Talk to us
by DarktraceTechBag Intel Page

Darktrace Managed Detection & Response

Darktrace contains a threat at 3 a.m. and nobody reviews it until morning. Someone who knows the platform should be watching it — Darktrace Managed Detection & Response puts Darktrace’s own follow-the-sun SOC on the Darktrace deployment you already run, extending Autonomous Response overnight while remediation stays with your team.

Darktrace’s SOC on your Darktrace estateNo India SOC or India hosting regionQuote-only, on top of the platform licence

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Pricing
No public rate; the two AWS Marketplace MDR listings take a private custom offer
Quote
Analysts
Vendor in Gartner’s Market Guide for MDR (year not stated); Gartner has no MDR Magic Quadrant
Representative
Scale
Customers on the Darktrace platform, by Darktrace’s own 2026 company boilerplate
~10,000
India
Neither an India SOC nor an India hosting region appears in Darktrace’s documents
No India SOC

Quick answer

Darktrace Managed Detection & Response puts Darktrace’s own follow-the-sun SOC on the Darktrace deployment you already run, across network, cloud, SaaS and OT. Analysts investigate Enhanced Monitoring model alerts, call your named contacts and can extend Autonomous Response on eligible devices; remediation stays with you. It is quoted on top of the platform licence, and no India SOC or India hosting region is documented. Read more ↓ Show less ↑
Part 01 · Orient

The Darktrace platform family

This page covers Darktrace Managed Detection & Response — the service bundle, plus the lighter Managed Threat Detection and Security Operations Support services. The rest:

Quick facts

30-second orientation
Product
The Managed Detection and Response Service Bundle: a 24/7 SOC over your Darktrace estate
Maker
Cambridge-based Darktrace, Thoma Bravo-owned since October 2024; Ed Jennings has been CEO from March 2026
Platform
Darktrace Behavioral Defense Platform (renamed August 2026), with the Real-Time AI Analyst
Price
Quote-only; both AWS Marketplace MDR listings show a custom-offer placeholder, not a price
Scope
Network, cloud, SaaS and OT as Darktrace sees them; no third-party EDR telemetry
Response
Analysts may extend Autonomous Response on eligible devices; other actions need your written approval
Remediation
Follow-up analysis and clean-up stay with the customer, per the service definition
Lighter tiers
Managed Threat Detection and Security Operations Support, contracted as separate services
India
No India SOC is documented; Darktrace-hosted masters reach Singapore at the nearest
In India via
TechBag — scope review, quote in INR with GST, readiness-check preparation
Part 02 · Learn

Understand vendor-run MDR before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is vendor-run MDR?

The maker of your security platform staffs the SOC that watches it, around the clock, and escalates what is real.

Darktrace alerts nobody reads overnight vs Darktrace Managed Detection & Response — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionDarktrace alerts unread overnightDarktrace Managed Detection & Response
Darktrace alerts after hoursQueued until someone logs inPicked up by a follow-the-sun SOC
An overnight containmentExpires before anyone reviews itExtended by an analyst on eligible devices
Who gets calledWhoever picks up the shared phoneNamed contacts set in readiness workshops
Wider response actionsTaken in a hurry, then justifiedRecommended, then run on written approval
Reporting upwardScreenshots pasted into an emailA monthly SOC report on investigations
What it is NOT—Remediation, multi-vendor MDR, or India-hosted

The cheapest first step is a scoping call: list your mirrored segments and cloud accounts, and see what the SOC could actually watch.

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
Where the alerts come from

Platform

Your Darktrace deployment

The service rides on the platform you already license: appliances, vSensors and osSensors feed Darktrace’s models, and the Real-Time AI Analyst is the layer that investigates first.

02
How the scope is fixed

Readiness

Service Readiness Check

Before go-live a readiness check sets the scope, and up to three workshops within 30 days settle named contacts, eligible devices and which model alerts reach the SOC.

03
Who watches, and when

SOC

Follow-the-sun analyst rota

Darktrace analysts working a follow-the-sun pattern pick up Enhanced Monitoring model alerts at any hour, investigate them, and raise the contacts you agreed in readiness.

04
What the SOC may do

Response

Autonomous Response, extended

On eligible devices the analysts can lengthen the Autonomous Response actions already running; anything wider goes to you as a recommendation that needs written approval.

Your Darktrace deployment raises the alerts — a follow-the-sun SOC investigates, extends containment and hands remediation back.

Part 03 · Evaluate

Nine capabilities. Watch, respond, report.

Darktrace Managed Detection & Response staffs the platform you already own — around the clock, on Darktrace telemetry only.

Watch
24/7 rota

Follow-the-sun cover

Darktrace staffs the service on a follow-the-sun pattern, so model alerts raised overnight in India meet an analyst on shift.

Watch
Model alerts

Enhanced Monitoring triage

The SOC investigates alerts from Darktrace’s Enhanced Monitoring models, the set agreed for it during the readiness work.

Watch
Surfaces

Network, cloud, SaaS, OT

Coverage follows what you license from Darktrace: network, cloud, SaaS and OT, judged against one behavioural model per estate.

Respond
Extend

Holds a containment longer

On eligible devices an analyst can extend an Autonomous Response action, keeping a suspect device restricted while you decide.

Respond
Approval

Your sign-off for the rest

Any action beyond extending Darktrace’s own response arrives as a recommendation; nothing wider runs without written approval.

Respond
Escalation

Named contacts, not a queue

Confirmed threats are raised with the people you name in readiness, so the call reaches someone who can act on the network.

Report
Monthly report

A SOC report every month

Each month the service sends a SOC report summarising what the analysts investigated and what they escalated to your team.

Report
Workshops

Readiness before go-live

The bundle carries up to three service readiness workshops inside 30 days, where scope, contacts and eligible devices are agreed.

Report
Health

Tuning sold alongside

Proactive Health Optimization, offered at Essentials, Standard and Premium levels, is defined as its own service beside MDR.

See it, don’t just read it

Watch Darktrace Managed Detection & Response in action

Darktrace’s service analysts containing and investigating a business email compromise, and the AI investigation layer that hands them incidents.

Darktrace (official)·Case walk-through, 2024

Containing and Investigating BEC Attacks with Darktrace Services

How Darktrace’s service analysts contained and then investigated a business email compromise, told from the SOC’s side.

Darktrace (official)·Explainer, 2024

Improve Cybersecurity Incident Investigations with AI

The AI investigation layer that hands the SOC its incidents, shown under its older Cyber AI Analyst name.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Darktrace Managed Detection & Response

Darktrace raises alerts around the clock, and most teams read them nine to five. Its own SOC reads them overnight.

Here’s what genuinely sets it apart — and exactly where it stops.

01

The analysts know the platform they watch

This is Darktrace’s own SOC working Darktrace’s own models, not a third party learning your tooling. Analysts start from Enhanced Monitoring model alerts on a platform they work on daily, so nobody has to learn your stack first.

02

Containment that is already wired in

Autonomous Response comes with the network licence, so the SOC needs no new agent to act. On eligible devices analysts can extend an action the platform started, holding a suspect device in check overnight, and everything wider comes to you as a recommendation you approve in writing.

03

A scope agreed before the first alert

A Service Readiness Check and up to three workshops in the first 30 days fix which devices are eligible, which models the SOC watches and whom it calls. Lighter options exist: Managed Threat Detection and Security Operations Support.

04

Where it stops

It watches Darktrace only; CrowdStrike, Defender or SentinelOne alerts are outside it. Remediation and follow-up analysis stay with you. Cloud-hosted masters need a probe or firewall integration before resets work, and detection is only as good as your traffic mirroring. No price, India SOC or India region is published.

The idea
Darktrace’s SOC on your Darktrace estate
The residency
No India SOC or India hosting region
The price
Quote-only, on top of the platform licence
Proof, not promises

The numbers behind the platform

24/7
SOC coverage, staffed on a follow-the-sun pattern rather than one night shift
— Vendor
up to 3 workshops
service readiness sessions in the bundle, held within the first 30 days
— Vendor
2 listings
MDR entries on AWS Marketplace, both with a custom offer in place of a price
— Marketplace
4 surfaces
network, cloud, SaaS and OT, as the services page lists them for MDR
— Vendor
~10000
customers on the Darktrace platform, by its own 2026 company boilerplate
— Vendor
110 countries
the reach Darktrace’s services page gives for the company
— Vendor

What your Darktrace Managed Detection & Response rollout looks like

Week 1Model

Confirm what Darktrace already sees

List which network segments, cloud accounts, SaaS apps and OT sites feed Darktrace, and where mirroring is incomplete.

Week 2Decide

Choose the service level

Weigh full MDR against Managed Threat Detection or Security Operations Support, and decide who owns remediation.

Week 3Pilot

Run the readiness check

Work through the Service Readiness Check and workshops: eligible devices, named contacts and the models the SOC watches.

Month 2Prove

Test an escalation end to end

Trigger a benign test, watch the SOC extend a response and call your contact, and time each step against your plan.

Month 3Commit

Read the first monthly report

Review the first SOC report with your team, close the gaps it names, and write your own remediation runbook.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.1
38+ reviews*
80% would recommend
Platform expertise4.4
Overnight coverage4.3
Escalation clarity4.0
Remediation help3.5
Value for money3.6
5★
42%
4★
37%
3★
14%
2★
5%
1★
2%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Manufacturing
“A server started beaconing at 2 a.m. The analyst kept the Darktrace block in place and our on-call lead woke to a clear note.”
IT Manager
Manufacturing
BFSI
“We bought Darktrace for the network and had nobody reading it at night. This closed that gap without hiring.”
Head of IT
BFSI
Healthcare
“The readiness workshops forced us to decide who gets called. That alone fixed an escalation list nobody had owned.”
Security Lead
Healthcare
Logistics
“They contain and explain, then hand it back. The clean-up on two laptops was ours, so plan your own runbook.”
Infrastructure Engineer
Logistics
Retail
“Our Defender alerts are outside its scope, so we still run two queues. Know that before you sign.”
SOC Analyst
Retail
Education
“The monthly SOC report goes straight into our audit committee pack; it reads well for non-technical directors.”
CISO
Education
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the managed detection and response market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag MDR Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
Darktrace Managed Detection & ResponseThis page

Sold to Darktrace platform customers only; quoted per scope.

Grid 02 · The architecture

Telemetry Openness × Response Depth

The grid nobody publishes — how much third-party telemetry the SOC reads vs how much response and remediation the fee covers.

Own-platform remediatorsOpen full respondersOwn-platform watchersOpen contain-first
Darktrace Managed Detection & ResponseThis page

Darktrace telemetry only; extends containment, remediation stays with you.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Darktrace Managed Detection & Response vs the MDR field

Set beside Arctic Wolf Aurora MDR, CrowdStrike Falcon Complete, Sophos MDR, Rapid7 Managed Threat Complete and Trend Service One — on telemetry, response, remediation, price, India and exit.

DimensionDarktrace Managed Detection & ResponseArctic Wolf Aurora MDRCrowdStrike Falcon CompleteSophos MDRRapid7 Managed Threat CompleteTrend Service One
What it isDarktrace’s own SOCAgentic SOC, ConciergeFalcon, run for youLargest pure-play MDRThree-tier managed SOCMDR on Vision One
What you must runA Darktrace licenceSensors plus your EDRThe Falcon agentSophos or your agentsRapid7 Agent requiredVision One sensors
Telemetry and coverageDarktrace-only, 4 areas200+ integrationsFalcon modules first500+ integrationsSIEM, no ingest capSix vectors named
Response authorityExtends its own actionsPre-agreed containmentRemediates end to endRemoves at CompleteIsolate or disableContain, clean-up tools
Incident responseCustomer finishes itIncident360 retainerIn the fee + warrantyUncapped at CompleteUnlimited, remote40 IR hours, Complete
SOC and contactFollow-the-sunNamed Concierge team24/7, sites unnamedGlobal team, no cities15-minute contractService manager
Pricing modelBundle on the licencePer user, 1–3 yearsScope-based quotePer user or devicePer asset, per monthCredits plus a tier
Published entry priceQuote only$44,000/yr, 100 users~$25–45/endpoint/mo$239.64/endpoint/yr~$15–22/asset/moNot published
Included vs add-onWorkshops includedExtras in bundlesWarranty bundledIntegrations includedScans and IR in priceAdvisory sold apart
Reporting and retentionMonthly SOC reportDays not statedRetention unpublishedRetention unpublished13 months, all tiersMonthly summaries
India storage and SOCNo India region or SOCNeither in IndiaAnnounced, not liveMumbai regionSOC in Pune, data abroadIndia Vision One site
Analyst standingGartner RepresentativeIDC Leader, 2026IDC + ForresterIDC Leader, 2026Frost Leader, 2025MITRE 2024 result
Lock-in and exitPlatform stays if you goYour EDR remainsFalcon is the baseAgents can stayUninstall the agentVision One underneath
Best fitUnwatched DarktraceMixed EDR, no SOCFalcon-standard estatesFull IR, mixed agentsContract SLAs + scansTrend platform buyers
● Strong◐ Partial / add-on○ Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Which approach fits you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Darktrace Managed Detection & Response if…

  • ✓Darktrace already runs on your network and nobody reads its alerts between midnight and morning
  • ✓You want analysts who can keep a Darktrace containment in force overnight, with wider actions only on your written approval
  • ✓Your scope spans network, cloud, SaaS and OT, and you would rather extend one platform than add a second vendor’s agent

Compare alternatives if…

  • ✓Your alerts come from CrowdStrike, Defender or SentinelOne — Arctic Wolf and Sophos read those, and Darktrace MDR does not
  • ✓You want remediation done for you — Falcon Complete, Sophos MDR Complete and Rapid7 put it inside the fee
  • ✓Data must sit in an Indian region — Trend Vision One lists one, and Sophos Central runs a Mumbai data centre

Do not expect…

  • ✓The SOC to clean up after an incident; follow-up analysis and remediation remain your job
  • ✓A published price — the marketplace listings take a private custom offer
  • ✓A Magic Quadrant placement — Gartner covers MDR only in a Market Guide

Darktrace Managed Detection & Response is one of 19 managed detection & response products TechBag carries. The Managed Detection & Response guide narrows them to a shortlist and shows the reasoning. →

Do the math

What does watching Darktrace overnight cost you?

Drag the sliders (devices Darktrace monitors; security-analyst hour cost). Estimates model in-house time spent reviewing Darktrace alerts out of hours at an assumed 1.5 hours per monitored device a year, with 70% of it handed to a managed SOC. Both figures are assumptions. Illustrative.

300
2510,000
₹800
₹300₹2,000

Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.

Current annual out-of-hours triage cost
₹3,60,000
Estimated annual savings
₹2,52,000
≈ ₹12,60,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Not published: Darktrace prints no MDR price, and its two AWS Marketplace MDR listings take a private custom offer rather than showing a figure. The service is quoted per scope on top of your Darktrace platform licence; Managed Threat Detection and Security Operations Support are lighter, separately contracted services. TechBag scopes what Darktrace already sees, then quotes in INR with GST.

Managed Detection & Response

Best for Darktrace estates with no night shift

  • Quote-only, per scope
  • Follow-the-sun SOC; extends Autonomous Response
  • Up to 3 readiness workshops in 30 days

+ Platform add-ons

Best for a broader rollout

  • Scoped to your estate
  • Add-on modules as needed
  • Phased, right-sized deployment

Lighter Darktrace services

Best for teams that keep response in-house

  • Managed Threat Detection: 24/7 triage and notification
  • Security Operations Support: analysts on demand
  • Each quoted separately; no public price

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every vendor

Take this into your next vendor call — including ours.

1
Platform coverage

Which network, cloud, SaaS and OT segments does Darktrace see today? The SOC can only watch what the platform does.

2
Traffic mirroring

Is every SPAN or mirror feed complete? Darktrace warns analysis suffers badly when the traffic feed has gaps.

3
Other telemetry

Who will watch your EDR and identity alerts? This service covers Darktrace only, not CrowdStrike or Defender.

4
Eligible devices

Which devices will be eligible for analysts to extend Autonomous Response, and which must always wait for you?

5
Firewall link

If your master is cloud-hosted, is there a probe or firewall integration so containment resets can be sent?

6
Remediation owner

Who in your team finishes each incident? The service definition leaves follow-up and clean-up with you.

7
Residency

Is metadata outside India acceptable, or do you need an on-premises Master appliance to keep it in-country?

8
Contract

Does the quote itemise MDR, the platform licence and any health service? Request rupee pricing with GST and the contract term.

FAQ

Questions buyers ask

Contracted as the Managed Detection and Response Service Bundle, it puts Darktrace’s own analysts on your Darktrace deployment. A follow-the-sun SOC investigates Enhanced Monitoring model alerts across network, cloud, SaaS and OT, alerts your named contacts and can extend Autonomous Response on eligible devices.

Ready to evaluate Darktrace Managed Detection & Response?

Map what Darktrace already sees across network, cloud, SaaS and OT first, or let a TechBag advisor compare full MDR with the lighter Darktrace services.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.