Apate Security follows one clear defensive flow - and it does the whole thing passively. It observes and alerts; it never spoofs, injects or attacks. Here is exactly what happens, step by step.
Seven stages, one console. Every stage is read-only by default.
Point Apate at your WiFi or LAN and it passively finds every connected device - phones, laptops, IoT, cameras, printers and anything that shouldn't be there. For each one it learns IP, MAC, vendor, OS, open ports and a risk score.
Passive discovery · device inventoryIt keeps watching - mapping how devices connect, which services are open, and DNS/browsing activity - and alerts the moment something new joins or a risky change happens, even while you're away.
Live topology · DNS & traffic · alertsObserved activity is matched against threat-intel feeds, behavioral rules and encrypted-fingerprint checks (JA3) to surface rogue devices, beaconing/C2, DNS tunneling and other threats - correlated with ATT&CK.
Threat detection · ATT&CK mappingPaste any indicator - an IP, domain, URL, hash, email, header, JWT or certificate - and Apate auto-detects the type, runs the right tools, and builds one combined case with a verdict, pivots and a timeline. Most of it works offline.
One-click case · forensics & OSINTWhen you decide to act, response tools are there - and stay under your control. Active steps are opt-in and clearly separated from the passive core, so nothing happens on your network without you choosing it.
Opt-in response · fully under your controlTurn findings into fixes: exposed ports, weak TLS, unpatched or end-of-life systems and risky devices are flagged with prioritized, plain-language recommendations you can act on.
Exposure & hygiene · prioritized fixesOne click turns live findings into a board-ready briefing - an overall posture score and letter grade, top business risks, and a prioritized action plan - exported as clean HTML/PDF, with CIS / NIST / ISO 27001 mapping and SIEM export.
Board-ready reports · compliance · SIEMApate observes your network without ever being on-path for it - and reports outward only.
The monitored network only sends data one way - to the sensor. Nothing is ever sent back into it.
No endpoint agents. No listening ports on monitored segments. No outbound telemetry. Apate works entirely by observation - watching everything and changing nothing - so it runs safely and continuously on production, OT and other sensitive networks. See every device. Touch nothing.