Knowledge / detection network IR

Network detection and response

NDR. Watch the wire or the flow for threat behaviour, not just known signatures. Complements EDR. Does not replace it.

Network detection and response watches east-west and egress for command-and-control, lateral movement, and exfiltration the endpoint agent never saw: unmanaged devices, OT, and the host whose EDR was quietly killed.

It needs sensors (packet capture, NetFlow/IPFIX, or a tap) and a place to hunt. Signature-only intrusion detection is the ancestor. NDR that cannot explain a flow is a dashboard.

See also: EDR, NetFlow, Packet capture, Intrusion detection system (IDS), SIEM.