NOCSIGHT
sensors live Try in your lab

Network Detection & Response

Reasoning by an AI agent

Spot lateral movement before it becomes an incident.

NOCSIGHT attaches to the switches, firewalls, and flow logs you already run. Its detection models learn each host's normal behavior and flag deviations with a risk score and a MITRE ATT&CK technique. Then an AI agent stitches the evidence into one readable explanation — not 10,000 alerts you have to triage yourself.

38
Built-in ATT&CK detections
4
Telemetry sources
90 days
Flow & session retention
<5 min
From alert to ticket
nocsight — console / main-lab sample data ● live
Sensors
Core router IPFIX
Edge firewall syslog
Switch DC-1 SPAN
DNS resolver query log
Guest VLAN limited
Cloud VPC flow logs
Host agents 14 hosts
Last 24 hours
Flow events1.24 M
Anomalies flagged47
Auto-blocked12
Median triage38 s

Network threat score

24 h · all segments combined

Alert queue

6 latest · ranked by risk
22:40 critical Lateral movement over SMB 10.42.7.19:445 → DC01 T1021.002 Blocked
22:12 high DNS tunneling 10.42.9.4 → 8.8.4.4 · 4.1 KB/min T1071.004 Quarantined
21:48 medium Port scan from guest VLAN 10.42.30.77 → 10.42.0.0/16 T1046 Rate-limited
20:31 high Egress to unknown ASN 10.42.5.12 → 45.148.10.0/24 · 1.8 GB T1567 Session held
19:05 medium New device with no profile MAC 8c:1f:64:aa:31:0c · VLAN 30 T1200 Watching
17:22 info Firewall config drift rule #214 differs from baseline — Ticket filed

AI analyst

AI agent · alert #4816 · baseline
Verdict

Host 10.42.7.19 opened SMB to DC01 at 22:40 — the first connection between the two in a 30-day baseline. The pattern matches lateral movement, and it is not scheduled admin activity.

Risk score (from the model)
Incident probability 0.94
Baseline similarity 0.06
Suggested actions

1. Block 10.42.7.19 → DC01:445 2. Isolate the host for review 3. Revoke sessions & rotate credentials

Why — factors behind the score
First-time host pair 0.34
Off-hours admin account 0.27
Model: claude-sonnet-4-5 Confidence: 0.94 Explainability: SHAP Human-in-the-loop: on Basis: 1.2 M flows · 30 days Source: baseline

Configure an API key to have the reasoning layer write this in real time.

The reasoning layer

The brain is an AI agent.

NOCSIGHT does not train its own language model. The reasoning and language layer runs on a configurable AI agent — it weighs the evidence, writes the summary, and proposes the next step. The numeric detection stays deterministic; the agent turns it into a decision an analyst can read.

AI agent Reasoning engine

Weighing the evidence

The agent reads the flows, sessions, and alert history the detection models have already gathered, then assembles them into one explanation you can verify.

Writing the summary

Every alert arrives with a plain-language paragraph: what happened, why it looks suspicious, and what to check first.

Proposing the next step

Block, quarantine, or escalate — always with a reason and a confidence score, and always waiting for analyst approval.

Long-context reasoning Tool use Structured output Streaming Human-in-the-loop

Detection models flag anomalies; the AI agent assembles them into a decision. Both can run inside your infrastructure.

01

Filtering the noise

Thousands of events per minute are grouped and ranked, so what reaches the screen is the riskiest — not the loudest.

grouping & ranking
02

Recognizing behavioral drift

The model compares a host's activity against its own normal profile, not a signature list. Subtle anomalies show up without needing a name for the attack first.

anomaly detection
03

Stitching the kill chain

Related alerts are sewn into a single timeline, so an analyst sees one whole incident instead of ten separate tickets.

AI agent · correlation
04

Writing the triage summary

Every alert arrives with a plain-language explanation: what happened, why it is suspicious, and the first step to take.

AI agent · LLM
05

Proposing a response

The system prepares a block or quarantine, but runs it only when your policy allows. Full execution always needs approval.

AI agent · recommendation, not autonomy
What the AI agent runs
  • Weigh evidence & judge context
  • Group and prioritize alerts
  • Write plain-language summaries
  • Build the kill-chain timeline
  • Propose actions & confidence scores
What always stays with a human
  • Declare an incident real
  • Decide to block or isolate
  • Change response policy
  • Close the ticket & final report
  • Add or disable detections

Privacy & data

The AI agent works from flow and DNS metadata. Payload contents are never read, and raw data can stay inside your infrastructure.

Explainable

Every score ships with the factors behind it, so an analyst can inspect why the model reached a decision.

Tamper-resistant

Baselines update gradually and within limits, so an attacker cannot slowly train the model into treating them as normal.

Auditable

Model version, thresholds, and the reasoning behind each decision are retained for investigation and audit.

How it works

Four steps from raw packets to action.

The flow is sequential — each step works only because the one before it finished.

01 / Collect

Pull telemetry

Sensors read flow (NetFlow/IPFIX), DNS queries, and session metadata from gear you already have. No physical tap, no topology change.

02 / Understand

Build the baseline

Over the first 30 days, the system profiles each host and VLAN: who it usually talks to, over which ports, and at what hours.

03 / Flag

Score every deviation

The model gives each deviation a risk score, a MITRE ATT&CK technique, and an evidence chain you can open. One alert, one verifiable story.

04 / Act

Notify or execute

The AI agent proposes the action; an analyst decides. For policies you allow, the system can block or quarantine directly.

Detection coverage

What it looks for on your network.

All eight ship on by default. Each maps to a MITRE ATT&CK technique so the results line up with your playbooks.

T1021

Lateral movement

SMB, RDP, and WinRM between hosts that have never talked to each other before.

Critical risk
T1071

DNS & HTTP tunneling

C2 beacons and covert channels that smuggle data through DNS resolution or HTTP requests.

High risk
T1046

Service scanning

Port scans and sweeps from any segment, including from a guest VLAN that should be fenced off.

Medium risk
T1567

Data exfiltration

Outbound volume spikes to an ASN or destination that never appeared in the baseline.

High risk
T1557

L2 man-in-the-middle

ARP spoofing, rogue DHCP, and traffic positioning in the middle of a conversation.

High risk
T1200

Unknown devices

New MACs and DHCP leases appearing on a sensitive segment with no known profile.

Medium risk
T1498

Volumetric attacks

L3/L4 floods and L7 connection spikes that drain link capacity.

High risk
T1078

Valid-account abuse

Successful logins from a segment or at an hour that is unusual for that account's owner.

Medium risk

Deployment

Three ways to install, one console.

Pick by segment. All three can run at once and feed the same console.

Mode A

Passive sensor

Traffic copied from a SPAN port or TAP. Zero risk to the production path.

  • Points: core switch, DC, DMZ
  • Visibility: L2 through L7
  • Best for: deep investigation
Mode B

Flow & logs

Just enable IPFIX, syslog, and VPC flow logs. Nothing touches the topology.

  • Points: routers, firewalls, cloud
  • Visibility: session & DNS metadata
  • Best for: broad, fast coverage
Mode C

Lightweight agent

eBPF on hosts that need process-level and application-level connection visibility.

  • Points: servers, VMs, containers
  • Visibility: process → connection
  • Best for: critical hosts
Ship to Slack Teams Jira ServiceNow PagerDuty Syslog-out REST API Webhook

Pricing

Pay per device, not per gigabit.

Pricing follows the number of devices sending telemetry. No per-event fees.

Start here

Sensor

Free

To prove its value in one lab or a small office.

  • Up to 10 devices
  • Community detections
  • 7-day retention
  • 1 user
Install a sensor
Most teams pick this

NOC

$6 / device / month

For IT teams running their own network who want answers, not a pile of logs.

  • All 38 ATT&CK detections
  • Automatic triage & summaries
  • 90-day retention
  • Every integration & role
  • Auto-block (optional)
Start 30-day trial
For service providers

MSSP

Custom

For ISPs, MSSPs, and groups watching many networks at once.

  • Multi-tenant & white-label
  • Per-client custom detections
  • SSO & access control
  • 99.9% SLA & priority support
Talk to us

Get started

Deploy your first sensor today.

Try it for 30 days on your own telemetry. If it finds nothing worth acting on, walk away.

Start 30-day trial See the console again