Manual network containment is slow, allowing threats to spread. This autonomous workflow triggers when a Network Detection and Response (NDR) tool like Darktrace or Vectra AI signals lateral movement within a subnet. The orchestrator immediately evaluates the blast radius and initiates a quarantine sequence, updating ACLs in Cisco ACI or SDN policies in VMware NSX. This reduces mean time to contain (MTTC) from hours to seconds, directly limiting data exfiltration and ransomware propagation risk across hybrid environments.




