Network detection built with telecom context.
Detect security behavior across flow, DNS, RADIUS, BNG, CGNAT, OLT/ONU, CPE and routing signals — then connect it to the incident that matters.
Fourteen signal families. One pipeline.
OneMesh ingests the telemetry an operator network actually produces — not just what an enterprise NDR expects to see.
Source availability depends on your release configuration — only approved sources are shown as active in the product.
Detections written for operator networks.
Behavioral detections tuned to subscriber-scale baselines — where "normal" looks nothing like an office LAN.
Periodicity and destination analysis across subscriber flows at CGNAT scale.
Entropy, label length and resolver behavior against per-tenant baselines.
Inbound and lateral scanning, credential-stuffing patterns against exposed services.
Volume, timing and destination anomalies scored per asset and subscriber class.
Translate abuse reports and detections back through CGNAT to the right session.
Weak credentials, unexpected management traffic and access-layer anomalies.
Session storms, impossible geographies and privileged command anomalies.
Routing events that put subscriber traffic somewhere it should never go.
Attack context correlated with the assets and subscribers actually affected.
From threat IP to incident — with privacy intact.
OneMesh models the path a threat actually takes through an operator network, and keeps subscriber identity behind an audited gate the whole way.
Actions your network team will actually allow.
Every OneMesh action carries approval, expiry and rollback. Nothing touches the network without a signed, scoped, time-limited command — and a way back.
Push scoped blocks to edge firewalls and router address lists with automatic expiry.
Redirect known-malicious resolution for affected scopes while investigation continues.
Change-of-Authorization to re-scope or suspend a compromised session cleanly.
Move a subscriber to a quarantine profile through the authorized XIMS bridge.
Request blackhole or FlowSpec mitigation — and restore service on one screen when it clears.
A narrow signed bridge — not a giant data pipe.
XIMS keeps subscriber lifecycle, CRM, billing, provisioning and RADIUS operations. XSecurity One receives only authorized security context: pseudonymous references, active IP mappings, CPE/ONU identifiers and security-relevant events.
PURPOSE-BOUND. MINIMAL. AUDITED.
About OneBridgeTest your telecom use case.
Bring one real scenario — a compromised CPE, a beaconing subscriber, a routing anomaly — and see how OneMesh handles it end to end.