Seraxi
Seraxi Trace

The forensic black box for your network

Trace records every packet that crosses your SPAN — full-fidelity, not just logs — so after a leak, a targeted attack, or any investigation you can pull the exact raw traffic to the minute. ML-driven NDR catches what static rules miss, and a self-hosted AI analyst answers in plain language, all on your own hardware.

From wire to verdict

Trace records the raw wire, finds what matters, and answers in plain language.

  1. 1

    Record

    Capture every packet on your SPAN at line rate — lossless, timestamped, indexed, and searchable for weeks.

  2. 2

    Detect

    Machine-learning NDR runs over the live traffic and fuses sensor signals into verdicts on the attacks and anomalies rules miss.

  3. 3

    Investigate

    Replay the exact raw traffic to the minute, detonate suspicious payloads on a local GPU, and ask the network questions in plain language.

See it in action

From wire to verdict, in one place.

The capture view streams flows at line rate onto a searchable timeline, with ML classification and anomaly scoring riding alongside; ask the network a question in plain language and the self-hosted analyst returns the query, the packets, and a correlated incident verdict — all on your own appliance.

trace · capture Live capture eth4 · span port · 0 drops · indexed retention 14d THROUGHPUT 9.4 Gbps CAPTURED 42.7 TB PACKETS/S 1.31 M CAPTURE VOLUME · packets/s now anomaly +3.2σ PROTO SOURCE DESTINATION BYTES ML CLASS TLS 1.3 10.4.2.18 edge-gw-02:443 1.8 MB web · benign open › DNS 10.4.2.51 8.8.8.8:53 12 KB tunnel-like open › TLS 1.2 10.6.9.7 185.x.x.44:443 640 KB C2 beacon open › SMB 10.4.5.30 10.4.5.31:445 94 MB lateral · scan open › QUIC 10.4.2.18 fcdn-04:443 3.2 MB media · benign open ›
Capture — line-rate flow timeline, throughput, and ML/anomaly strip
trace · ai analyst Ask the network self-hosted · runs on appliance “Did finance-ws-12 talk to anything suspicious last night?” plain language · no traffic leaves the appliance Yes. At 02:14 it opened a TLS session to 185.x.x.44 with a regular 60-second beacon — consistent with C2. 41 flows, 2.1 MB out. The full packets are retained and linked below. 41 flows · pcap 02:14 → 06:02 verdict: C2 GENERATED QUERY flow.host == "finance-ws-12" and ts between 02:00..06:00 and ml.beacon_score > 0.8 | sort bytes_out ALERT FUSION 4 signals · 1 incident ML anomaly beacon periodicity 60s ±2 IDS sig ET MALWARE · TLS JA3 match Asset graph host = finance-ws-12 Threat intel 185.x.x.44 · known C2 INCIDENT · C2 beacon finance-ws-12 · confidence 0.94 · critical Triage
AI analyst — plain-language Q&A, generated query, and fused incident

What it does

01

Full-fidelity black box

Records every packet on your SPAN, indexed and searchable — replay the raw wire to the exact minute, weeks after the fact. The firewall only kept the log; Trace kept the evidence.

02

Live & real-time capture

Capture during a DDoS or an active incident as it unfolds — something you can never pull from a live firewall or switch in debug mode.

03

AI-powered NDR

Machine-learning detection over live traffic surfaces the attacks and anomalies static rules miss, fusing every sensor signal into a single verdict.

04

Asset & IoT/OT visibility

Because Trace listens to live traffic and ties into endpoint management, Active Directory and Infoblox, it sees more assets — including IoT and OT — than tools built only for the job.

05

Local GPU malware analysis

A local GPU and on-device LLM detonate and explain suspicious files and payloads, with nothing ever leaving your environment.

06

Self-hosted AI analyst

Ask the network in plain language — get the query, the packets, and an explanation — from a model that runs entirely on your own hardware, not a vendor's cloud.

Why teams run Trace

  • Pull the actual packets behind a leak or targeted attack — to the exact minute, weeks later — not just the firewall's log.
  • Capture live through a DDoS or active incident, the moment you can't get from a firewall in debug mode.
  • Catch the attacks and anomalies static rules miss with machine-learning NDR over real traffic.
  • See more assets — including IoT and OT — by listening to the wire, not just polling an inventory.
  • Investigate in plain language with a self-hosted AI analyst and local GPU malware analysis — nothing leaves your hardware.
trace · sensor-01 live

Live capture

last 24h
9.4 Gbps
Throughput
30 d
Full retention
2.1 M
Active sessions
0.00 %
Packet drops
Throughput peak 12.0 Gbps

See Seraxi on your environment.

Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.

Book a demo