Network detection and response (NDR) detects threats from network traffic: sensors analyse flows, metadata and behavioural patterns — and raise alarms when something moves atypically, such as lateral movement, data exfiltration or communication with command servers.
The strength of NDR: it also sees what agentless systems do — printers, IoT and OT devices, appliances, third-party laptops. Exactly where EDR cannot be installed, the network remains the only observation layer.
How does NDR work?
NDR systems learn the normal behaviour of the network — who talks to whom, when, how much — and detect deviations via behavioural analytics and machine learning rather than signatures alone. Encrypted traffic also yields usable features: connection patterns, certificates, timing.
Combined with EDR and identity signals a more complete picture emerges: the network reveals the movement, the endpoint the tool, the identity the actor. Microsegmentation complements NDR ideally — it not only provides visibility into east-west traffic but can directly prevent spread.
Typical NDR detections
- Lateral movement: unusual connections between internal systems.
- Data exfiltration: atypical volumes or destinations, including DNS tunnels.
- Command-and-control communication of compromised systems.
- Suspicious activity of agentless devices — IoT, OT, appliances.