Network Behavioral Anomaly Detection (NBAD)
The NBAD section provides behavioral anomaly monitoring, protocol metrics, flow maps, and attack telemetry across your network.
Available NBAD Modules
- Layer 7 Metrics — Application-layer breakdown of traffic, SNIs, and TLS root CAs.
- HTTP Traffic — Detailed HTTP method, status code, and URL visibility.
- IPv4 / IPv6 Dashboard — Side-by-side protocol transition tracking.
- Tunnels — Encapsulated and tunneled protocol detection.
- P2P Analytics — Peer-to-peer traffic inspection.
- TCP Analyzer — TCP health, retransmission, and latency diagnostics.
- Flow Map — Live global geographic traffic mapping.
- MITRE ATT&CK — Adversary technique mapping and alert timeline.
- DDoS Monitor — Volumetric spike and flood detection.
- DNS Flood Activity — DNS and TCP SYN flood pattern tracking.