sequenced.ai
Articles/Agents & support/Blueprint//8 min read

ExtraHop turns network traffic into evidence for AI security decisions

Explore ExtraHop RevealX’s network detection, packet forensics, integrations and device-based pricing, with a proposed investigation pilot.

By Sequenced deskAI-assisted, source-led · how we work
Visit ExtraHop website ↗
RevealXNetwork security and observability
Machine learningBehavioral threat detection
Packet ForensicsOptional investigation module
360 or EnterpriseSaaS and on-premises routes
ExtraHop mark
ExtraHopextrahop.com · independent research

Represent this company? Verify your work email to access its workspace, or send the desk a factual correction.

ExtraHop builds network evidence into security investigations through its RevealX platform. It combines behavioral machine learning with network visibility and optional packet forensics, helping analysts examine what systems communicated rather than relying entirely on endpoint alerts. The practical question is whether the available traffic evidence resolves an incident quickly enough, with sufficient detail and control, to change the response.

In brief
  1. 01Platform RevealX brings network detection and performance analysis into a shared platform.
  2. 02Workflow Move from a suspicious conversation to supporting records and, when licensed, captured packets.
  3. 03Buying Device counting, sensor layout and retention affect the commercial scope.

01 / CompanyRevealX combines detection with the underlying network conversation

The RevealX platform spans network detection and response, network performance monitoring, intrusion detection and packet forensics. These functions answer related but different questions. Security analysis asks whether behavior is malicious; performance analysis asks why an application is slow or unavailable. Packet evidence can help either investigation, provided the relevant traffic was actually captured.

The NDR product page describes cloud-scale machine learning and out-of-band decryption. Behavioral detection can surface unusual activity, while decrypted protocol information may help explain a suspicious exchange. Decryption is a configured capability with prerequisites, not a promise that every encrypted conversation will automatically become readable. The evaluation must identify which protocols and keys are available in the intended environment.

ExtraHop remains the active company and product identity. Its ownership history records the acquisition by Bain Capital Private Equity and Crosspoint Capital Partners. RevealX is the platform within this coverage, rather than a separate company to count again. The current site continues to offer demonstrations and commercial deployment routes.

02 / AudienceInvestigators need visibility beyond managed endpoints

ExtraHop is relevant when a security team needs evidence about traffic between systems, including devices where an endpoint agent is unavailable or insufficient for the investigation. A concrete example is an unexpected sequence of internal connections that looks like lateral movement. The buyer wants to establish which systems participated and what the network observations can actually demonstrate.

Network and operations teams may also share an interest in the platform. A service disruption can arise from a malicious action, a configuration mistake or an application fault. Shared evidence can help them agree what happened, but ownership should remain clear. A performance engineer and a security analyst need different permissions and escalation paths even when they examine the same conversation.

SentinelOne offers a useful endpoint and security-operations comparison; Darktrace offers a behavioral-security comparison. The distinction is which evidence the buyer needs and where it can be collected. Do not expect a network platform to replace every endpoint action or identity control merely because it can identify activity associated with the same incident.

03 / WorkflowA proposed pilot works backward from a question investigators could not answer

This proposed evaluation has not been performed by Sequenced. Choose an approved historical investigation pattern or a controlled test environment in which the security team can generate representative, benign traffic. Specify the question first: for example, can the investigator establish which internal services a test account reached after an unusual connection? Keep the expected activity in a separate record.

Map the collection points before discussing detection quality. Identify which communication paths reach each sensor and where packets may be absent, duplicated or truncated. Include traffic that crosses the boundary between a data center and a cloud service if that is material to the use case. A detection cannot supply a complete story about a path the deployment never observed.

Work through the alert using the analyst’s normal permissions. Record which details are available immediately, which require another query and which require another person. The Packet Forensics offer describes moving between metrics, records and packets in one investigation. If that module is in scope, verify that the retained packet evidence covers the relevant time and conversation.

Test the distinction between suspicious behavior and a confirmed incident. Include a legitimate administrative operation that resembles part of the scenario. An analyst should be able to explain why one case warrants escalation while the other can be closed. Keep missing context visible; a confident-looking classification should not substitute for evidence about who performed the activity and why.

Next follow the case into the existing response process. ExtraHop’s integration catalog includes SIEM, ticketing, endpoint and firewall connections. Select the exact integration the team plans to use and verify the fields transferred. A useful integration preserves enough evidence for the next analyst to continue the case without reconstructing it from a separate dashboard.

If a containment integration is included, execute it only against a disposable, authorized test device. Check target resolution, acknowledgment, failure reporting and release. Sending an instruction is different from confirming that the external control enforced it. Have the receiving system’s administrator verify the outcome and preserve the action in the case record.

Conclude with a blind review by an analyst who did not configure the environment. Measure how much of the investigation they can reconstruct from the evidence alone. Separate collection completeness, analytical usefulness, response reliability and analyst effort. This makes the pilot useful even when it reveals that sensor placement or retention needs improvement before detection quality can be judged.

04 / PricingThe number of devices depends on where sensors see them

ScopePublished basisBuyer implication
RevealX 360Discovered devices, daily record ingest, record lookbackSize device and evidence capacity together.
RevealX EnterpriseDiscovered devices; record capacity excludedSpecify separate record requirements.
Device countingCounted for each sensor that discovers itAccount for overlapping collection.
IDS and Packet ForensicsAdd-on modules to core NDRConfirm entitlements for the pilot.

Commercial model from ExtraHop’s current FAQ, consulted 24 September 2026. The FAQ does not publish a universal rate; request a scoped quote.

The commercial FAQ describes subscription pricing and two deployment models: SaaS-based RevealX 360 and on-premises RevealX Enterprise. It does not provide a universal numeric rate card. RevealX 360 combines discovered-device capacity with daily record ingest and a selected record lookback; Enterprise device pricing excludes record capacity, which therefore needs separate planning.

The counting rule deserves attention. A device observed by multiple sensors counts toward capacity for each sensor that discovers it. An organization’s inventory total may therefore differ from the licensed discovered-device total. Before requesting a proposal, draw the intended sensor layout and ask for an estimate that handles overlapping visibility rather than assuming each physical device is counted once.

Confirm the modules needed for the proposed investigation. The FAQ states that IDS and Packet Forensics are add-ons to the core NDR module and cannot be purchased as standalone products. Record retention and packet retention also serve different purposes. A longer record lookback does not by itself establish that full packet evidence is retained for the same duration.

05 / DistinctionsPacket context can make the reason for an alert easier to examine

ExtraHop’s strongest editorial distinction is the route from a detected behavior to the underlying network evidence. An investigator may need to distinguish a failed connection attempt from a successful exchange, or identify whether an unexpected service was actually contacted. A platform that makes those observations accessible can support a more precise response than an alert summary alone.

The shared security and performance view is also useful when teams disagree about the cause of a disruption. Rather than treating every unusual spike as an attack, they can inspect the same timeline and decide which explanation fits. This is a proposed operational advantage, not a measured outcome from this review. Its value depends on the evidence retained and the team’s ability to interpret it.

Integration breadth matters when the network tool is an evidence source within a larger security workflow. The catalog describes exporting detections and network intelligence to other systems, as well as actions through enforcement tools. Evaluate the specific direction of each connection. A searchable event export is useful, but it is not the same capability as a supported containment action.

06 / QuestionsDecryption, retention and data movement determine the practical boundary

Ask which traffic can be decrypted in the actual architecture and how the required material is protected. The answer may differ between internal authentication protocols, application TLS and cloud services. Do not use the existence of a decryption feature to assume universal payload visibility. Document the blind spots that remain so an analyst understands what an absent detail means.

Also examine the relationship between local deployment and cloud analysis. The public FAQ describes structured network records being sent to ExtraHop Cloud Services for machine learning. An on-premises component does not automatically imply that all analytical processing stays inside the organization. Establish the precise data flow, permissions and deployment-specific arrangements before approving the collection scope.

This article is based on public product and commercial sources. It does not report a deployed sensor test, independently measured detection performance or a customer-specific retention agreement. Some documentation routes returned access errors during research, so the proposed workflow stays at the publicly documented product level. Buyers should verify detailed configuration and supported versions with current implementation documentation.

07 / DecisionBuy the evidence path the incident process needs

ExtraHop is worth evaluating when network conversations would materially improve investigation and the organization can provide the necessary collection coverage. Begin with a difficult but bounded question and prove the path from observation to response. Expand after confirming the sensor footprint, module entitlements and retention required to keep that path reliable over time.

Evaluate

An incident with missing network evidence

Use one controlled scenario to inspect the complete conversation and response handoff.

Start with collection coverage.
Compare

Strong endpoint controls already in place

Determine which additional network observations change an investigation.

Measure complementary evidence.
Prepare

Unclear sensor or retention architecture

Map overlapping sensors and required records before accepting a quote.

Make capacity estimates reproducible.
What should we explore next?

A business worth understanding.

Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.

Suggestions are free. Selection and publication stay with the desk.

Sources
Filed under Agents & supportCompany ExtraHopNot affiliated with ExtraHopRequest a correctionRequest a refresh by email

Continue reading

All in this category