Platform capability
In deploymentNetwork detection and traffic visibility
Signature-based intrusion detection combined with protocol metadata, giving visibility into traffic that never touches a monitored endpoint.
Overview
Endpoint agents cannot be installed everywhere. Printers, cameras, building management controllers, contractor laptops and network appliances all generate traffic and none of them will run your agent. Network detection is how those blind spots become visible.
Vanguard analyses traffic from a mirror or span port in two complementary ways. Signature-based detection identifies known exploitation attempts and malicious traffic patterns. Protocol metadata analysis records the shape of every connection - DNS queries, TLS certificates, HTTP requests, connection duration - which is what makes retrospective hunting possible.
This capability is introduced one component at a time, each with its own tuning window. An untuned network ruleset generates more noise than the rest of the platform combined, and an alert stream nobody reads is worse than no alert stream at all.
What this identifies
- Command-and-control channels, including DNS tunnelling
- Internal reconnaissance and port scanning
- Connections to newly registered or low-reputation domains
- Data transfers that are anomalous in size, timing or destination
- Expired, self-signed or otherwise suspicious TLS certificates in use
Delivery status: In deployment - actively being rolled out and available on request, with per-environment tuning.
Capabilities
What network detection does
Intrusion detection
Signature-based identification of exploitation attempts, malware traffic and scanning activity.
Protocol metadata
Connection, DNS, HTTP, TLS and certificate records retained well beyond payload data, because they are small and disproportionately useful.
Lateral movement visibility
East-west traffic between internal hosts, where an intrusion becomes a breach.
Unmanaged device discovery
Devices that appear on your network without an agent and without a change record.
Under the hood
The engineering underneath
How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.
- Signature-based inspection and protocol metadata extraction run side by side, both feeding the central detection pipeline.
- Connection, DNS, HTTP, TLS and file records are retained well beyond payload data.
- Deployed on a span or mirror port, or at the gateway, depending on your network topology.
- Components are introduced one at a time, each with a dedicated tuning window.
The full platform architecture is documented on the architecture page.
Services
Services delivered on this capability
The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.
- In deployment
Threat Hunting
Analyst-led hunts across your Namibian estate for intrusions that never triggered an alert, delivered as a scheduled engagement or on suspicion.
Explore
Related
Capabilities that work with this one
- Operational
SIEM & XDR
Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.
Explore - In deployment
Threat Hunting
Analyst-led search for activity that did not trigger an alert, supported by fleet-wide query and remote forensic collection.
Explore - Operational
Deception
Decoy systems placed inside your network that no legitimate process should ever touch, producing near-zero false positives.
Explore
Get started
Find out what is actually happening on your network
A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.