Skip to content
All security projects
Security projectDemo readyNetwork anomaly

Network Baseline

Builds a normal traffic baseline from a sample of network logs, then flags unusual source IPs, destination ports, and connection volume spikes in observed traffic.

Takes a 'normal' sample of network connections, learns typical source IPs, destination ports, and per-host volume, then compares against an 'observed' sample to detect anomalies. Outputs severity-scored anomalies, per-source risk tables, and an analyst triage handoff.

PythonCLINetwork logsBaselining

Catalog entry only — a full write-up lands closer to release.

Related across catalogs

Want a heads-up when Network Baseline releases?

Subscribe via blog