Detection & Response

Network Detection & Response NDR

A system that analyzes internal network (east-west) traffic to detect lateral movement, data exfiltration and suspicious behavior on devices that can't run an agent (printers, cameras, IoT, OT).

When you need it

  • You have many devices that can't run an agent (IoT, medical devices, OT)
  • You have no visibility into traffic inside your data center
  • You have a SOC team and want to cover the areas EDR can't see

When you do not need it

  • Without a security team, nobody can interpret NDR alerts; start with EDR + MDR.
  • On small networks, the firewall's IPS and traffic logs give enough visibility.

Via traffic copies (SPAN/TAP) from core switches; prioritize the data center entry point and critical segments.