NDR

Network Detection and Response (NDR) analyses network telemetry (flow data, TLS and DNS metadata, east-west traffic) with behavioural analytics. Its detections complement EDR and SIEM, especially for unmanaged devices, OT and lateral movement.

Context

NDR complements EDR and SIEM with the network view. This includes TLS, DNS and HTTP metadata, east-west traffic between servers, and communication from printers, cameras and production equipment. NDR makes endpoints visible where agents cannot run or are not permitted (OT, IoT, guests, processors). The SOC as a Service Switzerland pillar explains the framework and how these technologies work together in SOC operations.

Where NDR delivers the most value

  • Manufacturing and OT environments without endpoint agents.
  • Environments with many BYOD and guest devices.
  • Lateral movement between servers that looks normal on individual endpoints.
  • Command-and-control over encrypted channels where endpoint signals arrive late or not at all.

How this compares to neighbouring topics

NDR is not EDR and does not replace SIEM. EDR sees processes on the endpoint, while NDR sees communication on the network. SIEM correlates both over time. Running only one layer leaves blind spots; running all three without a SOC team produces alerts without response. The SOC as a Service Switzerland page explains how ANOMAL combines these layers into one operating model.

Related terms

    Want to see this term in a real SOC context? Talk to us →