Darktrace DETECT
You can integrate Darktrace DETECT with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Darktrace DETECT product overview
Darktrace DETECT utilizes artificial intelligence to autonomously detect, investigate, and respond to cyber threats in real-time.
What we ingest
Sophos XDR collects Darktrace DETECT data via syslog by listening for messages your Darktrace deployment forwards to a Sophos XDR data collector. Records are parsed from both CEF and JSON formats. The following data is collected:
- Model breach alerts: Detections raised when monitored activity breaches a Darktrace behavioral model, including the model, breach score, and breach details.
- AI Analyst incidents: Darktrace AI Analyst investigations that correlate related model breaches into summarized incidents, with an AI Analyst score.
- Autonomous Response actions: Actions Darktrace Autonomous Response takes to contain detected threats, including the action family and applied inhibitor.
Event and data types
All Darktrace events are normalized uniformly to third-party security alert telemetry. They include:
- Model breach alerts: Device, connection, and SaaS detections such as anomalous connections, compromise patterns, and unusual administrative or Microsoft 365 activity.
- AI Analyst incidents: Autonomously correlated and summarized investigations spanning multiple related model breaches.
- Autonomous Response actions: Containment actions taken against detected threats.
Data provided by this integration
Data provided by Darktrace DETECT gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.