Recognition is not understanding.
Deep packet inspection tells you a protocol was present. WireTrace decodes protocol payloads, not just headers, so it knows what a conversation did: a read, a write, a program transfer, a mode change.
What recognition gives you, and what understanding adds.
| Question | Recognition (traditional DPI) | Understanding (WireTrace) |
|---|---|---|
| What protocol is this? | A name, usually from the port | A name, plus the decoded fields and operations |
| What did it do? | Not known | Reads, writes, program transfers, mode changes and exceptions |
| What device sent it? | An address | The device's own identity record, where the protocol carries one |
| Is it normal? | Volume and port thresholds | Field-level baseline: a previously unseen function code or value raises a deviation |
| Can I prove it? | Flow records | Decoded evidence, attributed to the observation that produced it |
Fields that carry meaning.
WireTrace extracts identity and operational fields such as vendor, order number, firmware, station and host names and certificate details, and records which observed evidence produced each attribute. Many industrial, building and network protocols carry the device's own identity record; WireTrace decodes these and uses them as primary evidence.
250+ protocols decoded, across four domains.
Industrial
Modbus, S7comm/S7CommPlus, EtherNet/IP & CIP, PROFINET, DNP3, IEC 60870-5-101/103/104, IEC 61850 MMS/GOOSE/SV, OPC UA, EtherCAT, Omron FINS, Mitsubishi SLMP/MELSEC, CODESYS, HART-IP, SEL Fast Message, IEEE C37.118, PRP/HSR, PTP.
Building and IoT
BACnet, KNXnet/IP, Niagara Fox, MQTT, CoAP, LwM2M, ONVIF, SNMP.
IT and network
DNS, DHCP, TLS, SSH, HTTP, SMB, Kerberos, LDAP, RDP, NetBIOS, mDNS, LLDP, CDP, RADIUS, syslog, NTP.
Medical protocols (DICOM, HL7 and medical-device vendor protocols) are covered on the Healthcare & IoMT page. Coverage of encrypted payloads is limited to metadata: WireTrace does not decrypt traffic.
Honest about encryption.
TLS client fingerprints and certificate details are recorded for identity, hygiene and threat matching. WireTrace does not decrypt traffic, and where a session is encrypted end to end, such as SMB3 with encryption, file operations are not visible. We would rather state the limit than imply coverage we do not have.
Bring a capture. See what it actually says.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.