SEC536: Adversarial AI - Penetration Testing AI Systems

Your biggest email threats aren’t strangers, they’re trusted partners whose accounts have been compromised. Discover how self‑learning AI uncovers subtle behavioral shifts that signal BEC and supply chain attacks before damage is done.

Traditional tools match incoming messages against signatures and known-bad indicators from historical attacks. Darktrace / EMAIL instead builds behavioral baselines for every internal user and external correspondent, flagging deviations from established "patterns of life" — which allows it to catch novel phishing and compromised trusted accounts with no prior signature.
Trusted sender compromise occurs when a vendor, partner, or other established contact's account is taken over, so the resulting phishing emails come from a legitimate sender with real communication history. Signature-based tools struggle here because the sender metadata, headers, and content all check out; Darktrace / EMAIL instead flags "out of character" deviations from that sender's known behavioral baseline.
No. Its core license covers inbound, outbound, and lateral (internal-to-internal) email analysis, and it also extends behavioral monitoring to Microsoft Teams messages — during the review, outbound "Response to Solicitation" detections increased 500% over 28 days, illustrating the value of outbound coverage.
Analysts can request an AI-proposed exception, which is tailored to the specific sender and detection type. Unlike a static rule library, these exceptions expire automatically as the platform's baseline learns the legitimate pattern, so the tuning is self-correcting rather than requiring ongoing manual maintenance.
Over one month, the platform analyzed 253,882 inbound emails and flagged 5,523 threats affecting 13% of the userbase, with phishing links (2,705), credential harvesting (1,638), and forged addresses (849) as the top categories.