← All Netgraph solutions
NDRDetect & Respond

Every endpoint is a sensor. Every packet has context.

Netgraph NDR builds flow, protocol and connection analytics on the security knowledge graph — connection and flow records, application and protocol breakdown, baselines and anomalies. The endpoint agent's netcollect module turns the fleet into a distributed sensor grid, dedicated TAP/SPAN sensors add depth where you need it, and every network detection lands in the same central alert queue as SIEM, EDR and cloud — triaged by the agentic SOC.

Host-as-sensor coverageTAP / SPAN sensorsATT&CK coverage matrixMulti-format PCAP forensicsIdentity-aware east-west

What is NDR (Network Detection & Response)?

NDR watches the traffic your endpoints can't or won't report — east-west movement, unmanaged devices, OT segments, encrypted-traffic metadata — using sensors on TAP/SPAN ports, and raises detections mapped to MITRE ATT&CK techniques. In Netgraph, network detections land on the same knowledge graph as endpoint and identity signals, so a beaconing alert is automatically connected to the host that beaconed, the user logged into it, and the CVE that let the attacker in.

What ships in the module

Network detection without the hardware tax.

01

Flow & connection analytics

Connection and flow records with application and protocol breakdown — who talks to what, over which protocol, how often — with baselines and anomaly detection over the top.

02

Host-as-sensor

The endpoint agent's netcollect module contributes host-observed connections plus live capture with an auto-installed packet driver — network coverage across the fleet without deploying extra hardware.

03

TAP / SPAN sensors

Dedicated sensor support via the netcollect Rust module and a sensor and policy control surface — including sensor & decryption control — for the segments where a mirror port beats a host view.

04

Rule engine + detector fabric

Detections run over the wire through a rule engine and detector fabric — authored, tuned and evaluated like every other detection plane on the platform.

05

ATT&CK technique matrix

Network detections map onto an ATT&CK technique coverage matrix, so you can see which techniques the wire actually covers — and where the gaps are.

06

Multi-format PCAP forensics

Packet, IDS and flow forensics — tshark-powered — for deep investigation. Upload a capture, dissect it in-console, pivot into the graph.

07

Identity-aware east-west

Lateral traffic is joined to identity context on the graph — east-west visibility that names the user behind the flow, not just the IP pair.

08

Central alerting

NDR detections land in the central alerts table alongside SIEM, EDR and cloud — same queue, same case management, same agentic-SOC triage.

09

Open sensor ecosystem

Honest scope: heavy-duty external sensor planes (Zeek / DPDK class) integrate as sources. The in-app slices are the rule engine, detector fabric, ATT&CK matrix, forensics and the sensor control surface — and they read whatever the sensors feed them.

Detection on the wire

From flow anomaly to named user — on one graph.

A flow anomaly on its own is a statistic. On the knowledge graph it becomes a story: the detector fabric flags the deviation, identity context names the account behind the connection, and the ATT&CK matrix places the technique — before the alert ever reaches an analyst, the agentic SOC has the same context you do.

  • Baselines and anomalies over connection, flow and protocol records.
  • Detector rules mapped to ATT&CK techniques — coverage you can audit, not assume.
  • PCAP deep-dive when you need packets, not summaries — packet, IDS and flow views.
  • Sensor & decryption control from one policy surface.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Flow & protocol analyticsConnection and flow records, application/protocol breakdown, baselines and anomaliesNDR pages under SOC / Visibility
Host-as-sensorEndpoint agent netcollect: host-observed connections + live capture with auto-installed packet driverEndpoint agent (netcollect module)
TAP / SPAN sensorsDedicated sensor support with a sensor & decryption policy control surfaceNDR ▸ Sensor control
Rule engine & detectorsDetection rules and detector fabric evaluated over wire telemetryNDR ▸ Detections
ATT&CK matrixTechnique coverage matrix mapping detectors to ATT&CKNDR ▸ Coverage matrix
PCAP forensicsMulti-format packet / IDS / flow analysis, tshark-poweredNDR ▸ PCAP analysis
Central alertingNDR detections write to the central alerts table, triaged by the agentic SOCSOC ▸ Detect ▸ Alerts

Common questions

NDR — asked and answered

Why do I need NDR if I already have EDR?+

EDR only sees hosts where the agent runs. NDR covers the gaps — unmanaged and BYOD devices, IoT/OT equipment, appliances, and lateral movement between hosts. The two together, correlated on one graph, are how you catch attacks that either alone would miss.

Does Netgraph NDR support packet capture and forensics?+

Yes — multi-format packet, IDS, and flow forensics with sensor control from the console, so an investigator can pivot from a detection to the underlying capture without leaving the platform.

Can Netgraph NDR run in air-gapped or OT environments?+

Yes. Netgraph supports fully air-gapped deployment, and the manufacturing case study on our resources page covers an air-gapped OT/IT SOC across four plants with 3,800 OT devices.

See it live

Light up east-west traffic. No appliance required.