Managed NDR
EXEON
Managed NDR is our network scope: sensor and flow planning, behavioural baselines per segment, detection on metadata and normalisation of signals into the case flow. Examples are Exeon, Corelight, Darktrace or Vectra AI.
What sets this service apart: NDR sees what carries no agent. Unmanaged devices, OT and IoT, legacy systems, lateral movement between zones and C2 in encrypted channels. Because NDR brings its own pipeline, use case and playbook development and log source integration are part of the scope here.
Typical detections
- Lateral movement across zone boundaries
- C2 beaconing in encrypted channels
- DNS tunnelling and data exfiltration
- Unauthorised access from IT zones into OT zones
- New or unknown assets without an agent
- Internal scanning and reconnaissance
Response actions within mandate
- Network isolation via firewall, NAC or switch port per mandate
- Blocklisting of domains, IPs and destinations
- Segment-specific blocking without intervening on the host
- Example mandate: auto block in client zones, approval required in OT and production zones
Limits of this service
- No process or file forensics on the host, that is Managed EDR
- Packet payloads are not captured, analysis runs on metadata
- Detection quality depends on sensor and flow coverage per segment
SLAs
Included
- Use case and playbook development and management: network use cases and playbooks are built, versioned and tuned
- Log source integration and management: flows, DNS, proxy and sensor onboarding including health monitoring
- Segment baselining per zone with documented drift control
Not included
- Platform and sensor licences (yours, or passed through at cost)
- Anti-ransomware (e.g. Halcyon) as a separate add-on module
- Eradication and recovery inside your systems, executed by your IT with our coordination
- On-prem hardware, collectors and network taps
Process
- Assess
Network topology, critical segments, blind spots, sensor and flow placement plan.
- Integrate
Onboarding of existing flow sources, baseline over the first weeks, enrichment with asset context.
- Automate
Playbook per detection, block and isolation actions pre-authorised per zone, SOAR enrichment.
Deliverables
- Network coverage map with sensor and flow coverage per segment
- Baseline report and drift overview per zone
- Asset list from a network perspective, including devices without an agent
FAQ
Do you need decrypted traffic?
No. Detection works on metadata, TLS fingerprints and behavioural patterns. If you run SSL inspection we use it, but it is not a requirement.
Does this work in OT zones as well?
Yes, and that is where the value is highest. We work passively on metadata, without an agent and without touching control systems. Response actions in OT zones require approval by default.
Included in every ANOMAL managed service
- 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
- Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
- Further analysis on every suspected true positive, including log, telemetry and asset context
- Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
- SOC platform operations: backend, updates and health monitoring of the SOC stack
- Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
- Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
- Effectiveness testing once a year, e.g. together with an external purple team
- Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
- Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation
Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.
Let's talk about Managed NDR.
30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.
More managed services
We run your SIEM and keep it sharp: we connect new log sources, build detection rules and maintain them.
We monitor your endpoints around the clock and step in immediately during an attack. It works with all leading EDR platforms.
We correlate signals from endpoint, identity, cloud, email and network. Everything lands in one case with one response path.
We protect your accounts in Entra ID, Okta and Active Directory. We detect suspicious sign-ins and stolen credentials early and revoke affected sessions automatically.