Seraxi
Seraxi Trace

Network memory and threat detection — one sensor, modular

Trace records the raw traffic on your network so an investigation never depends on a firewall's accept/deny log, detects threats with machine learning and a real, self-hosted AI, and brings the same visibility to OT networks — Modbus, DNP3, IEC 104, OPC UA and the PLCs behind them. Underneath, a live asset inventory built from the wire. One appliance; Analysis, TDS and Assets as modules — and Seraxi Relay for OT.

What it answers

From wire to verdict

You suspect an attack happened last night. Today the only evidence is a firewall log that says accept or deny. Trace changes what you have: Analysis keeps the packets themselves, so you replay the hour or hand the PCAP to incident response. TDS watches the same traffic with static and dynamic ML detection and a self-hosted AI that learns your organisation's own threat model inside a closed network — with global threat intelligence layered on when you want it. Seraxi Relay does the same on the plant floor, speaking industrial protocols natively and mapping assets on the Purdue model.

We suspect an attack happened last night. What do we actually have?
The packets. Trace Analysis replays the raw traffic for that hour — not a firewall log that only says accept or deny.
Is something on the network talking to a domain nobody recognises?
Trace TDS flags the behaviour on live traffic with ML and a self-hosted AI, and shows the packets behind the verdict.
A PLC started talking to a workstation it never did before. Is that normal?
Trace OT knows the Purdue level and the protocol; the deviation is flagged and the raw data is one click away.
Can we hand evidence to incident response or a regulator?
Export the exact PCAP for the window in question, with timestamps intact.

Four modules, one appliance

Analysis · TDS · Seraxi Relay · Assets

Analysis, TDS and Assets are modules of the same sensor; Seraxi Relay is the OT product built on it. Start with one; the others switch on without new hardware.

01 — Network memory

Trace Analysis

Full-fidelity capture of your mirrored traffic, indexed and searchable for weeks. When you suspect last night's attack, the only place to look is no longer the firewall's accept/deny log: replay the raw traffic on Trace Analysis, or hand the PCAP to your incident-response team.

  • Line-rate capture on SPAN / TAP — lossless, timestamped, indexed
  • Replay any minute, weeks later: packets, not summaries
  • Export PCAP evidence for IR, legal and regulators
  • Raw-data inspection for OT incidents

02 — Threat Detection System

Trace TDS

Static and dynamic detection backed by machine learning and a real, self-hosted AI. TDS learns a threat model that is specific to your organisation, in real time, inside a closed network — and layers Seraxi's global threat intelligence on top when you allow it.

  • Behavioural ML over live traffic, tuned to your network
  • Static detection: signatures, IOCs, YARA on payloads
  • Self-hosted AI analyst — prompts and data never leave the appliance
  • Global threat-intelligence feed, optional and air-gap deliverable

03 — OT security · built on Trace

Seraxi Relay

Passive visibility and AI-assisted threat analysis for OT networks, organised by Purdue level. Relay runs on the same sensor, understands industrial protocols natively and identifies PLC, RTU, HMI and SCADA assets from the wire — no agents, no impact on the process. It has its own page because its buyer is the plant, not the SOC.

  • Protocols: Modbus/TCP, DNP3, IEC 60870-5-104, IEC 61850 (GOOSE / MMS), OPC UA, PROFINET, EtherNet/IP (CIP), S7comm, BACnet
  • Vendors: Siemens, Schneider Electric, Rockwell Automation, ABB, Honeywell, Emerson, Mitsubishi Electric, Omron, GE Vernova, Yokogawa, Phoenix Contact, Beckhoff, Hitachi Energy
  • Purdue-model asset map and IT/OT boundary monitoring
  • When something critical happens, the raw data is in Trace Analysis

04 — Inventory from the wire

Trace Assets

Every host, service and device that actually talks on the network, discovered passively and enriched from the sources you already run — Active Directory, endpoint management, Infoblox, CMDB. Coverage and compliance views show what is monitored, what is not, and why.

  • Passive asset inventory — IT, IoT and OT — with auto-tagging rules
  • Discovery & integrations: AD, EDR/endpoint management, Infoblox, CMDB
  • Coverage & compliance: which segments and assets are actually monitored
  • The same inventory feeds TDS verdicts, OT maps and Analysis searches

How it differs

Trace TDS against cloud-first NDR

Teams evaluate Trace TDS alongside cloud-first network detection platforms. The differences are structural, not feature-list details.

Trace TDS Cloud-first NDR
Where the AI runs On your appliance, self-hosted — air-gap included In the vendor's cloud; sensors ship metadata out
What is kept The packets — full-fidelity capture, exportable PCAP Metadata and enriched records; packets are usually not retained
Threat model Learned per organisation, in real time, in a closed network — plus optional global intelligence Vendor-global models; tuning to your estate is limited
OT networks Native industrial protocols and Purdue mapping, same sensor Separate product or add-on, if at all
Investigation Verdict → packets → PCAP, on one screen Verdict → ticket; raw evidence lives elsewhere
Data sovereignty Nothing leaves the perimeter unless you export it Telemetry leaves the country by design

Characterisation of cloud-first NDR as a category; confirm specifics against each vendor's current documentation.

See it in action

The packets behind every verdict.

Analysis streams flows at line rate onto a searchable timeline; TDS rides alongside with ML classification and anomaly scoring. Ask the network a question in plain language and the self-hosted analyst returns the query, the packets and a correlated verdict — on IT and OT segments alike.

Seraxi Trace TDS — threat detection stream with severity, source, destination and description
Trace TDS — threat events by severity, source, destination and description
Seraxi Trace Analysis — session browser with sub-second search over recorded traffic
Trace Analysis — sub-second session search over recorded traffic
Seraxi Trace TDS — detection engine with static rules and ML detectors per category
Trace TDS — detection engine: rules + ML detectors by category

Illustrative data shown. Your deployment runs entirely on your own appliance.

What it does

01

Full-fidelity network memory

Every packet on your SPAN / TAP is recorded at line rate, indexed and searchable — replay the raw wire to the exact minute, weeks after the fact.

02

PCAP hand-off for incident response

Export the exact window as PCAP, timestamps intact, for your IR team, external responders, legal or a regulator.

03

Static + dynamic ML detection

Signatures, IOCs and YARA on payloads, alongside behavioural machine-learning over live traffic that surfaces what static rules never see.

04

Real-time, self-hosted AI

A threat model specific to your organisation, learned inside a closed network by an AI that runs on the appliance — prompts and data never leave.

05

Global threat intelligence

Seraxi's threat-intelligence feed layers onto your local model — online, or delivered offline into air-gapped sites.

06

OT protocols & Purdue map

Modbus, DNP3, IEC 104, IEC 61850, OPC UA, PROFINET, EtherNet/IP and S7comm decoded natively; assets placed on the Purdue model automatically.

07

Asset inventory from the wire

Passive discovery of every host, service and device that talks on the network — IT, IoT and OT — enriched from AD, endpoint management, Infoblox and your CMDB, with coverage and compliance views.

How it works

Trace records the raw wire, detects what matters, and gives you the packets behind every verdict.

  1. 01

    Record

    Capture every packet on SPAN / TAP at line rate — lossless, timestamped, indexed, searchable for weeks. IT and OT alike.

  2. 02

    Detect

    Static and ML-driven detection runs on the live traffic; a self-hosted AI fuses the signals into verdicts tuned to your organisation.

  3. 03

    Investigate

    Replay the exact minute, ask the network questions in plain language, and hand the PCAP to whoever needs the evidence.

Why teams run Trace

  • Investigate last night's attack from the packets — not from a firewall log that only says accept or deny.
  • Hand incident response, legal or a regulator the exact PCAP for the window in question.
  • Detect with static rules and behavioural ML, explained by a real AI that runs on your own hardware.
  • Get a threat model specific to your organisation, in a closed network, with global intelligence on top.
  • See PLCs, RTUs and SCADA on the Purdue model, with industrial protocols decoded natively.
trace · sensor-01 live

Live capture

last 24h
9.4 Gbps
Throughput
30 d
Full retention
2.1 M
Active sessions
0.00 %
Packet drops
Throughput peak 12.0 Gbps

Part of the Seraxi platform

See Seraxi on your environment.

Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.

Book a demo