Integrations · Threat Intelligence
Your indicators, matched against what really happened.
Observed traffic is matched against public threat-intelligence feeds and indicators you supply (CSV, STIX 2.1, or a commercial feed using your own key): IPs, ranges, domains, URLs, file hashes and TLS fingerprints.
Sources
Threat and vulnerability intelligence.
Indicators
STIX 2.1 import and export, CSV and custom feed URLs.
Vulnerabilities
NVD and CVE records, CISA KEV, FIRST EPSS, CISA ICS advisories, OT vendor advisories and end-of-life data.
See it on your network.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.