Darktrace detects threats in encrypted traffic without needing decryption by analyzing rich metadata and behavioral patterns rather than payload content. This includes analysis of metadata such as packet headers and session parameters including origin, destination, data volumes, TLS handshake details, and JA3/JA3S fingerprints to learn what is “normal” and surface anomalies.
Darktrace Self‑Learning AI also models the typical behavior of devices and users. Even in fully encrypted sessions, unusual destinations, uncommon user agents, rare JA3 hashes, or abnormal data transfer patterns become detectable signals that can be used to detect known, novel and insider threats.
Encrypted traffic analysis using Darktrace's methods is very effective, and Darktrace has published many advanced or new threat findings involving some or nearly all encrypted traffic, notably using traffic feature rarity analysis (e.g. connecting to a rare internet destination with a rare user agent or JAx).