Skip to content
NETWORK DETECTION AND RESPONSE

MNX is an AI-native NDR that analyzes full-packet network traffic and connects scattered detection events into a single attack narrative, helping security teams detect, investigate, and respond to threats faster.

Full-Packet VisibilityAI-Based Attack Narrative AnalysisUnknown Threat DetectionLLM-Assisted Threat Investigation
WHY MNX

What security teams need isn't more alerts — it's better context.

Today’s attackers can blend into legitimate account activity, hide within encrypted traffic, and move quietly through internal networks. Security teams must distinguish real threats from a flood of events and respond quickly.

01 — ENCRYPTED TRAFFIC

Hiding behind encrypted traffic.

As encrypted traffic becomes the norm, relying on payloads and logs alone can leave gaps in network visibility.

02 — LATERAL MOVEMENT

Moving quietly through the network after initial access.

After gaining initial access, attackers move laterally between assets using internal network traffic that existing security tools may not fully observe.

03 — UNKNOWN THREATS

Threats emerge before signatures exist.

Zero-days, novel threats, and low-and-slow attacks are difficult to detect with signature-based methods alone.

04 — SOC OVERLOAD

Important attacks get lost in a flood of alerts.

Security teams can’t investigate every event that comes in—they need to prioritize the events most likely to represent real threats.

MNX STORY

MNX turns network traffic into actionable threat context.

A single DNS request, TLS session, or file transfer can’t tell you the full context of an attack. MNX connects traffic, sessions, assets, files, and threat intelligence to reconstruct attack behavior in context.

01TRAFFIC

Traffic Collection & Normalization

Collects and normalizes network traffic.

02SESSION

Session Reconstruction & Asset Mapping

Reconstructs sessions and maps relationships between assets.

03BEHAVIOR

Behavior Pattern Analysis

Analyzes behavior patterns and anomalies to identify attacker intent.

04INVESTIGATION

Investigation & Response Support

Provides the context and insight needed for investigation and response.

AI ATTACK NARRATIVE

Correlated detections reveal a single attack narrative.

MNX’s AI doesn’t simply surface more events. It selects meaningful network events, connects related activity, prioritizes them by risk, and presents them as a single, explainable attack narrative.

01AI TRIAGE

Identifying events most likely to represent real threats

Distinguishes routine activity from events most likely to indicate a real threat.

02AI CORRELATION

Connecting related activity into a single attack flow

Connects multiple sessions, assets, files, and threat data into a single attack context.

03AI PRIORITIZATION

Highest-risk attacks first

Prioritizes investigation targets based on assessed risk.

04AI EXPLAINABILITY

Explaining why an attack is considered risky

Provides the detection rationale and supporting evidence so analysts can understand the attack flow.

AI THREAT DETECTION

From known attacks to previously unseen threats.

MNX combines supervised-learning detection with unsupervised behavioral analysis. Known attacks are identified using learned threat patterns and multiple detection layers, while unknown threats are detected by analyzing deviations from your network’s own behavioral baseline.

KNOWN THREATS

Detecting known attack patterns

Identifies known attack activity—including C2 communication, data exfiltration, exploits, malware, and DB reconnaissance—using supervised learning and multiple detection layers such as signatures, threat intelligence, AV + AI file detection, YARA, and blacklists.

UNKNOWN THREATS

Unsupervised Behavioral Analysis

Detects new or low-frequency communication, low-and-slow attacks, abnormal lateral movement, and other deviations from a behavioral baseline built from your network’s own traffic.

NETWORK VISIBILITY

Make hidden network activity visible —and ready for analysis.

MNX identifies and structures network traffic, sessions, assets, and files, giving security teams the visibility needed to trace internal activity and threat progression.

Step 1Mirror IngestStep 2Full Packet CaptureStep 3DPI AnalysisStep 4Metadata IndexingStep 5PCAP & Analysis DataManagementBackboneNetworkDDNSFirewallEncryptionWorkgroupSwitchAggregationSwitchDECRYPTIONMirror Port10GbpsMGMT Port1GbpsMGMT IPMIRRORIngestAnalyzeDataStorageMNXApplianceSystemMNXAnalysisEngineSensorDatabaseDataStorageFull packetcapture(10GbpsPromisc Capture)PcapStorage(Long termpcap Archive)DPIPreassembly(application /protocol)MetadataStorage /AnalysisMNX WEB UIDATA VIEW
01

Comprehensive Traffic Visibility

Collects and analyzes traffic between the internet and the internal network using an out-of-band deployment.

02

Protocol & Application Identification

Identifies 500+ protocols and 2,500+ applications, providing Layer 7 visibility into network activity.

03

Encrypted Traffic Behavioral Analysis

Analyzes application and behavioral patterns even when traffic is encrypted with TLS, using metadata and communication characteristics.

04

In-Depth Session Analysis

Reconstructs sessions and analyzes asset relationships and anomalous communication flows.

05

Internal Asset Identification

Identifies asset information—including IP address, MAC address, OS, and browser—to help trace the asset from which a threat originated.

06

Incident Tracing & Evidence Collection

Uses searchable metadata and historical raw data to quickly trace past communications based on specified conditions and collect evidence for breach investigations.

RESPONSE & INVESTIGATION

MNX goes beyond detection — supporting investigation and response.

PLAYBOOK

Automated Response

Runs a playbook-based response process based on the detection scenario.

SIEM / SOAR

Integration with Existing SOC Systems

Connects with existing SOC systems through Syslog and other supported methods.

FIREWALL / WAF

Blocking Policy Integration

Integrates with IP- or domain-based blocking policy enforcement.

ALERT

Alert Delivery

Delivers alerts via email, messaging platforms, and other supported channels.

API

External System Integration

Supports API-based connections to external systems.

AI INVESTIGATION

Ask in natural language. Get answers grounded in attack context.

MNX uses SANDS Lab’s own LLM to investigate detected threats and support analyst decision-making. Deployment options and LLM usage scope are configured based on your environment and operational policies.

01

Natural-Language Queries

Investigate detected threats by asking questions in natural language.

02

Risk Summary

Summarizes the risk level and key details of a detected threat.

03

MITRE ATT&CK Mapping

Maps detected attacks to the MITRE ATT&CK framework for easier investigation and analysis.

04

Response Recommendations

Generates response recommendations based on the analysis results.

DEPLOYMENT & INTEGRATION

Deploy where you need visibility— without redesigning your network.

SPAN / TAP

Passive Deployment

Receives mirrored traffic via SPAN/TAP in an out-of-band deployment, minimizing impact on your production network.

ENVIRONMENT

Supports Diverse Network Environments

Supports traffic monitoring and centralized analysis across on-premises, closed networks, multi-site, and IT/OT environments, as well as cloud and hybrid infrastructures.

SCALE

Scales with Your Network

Available in 500 Mbps, 1 Gbps, 5 Gbps, and 10 Gbps configurations to match your network requirements.

INTEGRATION

Integrates with Your Existing Security Stack

Connects with SIEM, SOAR, EDR, firewalls, WAFs, and other security systems through REST APIs, Syslog, email, webhooks, messaging platforms, and other supported methods.

WHERE MNX DELIVERS VALUE

Environments change. Network visibility still matters.

Public institutions, manufacturing/OT, media & broadcasting, education & healthcare, and cloud environments all have different infrastructure, but security teams need the same fundamentals: visibility into internal traffic, scattered detections connected into a single attack context, and the highest-risk threats prioritized first.

Internal Visibility for On-Premises, Isolated, and Air-Gapped Environments
Public Institutions

Internal Visibility for On-Premises, Isolated, and Air-Gapped Environments

Provides internal visibility and evidence-backed analysis across on-premises, isolated, and air-gapped environments, supporting security operations and compliance.

Passive Monitoring Without Operational Impact
Manufacturing · OT

Passive Monitoring Without Operational Impact

Detects anomalous communications and internal activity across IT/OT environments through SPAN/TAP-based passive monitoring, without disrupting operations.

Fast Anomaly Detection in High-Volume Traffic Environments
Media · Broadcasting

Fast Anomaly Detection in High-Volume Traffic Environments

Helps quickly identify anomalous communications and hidden security risks even in high-volume traffic environments.

Asset & Behavioral Analysis for Mixed Networks
Education · Healthcare

Asset & Behavioral Analysis for Mixed Networks

Analyzes assets and behavioral patterns across mixed networks where personal devices and unmanaged endpoints coexist.

Centralized Monitoring for Hybrid, Multi-Site Environments
Cloud & Enterprise

Centralized Monitoring for Hybrid, Multi-Site Environments

Supports centralized monitoring and AI-assisted threat investigation across hybrid and multi-site environments.

PROVEN IN THE FIELD

An NDR proven across real-world environments.

Deployed across diverse network environments—from the public sector to manufacturing, education, healthcare, and cloud. More than 20 years of attack-response technology and accumulated threat data form the foundation of MNX’s AI analysis.

01APT / PACKET ANALYSIS

Packet-Based Deep Analysis & APT Response

Built on SIMBA-HV deep packet analysis technology to detect C2 communications and respond to APT attacks.

02THREAT INTELLIGENCE

Threat Intelligence Built Over Time

Continuously accumulates IoCs, campaign data, and other threat intelligence through malwares.com, CTX, and related services.

03AI-NATIVE NDR

Evolved into an AI-Native NDR

This foundation evolved into MNX, bringing together AI-based detection, behavioral analysis, attack narrative, and LLM-assisted investigation.

FAQ

Frequently asked questions about MNX.

We already have firewalls, IPS, EDR, and SIEM — why do we need an NDR?

Existing security tools each cover specific areas, including access control, signature-based detection, endpoint activity, and logs/events. MNX adds network-level visibility by analyzing network traffic and activity between assets that these tools may not fully capture, then connecting related events into a single attack context.

Can it analyze encrypted traffic?

MNX provides visibility into network behavior even when traffic is encrypted by analyzing communication metadata and session/application characteristics. Whether decryption is used, and how it is implemented, depends on your network environment.

How does it detect unknown attacks?

MNX combines unsupervised behavioral analysis with supervised detection. It identifies unknown threats by analyzing statistical and time-series deviations from your network’s normal baseline, including anomalies such as new or low-frequency communications.

Can it integrate with our existing security stack?

MNX integrates with existing security systems, including SIEM, SOAR, EDR, firewalls, and WAFs, through REST APIs, Syslog, and other supported methods.

Can it be deployed in isolated or air-gapped environments?

MNX supports on-premises deployment, including isolated and air-gapped environments. Deployment architecture and the scope of LLM and external threat intelligence usage are configured based on your environment and operational policies.

What network sizes does MNX support?

MNX is available in 500 Mbps, 1 Gbps, 5 Gbps, and 10 Gbps configurations to match different network requirements. In multi-site environments, collection sensors can be deployed with centralized analysis and management.

Not more alerts — see the full attack context.

MNX gives you visibility into behavior across your network, helping you prioritize threats for investigation and understand how an attack unfolded—faster.

How does this product behave in your environment?

Whether you're exploring, evaluating, or rolling out, you connect directly with a SANDS Lab solutions engineer. Clear every question before contract — that's the point.

FOR EVALUATORS

Product evaluation & PoC

Real-data PoCs, technical deep-dive sessions, and custom integration scoping. Everything you'd need to validate technical fit before the paperwork starts.

FOR RESEARCHERS

Technical collaboration & licensing

If you want to use the product in an academic benchmark or co-authored paper, we support research licenses and the underlying datasets. Co-authorship is on the table.