What you are evaluating
This profile evaluates the NDR workflow with an explicitly configured sensor and evidence-storage design. RevealX 360 and Enterprise differ in management; IDS, packet forensics and performance monitoring are separate modules or components that need license verification.
A useful evaluation context
Teams that want to connect network detections with deeper transaction or packet evidence.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Rules and behavioral models generate detections with participants, timing and investigation context.
- Detection details can link to records and packets, subject to collection and storage prerequisites.
- Related detections and investigation views help examine activity spanning multiple observations.
Where it fits in the work
- Validate the sensor and determine which encrypted or unmirrored traffic cannot supply the required evidence.
- Open a detection and follow its participants and related observations.
- Preserve available records or packets and distinguish missing storage from absence of malicious activity.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Investigate a synthetic unusual DNS exchange twice: once with supporting records and once with the recordstore unavailable. Compare what an analyst can conclude from each case.
Evidence to look for
Keep the detection ID, participant identities, time range and evidence location. Explain which conclusion remains unsupported when raw evidence was never retained.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which detections require decryption or do not support the selected sensor type?
- Are the recordstore, packet capture and lookback needed for the pilot configured and licensed?
- Which users may view or export sensitive packet contents?