Every module, explained. One graph underneath.
Netgraph is one product, not a suite of acquisitions — but each capability is a full slice with its own model, console and API, all reading and writing the same security knowledge graph. Pick a module below for the complete functionality breakdown.
Detect & Respond
The streaming core — ingest to verdict to containment, in one loop.
NextGen SIEM
Streaming ingest, OCSF/ECS open schema, NQL — the platform-native query language — Detection-as-Code with backtesting, 1,100+ curated detections, ingest-time suppression, retro replay, tiered open storage.
Full functionality breakdown→EndpointEDR / EPP — Unified Endpoint Agent
One cross-platform agent (macOS · Linux · Windows): rich telemetry, on-host behavioural scoring, AV/EPP with quarantine, 2,600+ YARA rules, OSQuery, FIM, live response, and full fleet management.
Full functionality breakdown→NetworkNDR — Network Detection & Response
Flow, protocol and host-observed connection analytics, a rule engine and detector fabric mapped to ATT&CK, TAP/SPAN sensor control, and multi-format packet / IDS / flow forensics.
Full functionality breakdown→BehaviourUEBA — Behaviour Analytics
20-model analytics across the full Gartner taxonomy — baselines, peer groups, link analysis, Bayesian risk — 62 use-cases with sector packs, visual rule canvas, watchlists, and explainable 0–100 entity risk.
Full functionality breakdown→AI SOCAgentic AI SOC
An eight-agent SOC — L1, L2, L3, RCA, Threat Analyst, Threat Hunter, Forensic, SOC Manager — plus Phish-Triage, a SOAR agent and the app-wide Frontal assistant, with a 75-skill library and HITL approval gates.
Full functionality breakdown→AutomationSOAR & Case Management
Code-first playbooks with approval ladders, a durable HITL queue, full case lifecycle with evidence vault, PICERL checklists that auto-progress, semantic timelines, and on-call escalation.
Full functionality breakdown→Cloud & Data Security
Control plane to data plane — posture, runtime and sensitive data on the same graph.
Cloud Security — CDR · CNAPP · CSPM
Cloud detection & response across AWS, Azure and GCP; workload, IaC and supply-chain scanning with drift detection and admission control; CIS benchmarks, framework mapping and custom policy-as-code.
Full functionality breakdown→DataDSPM — Data Security Posture
Discover, classify and monitor sensitive data in the cloud and on the endpoint — with out-of-box recognizers for Aadhaar, PAN, bank, passport and health identifiers, and custom classifier packs.
Full functionality breakdown→Exposure & Validation
Find what's reachable, prove what's detectable, close the gap.
CTEM — Continuous Threat Exposure Management
The full five-stage lifecycle — scoping, discovery, prioritization by real attack paths, validation, mobilization — with reachability-aware ranking across runtime, code, identity and data.
Full functionality breakdown→Add-onDark Web Monitoring
Licensed CTEM add-on: feed-agnostic dark-web ingest, credential-liveness checks, exposure scoring, and graph fusion that publishes findings into alerts, TIP and compliance evidence.
Full functionality breakdown→VulnerabilityVulnerability & Asset Management
Full hardware / software / patch / kernel inventory from the endpoint agent, a rich per-asset profile, an incrementally-synced Asset Register, and findings prioritized by actual blast radius — not CVSS in isolation.
Full functionality breakdown→BASAttack Simulation — BAS & Red Team
Five-stage attack scenarios validated against real telemetry read-back, scheduled runs, endpoint deploy targeting, ATT&CK coverage mapping, and Detection-CI gap wiring into the flywheel.
Full functionality breakdown→PhishingPhishing Simulation
Real-send campaigns over your SMTP, cohort or direct-address targeting, templates and scheduling, just-in-time training, KPIs — and a native Phish-Triage agent for the inbound side.
Full functionality breakdown→Intelligence & Operations
Hunt it, attribute it, prove it — with the graph as evidence.
Threat Hunting & NQL Data Search
Hypothesis-driven hunts in NQL with natural-language synthesis, scheduled hunt jobs with run history, the interactive Data Search console, entity graph exploration and blast-radius analysis.
Full functionality breakdown→IntelThreat Intelligence Platform
Feed ingest with live OSINT, Indicator-Match against confirmed indicators, embedded local GeoIP/ASN/WHOIS enrichment, and detection orchestration that pushes IOCs to EDR, firewalls, proxies and zero-trust via enabled integrations.
Full functionality breakdown→ForensicsForensics & Incident Response
Tamper-resistant artifact vault with hash-chained chain-of-custody, scope/investigate/explore consoles, declared-incident statutory clocks, PICERL-driven response, and regulator-ready evidence exports.
Full functionality breakdown→Governance & Platform
Compliance evidence, KPI reporting, and the multi-tenant plane it all runs on.
Compliance & KPI Reporting
Continuous compliance scoring with evidence, a 136-KPI / 15-section report generator with prebuilt packs, cron-scheduled delivery over SMTP in CSV/XLS/HTML/PDF, and DPDP / CERT-In statutory-clock tracking.
Full functionality breakdown→PlatformPlatform, Multi-tenancy & Licensing
Native multi-tenancy with hard isolation, 390-permission RBAC/ABAC with SSO, hash-chained AAA audit, Ed25519-signed offline license files, region-aware billing, a super-admin plane — and cloud, on-premise or fully air-gapped deployment.
Full functionality breakdown→