The forensic black box for your network
Trace records every packet that crosses your SPAN — full-fidelity, not just logs — so after a leak, a targeted attack, or any investigation you can pull the exact raw traffic to the minute. ML-driven NDR catches what static rules miss, and a self-hosted AI analyst answers in plain language, all on your own hardware.
From wire to verdict
Trace records the raw wire, finds what matters, and answers in plain language.
- 1
Record
Capture every packet on your SPAN at line rate — lossless, timestamped, indexed, and searchable for weeks.
- 2
Detect
Machine-learning NDR runs over the live traffic and fuses sensor signals into verdicts on the attacks and anomalies rules miss.
- 3
Investigate
Replay the exact raw traffic to the minute, detonate suspicious payloads on a local GPU, and ask the network questions in plain language.
From wire to verdict, in one place.
The capture view streams flows at line rate onto a searchable timeline, with ML classification and anomaly scoring riding alongside; ask the network a question in plain language and the self-hosted analyst returns the query, the packets, and a correlated incident verdict — all on your own appliance.
What it does
Full-fidelity black box
Records every packet on your SPAN, indexed and searchable — replay the raw wire to the exact minute, weeks after the fact. The firewall only kept the log; Trace kept the evidence.
Live & real-time capture
Capture during a DDoS or an active incident as it unfolds — something you can never pull from a live firewall or switch in debug mode.
AI-powered NDR
Machine-learning detection over live traffic surfaces the attacks and anomalies static rules miss, fusing every sensor signal into a single verdict.
Asset & IoT/OT visibility
Because Trace listens to live traffic and ties into endpoint management, Active Directory and Infoblox, it sees more assets — including IoT and OT — than tools built only for the job.
Local GPU malware analysis
A local GPU and on-device LLM detonate and explain suspicious files and payloads, with nothing ever leaving your environment.
Self-hosted AI analyst
Ask the network in plain language — get the query, the packets, and an explanation — from a model that runs entirely on your own hardware, not a vendor's cloud.
Why teams run Trace
- ✓ Pull the actual packets behind a leak or targeted attack — to the exact minute, weeks later — not just the firewall's log.
- ✓ Capture live through a DDoS or active incident, the moment you can't get from a firewall in debug mode.
- ✓ Catch the attacks and anomalies static rules miss with machine-learning NDR over real traffic.
- ✓ See more assets — including IoT and OT — by listening to the wire, not just polling an inventory.
- ✓ Investigate in plain language with a self-hosted AI analyst and local GPU malware analysis — nothing leaves your hardware.
Live capture
last 24hSee Seraxi on your environment.
Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.