Passive Network Sensor · Egress Detection

GGSEC Sensor Edge

Most defenses read the address. Sensor Edge reads the envelope.

A passive appliance that watches your traffic leave and flags covert channels conventional firewall and DPI controls can miss — data hidden inside TCP timestamps, window sizes, sequence numbers, packet timing and DNS queries. It sits on a mirror port, touches nothing inline, and retains no raw packet payloads.

GGSEC Sensor Edge passive egress-detection appliance
Why GGSEC Sensor Edge

Traditional controls check where traffic goes. Sensor Edge also measures how it gets there.

Data can be smuggled out one bit at a time inside timing and header fields of otherwise ordinary packets, or tunnelled through DNS traffic a resolver handles every day. Sensor Edge is built to detect specific supported channel patterns — and to say clearly when the evidence is insufficient.

🧬

Covert channels, named

Not vague “anomaly” scores. Five specific exfiltration techniques from the literature — Giffin, Cabuk, Rowland, iodine, dnscat2 — each recognised by its own mechanism, not a generic threshold.

👁

Fully passive

A SPAN / mirror tap with no inline choke point. The detector works from packet/transport metadata plus selected DNS protocol fields and does not retain raw packet payloads. If the sensor fails, your traffic is untouched.

Honest verdicts

Four tiers, including one most tools refuse to ship: INSUFFICIENT — the sensor says “not enough evidence” instead of guessing. Every verdict carries the measurement behind it.

🔗

Fits your SOC

Alerts export to STIX 2.1, MISP and syslog, so findings land in the SIEM and threat-intel tooling you already run.

What it detects

Five covert-channel carrier families, including DNS tunnelling

Each supported carrier is matched against the technique that abuses it — and correlated across the flow rather than judged from one packet in isolation.

Carrier fieldTechniqueWhat the sensor looks for
TCP Timestamp
TSval option
Giffin delay-one-tickThe low bit of the timestamp modulated to carry data, against the flow’s own timing regime.
TCP Window
size field
ASCII / high-byte encodingWindow values cycling through printable or structured byte ranges instead of a congestion curve.
TCP Sequence
initial seq. number
Rowland Covert_TCP + bounceData planted in the ISN, including the third-party bounce variant.
Packet timing
inter-arrival
Cabuk on-off · TCPScript burstsSilence-and-burst patterns and paced bursts that encode bits in when a packet is sent.
DNS query
QNAME / QTYPE
iodine · dnscat2Supported detection profiles look for iodine NULL-mode command/data structure and dnscat2-over-TXT session/packet structure, with two-way correlation.
ggsec-sensor — egress scan (evidence-tiered output)
[CONFIRMED] DNS_TUNNEL 10.4.2.19 -> tunnel.evil.example iodine profile: iodine NULL-mode structure · two-way correlated · down=1088B [LIKELY] DNS_QNAME_XFER 10.4.2.31 -> data.example.net TXT high-entropy labels + tunnel QTYPE, no handshake structure · verify [INSUFFICIENT] IAT_COVERT 10.4.2.44 -> 203.0.113.7 only 6 bursts pattern present but below the sample floor · not enough evidence to classify [NO SIGNAL] TCP_TIMESTAMP 347 flows judged no supported covert signal -> 1 confirmed tunnel, 1 likely transfer, 1 held back honestly, 0 false alarms.

Illustrative output in the current prototype format. A confirmed tunnel is backed by recognised protocol structure and two-way correlation; a bare transfer with no recognised handshake drops to LIKELY; too little to judge is held at INSUFFICIENT rather than presented as a negative result.

Honest output

Four verdicts — including “I don’t know”

The difference between a sensor you can act on and one you learn to ignore is what it does when the evidence is thin. Sensor Edge tells you.

CONFIRMED

Proven channel

Recognised protocol structure and two-way correlation. This raises the banner and becomes an indicator for export.

LIKELY

Strong signal, verify

A transfer with the shape of exfiltration but without the structure that would make it certain. Flagged for a human, not auto-escalated.

INSUFFICIENT

Not enough to say

The pattern is there but below the sample floor. Kept as evidence, never counted as clean — the state most tools quietly drop.

NO SIGNAL

No supported signal observed

The observed traffic was judged by the supported detectors and no matching covert signal was found. This is not a claim that the host or network is globally clean.

Stated plainly

What it does not detect

A security product that hides its limits is a liability. These are the boundaries of this version, on the record — the honest edges of the envelope model.

🚫

Exfiltration via plain A/AAAA

Data smuggled in ordinary address lookups is indistinguishable from reputation and CDN traffic without a per-host baseline. That baseline is on the roadmap, not claimed today.

🔒

Encrypted DNS (DoH / DoT)

DNS wrapped in HTTPS or TLS is opaque on the wire by design. Out of scope for a passive sensor that does not break TLS.

📦

DNS over TCP & off-mirror traffic

DNS-over-TCP and UDP fragmentation are recognised and reported as unhandled — never counted as clean. And the sensor only sees what the mirror port carries.

Deployment & privacy

A silent box on your mirror port

📡

Passive placement

Connects to a SPAN / mirror port or a network TAP. It is never in the traffic path, so it cannot drop, delay or block a packet.

🔐

Privacy by construction

No raw packet-payload retention. Detection uses packet/transport metadata and selected DNS protocol fields; the capture buffer is measured in seconds — a privacy boundary you can explain to a works council, not just a spec-sheet claim.

🖥

Fanless hardware

A silent appliance with four 2.5 GbE ports. Drop it next to the switch, point the mirror at it, and it watches egress.

5Covert-channel vectors
4Honest verdict tiers
110Automated tests
0Observed false positives / 5,958 judged DNS groups

The two figures above are measured, not marketing: a suite of 110 automated tests, and zero observed false positives across 5,958 DNS groups judged during one hour of ordinary office browsing. They describe that DNS test path and dataset only — not a guarantee for every network or every traffic mix.

Product line

One engine, three form factors

The same detection engine, delivered for a branch, a company backbone, or a team that needs AI-assisted analysis on top.

📡

Sensor Edge

Single site · branch

The full engine in a silent, fanless mini-appliance. Drop it on a mirror port and it watches egress without ever touching the traffic path.

Target release · December 2026
🗄

Sensor Rack

Company networks

The same engine in a 19-inch rack build, for higher capture throughput and deployment across a company backbone.

Target · Q1 2027
🧠

Sensor Analyst

AI log & traffic analysis

Adds AI-assisted log and traffic analysis with per-host baselining on top of the detection engine — context, not just alerts.

Target · Q1 2027 · AI

See it on your own network

Request a demo and watch the sensor read a covert channel out of live traffic — with the evidence, the verdict, and the honest limits stated up front.

Passive network sensor · no raw packet-payload retention · STIX / MISP / syslog export · GG Advanced IT Security — ggsec.de