Virtual LECS:
virtualized cybersecurity for data center and IT/OT environments

Virtual LECS brings the same internal visibility capability and advanced traffic detection to virtualized environments, without physical appliances.

Why choose Virtual LECS

Virtual LECS is the ideal choice when you want to bring LECS security to virtualized environments by leveraging the infrastructure you already have.

It reduces installation time and complexity, standardizes deployment across multiple sites, and makes logs and telemetry already usable for SOC, SIEM, and incident response processes.

Designed for VMware, Hyper-V and Proxmox environments.

Stealth and response analysis

  • Virtual LECS observes traffic from a location inside the virtualized infrastructure, without interfering with protected hosts.
  • This enables improved visibility into east-west flows, intercepting anomalies and collecting data useful for operational response, while keeping the management plan and the traffic to be analyzed separate.
  • Internal traffic monitoring: Analyze flows by mirroring, physical or virtual, to increase visibility into places where perimeter firewalls and endpoint protection often do not reach.
  • Fast operation:
    Starts up by importing a ready-to-use VM, with simple initial configuration and reduced commissioning time.
  • Zero impact on hosts: Does not require dedicated physical appliances and maintains a clear separation between management and traffic collection.
  • Useful data for incident response: Telemetry and logs are already structured to support analysis, event correlation and response processes.
  • Architectural choice consistent with enterprise policy: The solution fits both centralized models and contexts that require greater localization of control.

From configuration to operation.

No host configuration changes, no interruption of active services.

It imports the Virtual LECS package into the chosen hypervisor and prepares the instance in the environment to be monitored.

Configures a network for management and two dedicated interfaces for mirrored traffic, according to the planned architecture.

Set up connectivity via DHCP or static IP and perform the necessary reachability tests.

Frequently asked questions about LECS technology in virtualized version

What hypervisors are supported by Virtual LECS?

Virtual LECS is designed for VMware, Hyper-V, and Proxmox environments so that it can be deployed consistently across different virtualized infrastructures.

Not necessarily. On-Premise management with local dashboard via HTTPS is also available. However, for some essential services such as updates and licensing, an outbound connection to LECS servers is required, consistent with corporate network policies.

Sizing depends on the volume of traffic and the number of hosts. The correct principle is not to stop at the minimum necessary, but to provide an adequate margin to ensure continuity, performance and scalability.

The solution uses two dedicated interfaces for mirroring traffic analysis, keeping the management network separate from the flow observation component.