Specula is a passive sensor that watches internal traffic, detects attacks in progress and scores risk per machine, showing at every point where the score came from.
In pilot. No off-the-shelf contract: we talk before we install.
Lateral movement, command and control, exfiltration and SMB ransomware all happen after the intruder is already through the door. There is no suspicious file for the antivirus to catch, no inbound connection for the firewall to block. What there is, is internal traffic with a pattern that stands out.
Today the alternative is an expensive imported product, priced in dollars and designed for another market, or nothing at all. Most Brazilian companies with their own network are on the second option.
The sensor receives a copy of the traffic and never sits in its path: if Specula goes down, the network keeps running. Zeek and Suricata do the reading; the rest is what we built on top.
Observes
A copy of the traffic over SPAN or TAP. Passive, outside the network's critical path.
Correlates
Around 40 detections mapped to MITRE ATT&CK, grouped into attack chains with a timeline.
Prioritises
A per-machine score built from behaviour, vulnerability exposure and indicators, with every part visible.
Justifies
Every score opens up and shows why. No black box telling you to trust the model.
Real product screens, with demonstration data.
Incident queue
Funnel at the top: events, findings, incidents, critical. The queue sorts by weight, with each incident's attack chain visible on the row.

Asset page
Who the machine is, what it did, and the score broken down part by part. Exposure cites the CVE, whether it is in the KEV catalogue and whether exploitation has been observed.

What is still being built is listed further down, separately. We don't sell promises as deliveries.
ATT&CK-mapped detection
Beaconing command and control, scanning, lateral movement, Active Directory attacks, exfiltration, SMB ransomware and SSH use (transfer, interactive session, port forwarding) inferred from traffic shape, without decrypting.
Passive inventory
Identifies software by its banner on the network and cross-references CVE, CISA's KEV catalogue, EPSS and public exploit availability.
Explained risk score
Behaviour, exposure and indicators, each with the weight it carried in the total. The arithmetic stays in view.
Incidents as steps
Not a loose alert: the sequence of what happened, in time order, with a graph of the machines involved.
Indicators with provenance
Public threat sources, each indicator carrying origin, collection date and licence. You can audit where it came from.
Console with access control
Login, second factor, roles and an audit trail. REST API to integrate.
Output to your SIEM
Export in CEF, LEEF and STIX. Specula doesn't ask to be the centre of your world.
Report and ANPD draft
When an incident requires notification, the draft comes out with what Brazil's LGPD asks for. You review and send.
Across eight labelled scenarios, six public captures of attack traffic (malware-traffic-analysis.net and CTU-13), one lab capture and one synthetic scenario, Specula detected all of them without missing any and without flagging what wasn't an attack.
That is a laboratory measurement, on labelled traffic. It is not a false-positive rate in a production network: that one has not been measured, and anyone quoting such a number without having run on your network is guessing. Finding it out is exactly what a pilot is for.
Listed here so you don't find out later.
Own network, and someone who does the triage?
Specula is in pilot. If your case makes sense, we install it, run it for a period and measure on your network, false positives included.