Local-First Network Detection & Investigation

BlackBox Analyst

Network evidence. Explained.

BlackBox Analyst captures network activity and applies deterministic detection rules. Analysts can reconstruct events without sending sensitive telemetry to a cloud service. AI is limited to explaining and correlating evidence produced by the detection engine.

Private Preview   In development

AIR GAP INTEL // BLACKBOX ANALYST
BlackBox Analyst network evidence system.
Product emblem / Private Preview

Detections come from rules

Deterministic rules produce findings, severity, and supporting evidence. The AI analyst can explain a finding, connect related activity, and suggest follow-up questions. It does not create alerts or add facts that are absent from the evidence.

Evidence before explanation
Deterministic source of truth
Local-first analysis
Human-controlled conclusions

From captured traffic to traceable analyst output

Every conclusion should remain connected to captured traffic, reconstructed activity, or a deterministic finding.

  1. Traffic Capture or PCAPPCAP replay: Active development
  2. Protocol and Flow AnalysisFull reconstruction: Active development
  3. Deterministic Detection
  4. ATT&CK ContextActive development
  5. Local AI Analysis
  6. Evidence-Backed Output
Prototype Foundation

Prototype foundation

  • Live network packet capture
  • Deterministic rule-based findings
  • Event and alert investigation views
  • Allowlisting and suppression controls
  • Local AI integration foundation
  • Simulation and demonstration mode
  • Exportable investigation reports
Active Development

Current development work

  • PCAP import, replay, and session reconstruction
  • Strict evidence citations in AI responses
  • ATT&CK context and attack-chain correlation
  • Investigation timelines and expanded protocols
  • Configurable model providers and security outputs
  • Signed offline application and model updates

Local operation without permanent cloud access

The target deployment performs capture, detection, investigation, and AI-assisted explanation locally. Operators retain control of sensitive packet data.

Security Operations

Investigate suspicious network activity with evidence attached to every finding.

Incident Response

Reconstruct activity and build a defensible timeline without uploading packet data to a third party.

Defense & Regulated Environments

Run AI-assisted investigation near sensitive networks while retaining operator control.

Purple Teams

Observe triggered detections, map activity to ATT&CK, and identify gaps in visibility and coverage.

Analyst output stays tied to evidence

Evidence-backed findings
Plain-language explanations
Attack-chain correlation
Investigation timelines
Recommended next steps
Exportable incident reports

Constraint: AI output is analysis, not evidence. Every factual claim must reference an observed artifact or deterministic finding.

Review the traffic and its supporting evidence

Ask about the BlackBox Analyst private preview and tell us what your investigation workflow requires.