Wireless network control and attack detection
You can build a perfect wired perimeter and still have somebody's personal router standing next to the finance department. The appliance listens to the air and shows what is going on.
- GHz, both bands
- 2.4 / 5GHz, both bands
- management frame dissection
- 802.11management frame dissection
- signal level for every device
- dBmsignal level for every device

How it works
The appliance uses its built in antennas and operates in listening mode. It does not join your networks and does not need their passwords: it analyses 802.11 management frames that access points and clients broadcast openly.
The device table shows everything within range: rogue access points, client devices, bridges. For each one you see the vendor, encryption, channel, signal level and activity. An access point with open encryption or an unfamiliar vendor next to the office stands out immediately.
In parallel the module looks for characteristic signs of wireless attacks and raises alerts with an event class and a threat level.
Which attacks are recorded
- Access point password guessing
- WPS PIN brute force
- PMKid key identifier capture
- Attacks on the WPA and WPA2 handshake
- Denial of service through client deauthentication
- Attempted exploitation of a WPA key handling vulnerability
- Network without management frame protection, allowing clients to be disconnected
- Access point with open encryption
- Legacy encryption algorithms instead of WPA3
- Congested channel and mutual interference


What you see for every device
Identification
MAC address, hardware vendor, device type: access point, client or bridge. First and last activity.
Radio side
Channel, signal level in dBm, traffic volume, a packet activity sparkline and channel utilisation per the 802.11e standard as a percentage.
Networks around
A dedicated section with the list of network names: encryption type, number of requests, responses and beacons, network name length.
All capabilities of the appliance
Capabilities of the appliance- Traffic monitoringThe appliance inspects a copy of your traffic, matches it against a signature database and raises an alarm when something happens that should not.Learn more
- Vulnerability scannerThe appliance looks for what someone could walk in through: outdated versions, weak algorithms, forgotten services and systems that reached end of life.Learn more
- Network inventoryThe appliance regularly recounts what lives in your network and reports when the picture changes: a new host appeared, a new port opened, a device went missing.Learn more
- Intruder honeypotThe appliance deploys a decoy in your network. A legitimate employee has no reason to touch it, so any request is a signal: somebody is already inside and looking around.Learn more
- File integrityA modified router config or a replaced executable on a server generates no suspicious traffic. They are found by comparison against a baseline.Learn more
- Reports and SIEMThe appliance does not try to replace your security operations centre. It delivers events where they are already collected, and writes directly to whoever is on duty today.Learn more
We will prepare a quote for your network
Tell us about your infrastructure: how many sites, which switch sits in the core, whether you already run a SIEM. We will pick the edition and the connection scheme, and calculate the cost.
- We reply within one business day
- We design the connection scheme for your topology
- We show the interface on a live demo unit
