Deploying a network tap without downtime
Choosing between a SPAN port and a passive TAP, what each misses, and how to verify the appliance is genuinely seeing the traffic you think it is.
We would rather ship a small number of genuinely useful write-ups than pad this page out. Here is what is being written and roughly what each will cover.
Nothing is published yet. The library below is the plan, not the archive. Subscribe at the foot of the page and we will let you know as pieces go live, or ask us directly if there is something specific you need now.
Choosing between a SPAN port and a passive TAP, what each misses, and how to verify the appliance is genuinely seeing the traffic you think it is.
The bandwidth, latency and privacy arithmetic behind running inference on the appliance, including where the cloud approach is genuinely better.
What each field means, how severity is decided, and which alerts warrant waking someone up versus waiting until morning.
Traffic patterns that give away mining activity, and why signature lists stop working almost immediately.
A reproducible setup using Suricata and open datasets, aimed at anyone who wants to test our claims rather than take them on faith.
How behavioural models cope with genuine change — new staff, new devices, seasonal load — without burying you in false positives.
The pages that already answer most of what people ask us.
Occasional email when we publish something. No newsletter cadence, no drip sequence.