Leave capability behind

StealthTrace

Leave it. Prove it’s really over.

When the responders leave, StealthTrace stays — a sensor that keeps capturing and watching the ruleset to confirm the incident is truly resolved before you trust the network again.

The hardest question after an incident is the simplest: is it actually over? StealthTrace is the concept for answering it — an autonomous sensor you leave behind when the response team rolls off. It keeps a full packet capture and watches against the ruleset Arbiter built, so you can confirm the threat hasn’t returned before you reconnect — air-gapped the entire time, then wiped on recovery.

What it's designed to do

Stay behind

Left in place when the response team rolls off.

Capture PCAP

Keeps a full packet record of the network.

Watch the ruleset

Checks traffic against the rules Arbiter built.

Confirm resolved

Shows the incident hasn’t returned over time.

Recover and wipe

Pulled out and reset— no data leaves with it.

The leave-behind that proves the incident is really closed.

1. Set the rules

Arbiter builds the ruleset from the incident and your network.

2. Leave behind

Place the sensor on a TAP or SPAN as the team rolls off.

3. Watch

It captures PCAP and checks traffic against the ruleset.

4. Recover

Confirm it’s clear, pull the sensor, wipe and reset.

The last step of an IR job

StealthOps gets the team onsite to find and contain. StealthTrace stays after — the leave-behind that turns “we think it’s clean” into evidence it stayed clean, without leaving an analyst parked on site.

Where teams would use it

Confirm an incident is resolved ⋅ Post-IR leave-behind ⋅ Watch before reconnecting⋅ Air-gapped evidence capture ⋅ Prove no recurrence ⋅ Unstaffed remote sites ⋅ Hand off to the operator