Detections that explain themselves.
90+ deterministic detection rules across IT, OT and network-integrity threats. Each is mapped to MITRE ATT&CK or ATT&CK for ICS, or declared as a policy or anomaly check, and states the evidence it rests on.
Catch the command, not just the connection.
Unauthorised writes, parameter changes, controller mode changes and stops, program download and upload, forced I/O, firmware transfers, new or rogue masters and illegal function codes.
Command monitoring covers the protocols listed. Other industrial protocols receive identity and discovery.
What WireTrace detects.
Behavioural deviations
First-seen and rare destinations, new services, new internet communication, peer-group differences, scanning, lateral movement, beaconing, algorithmically generated domains, DNS tunnelling and unusual outbound volume, each explained against its baseline.
Adversary-in-the-middle
TLS interception, TCP reset injection, layer-2 and name-resolution poisoning and DNS manipulation.
Threat indicators
Traffic matched against public threat-intelligence feeds and indicators you supply (CSV, STIX 2.1, or a commercial feed using your own key): IPs, ranges, domains, URLs, file hashes and TLS fingerprints.
Exposed credentials
Account names and credentials exposed by clear-text and legacy authentication, so weak practices can be fixed.
Web attacks
SQL injection and cross-site scripting attempts in unencrypted HTTP.
Mapped to ATT&CK and ATT&CK for ICS.
The coverage view separates techniques WireTrace can detect from those observed in your environment, and exports an ATT&CK Navigator layer for your threat model.
- One Alert Queue: assign, investigate, escalate, resolve or mark false positive
- Forward to your SIEM over syslog (CEF, LEEF, RFC 5424/3164) or Splunk HTTP Event Collector
See it on your network.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.