NDR stands for network detection and response. It reads the traffic moving inside your network, not just what crosses the perimeter or what happens on a managed laptop. This page explains what that buys you, in plain terms.
An attacker inside your network has choices about almost everything. They can pick a host with no agent installed. They can disable or blind an agent that is installed. They can work from a device that could never run one, such as a printer, a camera, an ESXi host or a programmable controller. They can stay inside living-off-the-land tooling that looks like ordinary administration.
What they cannot do is move without using the network. Finding the file shares is network traffic. Reaching the finance system is network traffic. Calling home for instructions is network traffic. Taking the data out is network traffic. That is the whole argument for NDR: it watches the one layer the attacker has to use.
This is not a criticism of your existing stack. EDR is the right tool for what happens on a host, and a firewall is the right tool for the boundary. These are simply the things that sit outside both:
The sensor is passive. It receives a copy of traffic from a SPAN or mirror port on a switch, or from your cloud provider's traffic-mirroring feature. It is never placed inline, so it is not in the path of a single production packet. If the sensor is switched off, unplugged or fails outright, your network does not notice.
There is nothing to install on any server, workstation or controller. Deployment is a mirror configuration and a sensor, and the sensor can sit on your own premises as an appliance or in a cloud region you choose.
One honest caveat we would rather you hear from us: cloud packet mirroring is not equally complete on every platform. In our own testing, one major provider's mirroring does not deliver the reply side of connections that the instance itself initiated, which makes any detection that depends on reading the response blind on that platform. We test per platform and tell you what your feed actually contains before you buy anything.
No. The sensor reads a mirrored copy of network traffic. Nothing is installed on any host, which is also why it works on devices that can never run an agent.
It cannot. The sensor is never inline; it only receives a copy of traffic. Removing it or having it fail has no effect on the traffic path. The one thing to plan properly is the mirror configuration on the switch itself, which we walk through with your network team.
Wherever you decide. The sensor and its analysis can run on your own premises or in a cloud region you nominate, so captured traffic does not have to leave your jurisdiction.
Usually within the first few days of a live feed, because misconfiguration and unsanctioned egress show up immediately. Behavioural baselines that flag a change in how a link is used need longer, since they have to learn normal first.
Tell us whether you suspect something is already inside, or whether you want to measure what your current tools would catch. Either way you get a concrete next step.
Contact us