EndaceProbe and EndaceProbe Cloud: Always-on, highly-scalable packet capture to secure OT security networks
Photo Gallery
![]() |
EndaceProbe and EndaceProbe Cloud: Always-on, highly-scalable packet capture to secure OT security networks

Additional Info
Company | Endace |
Website | https://www.endace.com |
Company size (employees) | 100 to 499 |
Headquarters Region | North America |
Overview
Endace’s customers include many US government agencies facing OT security challenges (DISA, US Marines, Federal Administration Agency, Bureau of Land Management, Department of Energy etc.), as well as many other organizations in the US and around the world that are responsible for operating critical infrastructure and keeping the public safe.
Security threats in industrial and critical infrastructure environments are growing rapidly with significant increases in attacks on OT devices and systems that rely on an organization’s IT networks to communicate. While connecting these devices to IT networks enables remote automation and monitoring by human operators, it also exposes vulnerable OT devices to attack and broadens the attack surface of the overall network.
OT devices, such as PLCs, and SCADA systems use M2M (machine-to-machine) protocols – e.g., MGTT, CoAP, AMCP – to transmit messages, commands, and responses to and from devices. OT devices typically lack secure authentication because it was never intended they be connected to a network outside of their local OT network. If an attacker can gain access to these devices from outside the OT network, it is often relatively trivial to compromise or attack them.
Commonly-used network security monitoring solutions that use network metadata to monitor for malicious activity often cannot detect attacks because they lack visibility into the content of actual communications to and from OT devices and the IT network. For that you need access to the actual network packets.
EndaceProbes deliver always-on packet capture that gives teams the detailed information they need to accurately investigate OT security threats. Teams can quickly locate the packet evidence related to OT network incidents to see exactly what took place on the network and determine whether traffic to and from devices is legitimate, or malicious. This enables them to investigate incidents faster, and more conclusively.
Key Capabilities / Features
EndaceProbe is the industry’s only open packet capture platform, offering highly-scalable, always-on packet capture and recording, across on-premises, private and public cloud environments with zero packet loss. With industry-leading speed, density, and storage capacity, EndaceProbes can record weeks or months of network traffic; allowing teams to go further back in time to accurately and decisively reconstruct, investigate and resolve threats, breaches, or performance issues.
Customers can deploy third-party security solutions (such as SOAR, IDS or AI-based tools), OT, or performance monitoring tools directly to where packet data is recorded, where they can analyze real-time traffic or replay recorded traffic for historical analysis. Endace partners with leading vendors such as Cisco, Palo Alto Networks, Fortinet, IBM, Darktrace and many others (see https://www.endace.com/fusion-partners) to integrate packet capture into their products. This integration allows analysts to go from alerts in their monitoring tools to related packet data with a single click.
Endace’s search and data mining component (InvestigationManager) provides fast, easy access to packet data across the entire network from a single pane of glass. EndaceCMS enables easy configuration and maintenance of the entire EndaceProbe estate from a central management console. EndaceVision is a browser-based traffic analysis tool within InvestigationManager. It gives teams a top-level view of the health of the network and provides a wide range of visualizations (including accurate microburst detection, traffic over time, and top talkers) for powerful analysis of network traffic and activity.
Detecting, investigating, and responding to threats is vital when time is of the essence and public safety is at risk. Endace’s modular architecture and decentralized data storage lets customers seamlessly expand throughput and/or storage capability of their monitoring infrastructure easily as their needs evolve, simply by adding additional EndaceProbes wherever they need them: on-prem networks (IT and OT) or in public or private cloud environments.
How we are different
• In December 2024, the US Defense Information Systems Agency (DISA) certified EndaceProbes on its Department of Defense Information Network Approved Products Lists (DoDIN APL). The certification means that EndaceProbes are certified as complying with the DoD’s stringent security testing and can be freely adopted and deployed at US federal agencies and defense departments with no further testing required. EndaceProbes are the only packet capture solution to pass this.
• Many OT devices were not designed with network security in mind, and are incapable of providing log data when, or after, an incident occurs. Deep, packet-level visibility may be the only way to determine if an event involving an OT device was malicious. The EndaceProbe enables always-on, zero loss packet capture across large, complex environments with the ability to store weeks or months of recorded network traffic. This gives customers an extensive “look-back” for conclusive forensic investigation and response to security threats and attacks. No other solution provides the same unlimited scalability and deep packet-level visibility across all hybrid cloud infrastructure. EndaceProbe Cloud works seamlessly with on-prem EndaceProbe appliances for single-pane-of-glass visibility and management. Teams can apply their tried-and-true workflows and investigation processes to all systems and assets on their network, regardless of architecture.
• EndaceProbe is the industry’s only open platform, having the ability to integrate and host third-party security and performance monitoring tools. This ensures all tools have access to a common, accurate source of network data for analysis and enables hardware consolidation and rapid tool deployment. The ability to integrate a common packet capture technology across tools from multiple vendors – including OT security vendors - as well as with custom or open-source solutions, gives teams complete visibility into activity on both OT and IT networks down to the packet level.
-
Vote for this Nomination
(click the thumbs-up icon to cast your vote)


