← Managed SOCNDR

Managed NDR

EXEON

Managed NDR is our network scope: sensor and flow planning, behavioural baselines per segment, detection on metadata and normalisation of signals into the case flow. Examples are Exeon, Corelight, Darktrace or Vectra AI.

What sets this service apart: NDR sees what carries no agent. Unmanaged devices, OT and IoT, legacy systems, lateral movement between zones and C2 in encrypted channels. Because NDR brings its own pipeline, use case and playbook development and log source integration are part of the scope here.

Typical detections

  • Lateral movement across zone boundaries
  • C2 beaconing in encrypted channels
  • DNS tunnelling and data exfiltration
  • Unauthorised access from IT zones into OT zones
  • New or unknown assets without an agent
  • Internal scanning and reconnaissance

Response actions within mandate

  • Network isolation via firewall, NAC or switch port per mandate
  • Blocklisting of domains, IPs and destinations
  • Segment-specific blocking without intervening on the host
  • Example mandate: auto block in client zones, approval required in OT and production zones

Limits of this service

  • No process or file forensics on the host, that is Managed EDR
  • Packet payloads are not captured, analysis runs on metadata
  • Detection quality depends on sensor and flow coverage per segment

SLAs

24/7 continuous
Sensor and flow health monitoring
weekly
Baseline drift review
< 60 min (24/7)
Critical incident response time (contractual)

Included

  • Use case and playbook development and management: network use cases and playbooks are built, versioned and tuned
  • Log source integration and management: flows, DNS, proxy and sensor onboarding including health monitoring
  • Segment baselining per zone with documented drift control

Not included

  • Platform and sensor licences (yours, or passed through at cost)
  • Anti-ransomware (e.g. Halcyon) as a separate add-on module
  • Eradication and recovery inside your systems, executed by your IT with our coordination
  • On-prem hardware, collectors and network taps

Process

  1. Assess

    Network topology, critical segments, blind spots, sensor and flow placement plan.

  2. Integrate

    Onboarding of existing flow sources, baseline over the first weeks, enrichment with asset context.

  3. Automate

    Playbook per detection, block and isolation actions pre-authorised per zone, SOAR enrichment.

Deliverables

  • Network coverage map with sensor and flow coverage per segment
  • Baseline report and drift overview per zone
  • Asset list from a network perspective, including devices without an agent

FAQ

Do you need decrypted traffic?

No. Detection works on metadata, TLS fingerprints and behavioural patterns. If you run SSL inspection we use it, but it is not a requirement.

Does this work in OT zones as well?

Yes, and that is where the value is highest. We work passively on metadata, without an agent and without touching control systems. Response actions in OT zones require approval by default.

Included in every ANOMAL managed service

  • 24/7 threat monitoring: every alert is picked up, enriched with context and documented in the ticket system
  • Incident triage on every severity from low to critical, classified as false positive, benign true positive or true positive
  • Further analysis on every suspected true positive, including log, telemetry and asset context
  • Incident response along NIST: containment and first response within your mandate. A full IR engagement for a major incident is billed separately.
  • SOC platform operations: backend, updates and health monitoring of the SOC stack
  • Automated incident response: SOAR enrichment, automated queries, pre-authorised response actions per mandate
  • Threat hunting and threat intelligence (e.g. MISP plus external feeds) feeding back into detections
  • Effectiveness testing once a year, e.g. together with an external purple team
  • Service management: monthly service efficiency report, quarterly optimisation meeting, live view in ANOVIEW
  • Ongoing operations: continuous tuning, detection maintenance and quarterly service optimisation

Scope, service level (e.g. business hours for low to high, 24/7 for critical) and volumes differ per environment. That is why there is no list price: every customer gets a dedicated quote with defined scope, service level and response mandate. With Managed SIEM and Managed NDR the scope additionally covers use case and playbook development as well as log source integration and management.

Let's talk about Managed NDR.

30 minutes with our SOC team. You describe your situation, we tell you clearly whether and how we can help.