Network detection and response
NDR. Watch the wire or the flow for threat behaviour, not just known signatures. Complements EDR. Does not replace it.
Network detection and response watches east-west and egress for command-and-control, lateral movement, and exfiltration the endpoint agent never saw: unmanaged devices, OT, and the host whose EDR was quietly killed.
It needs sensors (packet capture, NetFlow/IPFIX, or a tap) and a place to hunt. Signature-only intrusion detection is the ancestor. NDR that cannot explain a flow is a dashboard.
See also: EDR, NetFlow, Packet capture, Intrusion detection system (IDS), SIEM.
