
Network & Infrastructure SecurityCyber-Physical Systems (CPS) Security
Jizô AI
Agentless NDR for IT and OT networks, ANSSI-qualified and air-gap capable.
Jizô AI Overview
What it does
Jizô AI is a network detection and response (NDR) platform delivered as a single agentless appliance that passively captures and analyzes all network traffic through SPAN or TAP mirroring, with no endpoint agents and no inline disruption. It combines signature-based detection with an unsupervised behavioral engine that builds an adaptive baseline of each environment, then flags deviations, and it natively covers IT, OT/ICS, cloud, and IoT traffic, including fully air-gapped networks.
How it works
Mirrored traffic is processed in real time by the Jizô AI Core engine, which runs more than 250 embedded machine-learning models and maps activity to over 130 MITRE ATT&CK techniques, correlating DNS behavior and lateral movement into reconstructed attack timelines. A built-in threat-intelligence engine called Hoshi matches every flow against STIX 2.1 and TAXII indicators in real time, while the Jizô Advisor assistant answers natural-language questions in French or English and auto-generates incident reports. Automated playbooks push containment to firewalls, endpoint detection tools, and network access control, and can be rehearsed against live traffic without triggering blocks.
Credentials and traction
Jizô AI has been qualified by ANSSI, France's national cybersecurity agency, as a detection probe since 2021, carrying the Security Visa that authorizes its use on the sensitive networks of operators of vital importance (OIV). In 2026 it was evaluated in the Gartner Magic Quadrant for Network Detection and Response and scored among the four highest-scoring vendors across all four use cases of the companion Critical Capabilities report. It serves large enterprises and public administrations across France and Europe.
Key Capabilities
mapped to solution categoriesPerforms retroactive and forensic analysis using network flow data and scalable full-packet capture with long-term retention.
Includes traditional detection such as IDPS signatures, rule-based heuristics and threshold alerts alongside behavioral analytics.
Performs deep packet inspection on industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC-UA), for behavioral monitoring of OT environments alongside IT network analysis.
Integrates with firewalls, NAC platforms, and switches to automatically block or quarantine hosts and traffic flows in response to confirmed detections, without requiring analyst-initiated action.
Uses an AI-based search assistant to accelerate threat hunting and surface actionable insights.
Groups related network alerts into structured incidents that reconstruct an attack across hosts and time, reducing alert volume and giving analysts a single investigation timeline instead of disconnected events.
Detects threats using intelligence feeds from internal and external sources.
Detects threats in TLS-encrypted traffic using JA3/JA3S fingerprinting, certificate anomaly detection, and traffic behavioral analysis, without requiring decryption.
Monitors lateral movement traffic between internal network segments and hosts, distinct from perimeter monitoring. Requires network tap or span port placement on internal switch infrastructure.
Builds per-device and per-application baselines of normal network communication patterns and detects deviations, enabling detection of novel C2 channels, data staging, and lateral movement.
Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.
Dissects OT protocol payloads at the function code level, detecting unauthorized read/write operations, unusual register ranges, and firmware upload commands in Modbus, DNP3, EtherNet/IP, PROFINET, and OPC-UA traffic.
Discovers OT/ICS assets by analyzing existing network traffic (Modbus polls, Profinet broadcasts, EtherNet/IP connections), without sending any probe packets that could disrupt device operation.
Forwards enriched OT security alerts into enterprise SIEM and SOAR platforms with OT-specific context, enabling unified SOC operations without requiring OT-specialized analysts.
Baselines normal device communication patterns (command frequency, connection pairs, timing), and alerts on deviations, detecting reconnaissance, manipulation, and lateral movement.
Maps actual traffic flows between IT and OT zones and between Purdue model levels, revealing unauthorized cross-zone connections and segmentation failures.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on August 10, 2026
Buyers
See how Jizô AI fits your stack
Add Jizô AI to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.