Every endpoint is a sensor. Every packet has context.
Netgraph NDR builds flow, protocol and connection analytics on the security knowledge graph — connection and flow records, application and protocol breakdown, baselines and anomalies. The endpoint agent's netcollect module turns the fleet into a distributed sensor grid, dedicated TAP/SPAN sensors add depth where you need it, and every network detection lands in the same central alert queue as SIEM, EDR and cloud — triaged by the agentic SOC.
What is NDR (Network Detection & Response)?
NDR watches the traffic your endpoints can't or won't report — east-west movement, unmanaged devices, OT segments, encrypted-traffic metadata — using sensors on TAP/SPAN ports, and raises detections mapped to MITRE ATT&CK techniques. In Netgraph, network detections land on the same knowledge graph as endpoint and identity signals, so a beaconing alert is automatically connected to the host that beaconed, the user logged into it, and the CVE that let the attacker in.
What ships in the module
Network detection without the hardware tax.
Detection on the wire
From flow anomaly to named user — on one graph.
A flow anomaly on its own is a statistic. On the knowledge graph it becomes a story: the detector fabric flags the deviation, identity context names the account behind the connection, and the ATT&CK matrix places the technique — before the alert ever reaches an analyst, the agentic SOC has the same context you do.
- Baselines and anomalies over connection, flow and protocol records.
- Detector rules mapped to ATT&CK techniques — coverage you can audit, not assume.
- PCAP deep-dive when you need packets, not summaries — packet, IDS and flow views.
- Sensor & decryption control from one policy surface.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Flow & protocol analytics | Connection and flow records, application/protocol breakdown, baselines and anomalies | NDR pages under SOC / Visibility |
| Host-as-sensor | Endpoint agent netcollect: host-observed connections + live capture with auto-installed packet driver | Endpoint agent (netcollect module) |
| TAP / SPAN sensors | Dedicated sensor support with a sensor & decryption policy control surface | NDR ▸ Sensor control |
| Rule engine & detectors | Detection rules and detector fabric evaluated over wire telemetry | NDR ▸ Detections |
| ATT&CK matrix | Technique coverage matrix mapping detectors to ATT&CK | NDR ▸ Coverage matrix |
| PCAP forensics | Multi-format packet / IDS / flow analysis, tshark-powered | NDR ▸ PCAP analysis |
| Central alerting | NDR detections write to the central alerts table, triaged by the agentic SOC | SOC ▸ Detect ▸ Alerts |
Common questions
NDR — asked and answered
Why do I need NDR if I already have EDR?+
EDR only sees hosts where the agent runs. NDR covers the gaps — unmanaged and BYOD devices, IoT/OT equipment, appliances, and lateral movement between hosts. The two together, correlated on one graph, are how you catch attacks that either alone would miss.
Does Netgraph NDR support packet capture and forensics?+
Yes — multi-format packet, IDS, and flow forensics with sensor control from the console, so an investigator can pivot from a detection to the underlying capture without leaving the platform.
Can Netgraph NDR run in air-gapped or OT environments?+
Yes. Netgraph supports fully air-gapped deployment, and the manufacturing case study on our resources page covers an air-gapped OT/IT SOC across four plants with 3,800 OT devices.
Works with everything on the graph
EDR / EPP
The same unified agent that runs EDR carries netcollect — one deployment, endpoint and network coverage together.
Explore→NextGen SIEM
Network telemetry lands on the same open schema and answers to the same NQL as every other source.
Explore→Forensics
Pivot from a flow anomaly into full-fidelity investigation — PCAP dissection alongside endpoint and log evidence.
Explore→