Endace Ecosystem Expands: Is 2026 the Year of the Packet?

Original Entry by : Mark Evans

By Mark Evans, VP Marketing, Endace


Mark Evans, VP Marketing, EndaceA growing ecosystem, driven by increased demand

Endace’s Fusion Partner Program is expanding rapidly, with new partners, including  Microsoft Sentinel, Google SecOps, Sumo Logic and Exabeam (and more coming), and updated integrations to solutions from Cisco, Splunk, Palo Alto Networks, Elastic, Sumo Logic,  Fortinet, and others.

On the surface, this looks like steady ecosystem growth. In reality, it reflects a clear shift in what customers are asking for.

Organizations are rethinking how their security and network operations stacks work together and, more importantly, where reliable data comes from. As that conversation evolves, one thing is becoming clear. Full packet capture is no longer a niche requirement, but rather a foundational need.

The growth of the Fusion Partner ecosystem is a direct response to that shift. More vendors are integrating with Endace because their customers want immediate access to packet-level evidence inside the tools they already use.  When something happens on the network, teams need to be able to go straight from alerts to the ground truth. And quickly!

Integration first: from tools to a unified evidence layer

One of the biggest changes happening in security operations is how tools work together. Detection platforms are no longer enough on their own. They need access to reliable, underlying data to more accurately detect complex threats and malicious behaviour, and link together attacker activities to create an accurate picture for security teams.

Full packet capture strengthens existing platforms by acting as a shared evidence layer across the SOC and NOC stack. Instead of operating in silos, systems such as SIEM, SOAR, XDR, and NDR can all draw from the same packet-level data to enable SOC and NOC teams to investigate incidents quickly and make confident, evidence-backed decisions.

Through the Fusion Partner Program, this capability is embedded directly into existing tools and workflows, enabling analysts to move seamlessly from detection to deep investigation without leaving their primary tools.

From alerts to evidence

Rather than replacing existing platforms, packet capture strengthens them by acting as a common evidence layer across the SOC and NOC stack. Whether an alert originates in a SIEM, an XDR platform, or a performance monitoring tool, analysts can pivot directly to packet-level data to see exactly what happened.

This is what the Fusion Partner Program is designed to enable. It integrates packet data directly into platforms like Microsoft Sentinel, Google SecOps, and Splunk, so analysts have definitive forensic evidence at their fingertips when they need it most. It is a simple idea, but it changes everything about how investigations are conducted.

AI is raising the bar for evidence

The rise of AI in security operations is accelerating this shift. AI can identify patterns, surface potential threats, and recommend actions, but those outputs still need validation. Without access to underlying network data, teams are relying on probability rather than proof.

Packet capture provides the validation layer that AI necessitates. It enables teams to confirm whether alerts are real, supports more accurate automated responses, and helps ensure that investigations are grounded in evidence.

At the same time, AI is making packet data more accessible. As AI-assisted investigation improves, teams no longer need arcane, packet wrangling skills to extract value from pcap data. AI-enabled investigation and automation tools can put relevant pcap evidence right at their fingertips. This accelerates investigations, removes a potential barrier to packet capture adoption, and broadens its relevance.

Compliance is making packet capture unavoidable

Regulation is another major force driving packet capture adoption. Across global frameworks and industry standards, organizations are being asked to collect more detailed telemetry, respond to incidents more quickly, and provide stronger evidence when required. Increasingly, these expectations point directly to full packet capture.

Research shows that regulatory bodies are either explicitly requiring packet capture or setting requirements that cannot realistically be met without it. For example, in the SANS whitepaper Full Packet Capture as Strategic and Regulatory Imperative, author Matt Bromiley explains that some frameworks now mandate short retention windows for full packet data, while others emphasize comprehensive logging, forensic evidence preservation, and rapid incident reporting which implicitly require packet capture in order to meet their requirements.

Mandated packet capture requirements are already in place at the U.S. federal level. The U.S. government’s OMB M-21-31 requires US federal agencies to implement at least 72 hours of full packet capture (FPC) as part of baseline cybersecurity logging.

Many regulatory reporting timelines now also depend on forensic-grade network evidence. For example, under the EU’s NIS2 Directive, organizations must issue 24-hour early incident notifications and 72-hour full incident reports with detailed forensic evidence. These deadlines are nearly impossible to meet without full packet-level visibility, reinforcing full packet capture as a compliance enabler.

At the same time, best practice cybersecurity standards such as NIST CSF and ISO 27001 are placing greater emphasis on continuous monitoring and the ability to reconstruct complete network activity, rather than relying on logs or sampled data alone. In practice, this means organizations need access to full packet data to meet both compliance and operational requirements.

This is being reinforced across major frameworks. Requirements for continuous monitoring, detailed logging, and rapid incident reporting all point toward the same conclusion: logs and sampled data are not enough on their own. Organizations need complete visibility into network activity to meet both operational and compliance expectations.

The result is a shift in mindset. Packet capture is no longer a nice-to-have. It is becoming table stakes for both security architecture and compliance strategy. Packet capture provides a single, authoritative source of network truth to support detection, investigation, response, reporting, and auditing, while also strengthening overall security posture.

The shift to evidence-based network security and performance ecosystems

The expansion of the Endace Fusion Partner Program is a clear signal of where the market is heading. As demand for packet-level visibility grows, more vendors are looking to integrate it into their platforms to enhance incident detection, investigation, and response.

2026 may well be remembered as the year organizations recognized the limits of detection without evidence. As that realization spreads, packet capture is becoming a foundational component of modern security operations architecture.

As we move forward, we’ll continue to see real operational impact and faster, more confident responses. Most importantly, decisions are based on what actually happened on the network, rather than assumptions or partial visibility. And increasingly, the ecosystem forming around packet capture will define how security operations evolve next.


Endace Achieves Cisco Solution Plus Partner Status

Original Entry by : Michael Morris

By Michael Morris, Senior Director of Global Business Development, Endace


Michael Morris, Director of Global Business Development, Endace

I am excited to share that Endace has just achieved an amazing milestone. On March 17, 2026, Endace achieved Cisco Solution Plus Partner status.

This means our EndaceProbe™ Analytics Platform is now available on the Cisco Global Price List (GPL) and can be sold by Cisco sales teams and channel partners as a Cisco SKU (initially for USA-based customers only).

Solutions that are part of the Solution Plus Partner Program achieve that partnership level through strong sponsorship by a Cisco Business Unit that sees value in complementing Cisco’s solution offerings.

Endace’s tight integration with Cisco Security solutions, including Cisco Secure Network Analytics, Cisco Secure Firewall, and Cisco XDR, as well as Splunk Enterprise Security and Splunk SOAR, make Endace an extremely complementary solution for recording critical network forensic evidence for security and network teams.

Endace’s industry-leading platform – EndaceProbe – provides Always-On, full packet capture across on-prem, virtual, and cloud-native environments. With the ability to access and analyze recorded packet data quickly from a single-pane-of-glass, and full API integration with a wide range of security and performance monitoring solutions,

EndaceProbes make recording and using packet data easy for SOC, NOC and IT teams. The EndaceProbe platform’s scalability, performance, high-speed search and open architecture ensures customers can reliably record critical network evidence. Fast access to full packet data can be integrated directly into any SIEM, Firewall, NDR/XDR, SOAR or NPM solution, putting forensic evidence at analysts’ fingertips for incident investigation and threat hunting. Analysts can go directly from indicators of compromise to absolute network evidence with a single click.

Cisco selecting Endace as a complementary packet capture solution validates Endace as the BEST-IN-CLASS packet capture solution in network security.

Cisco Solution Plus Status listing is a testament to the scalability, reliability and usability of the EndaceProbe platform and the resiliency we’ve built into our solution by achieving compliance with military grade security standards such as FIPS 140-3, NIAP NDcPP, and US DOD APL.

Our goal is to ensure that customers have the ultimate network forensic evidence at their fingertips. Integrating this capability into Cisco Security and Splunk solutions enables SOC and NOC teams to quickly and accurately detect, investigate and remediate cyber threats and performance issues.

These integrations have been honed by real-life, hands-on, experience with our Engineers working alongside the Cisco and Splunk teams in SOCs at major events such as Cisco Live, RSAC, Black Hat and others.

This “in-the-field” experience has driven numerous product innovations for Endace, Cisco and Splunk, which ultimately benefits all customers. Our gratitude goes out to Jessica (Bair) Oppenheimer, Director SOC Integrations – Splunk Security, who worked with us to incorporate Endace packet capture as a fundamental component of Cisco’s SOC-in-a-Box architecture.

We are also grateful to be working with the amazing Cisco Solution Plus team, who see the value in Endace and have worked diligently to add EndaceProbe solutions to the Cisco SP+ portfolio.

Our team is excited and energised to help the Cisco and Splunk teams solve our customers’ toughest security challenges and protect some of the largest, most critical networks on the planet.

PCAP or It Didn’t Happen!

Please out to sales.cisco@endace.com or your Cisco Sales Rep for more information.

 


Introducing EndaceProbe Cloud

Original Entry by : Cary Wright

Scalable Packet Capture for Hybrid Cloud

By Cary Wright, VP Product Management, Endace


Cary Wright, VP Product Management, Endace

The rapid growth of cloud vulnerabilities, hijacked cloud credentials, APTs targeting cloud, and lack of network layer visibility in cloud has made one thing clear: recorded network packet data is just as essential in the cloud as it is in physical networks. 

Enterprises know the value of our packet capture solutions, and they have told us they need the power of packets in the cloud as well. In many cases, they have moved – or plan to move – workloads to the cloud but have been hampered by an inability to gain the same visibility into activity in their public cloud infrastructure as they are used to relying on in on-premise environments.

Leveraging our 20-plus years of experience in delivering accurate, reliable packet capture for some of the world’s largest organizations, Endace developed EndaceProbe Cloud as the first truly scalable, enterprise-class solution for providing always-on packet capture in public cloud environments.

Unlike many solutions on the market, we’ve done it in a way that scales easily and delivers truly unified visibility that lets security, network and IT teams analyze packet data from across hybrid cloud and multi-cloud environments quickly and easily from a central console. 

EndaceProbe Cloud delivers packet-level visibility for public cloud that is critical for threat hunting, incident response and performance management in those environments. It operates seamlessly with EndaceProbe hardware appliances to deliver always-on packet capture across on-premise, private and public cloud infrastructure, to provide unified visibility across the entire network.

See it in Action

The demo below shows how easy it is to quickly search for packet data across a multi-cloud – AWS and Azure – environment, recreate files from packet data and drill-in to analyze the full packets. All from a single console.

EndaceProbe Cloud is a full-featured EndaceProbe, purpose-built for deployment in AWS and Microsoft Azure environments that provides the following benefits to customers in cloud and hybrid cloud environments:  

    • Continuous, zero-loss, packet capture in public and hybrid cloud environments that provides weeks or months of visibility 
    • A unified console for fast global search and analysis across on-premise, private and public cloud environments.  
    • Full visibility into North-South and East-West traffic 
    • Secure packet storage within the customers’ own virtual network or virtual private cloud (VPC). 
    • Powerful traffic analysis and investigation tools including file extraction, log generation, and hosted Wireshark™ 
    • Seamless workflow integration with an open API and strong ecosystem of third-party network and security tools (https://www.endace.com/fusion-partners) 
    • Subscription-based pricing that offers flexibility and scalability  

EndaceProbe Cloud complements Endace’s hardware appliances to provide unified and seamless visibility across the entire network.