Secure Network Analytics
Network detection and response through behavioural analytics and encrypted-traffic insight.
Cisco Secure Network Analytics (formerly Stealthwatch) provides network detection and response by collecting and analysing telemetry from across the network — detecting threats through behavioural analytics and, uniquely, finding threats in encrypted traffic without decryption via Encrypted Traffic Analytics. It turns the network itself into a sensor. Faltrox operates it as the network-visibility and NDR layer of the SOC.
Overview
What Secure Network Analytics is
Attackers move through the network, but most tools only see the perimeter — leaving east-west traffic and encrypted flows as blind spots. Cisco Secure Network Analytics turns the whole network into a sensor: it collects telemetry (NetFlow and more) from existing network infrastructure and applies behavioural analytics to detect threats by how they behave, not just by signature.
Its standout capability is Encrypted Traffic Analytics, which identifies malware and threats in encrypted traffic without decryption — closing a blind spot that only grows as encryption becomes universal. It baselines normal behaviour to surface anomalies, detects lateral movement and data exfiltration, and integrates with Cisco XDR and the security stack for correlation and response. Faltrox operates it — tuning the analytics, investigating detections, and feeding them into the SOC it runs.
Coverage
What it protects
The platforms, threats, and surfaces this product is built to defend.
Whole Network
Turns existing network infrastructure into a sensor using NetFlow and telemetry.
Encrypted Traffic
Encrypted Traffic Analytics finds threats in encrypted flows without decryption.
Lateral Movement
Behavioural analytics detect east-west lateral movement inside the network.
Data Exfiltration
Surfaces anomalous data flows that indicate exfiltration of sensitive information.
Behavioural Baselines
Baselines normal behaviour to detect anomalies that signatures cannot.
Cisco XDR Integration
Feeds network detections into Cisco XDR for cross-domain correlation and response.
How it works
The mechanism
How the product moves from signal to protected state, step by step.
- 01
Collect
It collects telemetry — NetFlow and more — from existing network infrastructure across the whole environment.
- 02
Baseline
Behavioural analytics learn what normal looks like for every host and flow.
- 03
Detect
Anomalies, lateral movement, exfiltration, and encrypted-traffic threats are detected without decryption.
- 04
Correlate
Detections feed Cisco XDR and the security stack for cross-domain correlation and prioritisation.
- 05
Operate
Faltrox tunes the analytics, investigates detections, and drives response as part of the SOC.
Capabilities
Key capabilities
Network as a Sensor
Collects NetFlow and telemetry from existing infrastructure to give network-wide visibility.
Encrypted Traffic Analytics
Finds malware and threats in encrypted traffic without decryption — a growing blind spot elsewhere.
Behavioural Analytics
Detects threats by behaviour and anomaly rather than signature alone.
Lateral-Movement Detection
Surfaces east-west movement inside the network that perimeter tools miss.
Exfiltration Detection
Identifies anomalous data flows indicating exfiltration of sensitive information.
Behavioural Baselining
Learns normal behaviour per host and flow to expose deviations.
Scalable Telemetry
Scales to large, distributed networks by using telemetry rather than inline appliances.
Cisco XDR Integration
Feeds network detections into Cisco XDR for correlation across endpoint, cloud, and identity.
Works with
Part of the platform
Cisco products this pairs with, and the Faltrox services that operate it.
Delivery
You buy the outcome, not the console
Managed by Faltrox
Faltrox licenses, deploys, and tunes Cisco Secure Network Analytics for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.
FAQ
Common questions
01How does it find threats in encrypted traffic without decrypting it?
Through Encrypted Traffic Analytics, which analyses the observable characteristics and behaviour of encrypted flows — not their contents — to identify malware and threats. That keeps you compliant with privacy requirements while closing the blind spot created by universal encryption.
02Does it require inline appliances everywhere?
No — it uses telemetry (NetFlow and more) from your existing network infrastructure, turning the network itself into a sensor. That is what lets it scale to large, distributed networks and see east-west traffic without deploying inline devices at every point.
03What kinds of threats does it catch that a firewall misses?
Internal, behavioural, and encrypted threats — lateral movement between hosts, data exfiltration, and anomalies that deviate from normal behaviour. A firewall guards the perimeter; Secure Network Analytics watches behaviour across the whole network, including inside it.
04How does it fit with Cisco XDR?
It provides the network telemetry and detections that Cisco XDR correlates with endpoint, cloud, email, and identity signals — so a network anomaly becomes part of a prioritised, cross-domain incident rather than an isolated alert.
05How does Faltrox operate it?
We deploy the collectors, tune the behavioural analytics and baselines, investigate detections, and feed them into Cisco XDR and the SOC services we run — operating it as the network detection-and-response layer of your managed defence.
Start an engagement
Secure what’s next.
Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.
Contact us