Silent Security Agent
OEM / LICENSING
01 — MARKET PROBLEM
Generative AI, AI agents and MCP spread through organizations without waiting for approval. Shadow-AI visibility and governance is the next requirement for network and security products. Building it in-house means a detection catalog, a correlation engine and an AI investigation layer. SSA delivers all of it as one engine.
FIND
NDR-based network observation and protocol detectors catch unusual device behavior, known-bad indicators and multi-stage attack signs.
CONNECT
Facts from DNS, TLS, HTTP, LDAP, Kerberos, SMB, RDP, RPC, WinRM, ARP, DHCP and more are correlated across device, destination, role, time window and raw evidence.
EXPLAIN & ACT
Signals and incidents are promoted to Cases, with timeline, RCA, hunting, recommended actions, reports and notifications in one control panel.
From an NDR that only shows alerts, to an AI-agent-native NDR that follows the evidence and moves the investigation forward.
Not just “what happened” but “why we concluded it.” A core philosophy that differentiates your product.
02 — ARCHITECTURE
The sensor / detection platform Packet Pilot NDR ships together with SSA: control panel, AI investigation layer and AI-integration hub. Detection logic, storage, correlation and Case policy tune independently — a structure with high design freedom for embedding into your product.
Findings, facts, signals, incidents and Cases are linked by raw_refs, so any conclusion on screen traces back to the original traffic records. Not “because the AI said so” — the AI reads primary evidence and deterministic detections. A design that stands up to your customers' accountability demands.
03 — DETECTION
Protocol findings from DNS, TLS, HTTP, LDAP, Kerberos, SMB, RDP, RPC, WinRM, ARP, DHCP and more are correlated across device, destination, role, time window and raw evidence. From C2 to exfiltration, lateral movement, MITM and DDoS staging — full NDR coverage. Shadow AI / MCP detection is one category within it: the one everyone is watching.
DNS beacon · DGA · fast-flux · TLS beacon · malicious JA3 · rare SNI
DNS tunneling · TLS exfiltration · HTTP size anomaly
port scan · quiet recon · brute force · auth-failure burst
SMB admin share · Kerberos fanout · RDP · WinRM · RPC pipe
ARP conflict · gateway MAC change · rogue DHCP
UDP amplification · sync burst · SMTP relay
Tor · DoH · ECH hidden channel · old TLS · self-signed
AI vendor lookup · AI service SNI · MCP request
Which device connected to which AI service, was it approved, does it involve MCP traffic? Built on the same correlation engine: 8 direct signals, 5 correlation signals and 4 incident definitions for AI / MCP.
DNS AI-vendor lookups and TLS AI-service SNI are checked against the allowlist to detect unapproved usage per device.
Detects HTTP MCP requests, destinations, client counts, uniform request sizes and synchronized bursts.
Even for approved AI, C2, rare destinations, synchronized traffic and exfiltration signs are correlated as supporting evidence.
DNS tunneling, HTTP size anomalies and TLS data exfiltration are correlated with AI usage on the same device and time window.
AI usage, MCP, C2, connection anomalies and exfiltration support combine into possible-infostealer incident candidates. Detection doesn't stop at finding Shadow AI — it follows the post-compromise chain.
※ Screen is illustrative. Cases of every category — Shadow AI, C2, lateral movement, exfiltration — land in the same control panel, handled by the same correlation engine and evidence chain.
04 — MCP INTEGRATION
MCP (Model Context Protocol) is the common interface between AI agents and the Packet Pilot products. Even if you already run an AI security solution, it can connect through the MCP that SSA provides. Traffic facts, findings, signals, incidents and raw evidence extracted from packets become investigation context for your product's AI.
SSA
Query network state, signals, incidents and Cases. Identify devices and run proactive triage. Aggregate raw data and evidence by time window.
Review and change intake policy, budget, suppress rules and asset criticality. Operate NDR config and AI / MCP allowlists. Push DNS block/allow lists instantly.
Hand packet-derived evidence and findings to third-party AI security solutions in structured form. Deliver alerts / reports to Slack and hand over investigation sessions.
Connect Claude Desktop App or ChatGPT App to SSA's MCP and, inside your usual AI conversation, summarize the latest network status as a dashboard, drill into suspicious devices and drive the investigation. Your SOC team can always investigate with the latest frontier models.
05 — AI INVESTIGATION
SSA periodically ingests signals, incidents and findings from Packet Pilot NDR and opens Cases automatically, advancing through context gathering → external TI → Knowledge Graph enrichment → RCA → hunt planning → read-only hunting → report generation.
STEP 1
Collects the device's inventory, past behavior, related traffic, vulnerabilities and security findings.
STEP 2
Enriches IPs, domains and JA3 with threat intel. Explores similar Cases, MITRE ATT&CK and past paths from the KG.
STEP 3
Builds RCA separating facts, hypotheses and evidence gaps. Picks a playbook and runs read-only hunts.
STEP 4
Produces SOC-ready reports and recommended actions, through to notification in one flow.
Policy controls how far each Case may auto-progress; budget / throttle can stop it. Changes over MCP or shell execution require an approval token. Paused Cases become partial_completed for a human to review and resume. Approval boundaries are what let you sell it to your customers with confidence.
06 — PRODUCT LINE
The lead product unites the Packet Pilot NDR sensor with the SSA app. Match your lineup by extending to these two products.
DNS-PACK
An AI-agent-native DNS / DoH resolver. Agents update block/allow lists over MCP; policy applies immediately, blocking target domains at DNS level from the next query.
SWITCH
An XDP-based network / switch product line with a control CLI and MCP, connecting SSA to network functions.
07 — FAQ
The sensor / detection platform (Packet Pilot NDR) and the control panel / AI investigation layer / AI-integration hub (SSA) ship as one. Because the two layers are decoupled, detection logic, storage, correlation and Case policy can be tuned to your product's design. Branding and scope are discussed individually.
Auto-progress endpoints are policy-controlled per Case and can be stopped by budget / throttle. Hunting is read-only; changes over MCP or shell execution require an approval token. Structured tools with approval and audit trails sit behind every operation.
Yes — through the MCP that SSA provides. Packet-derived traffic facts, findings, signals, incidents and raw evidence can be passed as investigation context to your product's AI.
From Shadow AI detection to AI triage, delivered as OEM / license. We welcome technical evaluation, integration design and commercial discussions.
COMING SOONComing soon← Packet Pilot ProductsFor network-equipment vendors, security vendors and MSSP / SOC platform providers.
MADE IN JAPAN — NIHON-DO 100%