In one embodiment, the switch or other network device that detects a threat sends other information to security management in addition to mirroring the threat traffic flow, including information from the switch's forwarding database that correlates MAC addresses with IP addresses and/or port numbers.