From first packet to the board report.
Apate Security follows one clear defensive flow - seven stages in a single console. Here is exactly what happens, step by step.
The screen you open
Activate once with your license key, then step straight into the command center - a live device table, system status and posture, all in one window.
- integrity self-check ✓
- online verification ✓
- Ed25519 signature engine ✓
- license store ✓
Tier: Enterprise
Discover → Monitor → Detect → Investigate → Respond → Harden → Report
Seven stages, one console.
🔎 Discover
Point Apate at your Wi-Fi or LAN and it finds every connected device - phones, laptops, IoT, cameras, printers and anything that shouldn't be there. For each one it learns IP, MAC, vendor, OS, open ports and a risk score.
Network discovery · device inventory📡 Monitor
It keeps watching - mapping how devices connect, which services are open, and DNS/browsing activity - and alerts the moment something new joins or a risky change happens, even while you're away.
Live topology · DNS & traffic · alerts🛡 Detect
Observed activity is matched against threat-intel feeds, behavioral rules and encrypted-fingerprint checks (JA3) to surface rogue devices, beaconing/C2, DNS tunneling and other threats - correlated with ATT&CK.
Threat detection · ATT&CK mapping🔬 Investigate
Paste any indicator - an IP, domain, URL, hash, email, header, JWT or certificate - and Apate auto-detects the type, runs the right tools, and builds one combined case with a verdict, pivots and a timeline. Most of it works offline.
One-click case · forensics & OSINT⚡ Respond
When you decide to act, response tools are there - and stay under your control. Active steps are opt-in and clearly separated from monitoring, so nothing happens on your network without you choosing it.
Opt-in response · fully under your control🔒 Harden
Turn findings into fixes: exposed ports, weak TLS, unpatched or end-of-life systems and risky devices are flagged with prioritized, plain-language recommendations you can act on.
Exposure & hygiene · prioritized fixes📊 Report
One click turns live findings into a board-ready briefing - an overall posture score and letter grade, top business risks, and a prioritized action plan - exported as clean HTML/PDF, with CIS / NIST / ISO 27001 mapping and SIEM export.
Board-ready reports · compliance · SIEMThe things that slip past everything else.
Patterns Apate is built to surface - the moment they appear on your network.
A second network starts broadcasting your SSID with a stronger signal, hoping devices auto-connect to it.
Apate flags the duplicate SSID, its BSSID and vendor the moment it appears - the classic evil-twin signature.
A device you don't recognize joins at an odd hour and starts quietly probing the rest of the subnet.
Apate surfaces it the instant it speaks - IP, MAC, vendor and exactly what it's reaching for.
A smart plug or camera starts phoning home to an unfamiliar host on the other side of the world.
Apate shows the destination, port and cadence - steady beaconing stands out at a glance. You decide what it means.
Two devices suddenly claim the same gateway IP - someone is trying to sit in the middle of your traffic.
Apate catches the ARP conflict instantly - the tell-tale signature of a man-in-the-middle on the LAN.
Self-contained by design, outbound-only.
By default, Apate observes your network and reports outward only. Active and on-path modes are opt-in, off by default, and for authorized networks.
- Router / gateway
- Laptops & phones
- IoT · cameras · printers
- Unknown / rogue device
- Device inventory & risk
- Threat detection & alerts
- Investigation & forensics
- Board-ready reports
Findings flow outbound only - from the sensor to your own console.
The only thing it adds to your network is visibility.
No endpoint agents. No listening ports on monitored segments. No outbound telemetry. Apate is built to run safely and continuously on production, OT and other sensitive networks. See every device.
Know what you're looking for.
The network attacks Apate is built to surface - in plain language.
Evil twin
A fake Wi‑Fi access point that copies a real network's name (SSID) to trick devices into auto-connecting - so an attacker can intercept their traffic.
Rogue access point
An unauthorized Wi‑Fi access point added to your network - an easy, unmonitored backdoor that sits behind the firewall.
ARP spoofing (MITM)
An attacker poisons the ARP table to impersonate your gateway, quietly placing themselves in the middle of your traffic.
Beaconing / C2
Malware "phoning home" to a command-and-control server at steady intervals - a tell-tale rhythm of regular outbound connections.
Shadow / rogue device
An unknown device on the network - a curious neighbor, an unmanaged guest, or an intruder you never invited.
Lateral movement
An attacker hopping from one compromised machine to others across the LAN, looking for higher-value targets.
Port scan
Systematically probing a host for open services - often the first reconnaissance step before an attack.
Deauth attack
Forcing devices off Wi‑Fi, often to capture a login handshake or push victims onto an evil twin.
Apate surfaces every one of these patterns the moment they appear on your network.