tools
Darktrace DETECT
Darktrace DETECT monitors IT and OT environments for anomalous activity, identifies threats, and alerts security teams.

Darktrace DETECT is a behavioral threat-detection capability for enterprise and industrial environments. Its OT materials describe passive protocol analysis, asset identification, anomaly detection, and real-time alerting across industrial systems.
Security operations and industrial security teams use it to monitor network behavior, investigate suspicious activity, and identify known, unknown, and zero-day threats. The current Darktrace site presents related capabilities under Darktrace / NETWORK and Darktrace / OT; pricing is not publicly listed.
Features
- Passive analysis of industrial network protocols
- Asset identification and live inventory
- Anomaly detection across Modbus, DNP3, and 100+ ICS protocols
- Real-time threat alerting
- Self-Learning AI for normal behavior modeling
- Detection of known, unknown, and zero-day threats
- Cyber AI Analyst investigation and incident summaries
- Autonomous threat containment with permitted response actions
Use cases
- Monitor industrial networks for unusual protocol activity
- Identify previously unknown threats in IT and OT environments
- Inventory connected OT and IT assets
- Investigate suspicious activity across converged environments
- Prioritize incidents for security and production teams
- Contain threats while maintaining operational uptime