DPI sensor · Network module

See all your traffic,
down to the last packet.

Deep packet inspection in real time. The sensor sees everything crossing your LAN — connections, flows, exfiltration, Shadow IT, command-and-control. No traffic escapes it.

DPI L7Passive SPAN/TAP capture10 Gbps500+ protocolsLocal storage
10 Gbps
throughput analysed in real time
500+
protocols identified (L7)
< 5 min
detection of a C2 beacon

The DPI sensor is the SOC's eye on the network. Plugged into a mirror on your switch (SPAN or TAP), it inspects every packet without slowing anything down: it reassembles sessions, identifies application protocols, enriches each flow with GeoIP, ASN and CTI data, then passes everything to SYLink AI for correlation — without ever decrypting the content of your communications.

How it works

From threat to evidence, in real time.

The module captures the signal, SYLink AI correlates it and decides — you keep control.

Network traffic
Everything coming in and going out
DPI sensor
Real-time L7 inspection
SYLink AI
Correlates & qualifies
Alert / block
Before the impact
In the portal

What the sensor shows you.

The network as it actually is — not as it was documented three years ago.

01

Describe it, and the map builds itself

console.unisoc.fr/mon-reseau
You answer a few questions, the diagram draws itself — pre-filled with the machines, servers and assets already detected.
02

Dynamic traffic mapping

console.unisoc.fr/mon-reseau
Dynamic traffic mapping
148 hosts, 76 servers, 45 at risk, 6 active C2s — every machine with the applications it actually talks to.
03

Three-tier technical diagram

console.unisoc.fr/mon-reseau
Three-tier technical diagram
Core, distribution, access: what you declared, enriched with DPI traffic, EDR data and real alerts.
04

The guided questionnaire

console.unisoc.fr/mon-reseau
The guided questionnaire
Multiple sites, carriers, firewalls, VLANs: 31 questions, saved automatically, no Visio diagram to maintain.

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.

IDS vs DPI

Why “seeing” is not enough.

Most sensors on the market are IDS: they read the header. Our DPI looks inside.

Classic IDS Probe
It reads the envelope.
Blind to the content
Packet header
IP 10.0.4.12→ 45.83.12.7TCP :443
payload — not inspected
GET /update HTTP/1.1
Host: files.evil-cdn.io
x-token: 9f2a…
Classifies the flow on theport & the IP: ":443 → HTTPS, probably legitimate".
Misses theencrypted C2 tunnel, the Shadow IT and the exfiltration hidden inside "port 443".
DPI Probe · UniSOC
It reads what is inside.
Deep inspection
Packet header
IP 10.0.4.12→ 45.83.12.7TCP :443
Payload — metadata extracted
SNI / TLSfiles.evil-cdn.io
JA3 client5d4e6f… (suspect)
Behaviorregular beacon · 60 s
Real applicationC2 tunnel (≠ HTTPS)
Sees thereal application, even encrypted — through SNI, JA3/JA4 and the rhythm of the traffic.
Analysismetadata plus behaviour→ detects the C2 on port 443,without decryptingyour communications.
An IDS stops at the envelope.DPI reads what is inside — and sees what the ports hide.
Capabilities

The technology, in detail.

What the module actually does — functions, not promises.

L2–L7 inspection

  • Full-packet capture at 10 Gbps with automatic rotation
  • TCP / UDP / QUIC sessions reassembled
  • 500+ application protocols identified (HTTP, TLS, SMB, RDP, DNS, SSH…)
  • TLS/SNI metadata without decryption
  • JA3 / JA4 fingerprinting

Behavioural detection

  • C2 beacon (regular interval to a suspicious IP)
  • Suspicious tunnels (DoH, ICMP exfil, abnormal lengths)
  • Exfiltration: abnormal uploads, encrypted archives
  • Shadow IT / Shadow AI (ChatGPT, Claude, Notion, Slack…)
  • Internal lateral movement, LAN to LAN

SYLink AI enrichment

  • Three-layer GeoIP (DB-IP, MaxMind, Cloudflare)
  • ASN + Whois + 50 CTI reputation sources
  • Matched against 22M+ malicious IPs and domains
  • DPI × EDR cross-correlation by IP
  • Automatic alert triage by the AI

Forensics & investigation

  • JSON flows, 14 days hot plus 90 days archived
  • Animated replay to walk through an incident
  • Multi-source JSON evidence for DORA audits
  • Natural-language threat hunting
  • PCAP export filtered by session, IP or period

Sovereign deployment

  • Industrial fanless hardware or VM
  • No cloud egress — traffic stays on site
  • Mutual TLS probe → SOC, monthly cert rotation
  • Works with SPAN, ERSPAN and network TAPs
  • Multiple sensors across sites, correlated in real time

Compliance & visibility

  • No TLS decryption — GDPR respected
  • HMAC-signed audit trail (DORA art. 28)
  • MTTD / MTTR dashboards per tenant
  • NIS2 article 23 reporting
  • MITRE ATT&CK coverage: 76 techniques
Use cases

What is it actually for?

Detect a compromised endpoint

Regular C2 beacons, exfiltration to a typosquatted domain, a night-time SSH tunnel: the sensor sees the pattern and raises the alert before the ransomware starts.

Map Shadow IT and Shadow AI

How many upload code into ChatGPT? Who uses unmanaged tools? The sensor records actual usage — not what was declared.

Prove DORA and NIS2 compliance

Trace every outbound connection, keep 90 days of metadata, prove to the auditor that the anomalies were seen and qualified.

Forensic investigation

A machine hit by ransomware three days ago? Trace back to the entry point: who talked to whom, when, on which port, and how much data moved.

The method, in four steps
From raw signal to defensible evidence.
Detect
Understand
Decide
Prove
01The module captures the raw signal — traffic, behaviour or indicator.signal captured
Specifications
Max sustained throughput10 Gbps full packet capture
Flow storage14d hot (NVMe) · 90d HDS v2 archive
Beacon detection latency< 5 minutes
Protocols identified500+ (DPI L7)
CaptureSPAN, ERSPAN, TAP (1×10G or 4×1G)
Cloud egressNone — everything stays on-premise
Probe → SOC transportMutual TLS 1.3, 30-day rotation
DeploymentOn-premise · inside your own infrastructure
Natively integrated with
SYLink AI — automatic triage
EDR agent — network × endpoint correlation
HoneyPot — touches on the decoys
Automated pentesting — scope fed by the DPI map
Compliance module — NIS2 / DORA / GDPR
Sovereign

Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.

Live in under 48 hours

Ready to see what is really
happening on your network?

First trial free, no credit card, no commitment. On your existing infrastructure.

Cookie settings

We use cookies to improve your experience on our site. By continuing to browse, you accept our privacy policy and our use of cookies under the GDPR.