Local-First Network Detection & Investigation

BlackBox Analyst

Network evidence. Explained.

BlackBox Analyst captures network activity and applies deterministic detection rules. Analysts can reconstruct events without sending sensitive telemetry to a cloud service. AI is limited to explaining and correlating evidence produced by the detection engine.

Private Preview   In development

AIR GAP INTEL // BLACKBOX ANALYST
BlackBox Analyst network evidence system.
Product emblem / Private Preview

Detections come from rules

BlackBox Analyst separates detection from interpretation. Deterministic rules produce findings, severity, and supporting evidence. The AI analyst can explain a finding, connect related activity, and suggest follow-up questions. It does not create alerts or add facts that are absent from the evidence.

Evidence before explanation
Deterministic source of truth
Local-first analysis
Human-controlled conclusions

A traceable path from traffic to analyst output

Each conclusion must point back to captured traffic, reconstructed activity, or a deterministic finding. Generated analysis is labeled separately from observed evidence.

  1. Traffic Capture or PCAPPCAP replay: In active development
  2. Protocol and Flow AnalysisFull reconstruction: In active development
  3. Deterministic Detection
  4. ATT&CK ContextIn active development
  5. Local AI Analysis
  6. Evidence-Backed Analyst Output
Prototype Foundation

Prototype capabilities under review

These are prototype capabilities, not production promises.

  • Live network packet capture
  • Deterministic rule-based findings
  • Event and alert investigation views
  • Allowlisting and suppression controls
  • Local AI integration foundation
  • Simulation and demonstration mode
  • Exportable investigation reports

Current development work covers evidence preservation, local inference, analyst workflows, and application packaging.

Active Development

Work in progress

The items below are not presented as currently available.

  • PCAP import and timeline replay
  • Bidirectional session and flow reconstruction
  • Expanded DNS, ARP, TCP, TLS, and HTTP evidence
  • Strict evidence citations in each AI response
  • MITRE ATT&CK mapping
  • MITRE D3FEND recommendations
  • Attack-chain correlation
  • Investigation timelines
  • Configurable local and remote model providers
  • JSON, webhook, Syslog, and CEF output
  • Signed offline model and application updates

Local operation without permanent cloud access

The target deployment performs capture, detection, investigation, and AI-assisted explanation locally. Operators retain control of sensitive packet data. Planned enterprise packaging covers disconnected and air-gapped deployment workflows without a permanent cloud connection.

Investigation teams working close to sensitive evidence

Security Operations

Investigate suspicious network activity with evidence attached to every finding.

Incident Response

Reconstruct activity and produce a defensible timeline without uploading packet data to a third party.

Defense and Regulated Environments

Run AI-assisted investigation near sensitive networks while retaining operator control.

Purple Teams

Observe triggered detections, map activity to ATT&CK, and identify gaps in visibility and coverage.

Output tied to the investigation record

Evidence-backed findings
Plain-language technical explanations
Attack-chain correlation
Investigation timelines
Recommended next steps
Incident summaries
Exportable reports

AI output is analysis, not evidence. Every factual claim must reference an observed artifact or deterministic finding.

Release sequence

No release dates have been announced.

Now

Standalone Windows desktop private preview

The initial private preview targets a standalone Windows desktop experience.

Planned

Enterprise packaging

  • Enterprise software edition
  • Preconfigured investigation appliance
  • Air-gapped deployment bundle

Product screenshots forthcoming

These are labeled replacement frames, not representations of a finished interface.

Screenshot Placeholder

Live Capture

Replace with a verified capture workspace screenshot.

Screenshot Placeholder

Findings

Replace with a verified deterministic findings view.

Screenshot Placeholder

Evidence Inspector

Replace with a verified artifact inspection view.

Screenshot Placeholder

Investigation Timeline

Planned interface. Replace only after implementation is verified.

Screenshot Placeholder

AI Analyst

Replace with a verified evidence-cited analysis view.

Private Preview

Review the traffic and its supporting evidence

Ask about the BlackBox Analyst private preview and tell us what your investigation workflow requires.

Request Early Access

BlackBox Analyst private-preview questions

Does BlackBox Analyst use AI to detect threats?

No. Deterministic detection logic creates findings. AI explains, correlates, and summarizes the evidence produced by the detection pipeline.

Does network data leave the system?

Local processing is the default target. An operator must explicitly configure any future remote-model connection, with a clear account of the data it transmits.

Can it analyze PCAP files?

PCAP import and replay are in active development for the private-preview release.

Does it require an internet connection?

The target local deployment does not require a persistent internet connection. Installation, model distribution, licensing, and update workflows remain in development.

Which operating systems are supported?

The initial private preview targets Windows. Additional platforms will not be listed until they have been tested.

Is it already available?

BlackBox Analyst is currently in development and accepting private-preview inquiries.