North Star Labs
← FAQFREQUENTLY ASKED QUESTIONS

Core concepts

Last reviewed August 19, 2026 · Mitchell Sipus, PhD, Founder & CEO

IN SHORT

Passive means we never transmit into your network, deterministic means findings come from complete observation rather than statistical inference, and ground truth means the record has no sampling gaps for an adversary to hide in.

What is passive network sensing?

Passive network sensing means observing the communications already flowing across a network without sending anything into it. A passive sensor connects to a mirror or tap point and listens, so it cannot interrupt operations, crash a fragile industrial device, or alter the traffic it observes. This matters most in operational technology and defense environments, where active scanning can fault legacy equipment and where an observer that changes the thing it measures cannot be trusted as evidence. Some platforms in this market combine passive observation with active queries sent to devices, which extends inventory detail at the cost of touching production equipment. CyPhER stays entirely passive.

What does deterministic detection mean?

Deterministic detection means conclusions drawn from complete observation rather than statistical inference. A deterministic system can tell you that a specific communication occurred, when it occurred, and between which endpoints, because it saw all of the traffic rather than a sample of it. The alternative is probabilistic detection, in which a model trained on past behavior estimates whether current behavior looks anomalous and expresses that estimate as a confidence score. Probabilistic tools are useful for surfacing candidates, but a confidence score is not evidence, and a model that learned "normal" during a period when an adversary was already present will treat that adversary as normal. We built CyPhER to be deterministic because defenders eventually have to answer questions in front of commanders, regulators, or courts, and "the model was 87 percent confident" is not an answer that holds up.

What is network telemetry?

Network telemetry is the record of communications a network produces, describing who talked to whom, when, over what ports and protocols, and in what volume. Most security architectures build this record from samples, because collecting everything at scale has historically been considered impractical, and sampled telemetry is the quiet assumption underneath many popular tools. The problem is that adversaries do not politely confine their activity to the sampled fraction. Low-and-slow reconnaissance, staged lateral movement, and patient exfiltration are exactly the behaviors most likely to fall between samples. CyPhER produces full-fidelity telemetry at layers 2 through 4, meaning the record is complete rather than sampled, so the question "did this connection happen" always has a definitive answer.

What is east-west traffic and why does it matter?

East-west traffic is communication between systems inside a network, as opposed to north-south traffic crossing the perimeter. It matters because modern intrusions are mostly an east-west story. An adversary who gains an initial foothold spends the following days or months moving laterally, escalating access, and staging data, and all of that movement is internal. Perimeter tools do not see it, endpoint agents cannot be installed on much of the equipment involved, and sampled internal monitoring sees only fragments of it. Complete passive observation of internal communications is the most reliable way to catch lateral movement, because lateral movement cannot happen without producing network traffic, and traffic that is fully recorded cannot hide.

Can CyPhER support a zero trust architecture?

CyPhER converts a legacy network into a zero trust architecture through iteration, and this is one of the most practical things we do for organizations that have been told to adopt zero trust and cannot see a path from where they actually are. The obstacle is almost never the concept. Zero trust requires knowing what communicates with what, so that access can be restricted to what is genuinely necessary, and most organizations running decades of accumulated infrastructure do not have that knowledge and cannot get it from asset inventories or network diagrams that stopped matching reality years ago. A complete deterministic record of network activity supplies exactly what is missing, because it establishes what actually communicates rather than what someone believes communicates. From there the work becomes iterative and safe. Observe the real communication patterns, identify the connections that are genuinely required, restrict what is not, and then observe again to verify that the restriction broke nothing and that the remaining traffic is what you intended. Each cycle tightens the architecture against evidence rather than against assumption, which is why the approach works on brownfield networks where a redesign is impossible. Our framing throughout is trusted connections rather than zero trust as a slogan, since the useful question is not whether trust exists but whether every trusted connection is one you can see, justify, and verify.

What is cyber phenomenology?

Cyber phenomenology is the study of network behavior as observed phenomena, working from what actually happened on the network rather than from signatures of previously catalogued attacks. The name comes from the MIT research program from which CyPhER emerged, and it describes a real methodological difference. Signature-based tools ask whether traffic matches a known-bad pattern, and behavioral tools ask whether traffic deviates from a learned baseline. A phenomenological approach instead builds a complete picture of network activity and reasons over that picture, which allows it to surface adversary behavior that has no signature and that a baseline model would absorb as normal.

What is the difference between ground truth and sampled visibility?

Ground truth is a complete record of network activity, and sampled visibility is an estimate built from a fraction of it. The distinction sounds academic until an incident forces the question. With sampled visibility, an investigator asking "when did the adversary first touch this server" gets an answer with gaps in it, and every gap is a place where the timeline could be wrong. With ground truth, the answer is definitive because the record is complete. Most of the market accepted sampling as a necessary compromise years ago and built analytics on top of the gaps.

© 2026 North Star Labs LLC. All rights reserved.

Alexandria, VirginiaPittsburgh, PennsylvaniaSAM LHY2TGVEF8E5CAGE 9SV87

NORTH STAR LABS® is a registered trademark of North Star Labs LLC, USPTO Reg. No. 8157679.