The article describes Security Insights, an add-on to BlueCat LiveWire accessible through LiveNX that brings packet-level analysis and flow telemetry to the network edge to deliver fast, actionable security intelligence. It addresses the real-world problem of fragmented visibility between network and security teams and limitations of traditional NDR—such as high cost, latency, and blind spots—by performing edge-first analytics, correlating LiveNX flow data with LiveWire packet captures, and integrating findings into SIEM, SOAR, and XDR. Key outcomes include faster detection and response measured in minutes instead of hours, improved forensic depth without backhauling packet data, and unified, multi-telemetry visibility across LAN, WAN, SD-WAN, data center, and cloud environments.
How does Security Insights differ from traditional NDR solutions?
Security Insights differs from traditional NDR by operating at the network edge and using existing LiveNX flow telemetry and LiveWire packet captures rather than centralizing massive packet datasets in the cloud. This edge-first approach reduces data movement, latency, and cost while preserving full packet-forensic depth. It ingests multiple telemetry sources (NetFlow, IPFIX, sFlow, Cisco high-speed and unified logging), correlates them into a single view across LAN, WAN, SD-WAN, data center, and cloud, and maps detections to frameworks like MITRE ATT&CK and OWASP for easier integration with SIEM, SOAR, and XDR.
What types of detections and use cases does Security Insights support?
Security Insights identifies a wide range of anomalies and suspicious behaviors, including unexpected encrypted traffic on non-standard ports (e.g., malicious tunneling/T1571), web service C2 communications discovered via threat intel indicators (T1102), and unusual or self-signed TLS certificate activity indicating forged certificates (T1587.003). Typical workflows combine automated detection, LiveNX visualization and flow correlation, and LiveWire packet capture for forensic validation. Outcomes include rapid isolation of compromised devices, blocking of malicious domains, export of forensic evidence to SIEM, and reduced dwell time.
What operational benefits can organizations expect when deploying Security Insights with LiveNX and LiveWire?
Organizations gain faster detection and response by turning performance telemetry into security intelligence, shortening investigation time from hours to minutes through real-time edge analytics. They maximize ROI by leveraging existing raw flow data and packet captures without adding complex tooling or backhauling data to the cloud, enabling richer threat hunting and forensics. Unified visibility across network and security teams reduces blind spots, supports mapping to MITRE ATT&CK and OWASP, and enables seamless integration with SIEM, SOAR, and XDR for coordinated remediation and improved compliance and audit readiness.
Appendix: Security findings
This appendix provides a list of security findings generated by LiveNX and LiveWire. These findings highlight anomalies, suspicious behaviors, and policy violations detected through flow and packet analysis. While not an exhaustive NDR catalog, they represent high-value insights that accelerate detection, investigation, and response. As LiveNX and LiveWire evolve, this library of findings continues to expand, ensuring network and security teams benefit from richer visibility and stronger outcomes over time.
| Security finding | MITRE ATT&CK ID (if applicable) |
|---|---|
| Encryption On IANA Reserved Port | T1571 |
| Kerberos Detected | |
| Kerberos RC4 Detected | |
| Malicious IP or Domain Detected | |
| Microsoft IP Detected | |
| NTLM Protocol Detected | |
| RDP On Non-Standard Port | T1571 |
| Threat Intel Indicator | T1102 |
| TLS Certificate Anomalies Detected | TLS |
| TLS Client Excessive Handshakes | TLS |
| TLS Forbidden Version | T1071.002 |
| TLS Long Lived Connection | TLS |
| TLS Missing SNI | T1587.003 |
| TLS Self-Signed Certificate | T1587.003 |
| TLS Unusual Certificate | T1587.003 |
| Unassigned Encryption | |
| Unauthorized Application Use | T1071.002 |
| Unexpected Encryption | T1571 |
| TLS Unexpected Plaintext | T1571 |
| TLS Weak Cipher Suite | |
| RDP Connection After Brute Force Attempt | T1021 |
| SSH Connection After SSH Brute Force Attempt | T1021 |
| Unauthorized Application Use | |
| RDP Brute Force Attempt Detected | T1110 |
| SSH Brute Force Attempt Detected | T1110 |
| New Encryption Protocol | T1571 |
| Found RDP On Non-Standard Port | T1571 |
| New Encryption User | T1573 |
| New Encryption Service | T1573 |
| New SSH Client Version Found | T1573 |
| New SSH Server Version Found | T1573 |
| New TLS Version Found | T1573 |
| Insecure/weak cipher | T1587.003 |
| New TLS SHA1 Found | T1588 |
| New TLS JA3C Found | T1588.004 |
| New TLS JA3S Found | T1588.004 |
| Lateral Movement Anomaly <application> | |
| Clique Expansion | |
| Interface Volumetric Anomaly | |
| Application Interface Volumetric Anomaly | |
| DSCP Interface Volumetric Anomaly | |
| Application Site Volumetric Anomaly | |
| Site Volumetric Anomaly |



