Network detection & response

See the 68% of traffic that never crosses your perimeter

Most enterprise traffic is east-west, encrypted, and invisible to a firewall built to watch the edge. Guardian Sentinel's sensors read every conversation inside the estate, identify malicious behaviour in encrypted sessions without decrypting them, and block lateral movement at the hop where it starts.

68% Of enterprise traffic is east-west and never reaches a perimeter device
94% Of observed sessions are encrypted — analysed without decryption
40Gbps Sustained inspection per hardware sensor, full metadata extraction
11s Median time from first lateral hop to automated segment block
0 Private keys required — Sentinel never asks to break your TLS

Sensor placement

Coverage designed around traffic, not around rack diagrams

A sensor at the internet edge tells you about 32% of the picture. Sentinel places collection where the conversations actually happen: on core uplinks, between application tiers, inside cloud VPCs and on the branch links that terminate somewhere nobody has audited since 2019.

Internet north-south, 32% of volume Edge firewall Core fabric spine-leaf, 400G uplinks SPAN, TAP or ERSPAN feed Campus & branch 142 sites, SD-WAN Cloud VPC / VNet AWS, Azure, Google Application tier web, API, middleware 4,180 workloads Data tier databases, file, backup crown-jewel assets east-west — 68% S1 S2 S3 S4 S5 S6 S1 Edge sensor — north-south, inline capable S2 Branch uplink — virtual sensor on SD-WAN hub S3 VPC traffic mirror S4/S5 Tier uplinks — TAP or SPAN aggregation S6 East-west sensor — the traffic nothing else sees Agent-derived flow fills any remaining gap

Scroll horizontally to see the full topology on a small screen.

East-west visibility

The perimeter tells you an attacker arrived. East-west tells you what they did next.

Once an adversary has a foothold, everything that matters happens between your own systems: enumeration, credential reuse, share mounting, database access, staging. Sentinel treats internal traffic as a first-class detection surface rather than an afterthought.

Every internal conversation is modelled

Sentinel learns which workloads legitimately talk to which, over what protocols, at what volumes and at what hours — per service, not per subnet.

Flows carry identity

Because the agent and the sensor share an entity graph, an SMB session is attributed to a named human or service account, not to an IP address that changed at lunchtime.

Protocol-aware analysis

Full parsing for SMB, Kerberos, LDAP, RDP, DNS, HTTP, MySQL, PostgreSQL, MSSQL, SSH, RPC, NFS, Kafka and 68 more — including the odd ones OT networks rely on.

Segmentation you can prove

Sentinel shows what your segmentation policy actually permits versus what it intends, and flags every flow that crosses a boundary it should not.

Unmanaged devices are covered too. Printers, cameras, building management controllers, medical devices and contractor laptops cannot take an agent. The sensor profiles them passively, assigns a device class and behavioural baseline, and alerts when a thermostat starts speaking LDAP.

Encrypted traffic analysis

Ninety-four percent of your traffic is encrypted. Decrypting it is not the answer.

TLS interception is expensive, fragile, blocked by certificate pinning, hostile to privacy regulation and increasingly defeated by encrypted client hello. Sentinel identifies malicious sessions from their observable shape instead — fingerprints, cadence, size sequences and directionality.

Outbound connection cadence, same host, one hour Human browsing session Bursty, clustered, long idle gaps — interval standard deviation 214 s Beaconing implant Fixed 3.8-minute interval, 2.1 s jitter — periodicity score 0.96, severity high 00:00 00:15 00:30 00:45 01:00 No decryption required. Detection uses cadence, TLS fingerprint and byte-ratio asymmetry alone.

Scroll horizontally to see the full chart on a small screen.

Lateral movement

Break the chain at hop two, not at hop six

Breakout time — the interval between initial access and the first lateral hop — fell to 41 minutes in 2026. Sentinel scores the path an attacker is building as it forms, and blocks the next hop rather than reporting the last one.

Attack path, reconstructed automatically as it formed Workstation File server Jump host Domain controller Backup phished session T+00:00 share enumeration T+04:12 credential reuse T+09:38 LDAP recon T+11:02 BLOCKED T+11:13 SMB WinRM LDAP RDP Path score crossed the containment threshold at hop three. Sentinel blocked the fourth hop 11 seconds later and simultaneously isolated the workstation, revoked the reused credential and pushed a segment rule to the fabric. Attacker dwell time inside the estate: 11 minutes 13 seconds. Crown-jewel assets reached: none.

Scroll horizontally to see the full attack path on a small screen.

41min Global median breakout time, 2026 Threat Landscape Report
11s Median Guardian time from hop detection to segment block
2.3 Median hops an intrusion completes before containment
98% Of blocked paths never reached a tier-one asset

Deployment

Six ways to get traffic into Sentinel

Most estates use three of these at once. Sensors self-register to the tenant, pull policy automatically and require no local storage or management interface of their own.

Sensor form factors and their operating envelopes. All sensors emit the same normalised records into the Sentinel Data Fabric.
Form factor Typical placement Traffic source Sustained throughput Inline blocking
Virtual sensor Data centre core, DMZ, SD-WAN hub SPAN, ERSPAN, VXLAN mirror Up to 10 Gbps Via firewall or NAC integration
Hardware appliance GN-4200 Campus core, medium data centre Optical or copper TAP, SPAN 20 Gbps Yes, fail-open bypass pairs
Hardware appliance GN-8800 Large data centre, internet edge Optical TAP, packet broker 40 Gbps Yes, fail-open bypass pairs
Cloud mirror sensor AWS, Azure and Google Cloud VPCs VPC traffic mirroring, vTAP Up to 8 Gbps per instance Via security group or NSG update
Container sensor Kubernetes clusters, service mesh eBPF on each node, DaemonSet Node line rate Yes, via network policy
Agent-derived flow Anywhere an endpoint agent already runs Host socket telemetry, no mirror needed N/A Yes, host firewall

Scroll the table horizontally to see every column.

Sensors carry no persistent traffic storage by default. Optional rolling packet capture is written encrypted to local disk and released only on an authorised investigation.

Enforcement where it already lives

Sentinel pushes containment through the controls you own: Palo Alto, Fortinet, Cisco and Check Point firewalls, Cisco ISE and Aruba ClearPass for NAC, plus native security groups, NSGs and Kubernetes network policy.

Fail-open by design

Inline sensors ship with hardware bypass pairs. Power loss, software fault or an upgrade never becomes a network outage — traffic passes and the sensor rejoins when it is healthy.

Zero-trust groundwork

The observed communication map becomes a proposed segmentation policy you can review, simulate against 30 days of real traffic and export directly to your enforcement point.

Network questions

What network architects ask us first

Do we need sensors if every host already runs the agent?

Not for managed hosts — agent-derived flow gives you attributed socket-level visibility with no mirror infrastructure. Sensors matter for what cannot take an agent: appliances, printers, cameras, OT controllers, medical devices, contractor and BYOD endpoints, and any segment where you want inline blocking independent of the host.

How much storage does full packet capture need?

Metadata-only operation, which is the default, uses roughly 0.4% of inspected volume. Triggered capture writes only the sessions surrounding a detection, typically 2–6 GB per incident. Continuous capture is available and sized at approximately 430 GB per gigabit per day if you need it for regulatory reasons.

Will inline sensors add latency to production traffic?

Measured added latency is under 90 microseconds at 40 Gbps for the GN-8800. Most customers start in TAP or SPAN mode with enforcement delegated to an existing firewall, and move to inline only for specific high-risk segments.

Can Sentinel replace our NDR appliance fleet outright?

In most displacements, yes — and the consolidation usually reduces appliance count because agent-derived flow eliminates sensors that existed only to watch managed servers. Guardian will map your current sensor estate to a proposed Sentinel design during evaluation, including a like-for-like coverage comparison.

How do you handle OT and ICS segments?

Passively. The sensor is deployed off a TAP with no transmit path into the OT segment, parses Modbus, DNP3, S7comm, EtherNet/IP and BACnet, and never actively scans. Detection and asset inventory are read-only; enforcement, if any, happens at the IT/OT boundary. See energy & utilities for reference designs.

What about traffic that never touches our network at all?

Remote workers going straight to SaaS, and cloud-to-cloud traffic, are covered by the endpoint agent and by cloud security respectively. That is the point of a single data layer — the network module is one contributor to a picture that does not depend on traffic being backhauled anywhere.

We had east-west blindness we could not price. Six weeks after the sensors went in, Sentinel showed us 1,400 flows crossing a segmentation boundary we believed had been enforced since 2021. That finding alone paid for the programme.
Tomas Oberg Head of Network Security, Baltic Energy Partners

Find out what your east-west traffic is actually doing

A two-week visibility assessment with a virtual sensor on one core uplink. No agents, no inline change, and a written findings report at the end whether or not you proceed.