Partner Tool
Share:

ThreatBook TDP

Intelligence-driven network detection — read mirrored traffic and find the compromise the perimeter missed

Opens at threatbook.io — external site, RECATOOLS doesn't host this tool.
Quoted per throughput Out-of-band · never inline APAC-based vendor
ThreatBook TDP logo
Out-of-band
Mirrored traffic · never inline
Intel-driven
ThreatBook detection content
APT-aware
Actor infrastructure tracking
Asset discovery
Inventory from observed traffic
What it does

What traffic analysis finds that logs miss

An attacker can disable an endpoint agent and clear local logs. It's much harder for them to stop communicating on the network, which is why traffic inspection often catches intrusions that other controls miss.

Command-and-control detection

Callbacks to known actor infrastructure are surfaced with the intelligence behind the verdict.

APT and targeted activity

It detects more than commodity malware, drawing on ThreatBook's direct tracking of advanced actors.

Botnet and worm traffic

Automated propagation inside the network is identified from its traffic pattern.

Web and non-web attacks

Exploitation attempts are caught across protocols, not just HTTP.

Asset discovery

It builds an inventory of devices as it sees them on the network, giving you a more accurate picture than the CMDB alone.

Out-of-band by design

It reads a mirrored copy, so a detection failure can never drop production traffic.

Advertisement
After features · AD-W1 Responsive · Post-feature engagement
Detection Pipeline

From a packet to an investigation

STAGE 1
Mirror the traffic
A SPAN or TAP feeds a copy to the appliance
STAGE 2
Parse protocols
Sessions and application protocols are reconstructed
STAGE 3
Apply intelligence
Destinations and payloads matched to known threat infrastructure
STAGE 4
Detect behaviour
Beaconing, propagation and exploitation patterns identified
STAGE 5
Correlate
Related events grouped into one incident rather than many alerts
STAGE 6
Hand off
Findings routed to the SOC, SIEM or response workflow
Deployment

Three ways to get it running

Mode 02

Alongside the SOC stack

Feed detections into an existing SIEM or SOAR workflow.

  • SIEM integration
  • Incident correlation
  • Analyst hand-off
Mode 03

With endpoint + DNS

Network, endpoint and DNS telemetry against one intelligence source.

  • Pairs with OneSEC
  • Pairs with OneDNS
  • Shared intelligence
Advertisement
After deployment · AD-W2 Responsive
Regional presence

APAC offices & coverage

Same-jurisdiction threat-intel for ASEAN and East Asian compliance frameworks.

🇸🇬 Singapore 🇭🇰 Hong Kong 🇨🇳 China 🇦🇪 United Arab Emirates
FAQ

Common questions

Does TDP sit inline?

No, it reads a mirrored copy of traffic from a SPAN port or TAP. It can't block connections, but that out-of-band position also means a fault in the appliance can never take down production traffic. Blocking is handled by your existing inline controls.

What does it catch that an endpoint agent does not?

This covers devices that can't run an agent, endpoints where the agent has been disabled, and lateral movement between hosts. Network evidence is also much harder for an attacker to erase than a local log.

How does it handle encrypted traffic?

Even with encrypted traffic, the metadata—who is talking to whom, how often, and to what destinations—is valuable for spotting known-malicious connections. That context is visible even when the payload itself cannot be inspected. Discuss your TLS position with us before sizing a deployment.

What does it cost?

Pricing depends on throughput and deployment size and is not published. As an authorised reseller we can size it and quote — use the enquiry form above.

Does RECATOOLS get paid to list TDP (Threat Detection Platform)?

We earn no per-click fee for this listing and our editorial coverage is independent. For full disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor, so it earns revenue if you buy a commercial licence through us — the same relationship disclosed on our other ThreatBook listings.

Independently reviewed by RECATOOLS editorial on 16 Aug 2026. Listings are based on the vendor's public documentation; we don't accept payment for inclusion.
Disclosure: RECASYS is an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor. We may earn revenue if you buy a commercial licence through us. This does not affect the editorial assessment above, and any free tier stays free regardless of how you reach it.
Authorized reseller

Need pricing, a demo, or the full brochure?

Tell us about your environment and our team will get back to you with ThreatBook licensing, a guided demo, or the product brochure — usually within one business day.

Handled by RECASYS, an authorised reseller of ThreatBook products under SAIBERGARD Pte. Ltd., ThreatBook's authorised distributor for the region. Enquiries are copied to their sales desk. No obligation — your details are used only to answer you.

Prefer email? Write to [email protected]
Spam-protected · no account needed · see our Privacy Policy for how enquiries are handled.

Interested in TDP?

We can size an appliance for your traffic and arrange a demo.

See TDP
Related on RECATOOLS

Explore related tools & intelligence

Hand-picked RECATOOLS pages relevant to network detection and response.

Related News

You may be interested in these recent stories from our newsroom.

View all news →
Related

More Cybersecurity Tools