrowdStrike, Defender or SentinelOne alerts are outside it. Remediation and follow-up analysis stay with you. Cloud-hosted masters need a probe or firewall integration before resets work, and detection is only as good as your traffic mirroring. No price, India SOC or India region is published.
List which network segments, cloud accounts, SaaS apps and OT sites feed Darktrace, and where mirroring is incomplete.
Weigh full MDR against Managed Threat Detection or Security Operations Support, and decide who owns remediation.
Work through the Service Readiness Check and workshops: eligible devices, named contacts and the models the SOC watches.
Trigger a benign test, watch the SOC extend a response and call your contact, and time each step against your plan.
Review the first SOC report with your team, close the gaps it names, and write your own remediation runbook.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“A server started beaconing at 2 a.m. The analyst kept the Darktrace block in place and our on-call lead woke to a clear note.”
“We bought Darktrace for the network and had nobody reading it at night. This closed that gap without hiring.”
“The readiness workshops forced us to decide who gets called. That alone fixed an escalation list nobody had owned.”
“They contain and explain, then hand it back. The clean-up on two laptops was ours, so plan your own runbook.”
“Our Defender alerts are outside its scope, so we still run two queues. Know that before you sign.”
“The monthly SOC report goes straight into our audit committee pack; it reads well for non-technical directors.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the managed detection and response market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Sold to Darktrace platform customers only; quoted per scope.
The grid nobody publishes — how much third-party telemetry the SOC reads vs how much response and remediation the fee covers.
Darktrace telemetry only; extends containment, remediation stays with you.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
Set beside Arctic Wolf Aurora MDR, CrowdStrike Falcon Complete, Sophos MDR, Rapid7 Managed Threat Complete and Trend Service One — on telemetry, response, remediation, price, India and exit.
| Dimension | Darktrace Managed Detection & Response | Arctic Wolf Aurora MDR | CrowdStrike Falcon Complete | Sophos MDR | Rapid7 Managed Threat Complete | Trend Service One |
|---|---|---|---|---|---|---|
| What it is | Darktrace’s own SOC | Agentic SOC, Concierge | Falcon, run for you | Largest pure-play MDR | Three-tier managed SOC | MDR on Vision One |
| What you must run | A Darktrace licence | Sensors plus your EDR | The Falcon agent | Sophos or your agents | Rapid7 Agent required | Vision One sensors |
| Telemetry and coverage | Darktrace-only, 4 areas | 200+ integrations | Falcon modules first | 500+ integrations | SIEM, no ingest cap | Six vectors named |
| Response authority | Extends its own actions | Pre-agreed containment | Remediates end to end | Removes at Complete | Isolate or disable | Contain, clean-up tools |
| Incident response | Customer finishes it | Incident360 retainer | In the fee + warranty | Uncapped at Complete | Unlimited, remote | 40 IR hours, Complete |
| SOC and contact | Follow-the-sun | Named Concierge team | 24/7, sites unnamed | Global team, no cities | 15-minute contract | Service manager |
| Pricing model | Bundle on the licence | Per user, 1–3 years | Scope-based quote | Per user or device | Per asset, per month | Credits plus a tier |
| Published entry price | Quote only | $44,000/yr, 100 users | ~$25–45/endpoint/mo | $239.64/endpoint/yr | ~$15–22/asset/mo | Not published |
| Included vs add-on | Workshops included | Extras in bundles | Warranty bundled | Integrations included | Scans and IR in price | Advisory sold apart |
| Reporting and retention | Monthly SOC report | Days not stated | Retention unpublished | Retention unpublished | 13 months, all tiers | Monthly summaries |
| India storage and SOC | No India region or SOC | Neither in India | Announced, not live | Mumbai region | SOC in Pune, data abroad | India Vision One site |
| Analyst standing | Gartner Representative | IDC Leader, 2026 | IDC + Forrester | IDC Leader, 2026 | Frost Leader, 2025 | MITRE 2024 result |
| Lock-in and exit | Platform stays if you go | Your EDR remains | Falcon is the base | Agents can stay | Uninstall the agent | Vision One underneath |
| Best fit | Unwatched Darktrace | Mixed EDR, no SOC | Falcon-standard estates | Full IR, mixed agents | Contract SLAs + scans | Trend platform buyers |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Darktrace Managed Detection & Response is one of 19 managed detection & response products TechBag carries. The Managed Detection & Response guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (devices Darktrace monitors; security-analyst hour cost). Estimates model in-house time spent reviewing Darktrace alerts out of hours at an assumed 1.5 hours per monitored device a year, with 70% of it handed to a managed SOC. Both figures are assumptions. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
Not published: Darktrace prints no MDR price, and its two AWS Marketplace MDR listings take a private custom offer rather than showing a figure. The service is quoted per scope on top of your Darktrace platform licence; Managed Threat Detection and Security Operations Support are lighter, separately contracted services. TechBag scopes what Darktrace already sees, then quotes in INR with GST.
Best for Darktrace estates with no night shift
Best for a broader rollout
Best for teams that keep response in-house
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which network, cloud, SaaS and OT segments does Darktrace see today? The SOC can only watch what the platform does.
Is every SPAN or mirror feed complete? Darktrace warns analysis suffers badly when the traffic feed has gaps.
Who will watch your EDR and identity alerts? This service covers Darktrace only, not CrowdStrike or Defender.
Which devices will be eligible for analysts to extend Autonomous Response, and which must always wait for you?
If your master is cloud-hosted, is there a probe or firewall integration so containment resets can be sent?
Who in your team finishes each incident? The service definition leaves follow-up and clean-up with you.
Is metadata outside India acceptable, or do you need an on-premises Master appliance to keep it in-country?
Does the quote itemise MDR, the platform licence and any health service? Request rupee pricing with GST and the contract term.
Map what Darktrace already sees across network, cloud, SaaS and OT first, or let a TechBag advisor compare full MDR with the lighter Darktrace services.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.