Passive network sensors
Line-rate capture with zero footprint on production flows — sensors observe, they never respond.
Bifrost is the data layer of the DarkWatch platform — a planet-scale mesh of passive sensors, honeypots, and dark-IP listeners that captures attack traffic before it ever reaches a customer network.
Every DarkWatch product starts here. Bifrost nodes sit in dark address space, in front of emulated services, and on real networks — absorbing scans, exploits, and machine-driven campaigns and forwarding them to DarkWatch Live in under a second.
Passive, tamper-resistant, and everywhere — so the attacks you learn from are real ones, not lab traffic.
Line-rate capture with zero footprint on production flows — sensors observe, they never respond.
Millions of unused addresses instrumented to catch internet-wide scanning the moment it begins.
High-interaction decoys for SSH, HTTP, SMB, and ICS protocols that draw out full exploit chains.
Deploy a 1U appliance, a virtual image, or a managed cloud tap — all report to one control plane.
Signed telemetry and sealed enclosures keep the chain of custody intact from sensor to platform.
Enriched events reach DarkWatch Live and Valkyrie AI fast enough to watch a campaign spread live.
Representative figures for the current generation. Exact limits depend on edition and deployment.
| Specification | Detail |
|---|---|
| Sensor types | Passive network sensor · Dark-IP listener · Emulated-service honeypot (SSH / HTTP / SMB / ICS / MQTT) · Protocol decoy |
| Deployment models | Managed cloud tap · Virtual appliance (OVA / qcow2) · Hardware appliance (Bifrost Node, Gen 3) |
| Capture engine | eBPF zero-copy, line-rate PCAP, signed telemetry |
| Throughput | Up to 40 GbE per hardware node · up to 10 Gbps virtual · autoscaled cloud |
| Data retention | Rolling 90-day full packet (Enterprise) · 400-day metadata · configurable |
| Management | Central control plane · zero-touch enrollment · fleet health telemetry |
| Forwarding latency | Sub-second to DarkWatch Live, Valkyrie AI, and RuneFeed |
Managed in our cloud, self-hosted as a virtual image, or racked as a line-rate hardware node — the Bifrost Node.
Cloud Tap
Managed
Virtual Appliance
Self-hosted
Bifrost Node
Hardware appliance
Currently shipping Bifrost 7.2. Highlights from recent releases.
Collection is step one. These products turn Bifrost telemetry into a live map, enriched feeds, triage, and attribution.
The global attack map
Renders every attack the sensor grid sees, in real time, with AI-attack fingerprinting — the screen on the SOC wall.
Explore DarkWatch Live ▸Curated threat feeds & API
Enriched indicators and AI-attack signatures delivered as STIX/TAXII, a REST API, or native SIEM connectors.
Explore RuneFeed ▸Analyst copilot & triage
Clusters campaigns, flags machine-generated attacks, and drafts the investigation so analysts act instead of sift.
Explore Valkyrie ▸Attribution & infrastructure graph
Connects every indicator — domains, certs, ASNs, wallets, operators — into the whole adversary tree.
Explore Yggdrasil ▸Thirty minutes with a NorseStar intelligence engineer, a sample of the traffic hitting your sector, and a plan for where your first sensors go.
Request a demo ▸