What a host-local sensor actually buys, stated honestly
It is not attack detection. Inbound web traffic arrives TLS-encrypted from a CDN edge and the sensor cannot decrypt it, while the web server access logs already carry the true client IP. Roughly seventy percent of what “add an IDS” implies was already covered better elsewhere.
The value is egress, and egress did not exist anywhere on this fleet:
| Alert class 1 | severity 0 |
|---|---|
| Alert class 2 | severity 0 |
| Alert class 3 | severity 0 |
| Alert class 4 | severity 0 |
| Alert class 5 | severity 3 |
| Alerting floor | severity 10 |
DNS
Every host resolved over cleartext UDP with DNS-over-TLS off. Nothing could tell you what any host had ever looked up.
Outbound TLS destination and fingerprint
The payload stays encrypted, but where a host is talking becomes visible. A compromised application or database process calling home was invisible to every control in place.
Flow byte counts
Under GLBA Safeguards and state breach law, whether data left is the determination required in the first 72 hours. There was no artifact from which to make it.