See all your traffic,
down to the last packet.
Deep packet inspection in real time. The sensor sees everything crossing your LAN — connections, flows, exfiltration, Shadow IT, command-and-control. No traffic escapes it.
The DPI sensor is the SOC's eye on the network. Plugged into a mirror on your switch (SPAN or TAP), it inspects every packet without slowing anything down: it reassembles sessions, identifies application protocols, enriches each flow with GeoIP, ASN and CTI data, then passes everything to SYLink AI for correlation — without ever decrypting the content of your communications.
From threat to evidence, in real time.
The module captures the signal, SYLink AI correlates it and decides — you keep control.
What the sensor shows you.
The network as it actually is — not as it was documented three years ago.
Describe it, and the map builds itself
Dynamic traffic mapping

Three-tier technical diagram

The guided questionnaire

Real screenshots of the UniSOC portal. The data shown comes from a demonstration environment.
Why “seeing” is not enough.
Most sensors on the market are IDS: they read the header. Our DPI looks inside.
Host: files.evil-cdn.io
x-token: 9f2a…
The technology, in detail.
What the module actually does — functions, not promises.
L2–L7 inspection
- Full-packet capture at 10 Gbps with automatic rotation
- TCP / UDP / QUIC sessions reassembled
- 500+ application protocols identified (HTTP, TLS, SMB, RDP, DNS, SSH…)
- TLS/SNI metadata without decryption
- JA3 / JA4 fingerprinting
Behavioural detection
- C2 beacon (regular interval to a suspicious IP)
- Suspicious tunnels (DoH, ICMP exfil, abnormal lengths)
- Exfiltration: abnormal uploads, encrypted archives
- Shadow IT / Shadow AI (ChatGPT, Claude, Notion, Slack…)
- Internal lateral movement, LAN to LAN
SYLink AI enrichment
- Three-layer GeoIP (DB-IP, MaxMind, Cloudflare)
- ASN + Whois + 50 CTI reputation sources
- Matched against 22M+ malicious IPs and domains
- DPI × EDR cross-correlation by IP
- Automatic alert triage by the AI
Forensics & investigation
- JSON flows, 14 days hot plus 90 days archived
- Animated replay to walk through an incident
- Multi-source JSON evidence for DORA audits
- Natural-language threat hunting
- PCAP export filtered by session, IP or period
Sovereign deployment
- Industrial fanless hardware or VM
- No cloud egress — traffic stays on site
- Mutual TLS probe → SOC, monthly cert rotation
- Works with SPAN, ERSPAN and network TAPs
- Multiple sensors across sites, correlated in real time
Compliance & visibility
- No TLS decryption — GDPR respected
- HMAC-signed audit trail (DORA art. 28)
- MTTD / MTTR dashboards per tenant
- NIS2 article 23 reporting
- MITRE ATT&CK coverage: 76 techniques
What is it actually for?
Detect a compromised endpoint
Regular C2 beacons, exfiltration to a typosquatted domain, a night-time SSH tunnel: the sensor sees the pattern and raises the alert before the ransomware starts.
Map Shadow IT and Shadow AI
How many upload code into ChatGPT? Who uses unmanaged tools? The sensor records actual usage — not what was declared.
Prove DORA and NIS2 compliance
Trace every outbound connection, keep 90 days of metadata, prove to the auditor that the anomalies were seen and qualified.
Forensic investigation
A machine hit by ransomware three days ago? Trace back to the entry point: who talked to whom, when, on which port, and how much data moved.
Driven by SYLink AI, hosted 100% in France (HDS v2), with no Cloud Act exposure. Every decision is logged and defensible under NIS2 and DORA.
One building block of the SOC — never on its own.
Each module feeds the others through SYLink AI.
Ready to see what is really
happening on your network?
First trial free, no credit card, no commitment. On your existing infrastructure.
