Network Detection and Response · NDR
Specula

Specula is a passive sensor that watches internal traffic, detects attacks in progress and scores risk per machine, showing at every point where the score came from.

In pilot. No off-the-shelf contract: we talk before we install.

Acesso inicialExecuçãoMovimento lateralComando e controleExfiltração
- The problem

Lateral movement, command and control, exfiltration and SMB ransomware all happen after the intruder is already through the door. There is no suspicious file for the antivirus to catch, no inbound connection for the firewall to block. What there is, is internal traffic with a pattern that stands out.

Today the alternative is an expensive imported product, priced in dollars and designed for another market, or nothing at all. Most Brazilian companies with their own network are on the second option.

- How it works

The sensor receives a copy of the traffic and never sits in its path: if Specula goes down, the network keeps running. Zeek and Suricata do the reading; the rest is what we built on top.

01

Observes

A copy of the traffic over SPAN or TAP. Passive, outside the network's critical path.

02

Correlates

Around 40 detections mapped to MITRE ATT&CK, grouped into attack chains with a timeline.

03

Prioritises

A per-machine score built from behaviour, vulnerability exposure and indicators, with every part visible.

04

Justifies

Every score opens up and shows why. No black box telling you to trust the model.

De 4.995 eventos a 5 que merecem você
4.995
eventos
50
achados
20
incidentes
5
críticos
- The console

Real product screens, with demonstration data.

Incident queue

Funnel at the top: events, findings, incidents, critical. The queue sorts by weight, with each incident's attack chain visible on the row.

Incident queue

Asset page

Who the machine is, what it did, and the score broken down part by part. Exposure cites the CVE, whether it is in the KEV catalogue and whether exploitation has been observed.

Asset page
- What exists today

What is still being built is listed further down, separately. We don't sell promises as deliveries.

ATT&CK-mapped detection

Beaconing command and control, scanning, lateral movement, Active Directory attacks, exfiltration, SMB ransomware and SSH use (transfer, interactive session, port forwarding) inferred from traffic shape, without decrypting.

Passive inventory

Identifies software by its banner on the network and cross-references CVE, CISA's KEV catalogue, EPSS and public exploit availability.

Explained risk score

Behaviour, exposure and indicators, each with the weight it carried in the total. The arithmetic stays in view.

Incidents as steps

Not a loose alert: the sequence of what happened, in time order, with a graph of the machines involved.

Indicators with provenance

Public threat sources, each indicator carrying origin, collection date and licence. You can audit where it came from.

Console with access control

Login, second factor, roles and an audit trail. REST API to integrate.

Output to your SIEM

Export in CEF, LEEF and STIX. Specula doesn't ask to be the centre of your world.

Report and ANPD draft

When an incident requires notification, the draft comes out with what Brazil's LGPD asks for. You review and send.

1.00
recall and precision
- The measurement

Across eight labelled scenarios, six public captures of attack traffic (malware-traffic-analysis.net and CTU-13), one lab capture and one synthetic scenario, Specula detected all of them without missing any and without flagging what wasn't an attack.

That is a laboratory measurement, on labelled traffic. It is not a false-positive rate in a production network: that one has not been measured, and anyone quoting such a number without having run on your network is guessing. Finding it out is exactly what a pilot is for.

- To install

A Debian 12 Linux server with Docker (RHEL family in validation)
Port mirroring on the switch (SPAN) or a TAP
No agents on the machines in the network
The console and the data stay on your server; no data from your network is sent to the vendor
- Not there yet

Listed here so you don't find out later.

Automatic response (blocking). Today Specula detects and prioritises, it does not act on its own
Languages beyond Portuguese
Install from a prebuilt image (OVA/ISO). Today it is an assisted install
We have not published a throughput benchmark yet. A sensor's size depends on packets per second, flows per second, enabled features and retention, and it is set at the capture point, measuring the real traffic of your environment. The pilot starts at that point.
- Pilot

Own network, and someone who does the triage?

Specula is in pilot. If your case makes sense, we install it, run it for a period and measure on your network, false positives included.