SSA Silent Security Agent OEM / LICENSING

Silent Security Agent = NDR × Security AI Agent × MCP

The NDR for the AI-agent era, in your product line.

Silent Security Agent (SSA) is an NDR engine that chains evidence from packet to Case. It also detects today's hottest risk — Shadow AI and MCP usage. SSA itself is an MCP server and a security AI agent, so you can feed NDR-derived evidence into the AI security solutions you already use, over MCP. Offered to network-equipment and security vendors as an OEM / license.

MADE IN JAPAN — NIHON-DO 100% For network-equipment vendors, security vendors and MSSP / SOC providers. On-premises ready.

ALWAYS WATCHING — SILENTLY

01 — MARKET PROBLEM

Who is talking to which AI — and how? Your customers are being asked right now.

Generative AI, AI agents and MCP spread through organizations without waiting for approval. Shadow-AI visibility and governance is the next requirement for network and security products. Building it in-house means a detection catalog, a correlation engine and an AI investigation layer. SSA delivers all of it as one engine.

FIND

Packet Pilot NDR finds

NDR-based network observation and protocol detectors catch unusual device behavior, known-bad indicators and multi-stage attack signs.

CONNECT

Packet Pilot NDR connects

Facts from DNS, TLS, HTTP, LDAP, Kerberos, SMB, RDP, RPC, WinRM, ARP, DHCP and more are correlated across device, destination, role, time window and raw evidence.

EXPLAIN & ACT

SSA explains and makes it actionable

Signals and incidents are promoted to Cases, with timeline, RCA, hunting, recommended actions, reports and notifications in one control panel.

From an NDR that only shows alerts, to an AI-agent-native NDR that follows the evidence and moves the investigation forward.

Not just “what happened” but “why we concluded it.” A core philosophy that differentiates your product.

02 — ARCHITECTURE

Two layers keep the chain of evidence intact, from packet to Case

The sensor / detection platform Packet Pilot NDR ships together with SSA: control panel, AI investigation layer and AI-integration hub. Detection logic, storage, correlation and Case policy tune independently — a structure with high design freedom for embedding into your product.

packet raw record finding / signal incident SSA Case RCA / Hunt / Report

Findings, facts, signals, incidents and Cases are linked by raw_refs, so any conclusion on screen traces back to the original traffic records. Not “because the AI said so” — the AI reads primary evidence and deterministic detections. A design that stands up to your customers' accountability demands.

03 — DETECTION

A full NDR that detects and correlates network facts across layers

Protocol findings from DNS, TLS, HTTP, LDAP, Kerberos, SMB, RDP, RPC, WinRM, ARP, DHCP and more are correlated across device, destination, role, time window and raw evidence. From C2 to exfiltration, lateral movement, MITM and DDoS staging — full NDR coverage. Shadow AI / MCP detection is one category within it: the one everyone is watching.

C2 / malware traffic

DNS beacon · DGA · fast-flux · TLS beacon · malicious JA3 · rare SNI

Data exfiltration

DNS tunneling · TLS exfiltration · HTTP size anomaly

Recon & credential attacks

port scan · quiet recon · brute force · auth-failure burst

Lateral movement & remote exec

SMB admin share · Kerberos fanout · RDP · WinRM · RPC pipe

MITM & L2 anomalies

ARP conflict · gateway MAC change · rogue DHCP

DDoS / botnet / spam

UDP amplification · sync burst · SMTP relay

Evasion & crypto anomalies

Tor · DoH · ECH hidden channel · old TLS · self-signed

HOT

Shadow AI / MCP usage

AI vendor lookup · AI service SNI · MCP request

Featured category: detecting Shadow AI and MCP usage

Which device connected to which AI service, was it approved, does it involve MCP traffic? Built on the same correlation engine: 8 direct signals, 5 correlation signals and 4 incident definitions for AI / MCP.

detect

Unapproved AI usage

DNS AI-vendor lookups and TLS AI-service SNI are checked against the allowlist to detect unapproved usage per device.

detect

Unapproved MCP usage

Detects HTTP MCP requests, destinations, client counts, uniform request sizes and synchronized bursts.

correlate

Suspicious traffic from approved AI

Even for approved AI, C2, rare destinations, synchronized traffic and exfiltration signs are correlated as supporting evidence.

correlate

Suspected exfiltration via AI

DNS tunneling, HTTP size anomalies and TLS data exfiltration are correlated with AI usage on the same device and time window.

escalate

Suspected compromise of the AI environment

AI usage, MCP, C2, connection anomalies and exfiltration support combine into possible-infostealer incident candidates. Detection doesn't stop at finding Shadow AI — it follows the post-compromise chain.

SSA NDR healthy
SSA SoC — control panel (illustrative) operator: soc-admin
24h 48h 72h week month
Casestotal: 39
ssc_…_0002incidentreview
Unapproved AI service usage · AI policy: not_approved
ssc_…_0009signalmedium
Suspected DNS tunneling · correlating
ssc_…_0018signalmedium
SMB admin-share access · lateral-movement triage
ssc_…_0021signallow
Periodic TLS beacon · hunting C2 signs
Verdict distributiontotal 39
TYPE
VERDICT
Detections by hourmax 7
Most active devices10
192.168.x.56
192.168.x.34
192.168.x.84
192.168.x.163
192.168.x.233
192.168.x.222

※ Screen is illustrative. Cases of every category — Shadow AI, C2, lateral movement, exfiltration — land in the same control panel, handled by the same correlation engine and evidence chain.

ssc_…_0002 — Triage Ask the AI Agent
Overview Flow Triage Exploration Report Change candidates
The AI Agent organizes hypotheses, counter-evidence and evidence gaps built from primary evidence. Verify against the evidence — the SOC makes the final call.

Situation summary

TLS traffic from device X to an AI service correlates with suspected unapproved AI usage. Asset-inventory confirmation and long-term baseline comparison are missing, so no final verdict yet.

Hypotheses

hypothesisThe device may have used an unapproved or non-business AI service
hypothesisOther traffic in the window has no direct link to AI usage at this point

04 — MCP INTEGRATION

Investigate, operate and integrate over MCP — from your AI agents and existing products

MCP (Model Context Protocol) is the common interface between AI agents and the Packet Pilot products. Even if you already run an AI security solution, it can connect through the MCP that SSA provides. Traffic facts, findings, signals, incidents and raw evidence extracted from packets become investigation context for your product's AI.

“Investigate this device”
OPERATOR
AI
Agent
your product / existing AI
MCP
SSA
SSA = MCP server / Security AI Agent
TLS DNS HTTP SMB Kerberos
NETWORK — SSA continuously observes traffic facts from every device and reads them as evidence.

Investigate

Query network state, signals, incidents and Cases. Identify devices and run proactive triage. Aggregate raw data and evidence by time window.

Operate

Review and change intake policy, budget, suppress rules and asset criticality. Operate NDR config and AI / MCP allowlists. Push DNS block/allow lists instantly.

Integrate

Hand packet-derived evidence and findings to third-party AI security solutions in structured form. Deliver alerts / reports to Slack and hand over investigation sessions.

/ssa-mcp summarize the latest network status as a dashboard
Ran 6 commands, used 4 tools
Data is in. Building the dashboard from live data.
NDR dashboard — monitor-alast 24 hours
Signals (24h)
1,515
Incidents
4 / all low
Findings
261 high 25
High-severity findings by category
arp.mac_multi_ip
dns.flood
connection.c2
dns.unapproved
Type a message…

※ Illustration of an investigation over MCP from Claude Desktop App / ChatGPT App, etc.

Run security investigations with the frontier model you already use

Connect Claude Desktop App or ChatGPT App to SSA's MCP and, inside your usual AI conversation, summarize the latest network status as a dashboard, drill into suspicious devices and drive the investigation. Your SOC team can always investigate with the latest frontier models.

05 — AI INVESTIGATION

A security analyst in the shadows moves triage forward

SSA periodically ingests signals, incidents and findings from Packet Pilot NDR and opens Cases automatically, advancing through context gathering → external TI → Knowledge Graph enrichment → RCA → hunt planning → read-only hunting → report generation.

STEP 1

Gather context

Collects the device's inventory, past behavior, related traffic, vulnerabilities and security findings.

STEP 2

Enrich with TI & KG

Enriches IPs, domains and JA3 with threat intel. Explores similar Cases, MITRE ATT&CK and past paths from the KG.

STEP 3

RCA & hunt

Builds RCA separating facts, hypotheses and evidence gaps. Picks a playbook and runs read-only hunts.

STEP 4

Report & recommend

Produces SOC-ready reports and recommended actions, through to notification in one flow.

Not an agent that changes things on its own

Policy controls how far each Case may auto-progress; budget / throttle can stop it. Changes over MCP or shell execution require an approval token. Paused Cases become partial_completed for a human to review and resume. Approval boundaries are what let you sell it to your customers with confidence.

06 — PRODUCT LINE

Extensible as the Packet Pilot product family

The lead product unites the Packet Pilot NDR sensor with the SSA app. Match your lineup by extending to these two products.

DNS-PACK

Packet Pilot DNS

An AI-agent-native DNS / DoH resolver. Agents update block/allow lists over MCP; policy applies immediately, blocking target domains at DNS level from the next query.

SWITCH

Packet Pilot Switch

An XDP-based network / switch product line with a control CLI and MCP, connecting SSA to network functions.

07 — FAQ

FAQ

What does the OEM / license look like?

The sensor / detection platform (Packet Pilot NDR) and the control panel / AI investigation layer / AI-integration hub (SSA) ship as one. Because the two layers are decoupled, detection logic, storage, correlation and Case policy can be tuned to your product's design. Branding and scope are discussed individually.

Will the AI agent change my network on its own?

Auto-progress endpoints are policy-controlled per Case and can be stopped by budget / throttle. Hunting is read-only; changes over MCP or shell execution require an approval token. Structured tools with approval and audit trails sit behind every operation.

Can it integrate with our own AI / security products?

Yes — through the MCP that SSA provides. Packet-derived traffic facts, findings, signals, incidents and raw evidence can be passed as investigation context to your product's AI.

Put a security analyst in the shadows into your product.

From Shadow AI detection to AI triage, delivered as OEM / license. We welcome technical evaluation, integration design and commercial discussions.

COMING SOONComing soon← Packet Pilot Products

For network-equipment vendors, security vendors and MSSP / SOC platform providers.

MADE IN JAPAN — NIHON-DO 100%