Open-source · sits between Suricata and your SIEM

Turn a signature-only Suricata sensor into a behavioural NDR.

Suricata sees the packets. It does not see the behaviour — the beacon, the low-and-slow exfil, the internal fan-out. Cernity reads the same flows and turns them into named, MITRE-tagged, entity-scoped findings, and folds repeating alerts into single incidents.

What Cernity adds

Behavioural detection

Beaconing, low-and-slow exfil, DNS tunnelling, lateral fan-out — the patterns a signature IDS has no rule for. Derived from the flows Suricata already emits.

Signal, not volume

One classified incident instead of dozens of repeating alerts or raw flow rows. Repeated signature hits collapse into a single tracked finding identity.

Analyst-ready context

Every finding carries a category, an ATT&CK mapping, severity, and the scoped source→destination entities — not a flow row to interpret by hand.

Drops into your pipeline

Sits between the sensor and the SIEM. Same Suricata, same SIEM — Cernity is the only thing added. Open source at cernity/cernityndr.

The gap, in one example

A periodic C2 callback, seen by both — Suricata logged it and said nothing; Cernity named it.

Periodic C2 callback 10.0.0.5 → 203.0.113.66:443
Suricata alone
flow records
20
threat alerts
0
17 flow rows for the host, 0 alerts — nothing flagged
+ Cernity
finding
c2 / beacon
ATT&CK
T1071
cadence
5s over 20 conns
one C2-beacon finding with the measured cadence
Suricata logged the callbacks but raised no alert. Cernity derived the 5-second cadence and named it C2.

See all four verified comparisons →