Glossary · simply explained

NDR (Network Detection and Response)

Network detection and response (NDR) detects threats from network traffic: sensors analyse flows, metadata and behavioural patterns — and raise alarms when something moves atypically, such as lateral movement, data exfiltration or communication with command servers.

The strength of NDR: it also sees what agentless systems do — printers, IoT and OT devices, appliances, third-party laptops. Exactly where EDR cannot be installed, the network remains the only observation layer.

How does NDR work?

NDR systems learn the normal behaviour of the network — who talks to whom, when, how much — and detect deviations via behavioural analytics and machine learning rather than signatures alone. Encrypted traffic also yields usable features: connection patterns, certificates, timing.

Combined with EDR and identity signals a more complete picture emerges: the network reveals the movement, the endpoint the tool, the identity the actor. Microsegmentation complements NDR ideally — it not only provides visibility into east-west traffic but can directly prevent spread.

Typical NDR detections

  • Lateral movement: unusual connections between internal systems.
  • Data exfiltration: atypical volumes or destinations, including DNS tunnels.
  • Command-and-control communication of compromised systems.
  • Suspicious activity of agentless devices — IoT, OT, appliances.

Frequently asked questions about NDR (Network Detection and Response)

Why do you need NDR in addition to EDR?

EDR only sees systems running an agent. Printers, IoT and OT devices, appliances or unknown devices remain invisible — but not in network traffic. NDR closes exactly this gap and additionally detects movement patterns between systems.

Does NDR work with encrypted traffic?

Yes — even without decryption, metadata provides plenty of signal: connection patterns, volumes, timing, certificate features. Many detections such as lateral movement or DNS tunnelling are based on behaviour, not content.

What is the difference between NDR and IDS?

A classic IDS checks traffic against known signatures and reports hits. NDR additionally learns normal behaviour and detects deviations — including novel attacks without a signature — and connects detection with response options.

How do NDR and microsegmentation relate?

Both trade in the same currency: visibility into east-west traffic. NDR detects suspicious movement, microsegmentation prevents it structurally. Together, detection and containment emerge from one picture — a strong combination against ransomware.

Where are NDR sensors placed?

At the points with significance: transitions between segments, the data center backbone, cloud VPCs via traffic mirroring. The goal is sight of east-west traffic — not just the perimeter, which other controls watch anyway.

From term to implementation: KAEMI supports you from the first assessment to the ongoing managed service.