ThreatBook TDP
Intelligence-driven network detection — read mirrored traffic and find the compromise the perimeter missed
What traffic analysis finds that logs miss
An attacker can disable an endpoint agent and clear local logs. It's much harder for them to stop communicating on the network, which is why traffic inspection often catches intrusions that other controls miss.
Command-and-control detection
Callbacks to known actor infrastructure are surfaced with the intelligence behind the verdict.
APT and targeted activity
It detects more than commodity malware, drawing on ThreatBook's direct tracking of advanced actors.
Botnet and worm traffic
Automated propagation inside the network is identified from its traffic pattern.
Web and non-web attacks
Exploitation attempts are caught across protocols, not just HTTP.
Asset discovery
It builds an inventory of devices as it sees them on the network, giving you a more accurate picture than the CMDB alone.
Out-of-band by design
It reads a mirrored copy, so a detection failure can never drop production traffic.
From a packet to an investigation
Three ways to get it running
Out-of-band appliance
Fed from a SPAN port or network TAP. Nothing sits in the traffic path.
- No inline failure risk
- No endpoint agent
- Fast to pilot
Alongside the SOC stack
Feed detections into an existing SIEM or SOAR workflow.
- SIEM integration
- Incident correlation
- Analyst hand-off
With endpoint + DNS
Network, endpoint and DNS telemetry against one intelligence source.
- Pairs with OneSEC
- Pairs with OneDNS
- Shared intelligence
APAC offices & coverage
Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.
Common questions
Does TDP sit inline?
No, it reads a mirrored copy of traffic from a SPAN port or TAP. It can't block connections, but that out-of-band position also means a fault in the appliance can never take down production traffic. Blocking is handled by your existing inline controls.
What does it catch that an endpoint agent does not?
This covers devices that can't run an agent, endpoints where the agent has been disabled, and lateral movement between hosts. Network evidence is also much harder for an attacker to erase than a local log.
How does it handle encrypted traffic?
Even with encrypted traffic, the metadata—who is talking to whom, how often, and to what destinations—is valuable for spotting known-malicious connections. That context is visible even when the payload itself cannot be inspected. Discuss your TLS position with us before sizing a deployment.
What does it cost?
Pricing depends on throughput and deployment size and is not published. As an authorised reseller we can size it and quote — use the enquiry form above.
Does RECATOOLS get paid to list TDP (Threat Detection Platform)?
We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.
Need pricing, a demo, or the full brochure?
Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.
Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.
Interested in TDP?
We can size an appliance for your traffic and arrange a demo.
See TDPExplore related tools & intelligence
Hand-picked RECATOOLS pages relevant to network detection and response.
Related News
You may be interested in these recent stories from our newsroom.
-
Five APAC Markets, Five AI Rulebooks — but They Agree on the One That Matters
Korea has a comprehensive AI law; Australia decided against one. On text and data mining, three of the five markets have quietly converged.
-
ThreatBook Puts a Number on APAC's Year: 15,205 Incidents, and Indonesia Growing Fastest
The firm's first mid-year Asia-Pacific report covers twelve months and more than nineteen markets. Singapore ranks sixth by volume, Malaysia...
-
An AI Agent Ran Unsupervised Inside Thailand's Finance Ministry — Doing the Legwork, Not the Break-In
Researchers recovered five logs showing an open-source AI agent enumerating a ministry host without per-command approval. How the intruder g...