Detection coverage

What Intrudect catches.

Behaviour-based detection across reconnaissance, lateral movement, DNS/DHCP abuse, policy and threat intelligence, and asset visibility — plus native egress verification, a honeypot, and log monitoring. Every feature is included in every plan.

Network agent

Passive analysis of port-mirrored traffic.

Reconnaissance & discovery

  • Port scanning — single- and multi-target patterns
  • ARP scanning — host discovery
  • DNS scanning — dictionary discovery and PTR mapping
  • Unused-IP scanning — probing of empty address space
  • LDAP/AD mapping — enumeration and domain anomalies

Lateral movement & segmentation

  • Lateral movement on admin protocols (SSH, WinRM, RDP) to unauthorized destinations
  • Inter-segment policy matrix — user-defined, alerts on unauthorized initiation
  • Password spraying — sequential low-packet admin-protocol connections

Policy & threat intelligence

  • IOC matching — malicious IPs, DNS names, device names from aggregated feeds: MISP, public blocklists, your own IP/DNS lists
  • Suricata rule matching on analyzed traffic (HTTP, TLS, DNS)
  • IOC Proxy — aggregates MISP, Suricata rules, IP/DNS blocklists and Tor into unified feeds served locally, agents need no internet access
  • HTTP user-agent — suspicious or known offensive tooling
  • TOR traffic to/from the network
  • SMB directed to external destinations

DNS & DHCP security

  • DNS tunnelling / C2 communication patterns
  • DGA (domain generation algorithm) queries
  • Rogue DNS and rogue DHCP servers
  • DHCP anomalies — volume, MAC/hostname mismatches, offensive-tool hostnames
Intrudect DNS analytics: top queried domains ranked by volume, with per-source-IP breakdown.
// DNS analytics — top queried domains & sources
Intrudect TCP analytics: destination ports broken down by connections, packets, and bytes.
// TCP analytics — destination ports by connections · packets · bytes
Intrudect traffic-over-time: daily connections and RX/TX bytes, with one period expanded to its top destination ports by bytes and by connections.
// traffic over time — expand any period for its top ports, talkers & ASNs
Asset & service visibility

Know what's on the network — and what's new.

Device inventory
Every device from DHCP and traffic analysis: IP, MAC, vendor, hostname, first/last seen. Exportable.
New device alerting
Configurable per segment — alerts when a previously unseen device appears.
Service discovery
Passive discovery of TCP/UDP services, each tracked with first-seen and last-used timestamps.
Unauthorized services
Alerts when an unauthorized TCP/UDP service appears on the internal network.
Virtual sandbox
Per-device outbound policy by DNS, ASN, and IP — traffic outside the pattern generates an alert.
Intrudect device inventory: hostname, MAC, resolved vendor (Dell/HP/Cisco/Intel), IP count, and per-device IP history showing a device that roamed across several DHCP addresses over time.
// device inventory — vendor, IP count & per-device IP history (DHCP churn)
Intrudect discovered services: hosts grouped with their open TCP ports and per-port authorized or flagged status; an HR workstation is running an unexpected Apache+MySQL stack, all flagged.
// discovered services — each host's open ports; unexpected ones flagged for review
Intrudect device activity: daily active MACs, observed source IPs, and TCP/DNS/DHCP event counts over time, with a clear weekday/weekend rhythm.
// device activity — active identities & TCP/DNS/DHCP events per day
Egress · honeypot · logs

The parts other NDR platforms don't ship.

Egress agent

  • DNS channels — A / AAAA / TXT queries
  • IPv4 and IPv6 pathways and fallback routes
  • ICMP-based egress leak detection
  • Proxy abuse and discovered-gateway testing
  • Pinpoints the leaking segment and the method used
  • Local read-only status web UI and JSON API on the agent

Honeypot

  • Configurable TCP and UDP listeners
  • Protocol emulation — SSH, Telnet, FTP, mail (SMTP/POP3/IMAP), HTTP, Redis, PostgreSQL/MySQL/MSSQL, LDAP, VNC, SMB
  • Detects both SYN (half-open) and full connect scans
  • Multiple IP addresses per instance
  • Alert on connection, full PCAP on disconnect
  • Low-noise: contact means something is wrong

Log agent

  • Unlimited concurrent log files per agent
  • Custom alert message and severity per rule
  • Syslog, application, web server, database, audit logs
  • 404/403 patterns, SQL injection, honeyfile access

Alerting & integration

  • Agent-level aggregation prevents alert floods
  • Routing by weekday, work hours, category, priority
  • Web UI, e-mail, webhooks (Slack, Teams, Mattermost, Discord)
  • JSON export to Elastic, Wazuh, Security Onion
  • Public REST API (/api/v1) — alert and metadata search, exports, automation