The Olympus engine

Intelligence, automation
and tooling — built in.

What makes Olympus more than a data lake: a layer of AI, automation, and operational tooling that works across every byte you collect. Scroll the engine — or jump straight to any capability.

Understand & respond · AI analyst & agentic actor

Maya AI

Ask anything in plain language. The moment data lands in the lake, Maya mines it — clear explanations, root-cause analysis, and strategic insight — then goes agentic to run tests, remediate issues, and verify the fix.

  • Plain-language answers, grounded in your own packets, flows, & logs
  • Ask in natural language — no query syntax; Maya returns the full who, what, where, when & how
  • Automatically cross-correlates weak signals across packets, flows, logs, & events into one high-confidence incident
  • Root-cause across security and performance at once
  • Agentic: runs tests, pushes blocks & fixes, verifies outcomes
  • Every answer traces back to the raw evidence behind it
  • Agentic actions run through Playbooks' approvals — RBAC sets what Maya does on its own vs. what needs human sign-off
Explore Maya in depth
You

Why did checkout latency spike at 14:20, and is it a security issue?

MayaMaya AIroot-cause · 1.8s
A burst of retransmissions on the payment VLAN saturated the uplink. Correlated packets, flows, and logs trace this to a misconfigured load balancernot malicious. No threat matches in threat intel.
NPMAPMNDRThreat Intel
Xpert · root-causeSLA breach
NetXperts flagged HTTP response latency on the checkout app — root cause traced to slow Oracle query response. NetSLM raised a QoS alert as the SLA threshold was crossed.
Xpert: HTTP · application latency
Decode: Oracle response time
NetSLM: QoS alert · proactive
Understand & respond · Advanced analysis & SLM

NetXperts & NetSLM

Pre-built expertise and service-level assurance. NetXperts is a library of domain-specific “Xperts” that automate root-cause analysis across performance and security — while NetSLM adds real-time QoS and SLA monitoring with proactive alerts the moment performance drifts.

  • NetXperts: automated root-cause “Xperts” for performance & security
  • Application-layer decodes — HTTP, SMTP, FIX, ISO 8583, Oracle, Citrix, & more
  • NetSLM: real-time QoS / SLA monitoring with proactive alerts
  • Cut MTTR with auto-analysis from link to application layer
Explore NetXperts & NetSLM in depth
Understand & respond · Blocking & response

Remediation

Turn a detection into a block. The moment something is confirmed malicious, NIKSUN acts across every layer — on the endpoint, on the network, and at the domain — pushing the block to the enforcement points you already run and verifying it in the lake. Every action is triggered by correlated evidence and provable after the fact.

  • Block a confirmed-malicious host across firewalls, CDNs, & cloud security groups
  • View & manage all your firewall policies from one console
  • On-host blocking + Zero-Trust segmentation, air-gap capable — no third-party EDR required
  • Domain blocking for known-bad & disallowed destinations — with allow / deny lists & category policy
  • Triggered by correlated evidence — threat intel, detections, & Maya
  • Reaches the tools you already run through 500+ Connectors — no rip-and-replace
  • Verified in the lake — every block is re-checked and provable, not fire-and-forget
Explore Remediation in depth
One confirmed threat · blocked everywhere
EndShield · Endpoint block & segment
Enforced
Act on the host itself + Zero-Trust segmentation. No third-party EDR.
NetShield · Network block the host
Blocked
Push the block to firewalls, CDNs, & cloud security groups — one console.
RouteShield · Domain block the lookup
Denied
Stop known-bad & disallowed domains — allow / deny lists & category policy.
Automation & ops · Workflows, approvals, & remediation

Playbooks

Codify your response once, run it forever. Playbooks turn a detection into an orchestrated sequence — blocks, fixes, escalations, and notifications — run fully automated or gated for human sign-off, and verified in the data. Built-in approvals put a seatbelt on every action: RBAC defines exactly what each person and each AI agent may do alone, and what must be queued for a manager to review.

  • Trigger on any Maya-surfaced incident, alarm, or recommendation
  • Actions: firewall & endpoint blocks, config fixes, ticketing, alerts
  • One RBAC model for humans and AI agents alike — auto-execute trusted low-risk steps, queue sensitive ones for sign-off
  • Approvers see the full evidence and Maya's reasoning before they approve, reject, modify, or escalate
  • Closes the loop — verifies the fix worked before resolving, with a complete audit trail
Explore Playbooks in depth
Trigger
Incident surfaced

Lateral movement, 3 hosts · confidence 92%

Condition
If severity ≥ high

and asset in PCI scope

?
Approve
Manager sign-off

RBAC gate · full evidence shown

Action
Quarantine hosts & block C2

NetTrident + firewall · auto

Verify
Confirm & open case

Re-check traffic · notify SOC

CASE-4821
Lateral movement, finance segment
Active
ACJLMSassigned · 3Severity: High
Maya surfaced the incident — 6 signals correlated.
Maya attached root-cause & forensic timeline.
Playbook quarantined 3 hosts, blocked C2 domain.
A. Chen verified containment, escalated to IR.
📎 packets.pcap📎 timeline.json📎 threat list
Automation & ops · Incident tracking

Case Management

Every incident gets a home. Track, assign, and collaborate end-to-end — with the evidence, AI analysis, and remediation history attached automatically. No copy-pasting between a SIEM, a ticketing tool, and a spreadsheet.

  • Auto-created from incidents, with full evidence attached
  • Assign, comment, and collaborate across the team
  • Complete audit trail for compliance & post-mortems
  • One source of truth from detection to resolution
Explore Case Management in depth
Automation & ops · Scheduled reporting

ReportScheduler

Put the right report in the right inbox, automatically. ReportScheduler automates delivery of dashboards and executive reports to people across your organization — a daily read on your security posture, top network issues, and compliance standpoint, or any cadence you choose.

  • Schedule any dashboard or executive report for delivery
  • Hourly, daily, weekly, or monthly cadences
  • Target the right recipients — execs, SOC, NOC, auditors
  • Security posture, top issues, & compliance, in their inbox
Explore ReportScheduler in depth
📅
Daily Security PostureScheduled
Daily · 7AMSecurity posture → CISO, SOC
HourlyTop network issues → NOC
WeeklyCompliance summary → Audit
MonthlyExec scorecard → Leadership
auto-deliveredPDF · email
💻
WS-2241healthy
🖥️
SRV-DB-03healthy
Quarantined
💻
WS-1180isolated
💻
WS-2242healthy
🖥️
SRV-APP-01healthy
📱
MOB-77healthy
↑ NetTrident agents streaming to the NKW · endpoint action on demand
Collect & integrate · Universal agent

NetTrident

A single lightweight agent that collects data from anywhere — endpoints, servers, remote sites, and cloud — and feeds it into the lake. NetTrident also acts: quarantine a device, kill a process, or enforce compliance, right from the platform.

  • Collects from endpoints, servers, OT, and cloud workloads
  • Streams deep endpoint activity — processes, users, exploits, compliance violations, system health, & more — into the NKW
  • Endpoint Protection: centralized host-based policies, reusable across agents
  • Zero Trust segmentation: define zones & microsegments and block cross-zone traffic on the host — software air-gaps
  • Auto-quarantine compromised endpoints on intrusion or compliance violation
  • Transactions to test networks, VoIP, & infrastructure
  • Runs on Windows, macOS, Linux (Debian, Ubuntu, & more), FreeBSD — or a NikOS appliance
  • Remote packet capture from sites without 24/7 FPC — captured to NetBin
  • Drives EDR-style action through Playbooks
  • Powers endpoint protection & blocking — deep endpoint insight, correlated with the network, drives response right on the host
Explore NetTrident in depth
Collect & integrate · Integrations

Connectors

Olympus plays well with your world. 500+ connectors integrate your applications, clouds, and existing tools into the data lake — all UI-driven with no custom code, and many two-way so you can act, not just observe.

  • 500+ integrations, set up from the UI with no code
  • Every source lands in the NKW and cross-correlates
  • Two-way actions — e.g. block in your firewall
  • Run on a NIKSUN appliance or a remote NetTrident agent
Explore Connectors in depth
NIKSUN
Public cloud
🛡️
Firewalls
🔑
Identity
🎫
ITSM
💬
Chat / alerts
🧩
SIEM / SOAR
📦
EDR
& more
Collect & integrate · Backup & restore

Snapshots

Capture the state of your environment over time — and roll back when something changes for the worse. Snapshots back up and restore information across your network, from router and device configurations to system baselines.

  • Scheduled or on-demand snapshots of configs & state
  • Diff any two points in time to see exactly what changed
  • One-click restore to a known-good configuration
  • Pinpoint the change behind an outage or drift
Explore Snapshots in depth
core-router-01 · configurationRestore
May 24
May 25
May 26
May 27
acl outbound permit 10.0.0.0/8
- ip route 0.0.0.0/0 192.0.2.1
+ ip route 0.0.0.0/0 198.51.100.9
snmp-server community ******
Discover & test · Active testing

InfraPulse

Proactively test your infrastructure before users feel the pain — network & path tests for latency, RTT, loss, and hop-by-hop routing, plus DNS, SIP, and more. The difference: every result lands in the NKW, correlated with the CPU, memory, processes, and packets of the systems on both ends.

  • Network/path tests — latency, RTT, loss, & full hop analysis
  • DNS, SIP, and service tests from any vantage point
  • Results correlate with real metrics, traces, & packets — not a siloed score
  • Maya can launch tests on demand or agentically
Explore InfraPulse in depth
Path test · app-svc-01 → payment-gwRTT 42ms
1edge-rtr-28ms
2core-sw-114ms
3fw-dmz-a31ms
4payment-gw42ms
fw-dmz-a CPU 94%correlated hop
CVE-2024-3094Critical · CVSS 10.0SRV-APP-01
Backdoor in xz/liblzma 5.6.0 (CPE detected). Discovered on a host actively running sshd — and correlated with the rest of the lake.
2 processes using the package
IDS signature armed for this CVE
Reachable from 3 segments
Discover & test · Vulnerability scanning

VulnScan

Discover critical software, web, and infrastructure exploits — CVEs and CPEs — across your environment. Unlike a standalone scanner, every finding is correlated with what's actually on the system: the apps installed, processes running, IDS signatures that trigger, and the traffic to and from it.

  • Continuous CVE / CPE discovery for software, web, and infrastructure
  • Findings correlated with apps, processes, & live traffic
  • Prioritize by real exposure — not a context-free score
  • Maya can scan on demand and patch via Playbooks
Explore VulnScan in depth
Discover & test · Live threat-indicator feed

ThreatStream

A live feed of threat indicators (threats), built into the platform. Look at any IP, domain, hash, or other field and ThreatStream tells you what threats it's associated with — and which co-occurring indicators, if you also see them, mean those threats are live in your environment right now.

  • Live threat feed — IPs, domains, hashes, URLs, & more
  • Instantly see the threats any field is associated with
  • Correlates co-occurring indicators to confirm a live threat
  • Runs against the full NKW — alarms the moment a match appears
Explore ThreatStream in depth
185.220.101.44Malicious · TI matchlive now
This IP is associated with Cobalt Strike C2. ThreatStream flags the co-occurring indicators seen in your lake that confirm it's active:
Beacon interval to known C2 domain
JA3 hash matches the toolkit
2 internal hosts talking to it
In [1]:
from niksun import nkw df = nkw.query("flows where bytes > p99")
In [2]:
model = detect_anomalies(df, method="isolation_forest")
Build & learn · Data science

NIKSUN Labs

For teams who want to go further. Labs is a data-science environment that runs directly on your captured NIKSUN data lake — explore, model, and build your own detection algorithms against real packets, flows, and metadata.

  • Notebook environment on top of the live NKW
  • Build, test, & tune your own algorithms and models
  • Operationalize custom detections back into the platform
  • Petabyte-scale data, no extract-and-ship required
Explore NIKSUN Labs in depth
Build & learn · Training

NIKSUN Courses

Get your team up to speed fast. Courses are out-of-the-box trainings covering core IT and security concepts — and how to get the most out of NIKSUN — so analysts ramp quickly and grow into the platform.

  • Foundations of network security, forensics, & performance
  • Hands-on NIKSUN operation, from search to remediation
  • Self-paced tracks with progress & certification
  • Onboard new analysts in days, not months
Explore NIKSUN Courses in depth
📡
Network Forensics Fundamentals8 modules
100%
🛡️
Threat Detection with NIKSUN6 modules
65%
Performance & APM Essentials5 modules
20%
NIKSUN Certified AnalystComplete all tracks to earn your certification
One engine, over one data lake

Intelligence, automation
and tooling — unified.

インテリジェンスと
自動化とツール —
統合済み。

Every capability here works over the same NIKSUN data lake — so detection, investigation, response, and learning all share one source of truth.