Detection & Response
Network Detection & Response NDR
A system that analyzes internal network (east-west) traffic to detect lateral movement, data exfiltration and suspicious behavior on devices that can't run an agent (printers, cameras, IoT, OT).
When you need it
- You have many devices that can't run an agent (IoT, medical devices, OT)
- You have no visibility into traffic inside your data center
- You have a SOC team and want to cover the areas EDR can't see
When you do not need it
- Without a security team, nobody can interpret NDR alerts; start with EDR + MDR.
- On small networks, the firewall's IPS and traffic logs give enough visibility.
Via traffic copies (SPAN/TAP) from core switches; prioritize the data center entry point and critical segments.



