Find how Lumu measure compromise in real time

How does Lumu measure compromise in real time?

Lumu systematically collects, normalizes, and analyzes a wide range of network metadata, including DNS, Net flows, Proxy, Firewall Access Logs, Inbox and Email Intelligence. The level of visibility that only these data sources provide, allows us to understand the behavior of your enterprise network, which leads to conclusive evidence on your unique compromise level.


The following table describes the key elements of metadata Lumu uses to illuminate your compromised IT assets and the behavior of your enterprise network, which leads to  conclusive evidence on your unique compromise levels :

Network Metadata

Why it Matters

DNS Queries

Provides context into the  connections attempted  from the organization’s devices towards  adversarial infrastructure .

Network Flows

Among other malicious behavior, provides insights into an  organization’s devices  that are  controlled by adversaries  and attempting to move laterally.

Access logs of Perimeter Proxies or Firewalls

In cases where the attacks  avoid domain resolution,  the traces of adversarial contact will lie in the access logs of firewalls or proxies, depending on the organization's network configuration.

Lumu Email

Email is the preferred method by attackers  to deliver exploits. Analyzing the organization’s inbox provides insights into the  type of attacks  an organization is receiving, but more importantly if end-users are accessing such attacks and if the organization is at a  high risk of compromise .

Learn more about the Lumu Illumination Process.