Flowmon

Network and security monitoring for threat investigation and performance analysis.

Relevant where network and security teams need traffic evidence across distributed and cloud-connected environments.

Investigate network threats and performance issues

Network and security teams often need to distinguish suspicious activity from normal traffic while also investigating network or application performance deviations. That work depends on having relevant traffic and security data available for analysis.

Flowmon analyses network traffic and security data to detect threats and behavioural anomalies, investigate malicious activity and examine performance issues. It provides retained data and packet evidence for forensic analysis, alongside alerts and automated root-cause analysis for routine investigations.

Where Flowmon is used

Flowmon is useful for investigating suspicious network activity, including threat hunting and analysis of anomalous network or user behaviour. It also supports investigation of network and application performance deviations, using traffic data, alerts and automated root-cause analysis. Retained network security data and on-demand or on-event packet capture provide additional evidence for forensic work.

Fits within these solutions

Network Traffic Analysis
Network Detection & Response
Network Performance Monitoring
Ransomware Protection
Digital Forensics
Insider Threat Detection

Suitable environments

Flowmon is applicable across on-premises, public cloud, hybrid cloud, virtual, edge and branch-network environments. It can normalise proprietary and third-party data from diverse traffic environments and formats for analysis in one platform.

Benefits

Investigate suspicious activity

Gives security teams data to examine threats and anomalous network or user behaviour.

Analyse performance deviations

Provides alerts and traffic data for investigating network and application performance issues.

Retain network evidence

Keeps network security data available for later forensic analysis.

Reduce routine investigation work

Automated root-cause analysis supports routine investigations of network and application issues.

Capabilities

Threat and anomaly detection

Detects cyber threats and network or user behaviour anomalies using AI and machine learning.

Threat hunting

Supports investigation of malicious activity and its root cause using network and security data.

Forensic data retention

Collects, stores and retrieves network security data for forensic analysis.

Performance monitoring

Monitors network and application performance and alerts on deviations.

Automated root-cause analysis

Automates root-cause analysis for routine network and application investigations.

Packet capture

Provides full-packet capture on demand and in response to events.

Common Use Cases

Network threat hunting

Analyse network and security data to investigate potentially malicious activity.

Behaviour anomaly investigation

Examine detected anomalies in network or user behaviour using available traffic data.

Performance issue analysis

Investigate network and application performance deviations and their likely root causes.

Forensic network analysis

Retrieve retained network security data and packet evidence for forensic analysis.

Diverse traffic analysis

Normalise proprietary and third-party data from diverse traffic environments and formats.

Resources

More Resources

How would you like to proceed?