Request a demo
HomeBirdEye
Detection & response ยท correlation

An attack that looks quiet at one site is loud from above.

BirdEye lifts the view above individual segments. The same low-volume probe repeated at four branch offices is invisible locally and obvious once the sites are read as one system.

14Sites in one view
<60sCross-site correlation
1Baseline, shared
The pattern problem

Distributed attacks are designed to stay under local thresholds.

Anything loud enough to trip a single site's threshold was never the sophisticated attempt. BirdEye is built for the other kind.

Cross-site correlation

The same signature of behaviour appearing in several places is scored as one event, not four.

Regional baselining

Each site keeps its own normal, so a busy hub is never judged against a quiet branch.

Drift ranking

Sites are ranked by how far they have moved from their own baseline this week.

Propagation tracing

When something spreads, the order it spread in is reconstructed across the estate.

How it reads

Local normal, global judgement.

Two layers of model: one per site, one across all of them. A deviation has to clear both to earn your attention.

  • Per-site modelsEach location's traffic rhythm is learned independently, including its working hours.
  • Estate-level scoringCorrelated deviations are escalated even when no single site crossed a threshold.
  • Order of arrivalWhere it started and where it went next, reconstructed, not inferred.
Cross-site events caught94%
Sites needing local tuning6%
Correlation window60s
Duplicate alerts suppressed91%
In practice

What a distributed probe looks like.

A composite of patterns seen across live engagements, condensed into four beats.

A low, slow scan

Four sites each see a handful of unusual connection attempts. Nothing local fires.

Shapes match

BirdEye recognises the same timing and target pattern in all four.

One incident opens

A single correlated incident is raised with all four sites attached.

Containment lands everywhere

The response applies estate-wide, not just where the analyst happened to look.

Scale

What it takes to run.

Practical numbers for multi-site deployments.

Estate sizeCorrelation latencyDeployment effort
2, 5 sites<30sDays
6, 20 sites<60s1, 2 weeks
20, 60 sites<90s2, 4 weeks
60+ sitesStagedScoped per estate
Questions

What teams ask before they switch.

Straight answers, including the ones that make a sale harder.

Does every site need its own appliance?
Each site needs a collection point. Correlation happens centrally, so the heavy work is not duplicated.
What if sites have very different traffic profiles?
That is the normal case, and why per-site baselines exist. Differences between sites are expected; changes within a site are what matter.
Can we exclude a site?
Yes. Sites can be observed without contributing to estate-level scoring, which is useful for acquisitions mid-integration.
Does it work across cloud regions?
Yes, cloud regions are treated as sites like any other.
Multi-site walkthrough

Read your estate as one system.

Bring two sites that look unrelated and we will show you what the correlated view surfaces.