A defense systems integrator ran threatDefendr air-gapped across classified enclaves — attributing nation-state activity without a packet leaving the boundary.
IL5 Authorized | 0 Bytes egressed | 240 Campaigns tracked | 72h→3h Attribution |
Northwind defended classified networks where nothing — not a hash, not a byte of telemetry — can egress for cloud analysis. Commercial tools assumed a callback home they could never allow, leaving analysts to correlate nation-state activity by hand.
threatDefendr deployed fully air-gapped, with intelligence and models delivered on a one-way update path. Analysts tracked campaigns and built attribution on a shared graph — all inside the SCIF.
The full platform runs offline; intelligence arrives on a one-way path and nothing leaves the boundary. Campaign attribution that took weeks by hand now resolves in an afternoon, within an IL5 boundary with audited break-glass access.
“It runs entirely inside the wire and still tracks campaigns like a cloud platform. Nothing egresses, and attribution went from weeks to an afternoon.”