SecuTex NP

Turn internal network traffic into traceable packet evidence.

SecuTex NP is an enterprise-grade network traffic recorder for core, perimeter, DMZ, office, server, and critical network segments. Through Mirroring / SPAN / TAP, NP preserves the network-side evidence required for investigation.

SecuTex NP dashboard
NP dashboards consolidate network traffic, alerts, and investigation clues to help teams understand network-side incident context.

Core Capabilities

Turn network traffic into retrospective incident evidence.

SecuTex NP preserves network-side evidence through out-of-band capture, helping security teams correlate abnormal traffic, reconstruct incident context, and connect findings to existing response workflows.

Capture

Packet capture and evidence retention

Preserve traffic evidence at critical network segments so teams can review source, destination, and communication context after an event.

Detection

Abnormal traffic and intelligence correlation

Connect detection results, threat intelligence, and network behavior to help identify suspicious traffic and potential impact scope.

Operation

Investigation workflow integration

Plan capture roles by deployment environment and connect investigation findings to existing SOC, SIEM, or incident response processes.

Stories

NP in real investigations

Turn scattered alerts into actionable investigation context with packet evidence.

Scenario 01

Unauthorized host-to-host access

An internal system attempts SSH or RDP connections to other hosts. NP reconstructs the lateral probing path by source, destination, port, timeline, and connection frequency, even when no endpoint agent is installed.

Scenario 02

Malicious relay investigation

A critical device frequently connects to abnormal external networks. NP matches local intelligence, IoCs, and custom blocklists, then traces related internal hosts and packet content.

Scenario 03

Special packets trigger dormant behavior

Attackers may trigger dormant malware through specific packets. NP preserves raw packets for retrospective review by port, payload pattern, short connection sequence, and trigger time.

Scenario 04

Impersonated operation IP behavior

When an operation host IP is stolen or misused for abnormal scanning, NP observes the behavior from the network side and correlates MAC, mirrored traffic, and asset data.

Deployment & License

Plan deployment and licensing independently.

NP can be planned by Portal, Box, or One roles according to traffic scale, retention days, and hardware or VM resources.

Deployment Roles

Plan NP roles by site and capture point

Portal

Centrally manage multiple Box capture nodes and review device status, alert events, and query results.

Box

Deploy at critical segments or mirrored traffic points for packet retention, traffic parsing, alert detection, and forensic search.

One

Combine management and capture on one host for single-site, small-scale, or initial deployments.

License Planning

Plan licensing by scale and term

Hardware appliance cost

Select models based on capture role, traffic scale, storage demand, and deployment environment.

Software term license

Product functions, updates, and maintenance services are provided according to the licensed term.

VM plan assessment

Evaluate VM resources by Portal, Box, or One role, expected scale, and retention days.

Common deployment locations

Core switches, perimeter switches, server zones, DMZ, office networks, public cloud, or hybrid environments. A single device supports 1Gbps traffic; high-traffic environments can add storage expansion equipment to support up to 10Gbps capture and extend packet retention days.

PoC Planning

Need help deciding which network segments should be captured?

Share your topology, traffic scale, retention requirements, and SOC/SIEM integration needs. We can help plan a SecuTex NP PoC.

Book an NP PoC