One signal, not five dashboards.

Tessaract runs Zeek, Suricata, Sigma, and Log Analysis against the same traffic and correlates what they find into a single scored case. Every detection is enriched against MITRE ATT&CK, CAPEC, and D3FEND. Built to run fully disconnected, for the networks that can’t be.
The problem with one engine :
Every detection engine sees something different. None of them sees everything.
Running them side by side means four browser tabs, four alert queues, and an analyst doing the correlation by hand. Tessaract does that correlation first. The case that reaches you is already the answer, not the raw material.
- Zeek: Full protocol-level traffic logging. The record of what actually happened on the wire.
- Suricata: Signature-based detection against ET rulesets, tuned for the traffic Zeek has already parsed.
- Sigma: Vendor-neutral detection logic, matched against network-layer events as they’re generated.
- Log Analysis: Windows event log timeline analysis, for the host-side half of an incident the wire alone won’t show.

How it works :
From raw packets to a scored case, on one appliance.
- Passive capture. A mirrored or SPAN port feeds traffic in. Tessaract never sits inline and never touches the network it’s watching.
- Multi-engine detection. Zeek, Suricata, Sigma, and Hayabusa all run against the same evidence, each contributing what it’s actually good at.
- MITRE enrichment. Every detection is mapped against ATT&CK, CAPEC, and D3FEND, so a hit tells you the technique, not just a rule ID.
- Correlated scoring. Related detections across engines are merged into one case with a single confidence score. Not four separate alerts to reconcile.
Built for disconnected networks
Every update ships as a file, not a connection.
Most detection platforms assume live internet access for rules and threat intel. Tessaract assumes the opposite. It’s built to run on networks that are disconnected on purpose: industrial control systems, classified environments, and sites where the security posture is the isolation itself.
- Detection rules and MITRE knowledge bases update from prepared media, not a live feed.
- Every update backs up the running configuration first and verifies before it goes live. It rolls back automatically if verification fails.
- Licensing works the same way. You install a signed file. There’s no phone-home check.
- Ships as a single OVA appliance. Import it, attach two interfaces, done.
- First boot detects your hardware and network automatically. No manual interface configuration.
- Runs the same whether it’s evaluated on a laptop or racked at a client site. Identical binary, no cloud dependency.
Try Tessaract for 10 days
Import the appliance, point it at a mirrored port, and see what it finds. No sales call required to get started.
- Import the OVA and attach two interfaces.
- Email socks@ephemeralnetworks.com to request your trial license.
- Install your signed 10-day license.
- Traffic capture starts automatically.