Security Operations
Investigate suspicious network activity with evidence attached to every finding.
Network evidence. Explained.
BlackBox Analyst captures network activity and applies deterministic detection rules. Analysts can reconstruct events without sending sensitive telemetry to a cloud service. AI is limited to explaining and correlating evidence produced by the detection engine.
Private Preview In development
Deterministic rules produce findings, severity, and supporting evidence. The AI analyst can explain a finding, connect related activity, and suggest follow-up questions. It does not create alerts or add facts that are absent from the evidence.
Every conclusion should remain connected to captured traffic, reconstructed activity, or a deterministic finding.
The target deployment performs capture, detection, investigation, and AI-assisted explanation locally. Operators retain control of sensitive packet data.
Investigate suspicious network activity with evidence attached to every finding.
Reconstruct activity and build a defensible timeline without uploading packet data to a third party.
Run AI-assisted investigation near sensitive networks while retaining operator control.
Observe triggered detections, map activity to ATT&CK, and identify gaps in visibility and coverage.
Constraint: AI output is analysis, not evidence. Every factual claim must reference an observed artifact or deterministic finding.
Ask about the BlackBox Analyst private preview and tell us what your investigation workflow requires.