Behaviour-based detection across reconnaissance, lateral movement, DNS/DHCP abuse, policy and threat intelligence, and asset visibility — plus native egress verification, a honeypot, and log monitoring. Every feature is included in every plan.
Network agent
Passive analysis of port-mirrored traffic.
▸ Reconnaissance & discovery
Port scanning — single- and multi-target patterns
ARP scanning — host discovery
DNS scanning — dictionary discovery and PTR mapping
Unused-IP scanning — probing of empty address space
LDAP/AD mapping — enumeration and domain anomalies
▸ Lateral movement & segmentation
Lateral movement on admin protocols (SSH, WinRM, RDP) to unauthorized destinations
Inter-segment policy matrix — user-defined, alerts on unauthorized initiation
// DNS analytics — top queried domains & sources// TCP analytics — destination ports by connections · packets · bytes
// traffic over time — expand any period for its top ports, talkers & ASNs
Asset & service visibility
Know what's on the network — and what's new.
Device inventory
Every device from DHCP and traffic analysis: IP, MAC, vendor, hostname, first/last seen. Exportable.
New device alerting
Configurable per segment — alerts when a previously unseen device appears.
Service discovery
Passive discovery of TCP/UDP services, each tracked with first-seen and last-used timestamps.
Unauthorized services
Alerts when an unauthorized TCP/UDP service appears on the internal network.
Virtual sandbox
Per-device outbound policy by DNS, ASN, and IP — traffic outside the pattern generates an alert.
// device inventory — vendor, IP count & per-device IP history (DHCP churn)// discovered services — each host's open ports; unexpected ones flagged for review// device activity — active identities & TCP/DNS/DHCP events per day
Egress · honeypot · logs
The parts other NDR platforms don't ship.
▸ Egress agent
DNS channels — A / AAAA / TXT queries
IPv4 and IPv6 pathways and fallback routes
ICMP-based egress leak detection
Proxy abuse and discovered-gateway testing
Pinpoints the leaking segment and the method used
Local read-only status web UI and JSON API on the agent