Network Insight

Get complete visibility into network threat-related activities


Core Network Insight (formerly Damballa Failsafe) is an advanced threat detection solution that automatically and accurately identifies hidden infections, in real time, on live traffic. Built on over a decade of scientific research and big data visibility, Network Insight provides definitive evidence to help security teams reduce dwell time and rapidly prevent loss. Instead of monitoring the network, Network Insight monitors the traffic, looking for proof of advanced persistent threats (APTs), enabling swift detection action without needing to add to your headcount.

What Sets Network Insight Apart?

Uncover Infections in Every IoT Device on Your Network

Uncover Infections in Every IoT Device 

Do you know the status of every device in your organization? Most security products only protect a fraction of all endpoints or require an agent to be installed in order to monitor them. This leaves far too many high-end IoT and other devices unwatched, including security cameras, video conference units, MRIs, CT machines, SCADA systems, or even connected coffee makers and refrigerators. Network Insight is agentless, and OS and platform agnostic, covering any and every device in your network. 

Reduced Alert Fatigue Lets You Zero In On Threats

Reduced Alert Fatigue

You’ll only hear from Network Insight when it’s time to act. When Core Network Insight confirms a device is infected by advanced persistent threats or malware, it presents a full case of evidence, prioritized by risk. By limiting notifications to only those that contain actionable details on a live threat, false positives are eliminated, and analysts can associate alerts from Network Insight as those that should be investigated and remediated immediately.

How Does Network Insight Work?



Network Insight observes device behavior in real time. It is continually capturing and correlating evidence using multiple detection engines to arrive at a verdict of "suspected" or "infected."


The Case Analyzer, a context aware threat intelligence engine, confirms the infection, and a series of risk profilers assess and prioritize the infection based on the determined risk level.


Members of a security team receive definitive evidence and actionable alerts, so they can rapidly prevent loss on high-risk devices while blocking activity on the rest.

CTA Text

Identify infected devices and prioritize risk. 



Personalized Dashboards




Personalized dashboards provide visual displays of findings, threats, and status updates. Get insights from critical data, including:

  • Currently infected assets
  • Average infection age
  • Riskiest infected assets
  • Newly infected assets

Key Features


Analyze Behaviors and Confirm Threats

Card image cap

Analyze network behaviors, malicious payloads, threat actor, and Advanced Persistent Threat (APT) activity. Verify evidence by passing information to an automated Case Analyzer, which corroborates evidence. Once true positive infections are confirmed, risk-ranking is applied.

Prevent What You Can, Detect What You Must

Cybersecurity strategies often focus on prevention, which is a critical component of network safety, but it’s not the only activity to consider. In today’s world of advanced threats, the benefits of detection solutions like Network Insight are just as clear and crucial.


Shorten Dwell Time of Infections
Reduce risk of damage
Save time and resources

No Matter the Threat, We Can Detect It.

Detect everything from the latest threats to enduring and dangerous infections like:




CTA Text

Ready to See Network Insight in Action?

See what an advanced threat detection solution can do in this comprehensive, on-demand demo.