Integrations · Threat Intelligence

Your indicators, matched against what really happened.

Observed traffic is matched against public threat-intelligence feeds and indicators you supply (CSV, STIX 2.1, or a commercial feed using your own key): IPs, ranges, domains, URLs, file hashes and TLS fingerprints.

Sources

Threat and vulnerability intelligence.

Indicators

STIX 2.1 import and export, CSV and custom feed URLs.

Vulnerabilities

NVD and CVE records, CISA KEV, FIRST EPSS, CISA ICS advisories, OT vendor advisories and end-of-life data.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.