How DataSunrise Captures Activity
DataSunrise monitors databases through a proxy, passive network traffic, a host agent, or native audit records. Generative AI activity is monitored through Squid/eCAP.
Each method fits a different environment. The proxy monitors live traffic and can apply active controls. A passive sniffer watches mirrored traffic. A host agent captures local and loopback sessions. Native audit imports activity recorded by the database or cloud service.
Turn Events Into Investigation Context
DataSunrise enriches activity with identity, client, application, session, database object, operation, prompt, response, timing, outcome, rule, and alert details.
Teams can search and filter that context to investigate privileged access, unusual exports, failed operations, sensitive-data use, or Generative AI interactions.
Application-User Attribution helps teams see which application user performed each database action, even when the application connects through a shared database account.
Connect Visibility to Protection
Monitoring establishes what happened. Data Protection and Enforcement acts on live traffic with firewall, masking, and prompt controls.
Passive and native-audit paths provide visibility. Active paths can also change or reject a request or response.