-
Platform
Plixer FlowPro ā an advanced packet metadata generator using deep packet inspection for application performance monitoring, DNS analytics and threat detection
-
Subscription term
3-year subscription, billed annually ā this listing covers Year 1
-
Deployment method
Passive monitoring via TAP, SPAN or mirror port (ERSPAN supported) ā monitors mirrored traffic without touching the original packets, so it can be deployed where devices can't natively export flow data
-
Application performance monitoring
Flow-based analysis combined with deep packet inspection reveals packet loss, retransmissions, round-trip time, application latency, throughput and server performance per connection, for internal or cloud-bound traffic
-
DNS analytics
Real-time inspection of DNS requests and responses; detects NXDOMAIN bursts, irregular TXT record usage, malformed responses and abnormal query structures against a learned baseline of normal activity
-
Threat detection
Identifies DNS tunnelling, data exfiltration, algorithmically generated domains (DGAs), botnet activity, command-and-control beaconing and phishing infrastructure from domain behaviour and query timing
-
Encrypted traffic visibility
JA3/TLS fingerprinting and FQDN extraction give visibility into encrypted sessions without decryption
-
Selective packet capture
Event-driven capture activates only when anomalies are detected, minimising PCAP storage requirements; captured packets export to forensic tools such as Wireshark
-
Rule engine & threat feeds
Suricata-based custom NIDS rules covering unusual protocol usage, unexpected flow patterns, file transactions/extractions and other anomalies, plus threat feed and domain reputation integration with configurable whitelists and blacklists
-
Data output
Enriched flow metadata forwarded to Plixer One / Scrutinizer for enterprise-wide correlation, with pre-defined and custom report generation
-
Deployment options
Rack-mountable hardware appliance, or software deployable in a hypervisor (VMware ESXi, Hyper-V or KVM); distributed sensors supported for multi-site deployments; additional storage configurations available on request
-
Minimum system requirements
1 CPU with 2 cores at 2.0GHz+, 2GB RAM, 5GB storage and ESXi 5.0 or newer
-
Typical use cases
Application performance troubleshooting (packet loss, latency, throughput); DNS compromise risk (hijacking, cache poisoning, resolution disruption); VoIP/phone QoS monitoring (ToS, packet loss, jitter, codec usage); rule-based intrusion detection (botnet, C2, encryption anomalies); encrypted traffic analysis without decryption; deep packet inspection for forensic investigation via Wireshark