Network Detection & Response · IT + OT + AI

Your endpoints are watched.
Your network is not.

Your endpoint and perimeter tools are essential, and they stay. Lumetrace adds what they cannot see: passive, protocol-aware visibility inside the network, and a measured answer to what your current stack actually catches.

The blind spot

Most enterprises cannot say what one internal host said to another.

Ask your team what crossed the firewall last night and you will get an answer. Ask what one server said to another server at three in the morning, and in most enterprises there is no record to consult. Internal traffic is where an intruder does the work that matters: finding the file shares, reaching the finance system, stepping into the plant network. Without network detection, none of it is being examined, so none of it raises a hand.

📣

You are usually told, not alerted

With no network evidence, the first notice tends to come from outside: a bank flagging fraudulent transfers, a regulator asking a question you cannot answer, a customer whose data has surfaced, or a ransom note on a Monday morning.

📤

Information leaves quietly

Credential theft, customer databases, contracts, drawings and process recipes. Exfiltration happens on the network. If nothing reads the network, the theft leaves nothing you can go back and examine.

🛑

Ransomware stops you, or a controller breaks you

Ransomware does not begin with encryption. It begins with reconnaissance, credential reuse across shares, a command-and-control channel and backup deletion. In a plant it can end with a write command to a controller that should only ever be read. Each step is a network action first and a business loss second.

None of this needs a nation-state adversary. It needs only that nobody is watching the inside. That is a solvable problem: a passive sensor on a mirror port, reading traffic you already have, so the next incident comes with evidence and the one after that comes with a warning.

Why network-layer

Endpoint security is vital — but attackers move across the network.

EDR, MDR and firewalls do critical work at the endpoint and perimeter. Yet lateral movement, command-and-control, data exfiltration and OT control commands all play out across the network — often beyond an endpoint agent's view, and on devices (PLCs, RTUs, IoT) that can't run one at all. Lumetrace is the complementary layer that watches the wire, so a coordinated attack has nowhere to hide.

🛰️

Defense in depth

A passive network sensor that strengthens — never replaces — your existing security investments.

🏭

IT and OT

Unified visibility across enterprise IT and industrial OT/ICS, including unmanaged and agentless devices.

🔌

Passive by design

Deploys on a SPAN or mirror port, or on a network tap where a switch cannot mirror. Never inline and never an agent, so the sensor is not in the path of a single production packet. It does need a mirror configured on your switch, which is a planned change on your side, and we say so rather than calling the whole job zero-touch.

The platform

Lumetrace NDR — see the whole attack, not just an alert.

Protocol-aware network detection that reconstructs the full kill chain and explains it in plain language, mapped to MITRE ATT&CK and ATT&CK for ICS.

  • Kill-chain Attack Stories: recon → C2 → lateral movement → impact, correlated across signals
  • OT/ICS coverage: Modbus, DNP3, S7comm, EtherNet/IP, BACnet and OPC UA, with device identity (vendor, model, order number, firmware) taken from identity replies your own systems already ask for. We send nothing to your equipment, so coverage is whatever your estate reveals, and the report names the devices it could not identify rather than leaving a gap you cannot see
  • AI-driven OT reconnaissance: engineering-artefact discovery and OT asset-name enumeration, attributed to AI only when machine agency is independently evidenced
  • Executive, incident & technical reports — board-ready, in clear English
  • Threat-intel enrichment and C2 beacon detection, including low-and-slow channels built to evade volume-based alerting

Coverage at a glance

Enterprise IT detection
OT / ICS protocol analysis
OT device identity (vendor / model / serial)
AI attack detection + MITRE ATLAS
MITRE ATT&CK + ATT&CK for ICS
Passive deployment (SPAN / mirror)
Agent on every endpointnot required
New — AI detection

AI changed the attack surface. We detect it on the wire.

Three distinct problems, not one: attacks against your AI systems, AI used as an attacker’s tool, and staff sending your data to AI services. Every finding is mapped to MITRE ATLAS and carries the evidence behind it.

  • Attacks on your own AI — model-extraction query patterns, model-weight exfiltration, vector-store / RAG poisoning writes, and unvetted external MCP servers reached by your agents
  • AI used against you — AI-driven OT reconnaissance, corpus harvesting for training or RAG, and crawler-identity verification that tells a genuine AI crawler from anything wearing its name
  • Shadow AI & governance — which hosts reach which AI services across the major provider families, source code sent to assistants, and runaway inference spend with an estimated token count
  • Evidence, not just a verdict — what was targeted, what the attacker actually obtained, and who was doing it. A refused attempt is reported as attempted, never as a breach

What we detect — and what we don’t

Model extraction & weight exfiltration
Vector-store / RAG poisoning
AI-driven OT reconnaissance
Shadow AI & runaway inference spend
Prompt injection & output handlingnot network-visible

Prompt injection, insecure output handling and model overreliance live in the prompt and tool-call layer, which no passive sensor can see. We say so rather than claim them — closing that gap needs a different class of telemetry, not a detector we have quietly omitted.

AI Assurance

Your own AI can drift, or go rogue. Both show up before anyone complains.

These are two different failures and most vendors sell them as one. Rogue is your approved AI doing something it was never approved to do, which is a scope question the network answers well. Drift is your approved AI still doing its job, worse, which is a quality question the network can only indicate. We report them separately, and every finding states how much of the picture we actually have.

🚦

Rogue: it did something nobody approved

  • Shadow AI in genuine use that your approved-AI register never declared
  • Zombie AI, a service with real history that has gone quiet for weeks while its egress path and key stay open
  • Destinations, models and tools checked against your register, so the word approved means something
  • New external tool servers your agents have started reaching
  • Unattended autonomy, activity outside your declared working hours in your declared timezone
  • Consumption runaway and agent loops, reported as consumption rather than currency
How rogue detection works
📉

Drift: it still works, but not as well

  • Provider endpoint and client change, dated, and stated plainly as not proof that the model changed
  • A rolling baseline that admits it is learning and reports nothing until it holds fourteen daily samples
  • Sustained change, not a bad afternoon, expressed as a percentage with the date it began
  • With your AI gateway metadata, a real model or model-version change becomes certainty instead of inference
How drift detection works

What this does not do

Rogue behaviour and scope violationsdetected
Drift indicators from the networkindicative
Model version change, with gateway metadatacertainty
Hallucination, prompt injection, reasoning qualitynot network-visible
Your prompt textnever collected

Content fields are rejected on arrival by name, not filtered afterwards. A number derived from packets is never presented to you as a quality score.

Detection-Gap Assessment

Reconnaissancedetected
Command & Controlgap
Lateral movementgap
Data exfiltrationgap
Coverage scoremeasured, not guessed
Services

Prove what your stack catches — and what to improve.

We safely emulate a real attacker's kill chain in your staging environment using established, authorized tooling, with Lumetrace as the ground-truth referee. You receive a plain-English report comparing what actually happened to what your existing tools detected.

  • Authorized, assumed-breach adversary emulation — staging only, fully scoped
  • A dual-view detection-gap analysis: your tools vs. ground truth, per attack stage
  • Prioritised, plain-English remediation that strengthens your current investments
Straight answers

Ransomware, C2 and data theft: what network detection actually gives you.

The questions enterprises ask us first, answered without sales language.

What is NDR, and why do enterprises here need it?

NDR means network detection and response. It reads the traffic moving inside your network, not just what crosses the perimeter or what happens on a managed laptop. Without it, an intruder already inside has no observer: lateral movement, command-and-control and data theft all happen on the network. Most enterprises can describe their firewall and endpoint coverage in detail, but cannot say what one internal server said to another overnight.

Can you catch ransomware before the files are encrypted?

Ransomware is not one event. Before encryption there is reconnaissance, credential use across file shares, a command-and-control channel back to the operator, staging of data for extortion, and very often deletion of your backups. Every one of those steps is visible on the network. Lumetrace surfaces that sequence as a single story, so there is a chance to act during staging instead of reading a ransom note on Monday.

What is C2, or command-and-control detection?

C2 is the channel an intruder uses to control a machine inside your network. Modern C2 is built to look ordinary: long gaps between check-ins, ordinary ports, real cloud domains, encrypted payloads. We detect the behaviour of the channel rather than relying only on a blocklist, including low-and-slow beacons built to defeat volume-based alerting, and DNS and ICMP channels used to slip past web filtering.

How would we know if someone is stealing our information?

Stealing data is a network event. Customer records, contracts, drawings, source code and process recipes all have to travel somewhere. We watch for unfamiliar destinations, unusual volumes, encoded or tunnelled transfers, and uploads to unsanctioned cloud and AI services, and we report what actually left rather than only that something looked odd.

Does this replace our EDR, MDR or firewall?

No, and we would not sell it that way. Endpoint and perimeter tools do essential work and they stay. Lumetrace adds the layer they cannot see, including the devices that can never run an agent at all: PLCs, RTUs, printers, cameras and IoT. It is deliberately complementary, and the Detection-Gap Assessment is designed to make your existing tools measurably better.

Who it is for

Two very different conversations. Start with the one that is yours.

Enterprises come to us in one of two states, and they need opposite first steps. Tell us which one you are in and we will not waste your time on the other.

🚨

You think something may already be inside

Odd outbound connections nobody can explain. A finding your managed service closed as inconclusive. A server that reboots on its own. An auditor's question you could not answer. If you are already worried, what you need first is evidence, not a twelve-month procurement cycle.

  • A passive sensor on a mirror port, reading traffic you already carry
  • Nothing installed on a production host, nothing placed inline
  • Findings in plain language, each one shown with the traffic behind it
  • A written answer you can put in front of your board or your regulator-facing team
Ask for a network visibility review
🎯

You want to know before it happens

Your defenses may well be sound. The honest question is which stages of a real intrusion your current stack would actually catch, and no datasheet can answer that. So we measure it: an authorized attacker's kill chain, run in your staging environment, scored stage by stage against what your own tools reported.

  • Authorized, fully scoped, staging only, agreed in writing before anything runs
  • Per-stage coverage measured against ground truth, not estimated
  • Prioritised fixes that strengthen the tools you have already paid for
  • Evidence you can reuse in your own risk and assurance reporting
Ask for a Detection-Gap Assessment

We work with the kinds of enterprises that cannot afford a quiet week of unexplained traffic: banking, payments and insurance; logistics, shipping and port operations; manufacturing and utilities with live OT; healthcare; professional services holding client data; and government-linked operators. If you hold data worth stealing or run a process worth stopping, the network layer is not optional.

Contact us

Lumetrace is an Asia-based cybersecurity company working with enterprises in Singapore and Hong Kong. Whichever market you are in, you deal with the people who built the detection, in your own working hours.

  • Email: [email protected]
  • Your data: the sensor and its analysis can run on your own premises or in a region you choose, so captured traffic does not have to leave your jurisdiction.
Something may already be inside I want to test my coverage

Find your blind spots before an attacker does.

Add the network layer to your defense and measure your real detection coverage across IT, OT and AI. One conversation, in your time zone, with the engineers who built it.

Talk to us at [email protected]
About

Lumetrace

Lumetrace builds network-layer detection and adversary-emulation capability for IT, OT and AI environments. We help enterprises see more of their own network, validate the defenses they have already invested in, and close the gaps that matter, without ripping anything out.

We are engineers, not a reseller. The detection is ours, the reports are written by the people who built it, and we will tell you plainly what we cannot see as well as what we can.