Platform · Threat Detection

Detections that explain themselves.

90+ deterministic detection rules across IT, OT and network-integrity threats. Each is mapped to MITRE ATT&CK or ATT&CK for ICS, or declared as a policy or anomaly check, and states the evidence it rests on.

OT command monitoring

Catch the command, not just the connection.

Unauthorised writes, parameter changes, controller mode changes and stops, program download and upload, forced I/O, firmware transfers, new or rogue masters and illegal function codes.

ModbusS7commDNP3IEC 60870-5-101/104IEC 61850 MMSOmron FINSMitsubishi SLMP/MELSECSEL Fast Message

Command monitoring covers the protocols listed. Other industrial protocols receive identity and discovery.

Coverage

What WireTrace detects.

Behavioural deviations

First-seen and rare destinations, new services, new internet communication, peer-group differences, scanning, lateral movement, beaconing, algorithmically generated domains, DNS tunnelling and unusual outbound volume, each explained against its baseline.

Adversary-in-the-middle

TLS interception, TCP reset injection, layer-2 and name-resolution poisoning and DNS manipulation.

Threat indicators

Traffic matched against public threat-intelligence feeds and indicators you supply (CSV, STIX 2.1, or a commercial feed using your own key): IPs, ranges, domains, URLs, file hashes and TLS fingerprints.

Exposed credentials

Account names and credentials exposed by clear-text and legacy authentication, so weak practices can be fixed.

Web attacks

SQL injection and cross-site scripting attempts in unencrypted HTTP.

MITRE ATT&CK

Mapped to ATT&CK and ATT&CK for ICS.

The coverage view separates techniques WireTrace can detect from those observed in your environment, and exports an ATT&CK Navigator layer for your threat model.

  • One Alert Queue: assign, investigate, escalate, resolve or mark false positive
  • Forward to your SIEM over syslog (CEF, LEEF, RFC 5424/3164) or Splunk HTTP Event Collector

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.