◆ How it works

From first packet to the board report.

Apate Security follows one clear defensive flow - seven stages in a single console. Here is exactly what happens, step by step.

The console

The screen you open

Activate once with your license key, then step straight into the command center - a live device table, system status and posture, all in one window.

Apate Security - Activation
LIVETRK 8 · AZ 000°
Apate Security
See Everything · Catch What Hides
- LIVE DEVICES -
ASSETIPMAC ADDRESS
Analyst-PC (Local)192.••.••.••3c:••:••:••:••:04
Gateway-Router192.••.••.••9c:••:••:••:••:14
Analyst-Phone192.••.••.••f0:••:••:••:••:2c
Rogue AP ⚠192.••.••.••a0:••:••:••:••:10
Unknown device ⚠192.••.••.••de:••:••:••:••:19
- SYSTEM STATUS -
  • integrity self-check ✓
  • online verification ✓
  • Ed25519 signature engine ✓
  • license store ✓
⊙ --:--:-- · …
● Online● Ed25519● no telemetry
Welcome back
Licensed - Lifetime plan
Tier: Enterprise
PlansPlus $12.99Pro $24.99Business $82.99Enterprise Custom
Email
you@company.com
Stored on this device only · for your license certificate & support
License key
APATE-••••••••-••••••••-••••
✓ Activate
Machine ID · A1B2·••••·••••·9F3C⧉ Copy
Air-gapped? Send this ID to info@apatesecurity.com for a machine-locked key.
⊟ View all plans▣ Certificate☑ I accept the license terms
Need help? Email support: support@apatesecurity.com
Request a refundCheck for updateQuitEnter Apate Security →
The flow

Discover → Monitor → Detect → Investigate → Respond → Harden → Report

Seven stages, one console.

1

🔎 Discover

Point Apate at your Wi-Fi or LAN and it finds every connected device - phones, laptops, IoT, cameras, printers and anything that shouldn't be there. For each one it learns IP, MAC, vendor, OS, open ports and a risk score.

Network discovery · device inventory
2

📡 Monitor

It keeps watching - mapping how devices connect, which services are open, and DNS/browsing activity - and alerts the moment something new joins or a risky change happens, even while you're away.

Live topology · DNS & traffic · alerts
3

🛡 Detect

Observed activity is matched against threat-intel feeds, behavioral rules and encrypted-fingerprint checks (JA3) to surface rogue devices, beaconing/C2, DNS tunneling and other threats - correlated with ATT&CK.

Threat detection · ATT&CK mapping
4

🔬 Investigate

Paste any indicator - an IP, domain, URL, hash, email, header, JWT or certificate - and Apate auto-detects the type, runs the right tools, and builds one combined case with a verdict, pivots and a timeline. Most of it works offline.

One-click case · forensics & OSINT
5

⚡ Respond

When you decide to act, response tools are there - and stay under your control. Active steps are opt-in and clearly separated from monitoring, so nothing happens on your network without you choosing it.

Opt-in response · fully under your control
6

🔒 Harden

Turn findings into fixes: exposed ports, weak TLS, unpatched or end-of-life systems and risky devices are flagged with prioritized, plain-language recommendations you can act on.

Exposure & hygiene · prioritized fixes
7

📊 Report

One click turns live findings into a board-ready briefing - an overall posture score and letter grade, top business risks, and a prioritized action plan - exported as clean HTML/PDF, with CIS / NIST / ISO 27001 mapping and SIEM export.

Board-ready reports · compliance · SIEM
In the wild

The things that slip past everything else.

Patterns Apate is built to surface - the moment they appear on your network.

Evil-twin Wi‑Fi

A second network starts broadcasting your SSID with a stronger signal, hoping devices auto-connect to it.

Apate flags the duplicate SSID, its BSSID and vendor the moment it appears - the classic evil-twin signature.

Unknown device

A device you don't recognize joins at an odd hour and starts quietly probing the rest of the subnet.

Apate surfaces it the instant it speaks - IP, MAC, vendor and exactly what it's reaching for.

IoT beaconing

A smart plug or camera starts phoning home to an unfamiliar host on the other side of the world.

Apate shows the destination, port and cadence - steady beaconing stands out at a glance. You decide what it means.

ARP spoofing

Two devices suddenly claim the same gateway IP - someone is trying to sit in the middle of your traffic.

Apate catches the ARP conflict instantly - the tell-tale signature of a man-in-the-middle on the LAN.

Architecture

Self-contained by design, outbound-only.

By default, Apate observes your network and reports outward only. Active and on-path modes are opt-in, off by default, and for authorized networks.

Apate Security architecture Apate observes the monitored network through a mirror/SPAN port and pushes posture snapshots outbound only to your console. No agent on endpoints, no listening port on monitored segments, and no telemetry leaves your machine. Your monitored network Wi-Fi / LAN / OT segment Router / gateway Laptops & phones IoT · cameras · printers Unknown / rogue device Apate sensor agentless observes all traffic reports outbound only Your console & reports stays on your machine Device inventory & risk Threat detection & alerts Investigation & forensics Board-ready reports observe SPAN / mirror report outbound TLS only No agent on endpoints nothing installed on your devices No listening port nothing opens on monitored segments No telemetry your network data stays on your machine
Your monitored networkWi-Fi / LAN / OT segment
  • Router / gateway
  • Laptops & phones
  • IoT · cameras · printers
  • Unknown / rogue device
↓observe · SPAN / mirror
Apate sensoragentlessobserves all traffic · reports outbound only
↓report · outbound TLS only
Your console & reportsstays on your machine
  • Device inventory & risk
  • Threat detection & alerts
  • Investigation & forensics
  • Board-ready reports
No agent on endpointsnothing installed on your devices
No listening portnothing opens on monitored segments
No telemetryyour network data stays on your machine

Findings flow outbound only - from the sensor to your own console.

Why Apate

The only thing it adds to your network is visibility.

No endpoint agents. No listening ports on monitored segments. No outbound telemetry. Apate is built to run safely and continuously on production, OT and other sensitive networks. See every device.

Threat glossary

Know what you're looking for.

The network attacks Apate is built to surface - in plain language.

Evil twin

A fake Wi‑Fi access point that copies a real network's name (SSID) to trick devices into auto-connecting - so an attacker can intercept their traffic.

Rogue access point

An unauthorized Wi‑Fi access point added to your network - an easy, unmonitored backdoor that sits behind the firewall.

ARP spoofing (MITM)

An attacker poisons the ARP table to impersonate your gateway, quietly placing themselves in the middle of your traffic.

Beaconing / C2

Malware "phoning home" to a command-and-control server at steady intervals - a tell-tale rhythm of regular outbound connections.

Shadow / rogue device

An unknown device on the network - a curious neighbor, an unmanaged guest, or an intruder you never invited.

Lateral movement

An attacker hopping from one compromised machine to others across the LAN, looking for higher-value targets.

Port scan

Systematically probing a host for open services - often the first reconnaissance step before an attack.

Deauth attack

Forcing devices off Wi‑Fi, often to capture a login handshake or push victims onto an evil twin.

Apate surfaces every one of these patterns the moment they appear on your network.