Self-hosted Network Detection & Response

See the network activity
your controls do not explain.

obserae turns the NetFlow and IPFIX records your infrastructure already exports into named assets, expected connectivity, actionable detections and investigation evidence — without packet capture or a vendor cloud.

Install and start obserae

curl -fsSL https://get.obserae.com | sudo sh

amd64 / arm64 · systemd service

Self-hosted · Passive · No telemetry · Free Community edition

Network evidence without another data platform

Give security and network teams a shared view of who communicated, whether it was expected, and what evidence supports the next decision.

Coverage

See activity beyond managed endpoints

Map hosts, networks, groups and services so an investigation starts with assets your team recognizes, not anonymous addresses.

Control

Compare traffic to intended architecture

Describe what should be allowed in the Flow Matrix. Every session can then be matched against the architecture you meant to run.

Detection

Turn exceptions into reviewable signals

Unexpected east-west traffic, known-bad destinations, cloud outliers, scans and volume spikes become leads you can review.

Sovereignty

Keep network evidence under your control

Deploy on your own host, keep the data local, export configuration as YAML, and evaluate without a cloud dependency.

Start with questions that change a decision

Start with questions your firewall, endpoint and log tools often leave disconnected from the actual network conversation.

Threat intel

Which internal host reached Tor or a known-bad IP?

Sessions are checked against Tor and FireHOL sources so suspicious destinations are visible with source, time and context.

Segmentation

Which workstation talked directly to a server?

Unexpected east-west sessions stand out when they do not match the connectivity model you defined.

Cloud

Which cloud provider, region or ASN is this traffic using?

Public destinations are enriched with cloud, country and autonomous-system context so outliers are easier to explain.

Discovery

What devices or subnets are alive but undocumented?

Observed traffic proposes networks and hosts that can be added to the cartography instead of staying as shadow infrastructure.

Explore the use cases →

Product capabilities

The product surface is built around the daily NDR workflow: understand the network, define what is expected, and investigate what falls outside it.

obserae Flow Matrix — a table of connectivity rules with named source and destination, protocol and ports, each marked active.
Flow Matrix

Turn architecture into detection.

Define the communications your environment is expected to allow. obserae reveals sessions that fall outside that model.

Learn more →
obserae Investigation — an NFQL query filtering sessions by cartography names (network:work to internet4) on HTTPS/TCP, with the results table below.
Investigation

Ask better questions than "what is this IP?"

Investigate sessions and flows using names, groups, services, ports, protocols and available enrichment data. Save useful investigations as alerts.

Learn more →
See how the product works →

Evaluate it on your own traffic, without a platform project

Start with one exporter and one network segment. Validate the coverage, operating effort and quality of the evidence before making a broader deployment decision.

Self-hosted, offline-capable, signed releases, SBOM and provenance. The Community edition is free; commercial editions share one feature set and are priced only by organisation size.

  1. Run a local instance

    Start the Docker image or download a Linux release on amd64 or arm64.

    docker run -p 2055:2055/udp -p 4739:4739/udp -p 127.0.0.1:8080:8080/tcp ghcr.io/spartan-conseil/obserae:latest
  2. Send a copy of flow telemetry

    Point one router, firewall, virtual switch or host probe at UDP 2055/4739.

  3. Describe a small part of the network

    Name a few networks, key hosts and expected communications, then let discovery fill the gaps.

  4. Review what does not fit

    Use Cartography, Flow Matrix and Investigation to decide whether the signal is normal, misconfigured or suspicious.

Built for a security review, not just a product demo

The deployment and commercial model are designed to answer the questions a CISO, infrastructure owner or procurement team will ask before a trial.

Data

Where does sensitive network evidence go?

It stays on infrastructure you operate. There is no vendor cloud, telemetry service or remote access to the instance.

Operations

What happens if the product stops?

obserae is passive and out of band. An interruption affects visibility, never production connectivity.

Assurance

How can a release be trusted?

Signed artefacts, an SBOM and build provenance can be verified before deployment, including in an isolated environment.

Commercial

What causes the price to grow?

Organisation size — not flow volume, retention, exporters, addresses or a collection of feature add-ons.

Decide with evidence from your own environment.

Install obserae locally, connect one exporter and decide from evidence collected on your own network.