NORSESTAR
DarkWatch Platform · Bifrost

The sensor grid
under the internet.

Bifrost is the data layer of the DarkWatch platform — a planet-scale mesh of passive sensors, honeypots, and dark-IP listeners that captures attack traffic before it ever reaches a customer network.

8.2Msensors deployed
184countries observed
47 PBcaptured / day
3deployment models
Collect everything, everywhere

Attack traffic, at the source

Every DarkWatch product starts here. Bifrost nodes sit in dark address space, in front of emulated services, and on real networks — absorbing scans, exploits, and machine-driven campaigns and forwarding them to DarkWatch Live in under a second.

  • 8.2M sensors across 184 countries, one control plane
  • Dark-IP listeners that see internet-wide scanning as it starts
  • Emulated-service honeypots for SSH, HTTP, SMB, ICS, and more
  • Hardware, virtual, and cloud-native taps — mix and match
Capabilities

Collection built for the AI era

Passive, tamper-resistant, and everywhere — so the attacks you learn from are real ones, not lab traffic.

Passive network sensors

Line-rate capture with zero footprint on production flows — sensors observe, they never respond.

Dark-IP listeners

Millions of unused addresses instrumented to catch internet-wide scanning the moment it begins.

Emulated-service honeypots

High-interaction decoys for SSH, HTTP, SMB, and ICS protocols that draw out full exploit chains.

Hardware, virtual, cloud

Deploy a 1U appliance, a virtual image, or a managed cloud tap — all report to one control plane.

Tamper-evident capture

Signed telemetry and sealed enclosures keep the chain of custody intact from sensor to platform.

Sub-second forwarding

Enriched events reach DarkWatch Live and Valkyrie AI fast enough to watch a campaign spread live.

Specifications

Bifrost at a glance

Representative figures for the current generation. Exact limits depend on edition and deployment.

SpecificationDetail
Sensor typesPassive network sensor · Dark-IP listener · Emulated-service honeypot (SSH / HTTP / SMB / ICS / MQTT) · Protocol decoy
Deployment modelsManaged cloud tap · Virtual appliance (OVA / qcow2) · Hardware appliance (Bifrost Node, Gen 3)
Capture engineeBPF zero-copy, line-rate PCAP, signed telemetry
ThroughputUp to 40 GbE per hardware node · up to 10 Gbps virtual · autoscaled cloud
Data retentionRolling 90-day full packet (Enterprise) · 400-day metadata · configurable
ManagementCentral control plane · zero-touch enrollment · fleet health telemetry
Forwarding latencySub-second to DarkWatch Live, Valkyrie AI, and RuneFeed
Editions

Three ways to deploy a sensor

Managed in our cloud, self-hosted as a virtual image, or racked as a line-rate hardware node — the Bifrost Node.

Cloud Tap

Managed

MeteredPer GB ingested
  • Sensors in NorseStar cloud regions
  • Zero hardware to manage
  • Autoscaled capture
  • Sub-second forwarding to DarkWatch
Request a demo ▸

Bifrost Node

Hardware appliance

CustomPer appliance
  • 1U line-rate appliance
  • Up to 40 GbE capture
  • Tamper-evident enclosure
  • Zero-touch enrollment
  • 4-hour advance RMA
Talk to sales ▸
Release notes

Bifrost changelog

Currently shipping Bifrost 7.2. Highlights from recent releases.

7.2July 2026

Regions & zero-copy capture

  • Cloud Tap generally available in three new regions (São Paulo, Mumbai, Cape Town)
  • eBPF zero-copy capture on virtual appliances
  • Zero-touch enrollment for fleets over 1,000 nodes
7.1February 2026

Bifrost Node Gen 3

  • Hardware appliance Gen 3 (Bifrost Node X): 40 GbE, line-rate PCAP
  • Emulated-service honeypots add ICS / Modbus and MQTT decoys
  • Dark-IP listener v2 with per-/24 allocation
7.0October 2025

Unified control plane

  • One control plane across cloud, virtual, and hardware taps
  • Rolling 90-day full-packet retention (Enterprise)
  • New central enrollment and fleet health telemetry
The DarkWatch suite

Where Bifrost data goes

Collection is step one. These products turn Bifrost telemetry into a live map, enriched feeds, triage, and attribution.

DarkWatch Live

The global attack map

Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.

Explore DarkWatch Live ▸

RuneFeed Intelligence

Curated threat feeds & API

Enriched indicators and AI-attack signatures delivered as STIX/TAXII, a REST API, or native SIEM connectors.

Explore RuneFeed ▸

Valkyrie AI

Analyst copilot & triage

Clusters campaigns, flags machine-generated attacks, and drafts the investigation so analysts act instead of sift.

Explore Valkyrie ▸

Yggdrasil Graph

Attribution & infrastructure graph

Connects every indicator — domains, certs, ASNs, wallets, operators — into the whole adversary tree.

Explore Yggdrasil ▸
Deploy a sensor

See what Bifrost already collects

Thirty minutes with a NorseStar intelligence engineer, a sample of the traffic hitting your sector, and a plan for where your first sensors go.

Request a demo ▸