Trinetra
Open console

Use cases

Where passive observation is the right shape

A detection system that needs a return path cannot be deployed across a boundary that has none. That rules out a great deal of production networking, and it is the situation this system is built for rather than around.

These are deployment situations, not customers. Each entry states what the posture yields and what it costs, because a one-way guarantee is a real constraint with real limits.

Source → monitoring enclave

Deployment situations
7
Posture
Passive · one-way · detection only
Action on the monitored network
None, and none available

Where the sensor sits

Three shapes, all built. Traffic enters from the left and stops at the gate in every row — the return path is drawn so that it can be seen to be stopped, which is the only claim this page needs to make about placement.

Three TRINETRA deployment shapesThree rows, each reading the same way. First, a monitored network feeds a data diode or SPAN port and the copy arrives in a monitoring enclave. Second, a monitored network feeds a host-enforced receive-only interface whose host end carries an all-protocol ingress drop, and the copy arrives in detection infrastructure. Third, a stored capture file is read locally with no network path at all and processed on an analyst workstation. In all three rows the return path is drawn as a dashed line and stopped at the gate. Nothing travels back toward the source.Source zoneGateWhere the copy landsReturn pathMonitored networkData diode or SPAN portMonitoring enclaveno return pathMonitored networkHost-enforced receive-onlyDetection infrastructureno return pathStored capture fileLocal file, no networkAnalyst workstationno return path

Seven deployment situations

Each one names the boundary shape it usually involves, what a passive posture yields there, and what it does not do.

Government and defence

Hardware diode into a separate enclave

Networks are frequently separated by policy and sometimes by hardware, and a monitoring capability that requires a return path cannot be deployed across that boundary at all. An enclave with no path back lets a security team observe a network it is not permitted to connect to.

What the posture yields

Evidence with lineage
Every alert carries its detector version, model version, feature schema version, event schema version and pipeline run id — enough to reproduce the decision later, not just to read it.
A decision record
The alert ledger hashes the verdict, evidence and lineage, and is verified through a dedicated endpoint. Append-only: rows are never updated in place.
No pivot to argue about
The console cannot be turned into a route into the network it watches, because no route exists. That is a property of the deployment, not a setting.

What it does not do It cannot enforce anything. A finding becomes an action for someone who holds the authority you do not, and the system deliberately provides no way to skip that step.

How the boundary is enforced →

Critical infrastructure

SPAN or TAP port into a monitoring enclave

Operators of gateway and peering links usually have both regulatory and availability reasons not to place an inline device on the path. Passive mirroring keeps the monitored network observably untouched, which is often the condition that makes monitoring permissible at all.

What the posture yields

Flood detection with corroboration
Counted SYN, UDP, flow, packet and amplification thresholds, raised in confidence by source count, source entropy and baseline exceedance — and capped below critical when no baseline is warm, because the system will not claim traffic is abnormal for a host it has not established as normal.
Exfiltration on the way out
Outbound volume as the trigger and a corroborator on top of it: dominance ratio, destination rarity, or a deviation from the host's own warm baseline. Backups and video calls move large volumes every day, so volume alone never fires.
A comparison, not just a verdict
Alerts record what was observed and what it was compared against in separate blocks, so an operator can judge a finding against their own knowledge of the site.

What it does not do No inline mitigation, at all. A flood is detected, scored and reported. Stopping it is somebody else's job on somebody else's authority.

The flood and exfiltration detectors →

OT and ICS

Receive-only capture on a production segment

Control networks are the least tolerant of an active agent and the most tolerant of a passive one. They run flat naming, fixed polling intervals and long equipment lifetimes, so anything that opens a socket or changes a route is a larger risk than the one being looked for.

What the posture yields

Nothing in the collection path
The sensor holds one capture capability, drops every other, and cannot administer the interface it reads from. A test parses the AST of every module that touches captured data and fails if one imports a network or process module.
Reconnaissance that will not fire on a busy client
Counted port and host fan-out, gated on those connections having failed. A wide fan-out on its own describes a proxy or a backup agent, and there is a test for exactly that case.
Support for periodic traffic
A polling agent on a fixed interval is the textbook false positive for beaconing. Periodicity alone never fires; at least two corroborating signals are required before an alert is raised.

What it does not do There is no process-behaviour model, and no OT/ICS protocol coverage is built. Anomaly output is supporting evidence, not attack classes, and the anomaly model was fitted to a narrow benign reference. On an OT network, treat it as a network-behaviour monitor, not a process monitor.

The passive guarantee, layer by layer →

Data centres

SPAN or TAP into a monitoring enclave

Very high east-west volume, a large population of near-identical hosts, and a strong operational incentive not to interrupt anything. Uniform estates are exactly where per-host baselines stop being discriminative.

What the posture yields

Floods attributed to the target
The destination perspective keeps one flood as one event. Attributing it to one of 250 spoofed sources would mis-word the alert and scatter a single incident across hundreds of subjects.
Pair-perspective analysis
Beaconing is a property of a source-to-destination pair, not of a host, so periodicity and stability are measured where they actually live.
Bounded state under a spoofed flood
One entity per source address is a memory-exhaustion strategy, so the feature engine and the baseline store are both bounded and count their evictions.

What it does not do Per-host baselines are weak where hosts are clones of each other. Do not read anomaly evidence as host-specific truth on a uniform estate, and do not deploy it as the only discriminator for a datacentre segment.

How the flood detector decides →

Banking and telecom

Hardware diode, or SPAN into a segregated enclave

High sustained volume, an availability requirement that rules out anything on the path, and a supervisory expectation of demonstrable process rather than an assertion that one exists.

What the posture yields

Verifiable record integrity
The alert ledger hashes the verdict, evidence and lineage together and is verified through an endpoint, so a stored decision can be checked for alteration after the fact.
An auditable model lifecycle
Every promotion appends an actor, a reason and the gate results, including gates accepted as failing. “We knew and decided anyway” stays auditable instead of becoming folklore.
A narrow, declared attack surface
Mutating routes require an operator token. With no token configured they are permitted only while the API is bound to loopback; binding to a routable address without one disables them outright.

What it does not do Neither the ledger nor the promotion log is externally signed — integrity is by hash, authenticity is not established. Known gaps are listed rather than hidden: no authentication on read routes, no role-based authorisation, no TLS, no rate limiting.

The governance evidence →

SOC and CERT operations

Any of the three — the pipeline is the same

The scarce resource is the time between a signal and an explanation of it. Alert count is not the problem to optimise, and a console that cannot be trusted about its own state is worse than no console.

What the posture yields

Signal to story
One threat class is an alert. Two or more distinct classes on one subject within 300 seconds become an incident, which is the unit an analyst actually works.
Corroboration you can recompute
Confidence is the primary value plus 0.08 per distinct corroborating detector, capped at 0.99 — bounded, monotonic, and recalculable from the stored detector contributions rather than taken on trust.
Honest system state
A disconnected alert stream reads as disconnected. A sensor that is not publishing is named as such. A detector without a model reports itself unavailable with a reason instead of silently returning nothing. A zero is a measurement; absence of data is not a zero.

What it does not do No auto-triage and no autonomous promotion. An analyst labels an alert; a person decides whether a model reaches production. Neither step can be skipped by a pipeline.

The governance lifecycle →

Cyber R&D and evaluation

Offline PCAP replay into a workstation

A prototype has to be inspectable end to end or it is evidence of nothing. In an unidirectional setting, evaluation cannot be rescued by going back and asking the source a question, so the limits of the capture have to be designed for rather than discovered later.

What the posture yields

Versioned contracts
Event, feature and alert schemas are versioned independently. An unknown version is a validation error rather than a best-effort parse, and bumping the feature version invalidates every model trained against the old one.
A committed runtime bundle
Four champion artifacts with recorded hashes, so a fresh checkout needs no training, no artifact download and no promotion. Verification is a read-only script that makes no promotion, file or database change.
Evaluation against real captures
Public benign and malicious captures were run through the real pipeline and through raw PCAP transfer replay, with rejected candidates recorded alongside accepted ones.

What it does not do The analytical store is SQLite with a single writer. A ClickHouse migration is a planned seam rather than a measured one, and horizontal multi-worker scaling is available through consumer groups but was not benchmarked.

The evidence base, and its gaps →

What this page does not claim

Stated here rather than left implied, so nothing above has to be read against it.

No return path — and no claims past it

  • No customer, deployment or engagement is named or implied on this page.
  • No performance figure is quoted for any estate. The recorded benchmarks are on named hardware against fixtures and are published on the capabilities page with their conditions attached.
  • No threat map, no detection-rate claim, and no figure derived from anyone's production traffic.
  • No figure is quoted for a deployment that has not run this pipeline against this traffic.

For what the system actually does, read the detector specifications. For what has been measured, and what has not, read the research notes.