Turn a signature-only Suricata sensor into a behavioural NDR.
Suricata sees the packets. It does not see the behaviour — the beacon, the low-and-slow exfil, the internal fan-out. Cernity reads the same flows and turns them into named, MITRE-tagged, entity-scoped findings, and folds repeating alerts into single incidents.
What Cernity adds
Behavioural detection
Beaconing, low-and-slow exfil, DNS tunnelling, lateral fan-out — the patterns a signature IDS has no rule for. Derived from the flows Suricata already emits.
Signal, not volume
One classified incident instead of dozens of repeating alerts or raw flow rows. Repeated signature hits collapse into a single tracked finding identity.
Analyst-ready context
Every finding carries a category, an ATT&CK mapping, severity, and the scoped source→destination entities — not a flow row to interpret by hand.
Drops into your pipeline
Sits between the sensor and the SIEM. Same Suricata, same SIEM — Cernity is the only thing added. Open source at cernity/cernityndr.
The gap, in one example
A periodic C2 callback, seen by both — Suricata logged it and said nothing; Cernity named it.
- flow records
- 20
- threat alerts
- 0
- finding
- c2 / beacon
- ATT&CK
- T1071
- cadence
- 5s over 20 conns