Network Detection & Response · IT + OT

Advanced network detection & adversary emulation for IT, OT and AI — the layer that completes your defense.

Your endpoint and perimeter tools are essential. Lumetrace adds the network layer — passive, protocol-aware visibility — and proves exactly where you're covered.

Why network-layer

Endpoint security is vital — but attackers move across the network.

EDR, MDR and firewalls do critical work at the endpoint and perimeter. Yet lateral movement, command-and-control, data exfiltration and OT control commands all play out across the network — often beyond an endpoint agent's view, and on devices (PLCs, RTUs, IoT) that can't run one at all. Lumetrace is the complementary layer that watches the wire, so a coordinated attack has nowhere to hide.

🛰️

Defense in depth

A passive network sensor that strengthens — never replaces — your existing security investments.

🏭

IT and OT

Unified visibility across enterprise IT and industrial OT/ICS, including unmanaged and agentless devices.

🔌

Passive by design

Deploys on a SPAN/mirror port. Never inline, never an agent — zero impact on production traffic.

The platform

Lumetrace NDR — see the whole attack, not just an alert.

Protocol-aware network detection that reconstructs the full kill chain and explains it in plain language, mapped to MITRE ATT&CK and ATT&CK for ICS.

  • Kill-chain Attack Stories: recon → C2 → lateral movement → impact, correlated across signals
  • OT/ICS coverage: Modbus, DNP3, S7comm, EtherNet/IP, BACnet, OPC UA — with passive device identity (vendor, model, serial, firmware) read from the devices’ own protocol replies, plus CVE/KEV mapping
  • AI-driven OT reconnaissance: engineering-artefact discovery and OT asset-name enumeration, attributed to AI only when machine agency is independently evidenced
  • Executive, incident & technical reports — board-ready, in clear English
  • Threat-intel enrichment and C2 beacon detection, including low-and-slow channels built to evade volume-based alerting

Coverage at a glance

Enterprise IT detection
OT / ICS protocol analysis
OT device identity (vendor / model / serial)
AI attack detection + MITRE ATLAS
MITRE ATT&CK + ATT&CK for ICS
Passive deployment (SPAN / mirror)
Agent on every endpointnot required
New — AI detection

AI changed the attack surface. We detect it on the wire.

Three distinct problems, not one: attacks against your AI systems, AI used as an attacker’s tool, and staff sending your data to AI services. Every finding is mapped to MITRE ATLAS and carries the evidence behind it.

  • Attacks on your own AI — model-extraction query patterns, model-weight exfiltration, vector-store / RAG poisoning writes, and unvetted external MCP servers reached by your agents
  • AI used against you — AI-driven OT reconnaissance, corpus harvesting for training or RAG, and crawler-identity verification that tells a genuine AI crawler from anything wearing its name
  • Shadow AI & governance — which hosts reach which AI services across the major provider families, source code sent to assistants, and runaway inference spend with an estimated token count
  • Evidence, not just a verdict — what was targeted, what the attacker actually obtained, and who was doing it. A refused attempt is reported as attempted, never as a breach

What we detect — and what we don’t

Model extraction & weight exfiltration
Vector-store / RAG poisoning
AI-driven OT reconnaissance
Shadow AI & runaway inference spend
Prompt injection & output handlingnot network-visible

Prompt injection, insecure output handling and model overreliance live in the prompt and tool-call layer, which no passive sensor can see. We say so rather than claim them — closing that gap needs a different class of telemetry, not a detector we have quietly omitted.

Detection-Gap Assessment

Reconnaissancedetected
Command & Controlgap
Lateral movementgap
Data exfiltrationgap
Coverage scoremeasured, not guessed
Services

Prove what your stack catches — and what to improve.

We safely emulate a real attacker's kill chain in your staging environment using established, authorized tooling, with Lumetrace as the ground-truth referee. You receive a plain-English report comparing what actually happened to what your existing tools detected.

  • Authorized, assumed-breach adversary emulation — staging only, fully scoped
  • A dual-view detection-gap analysis: your tools vs. ground truth, per attack stage
  • Prioritised, plain-English remediation that strengthens your current investments

Find your blind spots before an attacker does.

Add the network layer to your defense, and measure your true detection coverage across IT and OT.

Talk to us — [email protected]
About

Lumetrace

Lumetrace Ltd is a cybersecurity company building network-layer detection and adversary-emulation capabilities for IT and OT environments. We help organisations see more of their network, validate their existing defenses, and close the gaps that matter.