drag to pan · scroll to zoom
Sanctioned app Undiscovered shadow app Discovered shadow app

Shadow SaaS Discovery: CASB Traffic Analysis (2D Top-Down)

Cloud Access Security Brokers can't inspect the content of every connection, so discovering unsanctioned SaaS apps — Shadow IT — has to work from traffic metadata alone: request rate, data volume, and whether the destination matches a known application signature. This 2D companion to the 3D orbit view flattens the same gateway-and-apps layout into a top-down diagram you can freely pan and zoom, and runs the identical EWMA-smoothed anomaly score per app that a production CASB uses. Tune the detection threshold and user load to see how quickly Shadow IT gets flagged, then flip on enforcement to watch the gateway start dropping packets bound for anything it has discovered.