Darktrace SOAR

Company: Victor Valley Transit Authority
Project URL: https://nathandowd.tech/projects/darktrace-implementation/

Implementing Darktrace in our environment was pretty straight forward. Rack and stacked the dark trace device Connected it to our network Setup the device with a static IP Reserved the IP in our router Set up admin accounts Installed Vsensors on Hyper-V VM Hosts (Linux) Quarantined hosts, and VM in test environment Connected to Taxii server to input threat intel Added Untrusted domains and IP ranges Enabled Antigena Network, and Email Created a test group for autonomous mode