Platform Tour · DPAI

The network already knows.
Nobody’s listening.

The devices, sessions and commands are already on the wire. WireTrace listens, passively by default, and turns that traffic into identity, exposure, detections, segmentation intent and evidence across IT, OT, IoT and IoMT.

The Platform

One platform. Four domains.

WireTrace turns the traffic already on your network into identity, exposure, detections and segmentation intent across IT, OT, IoT and IoMT: continuously, on your infrastructure, with no agents.

250+
Protocols decoded
600+
Classification rules
90+
Detection rules
0
Agents required
The Difference

Beyond DPI: Deep Protocol & Asset Intelligence.

Deep packet inspection tells you a protocol was present. DPAI decodes what the conversation did, remembers the device behind it, and judges whether it is normal: a shift from inspecting packets to understanding the network.

Packetaddresses · ports · volumesProtocolrecognised by namePayloadfields and operations decodedAssetdurable identity · type · roleIntelligencerisk · detection · policy intentTRADITIONAL DPI STOPS HERE ↑ PROTOCOLDPAI
How it works

Point a mirror port at it. It does the rest.

A sensor receives mirrored traffic from SPAN, TAP or ERSPAN. The capture interface only receives; it never transmits onto the monitored network. The platform identifies, classifies and analyses what it sees.

Capture
SPAN / TAP
Identify
Durable identity
Classify
Type · role · Purdue
Detect
Threats · deviations
Decide
Risk · intent
Asset Intelligence

Know the device behind the address.

One durable identity per physical device, even when its IP address changes. Vendor, model, firmware and role derived where supported by available evidence, each value with its source and confidence.

PLCHMISCADAMedical deviceImaging modalityServerWorkstationIP cameraPrinterBuilding automationIoT sensorUnmanaged host
ADDRESS OVER TIMEMon10.20.4.17DHCP leaseWed10.20.4.88re-addressedFri10.20.9.12moved VLANONE DURABLE IDENTITYPackaging-line controlleranchored on device-stated hardware identityaddress changes tracked as transitionshistory, risk and alerts stay attachedstale bindings expire safelyILLUSTRATIVE ADDRESSES
Deep Protocol Intelligence

Recognition is not understanding.

250+ protocols decoded down to the operation: reads, writes, program transfers and mode changes, not just protocol names. Many protocols carry the device's own identity record, used as primary evidence.

ModbusDNP3S7commEtherNet/IPOPC UABACnetIEC 61850DICOMHL7TLSSMBDNSKerberosMQTT
RECOGNITION"Modbus on port 502"— two devices talked— a protocol name— a byte count— no meaningUNDERSTANDING"Write to a setpoint"operationwrite single registerfromengineering workstationtoline-2 controllerbaselinenever seen beforemapped toATT&CK for ICS
When you need more

Passive by default. Governed when active.

Optional, administrator-governed active enrichment adds deeper inventory for IT and network devices. It needs defined scopes and read-only credentials, runs from the management interface, and an OT-safe profile keeps probes away from industrial and medical devices unless explicitly allowed.

Monitored networkIT · OT · IoT · IoMTSPAN · TAP · ERSPANmirrored copySensorcapture port: receive onlyWireTrace platformon your infrastructureYour toolsSIEM · API · email · ticketsOptional enrichmentmanagement interface · scopedPASSIVE BY DEFAULTOFF UNTIL AN ADMINISTRATOR ENABLES IT · OT-SAFE PROFILE
Exposure & Risk

Fix what is exploitable, first.

Clear-text credentials, weak cryptography, exposed services and OT exposure in one view. Vulnerabilities matched to the NVD and OT vendor advisories, prioritised with CISA KEV and FIRST EPSS, and a 0-100 Asset Risk Score per device.

Threat Detection

Catch what should not be there.

90+ deterministic detection rules and baseline deviations: new devices, rogue flows, unauthorised industrial commands, adversary-in-the-middle techniques and ransomware activity, mapped to MITRE ATT&CK and ATT&CK for ICS.

Policy & Micro-Segmentation

Define the network you intended.

Map dependencies, approve a baseline, declare zones, conduits and allowed services, and validate them against observed traffic. WireTrace detects crossings of that intent continuously; your firewalls, NAC and switches enforce.

WireTraceintelligence · intentvalidationMAPwho talks to whomBASELINEapprove normalPROPOSEsegmentation intentVALIDATEtest against trafficENFORCEvia your controlsMONITORviolations · driftENFORCEMENT STAYS WITH YOUR FIREWALL, NAC AND NETWORK TEAMS
Investigations

From alert to evidence.

Any alert, asset or indicator opens an investigation with a timeline, playbooks, and supporting and contradicting evidence with a confidence. Packet captures can be recorded on demand from sensors.

Alertlateral movementEvidence gatheredflows · decoded fieldsTimelinebefore · during · afterConclusionfor · against · confidenceALERT · ASSET · INDICATOR → INVESTIGATIONON-DEMAND PACKET CAPTURE FROM SENSORS FOR DEEPER ANALYSIS
Compliance

Evidence of what happened.

415 controls across seven frameworks, each rated observable, partial, manual assessment or not assessable from the network. About a third are evidenced automatically; auditors close the rest in the platform.

IEC 62443-3-3ISO/IEC 27001HIPAANCA ECCNCA OTCCNIST CSF 2.0NERC CIP
415 CONTROLS · 7 FRAMEWORKS · EVERY CONTROL RATEDObservableevidenced from network trafficPartialnetwork evidence plus your inputManual assessmentclosed in the assessment workflowNot assessableoutside what a network can showNIST CSF 2.0 · ISO/IEC 27001 · HIPAA · IEC 62443-3-3 · NERC CIP · NCA OTCC · NCA ECC
Safe by design

Built for fragile networks.

Passive by default, no agents, fully on your infrastructure and able to run air-gapped, including the AI assistant. Any active enrichment is opt-in and scoped by you.

See your network as it really is.

Watch WireTrace map your environment from your own traffic: the devices, protocols and communications you own.