Packet capture and evidence retention
Preserve traffic evidence at critical network segments so teams can review source, destination, and communication context after an event.
SecuTex NP
SecuTex NP is an enterprise-grade network traffic recorder for core, perimeter, DMZ, office, server, and critical network segments. Through Mirroring / SPAN / TAP, NP preserves the network-side evidence required for investigation.
Core Capabilities
SecuTex NP preserves network-side evidence through out-of-band capture, helping security teams correlate abnormal traffic, reconstruct incident context, and connect findings to existing response workflows.
Preserve traffic evidence at critical network segments so teams can review source, destination, and communication context after an event.
Connect detection results, threat intelligence, and network behavior to help identify suspicious traffic and potential impact scope.
Plan capture roles by deployment environment and connect investigation findings to existing SOC, SIEM, or incident response processes.
Stories
Turn scattered alerts into actionable investigation context with packet evidence.
An internal system attempts SSH or RDP connections to other hosts. NP reconstructs the lateral probing path by source, destination, port, timeline, and connection frequency, even when no endpoint agent is installed.
A critical device frequently connects to abnormal external networks. NP matches local intelligence, IoCs, and custom blocklists, then traces related internal hosts and packet content.
Attackers may trigger dormant malware through specific packets. NP preserves raw packets for retrospective review by port, payload pattern, short connection sequence, and trigger time.
When an operation host IP is stolen or misused for abnormal scanning, NP observes the behavior from the network side and correlates MAC, mirrored traffic, and asset data.
Deployment & License
NP can be planned by Portal, Box, or One roles according to traffic scale, retention days, and hardware or VM resources.
Centrally manage multiple Box capture nodes and review device status, alert events, and query results.
Deploy at critical segments or mirrored traffic points for packet retention, traffic parsing, alert detection, and forensic search.
Combine management and capture on one host for single-site, small-scale, or initial deployments.
Select models based on capture role, traffic scale, storage demand, and deployment environment.
Product functions, updates, and maintenance services are provided according to the licensed term.
Evaluate VM resources by Portal, Box, or One role, expected scale, and retention days.
Core switches, perimeter switches, server zones, DMZ, office networks, public cloud, or hybrid environments. A single device supports 1Gbps traffic; high-traffic environments can add storage expansion equipment to support up to 10Gbps capture and extend packet retention days.
PoC Planning
Share your topology, traffic scale, retention requirements, and SOC/SIEM integration needs. We can help plan a SecuTex NP PoC.
Book an NP PoC