You cannot scan a device attached to a patient.
WireTrace identifies clinical, imaging, building and IT devices from the traffic they already send. No agents, no device-side software, and passive by default.
Medical devices, recognised by what they say.
WireTrace recognises DICOM, HL7 and a range of medical-device vendor protocols, with patient values masked at the sensor. Field names are used to understand the device. Patient values are masked inside the sensor and never stored.
Ransomware is a patient-safety problem.
WireTrace correlates reconnaissance, lateral movement, mass file modification, ransomware extensions and ransom notes on unencrypted file shares into one corroborated verdict, and surfaces the clear-text credentials and exposed services that make it easier.
File activity is visible on unencrypted SMB. Encrypted SMB3 sessions expose no file operations.
Clinical networks that stay separated.
Declare which zones may communicate, validate clinical VLAN separation against observed traffic, and be alerted when a device crosses a boundary it should not. Your network team enforces.
HIPAA and beyond.
ISO/IEC 27001 and NIST CSF 2.0
Mapped alongside national frameworks.
See your clinical estate, without touching it.
A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.