Early access · waitlist open
See what your
network is actually
talking to.
Nyxtrace is Network Detection & Response for homelabs and small networks that want to be secure. It watches your traffic, keeps an inventory of every device and explains incidents in plain language — on your own appliance, with no cloud required.
- SourcesZeek · NetFlow · Suricata · DNS
- Runs onYour own appliance
- CoreOpen source
- StatusEarly access
Illustration of the Threat Visualizer: one home network, external destinations. Sample topology, not measured traffic.
Modules
Four modules, one product
Nyxtrace ships as one appliance with one data model. Time ranges, filters, device identities and evidence are shared across modules — the navigation only shows what you actually have data for.
Threat Visualizer
A live picture of your network: a 3D globe of external connections, a 2D map of internal relationships, and replay of any time window.
- 3D globe with live connection arcs
- 2D network map of device relationships
- Replay a time range, not just "now"
- Every relationship keeps its source record
Cyber AI Analyst
Correlates alerts into incidents and writes down what happened in plain language — with the observation, the model hint and the hypothesis kept apart.
- Merges related alerts into one incident
- Explains the timeline in plain language
- Points at possible lateral movement
- No automatic blocking or execution
Asset Inventory
Every device that speaks on your network, discovered passively: what it is, who it talks to, when it first and last showed up.
- Devices, categories and owners
- Active connections per device
- First-seen and last-seen timestamps
- Behaviour groups of similar devices
- coming soon
Email Security
The next module. Reads delivery and phishing decisions from your mail setup and links mail incidents to the devices and users you already have.
- Delivery and block figures from real events
- Phishing and spam decisions with a reason
- Per-user baselines
- Mail incidents joined to network evidence
A look inside
The actual interface
Screenshots from the current build, filled with synthetic demo data. The interface of this build is German — that is simply where the product stands today.



How it works
From packets to a decision you can defend
No agents on every machine, no traffic leaving your network. Nyxtrace listens where your traffic already passes and turns it into something readable.
- 01
Run the appliance
One box on your network: a Go data path with ClickHouse for storage and a Next.js interface. Bare metal or a VM — your data stays where you put it.
- 02
Point your sources at it
Zeek and Suricata events, NetFlow and DNS logs from OPNsense, plus a mirrored vSensor on Proxmox for the traffic your firewall never sees.
- 03
Let it learn your normal
Nyxtrace builds a baseline per device and behaviour group over a few weeks, then flags what deviates from it instead of matching signatures alone.
- 04
Read incidents, then decide
Alerts arrive merged into incidents with a written explanation and the raw evidence behind it. You keep the decision — nothing is blocked behind your back.
Data path: Zeek / NetFlow / Suricata / DNS → Go collector → ClickHouse → behaviour models → incidents
For homelabs
Built for the network you already run
Commercial NDR assumes a SOC team, a per-seat licence and a cloud tenant. Nyxtrace assumes a rack in a basement, a few VLANs and one person who wants to know what is going on.
OPNsense first
NetFlow, Suricata EVE events and DNS logs are read straight from OPNsense. Nothing to compile, no packages on the firewall you have to maintain yourself.
Proxmox vSensor
East-west traffic between VMs never reaches the firewall. A mirrored sensor on the hypervisor feeds it in, so lateral movement is not a blind spot.
Zeek and Suricata, not reinvented
Nyxtrace uses the tools the industry already trusts for protocol logs and signatures, and spends its own effort on correlation, inventory and explanation.
No cloud required
The appliance runs on your hardware and keeps its data locally. No account is needed to look at your own network, and no telemetry is required to use it.
Open source & Pro
Free core, paid depth
Nyxtrace is freemium. The core you need to see and inventory your own network will be open source and stay usable on its own. The parts that cost real money to build and run sit behind a Pro subscription.
Open source core
Self-host it, read the code, keep your data. Free of charge and intended to be genuinely useful without ever paying.
- Traffic collection from Zeek, NetFlow, Suricata and DNS
- Asset inventory with first-seen and last-seen
- Threat Visualizer: 3D globe and 2D network map
- Self-hosted, no account, no telemetry requirement
Pro
A subscription for the analysis-heavy features, aimed at homelab budgets rather than enterprise price lists.
- Cyber AI Analyst write-ups on your incidents
- Longer retention and longer-learning behaviour models
- Email Security once it ships
- Extensions for specific integrations, later on
Pricing coming soon — Pro is planned from around $20/month.
Which module ends up on which side is not finalised. The split will be published together with the licence and the repository before anyone is asked to pay — and nothing on this page is a purchase offer yet.
Early access
Get on the waitlist
Nyxtrace is being built and run on a real homelab first. Leave your address and you will hear from us when there is an installable build — not before.
What you can expect. One message when early access opens, and one more if the plan changes materially. That is it.
What we will not claim. There are no customer numbers, no detection rates and no case studies on this page, because there is nothing honest to put there yet.
Prefer email? Reach us at [email protected].