Network Detection & Response
Spot lateral movement before it becomes an incident.
NOCSIGHT attaches to the switches, firewalls, and flow logs you already run. Its detection models learn each host's normal behavior and flag deviations with a risk score and a MITRE ATT&CK technique. Then an AI agent stitches the evidence into one readable explanation — not 10,000 alerts you have to triage yourself.
Network threat score
24 h · all segments combinedAlert queue
6 latest · ranked by riskAI analyst
AI agent · alert #4816 · baselineHost 10.42.7.19 opened SMB to DC01 at 22:40 — the first connection between the two in a 30-day baseline. The pattern matches lateral movement, and it is not scheduled admin activity.
1. Block 10.42.7.19 → DC01:445 2. Isolate the host for review 3. Revoke sessions & rotate credentials
Configure an API key to have the reasoning layer write this in real time.
The reasoning layer
The brain is an AI agent.
NOCSIGHT does not train its own language model. The reasoning and language layer runs on a configurable AI agent — it weighs the evidence, writes the summary, and proposes the next step. The numeric detection stays deterministic; the agent turns it into a decision an analyst can read.
Weighing the evidence
The agent reads the flows, sessions, and alert history the detection models have already gathered, then assembles them into one explanation you can verify.
Writing the summary
Every alert arrives with a plain-language paragraph: what happened, why it looks suspicious, and what to check first.
Proposing the next step
Block, quarantine, or escalate — always with a reason and a confidence score, and always waiting for analyst approval.
Detection models flag anomalies; the AI agent assembles them into a decision. Both can run inside your infrastructure.
Filtering the noise
Thousands of events per minute are grouped and ranked, so what reaches the screen is the riskiest — not the loudest.
Recognizing behavioral drift
The model compares a host's activity against its own normal profile, not a signature list. Subtle anomalies show up without needing a name for the attack first.
Stitching the kill chain
Related alerts are sewn into a single timeline, so an analyst sees one whole incident instead of ten separate tickets.
Writing the triage summary
Every alert arrives with a plain-language explanation: what happened, why it is suspicious, and the first step to take.
Proposing a response
The system prepares a block or quarantine, but runs it only when your policy allows. Full execution always needs approval.
- Weigh evidence & judge context
- Group and prioritize alerts
- Write plain-language summaries
- Build the kill-chain timeline
- Propose actions & confidence scores
- Declare an incident real
- Decide to block or isolate
- Change response policy
- Close the ticket & final report
- Add or disable detections
Privacy & data
The AI agent works from flow and DNS metadata. Payload contents are never read, and raw data can stay inside your infrastructure.
Explainable
Every score ships with the factors behind it, so an analyst can inspect why the model reached a decision.
Tamper-resistant
Baselines update gradually and within limits, so an attacker cannot slowly train the model into treating them as normal.
Auditable
Model version, thresholds, and the reasoning behind each decision are retained for investigation and audit.
How it works
Four steps from raw packets to action.
The flow is sequential — each step works only because the one before it finished.
Pull telemetry
Sensors read flow (NetFlow/IPFIX), DNS queries, and session metadata from gear you already have. No physical tap, no topology change.
Build the baseline
Over the first 30 days, the system profiles each host and VLAN: who it usually talks to, over which ports, and at what hours.
Score every deviation
The model gives each deviation a risk score, a MITRE ATT&CK technique, and an evidence chain you can open. One alert, one verifiable story.
Notify or execute
The AI agent proposes the action; an analyst decides. For policies you allow, the system can block or quarantine directly.
Detection coverage
What it looks for on your network.
All eight ship on by default. Each maps to a MITRE ATT&CK technique so the results line up with your playbooks.
Lateral movement
SMB, RDP, and WinRM between hosts that have never talked to each other before.
DNS & HTTP tunneling
C2 beacons and covert channels that smuggle data through DNS resolution or HTTP requests.
Service scanning
Port scans and sweeps from any segment, including from a guest VLAN that should be fenced off.
Data exfiltration
Outbound volume spikes to an ASN or destination that never appeared in the baseline.
L2 man-in-the-middle
ARP spoofing, rogue DHCP, and traffic positioning in the middle of a conversation.
Unknown devices
New MACs and DHCP leases appearing on a sensitive segment with no known profile.
Volumetric attacks
L3/L4 floods and L7 connection spikes that drain link capacity.
Valid-account abuse
Successful logins from a segment or at an hour that is unusual for that account's owner.
Deployment
Three ways to install, one console.
Pick by segment. All three can run at once and feed the same console.
Passive sensor
Traffic copied from a SPAN port or TAP. Zero risk to the production path.
- Points: core switch, DC, DMZ
- Visibility: L2 through L7
- Best for: deep investigation
Flow & logs
Just enable IPFIX, syslog, and VPC flow logs. Nothing touches the topology.
- Points: routers, firewalls, cloud
- Visibility: session & DNS metadata
- Best for: broad, fast coverage
Lightweight agent
eBPF on hosts that need process-level and application-level connection visibility.
- Points: servers, VMs, containers
- Visibility: process → connection
- Best for: critical hosts
Pricing
Pay per device, not per gigabit.
Pricing follows the number of devices sending telemetry. No per-event fees.
Sensor
To prove its value in one lab or a small office.
- Up to 10 devices
- Community detections
- 7-day retention
- 1 user
NOC
For IT teams running their own network who want answers, not a pile of logs.
- All 38 ATT&CK detections
- Automatic triage & summaries
- 90-day retention
- Every integration & role
- Auto-block (optional)
MSSP
For ISPs, MSSPs, and groups watching many networks at once.
- Multi-tenant & white-label
- Per-client custom detections
- SSO & access control
- 99.9% SLA & priority support
Get started
Deploy your first sensor today.
Try it for 30 days on your own telemetry. If it finds nothing worth acting on, walk away.