NDR

Network Detection and Response

Netzwerk-Erkennung und -Reaktion

NDR monitors network traffic, models normal behaviour and detects deviations indicating lateral movement, data exfiltration or command-and-control. Where Endpoint Detection and Response (EDR) sees the endpoint, NDR sees the connections between them — including from devices on which no agent can be installed. Only the two perspectives together yield a complete picture.

History. NDR grew out of Network Traffic Analysis (NTA), which initially relied on pattern recognition in traffic. As encryption spread and it became clear that endpoint agents are never fully rolled out, the focus shifted from pure analysis towards detection and response at the network level.

Facts. NDR typically evaluates metadata and flow data, increasingly augmented by behavioural models, and is particularly strong at visibility of „east-west“ communication inside a network — the lateral movement following an initial compromise. Especially in environments with Operational Technology (OT), medical IT or unmanaged devices that cannot run Endpoint Detection and Response (EDR), NDR is often the only reliable source of visibility.

Outlook & recommendation. As the number of connected, unpatchable devices grows, agentless network visibility gains importance. NDR does not replace Endpoint Detection and Response (EDR) but closes its blind spots. In the Extended Security Incident and Event Management (XIEM) model, network security monitoring is part of the Sentry tier from the outset — deliberately also for environments where endpoint agents reach their limits.

NDR — Network Detection and Response