The questions that decide an evaluation.
Straight answers, including the ones about what WireTrace does not do.
Does WireTrace scan or probe the network?
WireTrace is passive by default: the capture interface only receives and never transmits onto the monitored network. Optional, administrator-governed active enrichment can add deeper inventory for IT and network devices. It is off until enabled, needs defined scopes and read-only credentials, runs from the management interface, and an OT-safe profile keeps probes away from industrial and medical devices unless explicitly allowed.
Do I need to install agents?
No. WireTrace works from mirrored traffic (SPAN, TAP or ERSPAN). Nothing is installed on the devices it observes.
Does WireTrace enforce segmentation or block traffic?
No. WireTrace provides the intelligence, policy intent and continuous validation layer, while your firewalls, NAC and network platforms execute enforcement. WireTrace exports proposed rules as text, publishes blocklists, and makes identity and risk available through its API.
How does WireTrace identify a device?
From the evidence the device puts on the wire: identity records carried in industrial, building and network protocols, DHCP, SNMP, SSH host keys, certificates, and names from DHCP, DNS, NetBIOS, mDNS, LLDP/CDP and directory protocols. Each value shows where it came from and how fresh it is. An IP address locates a device but never identifies it.
Can it identify model and firmware for every device?
Not from passive observation alone. WireTrace records model, firmware and serial number where a device states them, as many industrial controllers, IoT and network devices do. Credentialed collection and read-only switch polling add these details for IT and network equipment.
How many protocols does WireTrace support?
250+ protocols are decoded, across industrial, building, IoT, medical and IT traffic. Depth matters more than the count: WireTrace decodes payloads and operations, not just protocol names.
Can WireTrace decrypt traffic?
No. WireTrace records TLS client fingerprints and certificate details for identity, hygiene and threat matching, but it does not decrypt traffic.
Is WireTrace a SIEM?
No. WireTrace feeds your SIEM with device-aware detections over syslog (CEF, LEEF, RFC 5424/3164), Splunk HTTP Event Collector and webhooks.
Does any data leave our network?
All storage and processing stay on customer infrastructure. External feeds are optional.
Can it run air-gapped?
Yes. Installation, analysis, the AI assistant, end-of-life data and identity and classification knowledge all run on the appliance. Vulnerability and threat data are refreshed offline with a customer-run collector and a checksummed bundle.
Is compliance evidence fully automated?
No, and we do not claim it is. WireTrace maps network observations to 415 controls across seven frameworks and rates every control as observable, partial, manual assessment or not assessable from the network. About a third of controls have automated network evidence; auditors close the rest in the platform's assessment workflow.
Which compliance frameworks are mapped?
NIST CSF 2.0, ISO/IEC 27001, HIPAA Security Rule, IEC 62443-3-3, NERC CIP, NCA OTCC and NCA ECC.
Where does Rumi, the AI assistant, run?
Entirely on the WireTrace server, with no external AI service. Facts, counts and rankings come from deterministic queries with click-through evidence, and the language model only words the answer.
How is WireTrace sized and licensed?
Sensors are sized to link speed and the platform to asset count and retention; the public Deployment and Sizing Guide gives the figures. WireTrace is licensed by asset count, with optional modules. Contact us for a proposal.
See it on your network.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.