ISO 27001 CertifiedSOC 2 Compliant A product by Visit the Trust Center
Agent 06 · Network intelligence

Logs tell you a story. Traffic tells you the truth.

The Network agent reads the wire in real time, across your gateways and inside your network, and turns raw traffic into intelligence. It spots beacons, tunnelling and low-and-slow exfiltration from how traffic behaves, without ever decrypting what it shouldn’t.

The agent, thinking

It hears the beacon nobody else does.

A quiet, regular heartbeat to a brand-new host abroad, and the agent ties it to an exploit another agent already found. This is the Network agent reasoning, condensed.

Network agent · reasoning live
24/7
Real-time capture across gateways and internal nodes
0
Payloads decrypted, intent read from metadata
1
Wire tied to code, data and dark-web signals
The blind spot

Attackers live where your logs don’t.

The dangerous activity hides in the gaps a log never covers, encrypted channels, host-to-host movement, forgotten devices. The wire sees all of it.

01

Logs are curated

A system only records what it was told to. Traffic records what actually happened.

02

Encryption hides payload

The contents are encrypted, but rhythm, size and destination still give an attacker away.

03

East-west is invisible

Most tools watch the perimeter. The dangerous movement is host-to-host, deep inside.

What it reads

It reads the wire, not the write-up.

Real-time capture across gateways and internal nodes, turned into intelligence, without decrypting a thing it shouldn’t.

Packet & flow capture

Real-time capture and inspection at your gateways and internal nodes, plus flow metadata at scale.

DNS & destination intel

Every lookup and destination checked, new, unlisted and known-bad hosts surfaced the moment they’re contacted.

TLS & JA3 fingerprints

Encrypted sessions fingerprinted by how they connect, not what they carry, matched against known malware and tools.

Behavioural baselining

Normal for each host and segment is learned, so beacons, scans and low-and-slow exfil stand out on their own.

A detection, in full

Not an alert. A conclusion.

Every detection lands with the wire-level evidence, the mapped technique, the correlation to other agents, and the one action that contains it.

Detection · live capturelive
10.0.4.21 → 185.147.[.]0/24:443C2 beacon
Pattern
Beacon · every 60s
Protocol
TLS 1.2 · JA3 match
Data out
2.4 GB, low-and-slow
Destination
Unlisted host · 3 days old
ASN · geo
AS20473 · offshore
Correlates
SSRF on the same app (Agent 05)
T1041 ExfiltrationT1071 C2T1090 Proxy
CRITICALA quiet beacon exfiltrating in encrypted chunks, tied to a known exploit path.Isolate host
Always listening

A live feed, not a nightly report.

Sensitive data heading for an unknown destination is caught in real time and held pending confirmation, before it ever leaves.

Capture feedEdge Gateway 03 & internal nodes
NET-3310EgressSensitive data moving to an unknown external destination.Flow flagged in real time; traffic held pending confirmation. Contained
NET-3301BeaconA host calling home every 60 seconds to a 3-day-old domain.Identified as C2; host isolated, session cut. Contained
NET-3287Anomaly78,457 packets analysed, three critical anomalies.Correlated with a known exploit path; confidence raised to high. Contained
NET-3251BaselineDeep inspection at 00:30 daily.Per-segment baseline refreshed; adaptive thresholds tuned. Contained
Why it’s different

The wire, wired to everything else.

Most network tools flag traffic in isolation. VenusHawk reads intent from metadata, and ties every flow to what the rest of the constellation already knows.

Sees what logs can’t
Reads actual traffic, encrypted channels, east-west movement and shadow devices included.
Intent from metadata
Beacons, tunnelling and low-and-slow exfil detected from rhythm, size and destination, without touching payloads.
Correlated, not isolated
A flow here is tied to the exploit, the record and the exposure the other agents found, one story, not four alerts.
Explained, not just flagged
Every detection carries evidence and a mapped MITRE technique, so you know exactly why it fired.
A baseline that learns
Per-host, per-segment normal is learned continuously, so real anomalies rise and the noise falls away.
One action to contain
Isolate the host, cut the session, block the destination, from the same place you saw it happen.
Early access

Bring this agent into your constellation.

VenusHawk is rolling out to lighthouse customers and design partners. Tell us a little about your environment and we’ll see how we can accommodate you.