Most defenses read the address. Sensor Edge reads the envelope.
A passive appliance that watches your traffic leave and flags covert channels conventional firewall and DPI controls can miss — data hidden inside TCP timestamps, window sizes, sequence numbers, packet timing and DNS queries. It sits on a mirror port, touches nothing inline, and retains no raw packet payloads.
Data can be smuggled out one bit at a time inside timing and header fields of otherwise ordinary packets, or tunnelled through DNS traffic a resolver handles every day. Sensor Edge is built to detect specific supported channel patterns — and to say clearly when the evidence is insufficient.
Not vague “anomaly” scores. Five specific exfiltration techniques from the literature — Giffin, Cabuk, Rowland, iodine, dnscat2 — each recognised by its own mechanism, not a generic threshold.
A SPAN / mirror tap with no inline choke point. The detector works from packet/transport metadata plus selected DNS protocol fields and does not retain raw packet payloads. If the sensor fails, your traffic is untouched.
Four tiers, including one most tools refuse to ship: INSUFFICIENT — the sensor says “not enough evidence” instead of guessing. Every verdict carries the measurement behind it.
Alerts export to STIX 2.1, MISP and syslog, so findings land in the SIEM and threat-intel tooling you already run.
Each supported carrier is matched against the technique that abuses it — and correlated across the flow rather than judged from one packet in isolation.
| Carrier field | Technique | What the sensor looks for |
|---|---|---|
| TCP Timestamp TSval option | Giffin delay-one-tick | The low bit of the timestamp modulated to carry data, against the flow’s own timing regime. |
| TCP Window size field | ASCII / high-byte encoding | Window values cycling through printable or structured byte ranges instead of a congestion curve. |
| TCP Sequence initial seq. number | Rowland Covert_TCP + bounce | Data planted in the ISN, including the third-party bounce variant. |
| Packet timing inter-arrival | Cabuk on-off · TCPScript bursts | Silence-and-burst patterns and paced bursts that encode bits in when a packet is sent. |
| DNS query QNAME / QTYPE | iodine · dnscat2 | Supported detection profiles look for iodine NULL-mode command/data structure and dnscat2-over-TXT session/packet structure, with two-way correlation. |
Illustrative output in the current prototype format. A confirmed tunnel is backed by recognised protocol structure and two-way correlation; a bare transfer with no recognised handshake drops to LIKELY; too little to judge is held at INSUFFICIENT rather than presented as a negative result.
The difference between a sensor you can act on and one you learn to ignore is what it does when the evidence is thin. Sensor Edge tells you.
Recognised protocol structure and two-way correlation. This raises the banner and becomes an indicator for export.
A transfer with the shape of exfiltration but without the structure that would make it certain. Flagged for a human, not auto-escalated.
The pattern is there but below the sample floor. Kept as evidence, never counted as clean — the state most tools quietly drop.
The observed traffic was judged by the supported detectors and no matching covert signal was found. This is not a claim that the host or network is globally clean.
A security product that hides its limits is a liability. These are the boundaries of this version, on the record — the honest edges of the envelope model.
A/AAAAData smuggled in ordinary address lookups is indistinguishable from reputation and CDN traffic without a per-host baseline. That baseline is on the roadmap, not claimed today.
DNS wrapped in HTTPS or TLS is opaque on the wire by design. Out of scope for a passive sensor that does not break TLS.
DNS-over-TCP and UDP fragmentation are recognised and reported as unhandled — never counted as clean. And the sensor only sees what the mirror port carries.
Connects to a SPAN / mirror port or a network TAP. It is never in the traffic path, so it cannot drop, delay or block a packet.
No raw packet-payload retention. Detection uses packet/transport metadata and selected DNS protocol fields; the capture buffer is measured in seconds — a privacy boundary you can explain to a works council, not just a spec-sheet claim.
A silent appliance with four 2.5 GbE ports. Drop it next to the switch, point the mirror at it, and it watches egress.
The two figures above are measured, not marketing: a suite of 110 automated tests, and zero observed false positives across 5,958 DNS groups judged during one hour of ordinary office browsing. They describe that DNS test path and dataset only — not a guarantee for every network or every traffic mix.
The same detection engine, delivered for a branch, a company backbone, or a team that needs AI-assisted analysis on top.
The full engine in a silent, fanless mini-appliance. Drop it on a mirror port and it watches egress without ever touching the traffic path.
Target release · December 2026The same engine in a 19-inch rack build, for higher capture throughput and deployment across a company backbone.
Target · Q1 2027Adds AI-assisted log and traffic analysis with per-host baselining on top of the detection engine — context, not just alerts.
Target · Q1 2027 · AIRequest a demo and watch the sensor read a covert channel out of live traffic — with the evidence, the verdict, and the honest limits stated up front.
Passive network sensor · no raw packet-payload retention · STIX / MISP / syslog export · GG Advanced IT Security — ggsec.de