◆ How it works

From first packet to the board report.

Apate Security follows one clear defensive flow - and it does the whole thing passively. It observes and alerts; it never spoofs, injects or attacks. Here is exactly what happens, step by step.

The flow

Discover → Monitor → Detect → Investigate → Respond → Harden → Report

Seven stages, one console. Every stage is read-only by default.

1

🔎 Discover

Point Apate at your WiFi or LAN and it passively finds every connected device - phones, laptops, IoT, cameras, printers and anything that shouldn't be there. For each one it learns IP, MAC, vendor, OS, open ports and a risk score.

Passive discovery · device inventory
2

📡 Monitor

It keeps watching - mapping how devices connect, which services are open, and DNS/browsing activity - and alerts the moment something new joins or a risky change happens, even while you're away.

Live topology · DNS & traffic · alerts
3

🛡 Detect

Observed activity is matched against threat-intel feeds, behavioral rules and encrypted-fingerprint checks (JA3) to surface rogue devices, beaconing/C2, DNS tunneling and other threats - correlated with ATT&CK.

Threat detection · ATT&CK mapping
4

🔬 Investigate

Paste any indicator - an IP, domain, URL, hash, email, header, JWT or certificate - and Apate auto-detects the type, runs the right tools, and builds one combined case with a verdict, pivots and a timeline. Most of it works offline.

One-click case · forensics & OSINT
5

⚡ Respond

When you decide to act, response tools are there - and stay under your control. Active steps are opt-in and clearly separated from the passive core, so nothing happens on your network without you choosing it.

Opt-in response · fully under your control
6

🔒 Harden

Turn findings into fixes: exposed ports, weak TLS, unpatched or end-of-life systems and risky devices are flagged with prioritized, plain-language recommendations you can act on.

Exposure & hygiene · prioritized fixes
7

📊 Report

One click turns live findings into a board-ready briefing - an overall posture score and letter grade, top business risks, and a prioritized action plan - exported as clean HTML/PDF, with CIS / NIST / ISO 27001 mapping and SIEM export.

Board-ready reports · compliance · SIEM
Architecture

Passive by design, outbound-only.

Apate observes your network without ever being on-path for it - and reports outward only.

Apate Security passive architecture Apate passively observes the monitored network through a mirror/SPAN port and pushes posture snapshots outbound only to your console. No agent on endpoints, no listening port on monitored segments, and no telemetry leaves your machine. Your monitored network WiFi / LAN / OT segment Router / gateway Laptops & phones IoT · cameras · printers Unknown / rogue device Apate sensor passive · read-only observes traffic — sends no packets in — Your console & reports stays on your machine Device inventory & risk Threat detection & alerts Investigation & forensics Board-ready reports observe SPAN / mirror report outbound TLS only No agent on endpoints nothing installed on your devices No listening port nothing opens on monitored segments No telemetry your data never leaves your machine

The monitored network only sends data one way - to the sensor. Nothing is ever sent back into it.

Why passive

The only thing it adds to your network is visibility.

No endpoint agents. No listening ports on monitored segments. No outbound telemetry. Apate works entirely by observation - watching everything and changing nothing - so it runs safely and continuously on production, OT and other sensitive networks. See every device. Touch nothing.