← All services
Add-on

Network Detection & Response (NDR)

See what endpoint agents miss on the wire.

What this service offers

This service monitors network behavior at choke points and subnets to catch lateral movement, DNS anomalies, and command-and-control style traffic.

It adds network-edge detection alongside host monitoring.

  • Signature plus behavioral network monitoring
  • Visibility into east-west movement patterns
  • DNS anomaly and encrypted-session fingerprinting signals
  • NDR views in the customer portal when enabled

Limitations (honest scope)

Clear boundaries help you buy the right module — not oversell.

  • Needs sensor placement and SPAN/TAP or suitable traffic visibility — not magic without network access.
  • Encrypted payloads are not fully readable; analysis uses metadata and fingerprints.
  • Does not replace endpoint monitoring — strongest when paired with Core.
  • Sensor capacity and placement affect coverage.

Who should go for it

  • Estates worried about ransomware moving laterally after initial foothold.
  • Networks where endpoint coverage is incomplete.
  • Security teams that need packet-path visibility, not only host logs.

Usually not the best fit if…

  • Very small sites with no network sensor placement option and full endpoint coverage already.