Use case · Enterprise & Campus · OT & ICS

Threat detection and SOC triage with ATT&CK mapping

Triage starts from what the device is and what it did.

  1. 01

    Challenge

    Analysts get alerts about addresses, not devices, and spend the first half hour working out what the device is.

  2. 02

    What WireTrace sees

    Behavioural deviations, network-integrity attacks and indicator matches across IT and OT.

  3. 03

    What WireTrace understands

    Each detection mapped to ATT&CK or ATT&CK for ICS, with the device's identity, role and risk.

  4. 04

    What WireTrace decides

    Alerts are queued with severity and evidence; the coverage view shows detectable versus observed techniques.

  5. 05

    Integration / action

    Forwarded to any SIEM over syslog (CEF, LEEF, RFC 5424/3164) or Splunk HTTP Event Collector; an ATT&CK Navigator layer for the threat model.

  6. 06

    Outcome

    Triage starts from what the device is and what it did.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.