The Streaming Defense Platform
One real-time loop for network defense.
Built around the Signal Fabric, the platform turns raw activity into enforceable decisions across your entire environment — at wire speed, with a full audit trail.
Technical reference
Streaming Defense Detection Types
Download the V5 detection catalog for Hadron and Agentic Investigator API operations — aligned to dpi_risk_scores and built for SOC, MSSP and engineering review.
- 01Layer
Ingestion
Live network telemetry via Hadron sensors (bare-metal, VM, AWS/Azure/GCP), plus identity events, cloud activity, and endpoint signals. No decryption. No payload capture.
- 02Layer
Signal Fabric
Real-time behavioral extraction and correlation across identities, workloads, and time. Encrypted-traffic analysis via JA3/JA4, nDPI application ID, DGA/FastFlux, cumulative statistical scoring.
- 03Layer
Decision Engine
Deterministic policy evaluation on every signal. Composite scoring with override rules (IoC, C2, exfil). Kill-chain correlation fuses weak signals into strong, explainable cases.
- 04Layer
Enforcement
Active defense, automated firewall rule creation (Fortinet, Cisco), isolation. Native controls across all network types.
- 05Layer
Governance & AI SOC
Full decision logs, policy versioning, audit trails. Private SOC LLM ingests your policies, GRC docs, and architecture to produce environment-specific triage and treatment plans — with no data leakage.
Design principles
How we built a real-time platform.
No batch
Every signal is evaluated on arrival. Queries and log pipelines are optional consumers, never critical path.
Entity map
Every signal is bound to an entity — user, device, workload — for context-aware policy.
Auditable
Policies produce clear outcomes with full inputs, versions, and decisions recorded.
Open
API-first. Fits alongside SIEM, SOAR, XDR, IdP, EDR, and cloud-native controls.
Supporting material
Platform walkthrough
Short technical overviews of the platform in action.
The Streaming Defense System Overview
A concise overview of the Streaming Defense system — how the Signal Fabric, Attack Operations Theater and AI SOC come together to deliver real-time network defense.
The Attack Operations Theater
Operational awareness built on the Signal Fabric — real-time visibility, decision-grade signals, and active defense.
The Threat Stream
Live behavioral signals flowing through the Signal Fabric — extracted, correlated and scored in real time.
The AI SOC
A private SOC LLM grounded in your policies, GRC docs and architecture — environment-specific triage with no data leakage.