{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"network-detection","name":"Network detection & response","short":"NDR"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"network-detection-platforms","name":"Network detection & investigation platforms","scope":"Commercial platforms that collect network-derived evidence, generate detections and support analyst investigation. Packet and flow architectures remain visible constraints. Open-source telemetry engines, standalone packet brokers, managed-service staffing and unrelated cloud/identity/email bundles are excluded."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Completeness of the publicly documented operating model, not measured reliability, installed base or vendor size. Anchors are cumulative; missing evidence is unknown, never zero.","question":"How complete is the documented collection-to-investigation operating model?","anchors":["The evaluated offering explicitly has no collection or detection workflow.","A public product description identifies the collection or detection purpose.","The offering documents a collection path and alert generation.","Stage 2 plus alert-to-asset evidence context, explicit disposition controls and detection-tuning controls.","Stage 3 plus documented role permissions, audit of analyst or administrative actions, and collection-health monitoring.","Stage 4 plus independently evaluated repeatability of recovery and scaling procedures in the stated deployment."],"refinements":[{"base":2,"criteria":[{"id":"investigation-context","label":"Alert-to-asset and supporting-observation investigation context","weight":4},{"id":"disposition-controls","label":"Documented controls to disposition an alert or investigation","weight":3},{"id":"tuning-controls","label":"Documented controls to adjust detection or baseline handling","weight":3}]},{"base":3,"criteria":[{"id":"access-roles","label":"Documented operational role permissions","weight":3},{"id":"audit-actions","label":"Documented audit of analyst or administrative actions","weight":4},{"id":"sensor-health","label":"Documented collection or sensor health monitoring procedure","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented shipped investigation mechanisms beyond this cohort’s ordinary workflow. AI branding, roadmap promises and effectiveness claims alone earn no extra credit. Anchors are cumulative.","question":"What inspectable, shipped investigation mechanism goes beyond the cohort baseline?","anchors":["The evaluated edition explicitly excludes detection and investigation.","The offering documents collection or inventory only.","The offering additionally documents alert analysis.","Current cohort baseline: network detections, entity or connection context and analyst investigation. Ordinary rules, behavioral models and alert correlation are baseline capabilities.","Stage 3 plus an additional shipped investigation mechanism with inspectable output, analyst controls and documented prerequisites or limits.","Stage 4 plus a second distinct mechanism satisfying the same requirements and independent evaluation of the claimed operator benefit."],"refinements":[{"base":3,"criteria":[{"id":"inspectable-output","label":"An additional investigation mechanism produces inspectable evidence or reasoning beyond ordinary alert correlation","weight":4},{"id":"analyst-controls","label":"Documented analyst controls to inspect, adjust or challenge that mechanism","weight":3},{"id":"scope-limits","label":"Its prerequisites, scope and operational limitations are documented","weight":3}]}]},{"id":"breadth","name":"Capability breadth","description":"Documented capabilities within the exact evaluated bundle. Adjacent products, subscriptions and managed services do not inherit credit. Anchors are cumulative.","question":"Which capabilities and deployment environments are evidenced within this bundle?","anchors":["The evaluated edition explicitly has no network visibility capability.","Network traffic or flow collection is described.","Stage 1 plus network detections.","Stage 2 plus investigation context and documented coverage of more than one deployment environment.","Stage 3 plus underlying record or packet pivots, identity enrichment and an explicit capability/collection constraint matrix.","Stage 4 plus independently evaluated coverage and blind spots across the stated deployment environments."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"How clearly public sources establish exports and integrations, their scope and operating requirements. A logo wall alone does not prove a working connector.","question":"What integration can an operator actually explain and configure from the reviewed evidence?","anchors":["The offering explicitly excludes exports and integrations.","An integration approach is described at a high level.","Stage 1 plus a documented export or API surface.","Stage 2 plus at least one named integration with its transferred data or action described.","Stage 3 plus procedural configuration, authentication and operational limitation details for the evaluated integration.","Stage 4 plus independently tested failure handling and preservation of investigation context across multiple external systems."]},{"id":"governance","name":"Governance & control","description":"Evidence for who can access data or change operations and how those actions are governed. Missing public access-control detail remains unknown.","question":"Which access and audit boundaries are documented for this exact deployment?","anchors":["The offering explicitly has no access control.","Authentication to the management interface is documented.","Stage 1 plus differentiated operator and administrator roles.","Stage 2 plus documented audit of analyst or administrative changes.","Stage 3 plus granular data/action scope, authentication safeguards and a documented recovery or revocation procedure.","Stage 4 plus independent validation of separation of duties, audit completeness and emergency access within the evaluated edition."]},{"id":"operations","name":"Operator enablement","description":"How far the available documentation helps an operator carry out an investigation and keep collection useful. This measures accessible operating evidence, not staffing quality.","question":"What repeatable investigation and maintenance tasks can an operator learn from the reviewed sources?","anchors":["The offering explicitly has no operator workflow.","Public material explains the workflow at overview level.","Stage 1 plus a documented operator task with concrete interface controls or steps.","Stage 2 plus an analyst investigation task and guidance for adjusting detection handling.","Stage 3 plus collection-health troubleshooting and a reproducible evidence-export or query procedure.","Stage 4 plus a documented training/lab path and tested restoration or recovery procedure for this deployment."]}],"assessments":[{"vendor":"vectra-network","cohort":"network-detection-platforms","edition":"Vectra AI Platform Network detections in Respond UX; optional Match/Stream, cloud-log and identity detection surfaces, MDR and extra search entitlements excluded","asOf":"2026-09-21","status":"research-preview","summary":"Public triage and API documentation supports an explainable operating workflow. AI-Triage is evaluated as a documented mechanism, not as proof of superior detection quality.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Network collection and detections connect to scoped triage controls, disposition and tuning, satisfying stage 3. The appliance-health procedure adds 0.3. A complete Respond UX operational role matrix and action-audit procedure were not verified, so their credits are withheld.","sourceIds":["vectra","vectra-triage","vectra-health"],"refinement":{"base":3,"evidence":[{"criterion":"sensor-health","rationale":"The appliance-health guide provides operational monitoring of Brain and Sensor health.","sourceIds":["vectra-health"]}]}},"innovation":{"score":4,"confidence":"medium","rationale":"The network baseline is supplemented by AI-Triage with identifiable filtered outcomes, a view for inspecting them, and documented applicability and limitations. Respond UX cannot disable AI-Triage; the guide states the historical-data prerequisite. These controls expose the mechanism without proving its accuracy.","sourceIds":["vectra","vectra-triage","vectra-ai"]},"breadth":{"score":3,"confidence":"medium","rationale":"The platform documents network detections and investigation across campus, data-center and cloud network environments. Cloud-log/identity products are excluded. The complete identity-enrichment plus raw-evidence capability matrix required for stage 4 was not verified for this bundle.","sourceIds":["vectra"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"The Respond UX v3.4 API is a documented integration surface. This review did not verify a specific connector’s deployment and transferred context end to end, so a higher stage is not inferred from the platform’s integration claims.","sourceIds":["vectra-api"]},"governance":{"score":1,"confidence":"medium","rationale":"Respond UX SAML authentication is documented, meeting stage 1. Role claims are mapped, but the selected source does not enumerate operator versus administrator permissions; stage 2 is not assumed from generic role mapping.","sourceIds":["vectra-sso"]},"operations":{"score":3,"confidence":"medium","rationale":"Triage guidance supplies concrete investigation, disposition and filter-adjustment tasks. Health monitoring is documented, but a complete evidence-export/query procedure for the exact licensed network scope was not verified, so stage 4 is withheld.","sourceIds":["vectra-triage","vectra-health"]}},"constraints":["Respond UX and Quadrant UX have different APIs and operational behavior; procedures are not interchangeable.","Filtered detections and whitelist-hidden detections have different visibility consequences.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership.","AI-Triage cannot be disabled in Respond UX. Do not apply Quadrant UX toggle instructions to RUX."],"sources":[{"id":"vectra","title":"Vectra AI Platform","url":"https://www.vectra.ai/platform","accessedAt":"2026-09-21","kind":"product"},{"id":"vectra-triage","title":"Vectra triage best practices","url":"https://docs.vectra.ai/configuration/tuning/triage-best-practices","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-health","title":"Vectra appliance health monitoring","url":"https://docs.vectra.ai/deployment/appliance-operations/monitoring-appliance-health","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-api","title":"Vectra Respond UX API v3.4","url":"https://docs.vectra.ai/configuration/access/api-rux/v34-api-guide-rux","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-ai","title":"Vectra AI-Triage in detail","url":"https://docs.vectra.ai/operations/general/ai-triage-in-detail","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-sso","title":"Vectra Respond UX SAML SSO configuration","url":"https://docs.vectra.ai/configuration/access/saml-sso-rux/any-idp-saml-rux","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Vectra AI Platform (Network)","company":"Vectra AI","profileUrl":"/landscape/vendors/vectra-network/"},{"vendor":"extrahop-revealx","cohort":"network-detection-platforms","edition":"ExtraHop RevealX NDR with network sensor; records/packets credited only as documented conditional workflows, separate IDS/NPM and packet-forensics entitlements excluded","asOf":"2026-09-21","status":"research-preview","summary":"Detection documentation explicitly ties investigations to collection and storage prerequisites. Conditional evidence access is useful, but must not be mistaken for evidence included in every deployment.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Sensors and detections establish stage 2; participants, related detections and record/packet pivots add investigation-context credit (+0.4). The reviewed sources did not establish the complete disposition and tuning-control procedure for stage 3.","sourceIds":["extrahop","extrahop-detect"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"Detection cards link participants and related records or packets when their prerequisite stores are configured.","sourceIds":["extrahop-detect"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Rules, machine learning, related detections and investigation views meet the current network baseline. Optional IDS and packet-forensics modules are not treated as extra shipped innovation in the NDR-only scope.","sourceIds":["extrahop","extrahop-detect"]},"breadth":{"score":3,"confidence":"medium","rationale":"The documented platform offers sensor-based network detection and investigation in more than one deployment environment. Record/packet pivots are conditional; a complete in-scope identity-enrichment and constraint matrix was not established for stage 4.","sourceIds":["extrahop","extrahop-detect","extrahop-guide"]},"ecosystem":{"score":3,"confidence":"low","rationale":"RevealX integration documentation describes built-in export and a bidirectional REST API, plus named transfers such as detection events to Google Security Operations and detections and metrics to Splunk. This establishes stages 1–3. Connector configuration, authentication, operational limits and exact entitlements need verification before stage 4 can be credited.","sourceIds":["extrahop-integrations"]},"governance":{"score":null,"confidence":"low","rationale":"Detection viewing requires privileges, but the exact authentication and differentiated role matrix were not established in the reviewed sources. An inaccessible audit page is not evidence of absent auditing.","sourceIds":["extrahop-detect"]},"operations":{"score":2,"confidence":"medium","rationale":"Detection documentation supplies concrete navigation and evidence-pivot tasks, with recordstore and packet-capture prerequisites. Full detection-handling adjustment procedures were not reviewed, so stage 3 is withheld.","sourceIds":["extrahop-detect"]}},"constraints":["Viewing transactions requires a configured recordstore; downloading packets requires capture and storage.","IDS requires its own licensed module and sensor; no IDS API credit is transferred to NDR.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"extrahop","title":"ExtraHop RevealX platform","url":"https://www.extrahop.com/platform/revealx","accessedAt":"2026-09-21","kind":"product"},{"id":"extrahop-detect","title":"ExtraHop detections and evidence prerequisites","url":"https://docs.extrahop.com/current/detections-overview/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"extrahop-guide","title":"ExtraHop system user guide","url":"https://docs.extrahop.com/current/eh-system-user-guide/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"extrahop-integrations","title":"ExtraHop RevealX integration partners and data flows","url":"https://www.extrahop.com/partners/integrations","accessedAt":"2026-09-21","kind":"product"}],"name":"RevealX NDR","company":"ExtraHop","profileUrl":"/landscape/vendors/extrahop-revealx/"},{"vendor":"corelight-investigator","cohort":"network-detection-platforms","edition":"Corelight network sensors plus Investigator SaaS; exact sensor, retention and optional capability entitlements must be verified","asOf":"2026-09-21","status":"research-preview","summary":"The commercial bundle links network evidence to entity investigations. Current assisted-triage and response descriptions are product evidence, without independently verified operating controls or efficacy.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Network evidence collection and detection are documented. Entity cases and links to supporting observations earn 0.4; concrete disposition and tuning controls were not verified from the public product/data-sheet material.","sourceIds":["corelight","corelight-ds"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"Investigator connects an entity-oriented case to its underlying network observations.","sourceIds":["corelight","corelight-ds"]}]}},"innovation":{"score":3.7,"confidence":"medium","rationale":"Beyond the baseline, natural-language investigation exposes generated LQL queries (+0.4), which analysts can inspect and modify before execution (+0.3). Exact prerequisites and limitations for this mechanism remain insufficiently documented for the remaining credit.","sourceIds":["corelight","corelight-ds"],"refinement":{"base":3,"evidence":[{"criterion":"inspectable-output","rationale":"The data sheet describes converting plain-language investigation questions into visible LQL queries.","sourceIds":["corelight-ds"]},{"criterion":"analyst-controls","rationale":"The data sheet describes inspecting and modifying generated LQL queries before execution, preserving analyst control over the assisted investigation.","sourceIds":["corelight-ds"]}]}},"breadth":{"score":3,"confidence":"medium","rationale":"The product and data sheet establish network detections, evidence-led investigation and hybrid/multicloud scope. A complete capability/collection constraint matrix for the precise sensor bundle was not verified for stage 4.","sourceIds":["corelight","corelight-ds"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Current product material describes export of triage verdicts and supporting context to a SIEM. A named connector’s mapped fields and configuration requirements were not verified, so stage 3 is withheld.","sourceIds":["corelight"]},"governance":{"score":null,"confidence":"low","rationale":"Claims of transparent reasoning do not establish interface authentication, differentiated role permissions or audit controls. Those procedures were not available in the reviewed product material.","sourceIds":["corelight","corelight-ds"]},"operations":{"score":2,"confidence":"medium","rationale":"The data sheet identifies concrete analyst controls: inspect and modify a generated query before execution, then pivot to raw evidence. Complete investigation-disposition and detection-adjustment procedures were not verified as a stage-3 package.","sourceIds":["corelight-ds"]}},"constraints":["Open-source Zeek alone is outside this commercial bundle and receives no inherited scoring.","Assisted triage and integrated response need explicit availability, permissions and license validation.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"corelight","title":"Corelight Investigator","url":"https://corelight.com/platform/investigator","accessedAt":"2026-09-21","kind":"product"},{"id":"corelight-ds","title":"Corelight Investigator data sheet","url":"https://corelight.com/hubfs/resources/product-data-sheets/corelight-investigator-ds.pdf","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Open NDR with Investigator","company":"Corelight","profileUrl":"/landscape/vendors/corelight-investigator/"},{"vendor":"cisco-secure-network-analytics","cohort":"network-detection-platforms","edition":"Cisco Secure Network Analytics Manager and Flow Collector with flow licensing; optional Flow Sensor, ISE, XDR and Secure Cloud Analytics excluded unless stated as integration boundaries","asOf":"2026-09-21","status":"research-preview","summary":"A flow-oriented investigation option with explicit component and licensing boundaries. Metadata evidence is useful but does not imply retained packet contents.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Flow collection and alerts establish stage 2. Context including devices, users and timestamps earns investigation-context credit (+0.4); concrete disposition and tuning procedures were not verified in the product/data-sheet scope.","sourceIds":["cisco-ndr","cisco-ndr-ds"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"The product description connects alerts with user, device, location, timestamp and application context.","sourceIds":["cisco-ndr"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Behavioral network analysis, flow context and incident investigation meet the ordinary cohort baseline. Encrypted-traffic analytics and machine-learning descriptions alone do not establish a new operator mechanism with documented controls and limits.","sourceIds":["cisco-ndr","cisco-ndr-ds"]},"breadth":{"score":3,"confidence":"medium","rationale":"The data sheet describes network investigation across on-premises and cloud environments, with physical and virtual components. Optional sensors and ISE are not included as assumed raw-packet or identity-enrichment entitlements for stage 4.","sourceIds":["cisco-ndr-ds"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"The published ISE integration describes identity/context use for segmentation policy and alerts, establishing a named data-sharing path. Full connector authentication and operational procedures were not verified for stage 4.","sourceIds":["cisco-ndr","cisco-ndr-ds"]},"governance":{"score":null,"confidence":"low","rationale":"The selected product and component sources do not establish the console authentication, differentiated role and audit procedures. The deployment’s local management model is not a substitute for governance evidence.","sourceIds":["cisco-ndr-ds"]},"operations":{"score":1,"confidence":"medium","rationale":"Public material explains components and investigation use cases but a concrete user procedure was not successfully retrieved in this review. No higher operator-documentation stage is inferred from a self-guided demo link.","sourceIds":["cisco-ndr","cisco-ndr-ds"]}},"constraints":["The component data sheet is dated January 2024 and is still linked by the current product page; exact supported versions require procurement verification.","Flow sampling, exporter coverage and retention limit investigation; encrypted metadata is not decrypted payload.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"cisco-ndr","title":"Cisco Secure Network Analytics","url":"https://www.cisco.com/site/us/en/products/security/security-analytics/secure-network-analytics/index.html","accessedAt":"2026-09-21","kind":"product"},{"id":"cisco-ndr-ds","title":"Cisco Secure Network Analytics components and licensing","url":"https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/datasheet-c78-739398.html","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Cisco Secure Network Analytics","company":"Cisco","profileUrl":"/landscape/vendors/cisco-secure-network-analytics/"}],"scenarios":[{"id":"unmanaged-device","name":"Unmanaged device investigation","description":"A SOC must investigate a device without a usable endpoint agent.","priorities":["breadth","operations","ecosystem"],"questions":["Which traffic from this device is actually observed?","Can the alert be tied to retained evidence and a stable device identity?","Which separately authorized tool can contain it if needed?"]},{"id":"privacy-sensitive","name":"Privacy-sensitive network","description":"A team needs enough evidence to investigate while limiting access to sensitive traffic.","priorities":["governance","maturity","breadth"],"questions":["Which decisions need payload access rather than metadata?","Who can export packets and how is the action audited?","What do encryption and retention gaps prevent the analyst from proving?"]}],"researchNotes":["This first review is a dated baseline. Momentum begins only after a second comparable review; no trend is inferred from naming or scoring changes.","Scores reflect publicly evidenced stages, not observed efficacy, market share or maturity inferred from company age. Public documentation confidence is at most medium.","Ordinary network baselines include rules or behavioral detections, context and investigation. Additional innovation credit needs inspectable output, operator controls and explicit limits.","Equivalent scores are acceptable. Decimal credits apply shared criteria totaling ten tenths and are not graph jitter.","Zeek is an educational telemetry alternative, not a scored commercial platform. Darktrace, Fortinet and Arista remain substantive catalog profiles awaiting equivalent scoped assessments.","Some operator and audit sources could not be retrieved; unverified controls remain unknown instead of being scored as absent.","Packet- and flow-based architectures differ. A comparison must retain collection, encryption, sampling and licensing constraints."],"history":{"segment":"network-detection","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"network-detection","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"network-detection-platforms","name":"Network detection & investigation platforms","scope":"Commercial platforms that collect network-derived evidence, generate detections and support analyst investigation. Packet and flow architectures remain visible constraints. Open-source telemetry engines, standalone packet brokers, managed-service staffing and unrelated cloud/identity/email bundles are excluded."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Completeness of the publicly documented operating model, not measured reliability, installed base or vendor size. Anchors are cumulative; missing evidence is unknown, never zero.","question":"How complete is the documented collection-to-investigation operating model?","anchors":["The evaluated offering explicitly has no collection or detection workflow.","A public product description identifies the collection or detection purpose.","The offering documents a collection path and alert generation.","Stage 2 plus alert-to-asset evidence context, explicit disposition controls and detection-tuning controls.","Stage 3 plus documented role permissions, audit of analyst or administrative actions, and collection-health monitoring.","Stage 4 plus independently evaluated repeatability of recovery and scaling procedures in the stated deployment."],"refinements":[{"base":2,"criteria":[{"id":"investigation-context","label":"Alert-to-asset and supporting-observation investigation context","weight":4},{"id":"disposition-controls","label":"Documented controls to disposition an alert or investigation","weight":3},{"id":"tuning-controls","label":"Documented controls to adjust detection or baseline handling","weight":3}]},{"base":3,"criteria":[{"id":"access-roles","label":"Documented operational role permissions","weight":3},{"id":"audit-actions","label":"Documented audit of analyst or administrative actions","weight":4},{"id":"sensor-health","label":"Documented collection or sensor health monitoring procedure","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Documented shipped investigation mechanisms beyond this cohort’s ordinary workflow. AI branding, roadmap promises and effectiveness claims alone earn no extra credit. Anchors are cumulative.","question":"What inspectable, shipped investigation mechanism goes beyond the cohort baseline?","anchors":["The evaluated edition explicitly excludes detection and investigation.","The offering documents collection or inventory only.","The offering additionally documents alert analysis.","Current cohort baseline: network detections, entity or connection context and analyst investigation. Ordinary rules, behavioral models and alert correlation are baseline capabilities.","Stage 3 plus an additional shipped investigation mechanism with inspectable output, analyst controls and documented prerequisites or limits.","Stage 4 plus a second distinct mechanism satisfying the same requirements and independent evaluation of the claimed operator benefit."],"refinements":[{"base":3,"criteria":[{"id":"inspectable-output","label":"An additional investigation mechanism produces inspectable evidence or reasoning beyond ordinary alert correlation","weight":4},{"id":"analyst-controls","label":"Documented analyst controls to inspect, adjust or challenge that mechanism","weight":3},{"id":"scope-limits","label":"Its prerequisites, scope and operational limitations are documented","weight":3}]}]},{"id":"breadth","name":"Capability breadth","description":"Documented capabilities within the exact evaluated bundle. Adjacent products, subscriptions and managed services do not inherit credit. Anchors are cumulative.","question":"Which capabilities and deployment environments are evidenced within this bundle?","anchors":["The evaluated edition explicitly has no network visibility capability.","Network traffic or flow collection is described.","Stage 1 plus network detections.","Stage 2 plus investigation context and documented coverage of more than one deployment environment.","Stage 3 plus underlying record or packet pivots, identity enrichment and an explicit capability/collection constraint matrix.","Stage 4 plus independently evaluated coverage and blind spots across the stated deployment environments."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"How clearly public sources establish exports and integrations, their scope and operating requirements. A logo wall alone does not prove a working connector.","question":"What integration can an operator actually explain and configure from the reviewed evidence?","anchors":["The offering explicitly excludes exports and integrations.","An integration approach is described at a high level.","Stage 1 plus a documented export or API surface.","Stage 2 plus at least one named integration with its transferred data or action described.","Stage 3 plus procedural configuration, authentication and operational limitation details for the evaluated integration.","Stage 4 plus independently tested failure handling and preservation of investigation context across multiple external systems."]},{"id":"governance","name":"Governance & control","description":"Evidence for who can access data or change operations and how those actions are governed. Missing public access-control detail remains unknown.","question":"Which access and audit boundaries are documented for this exact deployment?","anchors":["The offering explicitly has no access control.","Authentication to the management interface is documented.","Stage 1 plus differentiated operator and administrator roles.","Stage 2 plus documented audit of analyst or administrative changes.","Stage 3 plus granular data/action scope, authentication safeguards and a documented recovery or revocation procedure.","Stage 4 plus independent validation of separation of duties, audit completeness and emergency access within the evaluated edition."]},{"id":"operations","name":"Operator enablement","description":"How far the available documentation helps an operator carry out an investigation and keep collection useful. This measures accessible operating evidence, not staffing quality.","question":"What repeatable investigation and maintenance tasks can an operator learn from the reviewed sources?","anchors":["The offering explicitly has no operator workflow.","Public material explains the workflow at overview level.","Stage 1 plus a documented operator task with concrete interface controls or steps.","Stage 2 plus an analyst investigation task and guidance for adjusting detection handling.","Stage 3 plus collection-health troubleshooting and a reproducible evidence-export or query procedure.","Stage 4 plus a documented training/lab path and tested restoration or recovery procedure for this deployment."]}],"assessments":[{"vendor":"vectra-network","cohort":"network-detection-platforms","edition":"Vectra AI Platform Network detections in Respond UX; optional Match/Stream, cloud-log and identity detection surfaces, MDR and extra search entitlements excluded","asOf":"2026-09-21","status":"research-preview","summary":"Public triage and API documentation supports an explainable operating workflow. AI-Triage is evaluated as a documented mechanism, not as proof of superior detection quality.","dimensions":{"maturity":{"score":3.3,"confidence":"medium","rationale":"Network collection and detections connect to scoped triage controls, disposition and tuning, satisfying stage 3. The appliance-health procedure adds 0.3. A complete Respond UX operational role matrix and action-audit procedure were not verified, so their credits are withheld.","sourceIds":["vectra","vectra-triage","vectra-health"],"refinement":{"base":3,"evidence":[{"criterion":"sensor-health","rationale":"The appliance-health guide provides operational monitoring of Brain and Sensor health.","sourceIds":["vectra-health"]}]}},"innovation":{"score":4,"confidence":"medium","rationale":"The network baseline is supplemented by AI-Triage with identifiable filtered outcomes, a view for inspecting them, and documented applicability and limitations. Respond UX cannot disable AI-Triage; the guide states the historical-data prerequisite. These controls expose the mechanism without proving its accuracy.","sourceIds":["vectra","vectra-triage","vectra-ai"]},"breadth":{"score":3,"confidence":"medium","rationale":"The platform documents network detections and investigation across campus, data-center and cloud network environments. Cloud-log/identity products are excluded. The complete identity-enrichment plus raw-evidence capability matrix required for stage 4 was not verified for this bundle.","sourceIds":["vectra"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"The Respond UX v3.4 API is a documented integration surface. This review did not verify a specific connector’s deployment and transferred context end to end, so a higher stage is not inferred from the platform’s integration claims.","sourceIds":["vectra-api"]},"governance":{"score":1,"confidence":"medium","rationale":"Respond UX SAML authentication is documented, meeting stage 1. Role claims are mapped, but the selected source does not enumerate operator versus administrator permissions; stage 2 is not assumed from generic role mapping.","sourceIds":["vectra-sso"]},"operations":{"score":3,"confidence":"medium","rationale":"Triage guidance supplies concrete investigation, disposition and filter-adjustment tasks. Health monitoring is documented, but a complete evidence-export/query procedure for the exact licensed network scope was not verified, so stage 4 is withheld.","sourceIds":["vectra-triage","vectra-health"]}},"constraints":["Respond UX and Quadrant UX have different APIs and operational behavior; procedures are not interchangeable.","Filtered detections and whitelist-hidden detections have different visibility consequences.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership.","AI-Triage cannot be disabled in Respond UX. Do not apply Quadrant UX toggle instructions to RUX."],"sources":[{"id":"vectra","title":"Vectra AI Platform","url":"https://www.vectra.ai/platform","accessedAt":"2026-09-21","kind":"product"},{"id":"vectra-triage","title":"Vectra triage best practices","url":"https://docs.vectra.ai/configuration/tuning/triage-best-practices","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-health","title":"Vectra appliance health monitoring","url":"https://docs.vectra.ai/deployment/appliance-operations/monitoring-appliance-health","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-api","title":"Vectra Respond UX API v3.4","url":"https://docs.vectra.ai/configuration/access/api-rux/v34-api-guide-rux","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-ai","title":"Vectra AI-Triage in detail","url":"https://docs.vectra.ai/operations/general/ai-triage-in-detail","accessedAt":"2026-09-21","kind":"documentation"},{"id":"vectra-sso","title":"Vectra Respond UX SAML SSO configuration","url":"https://docs.vectra.ai/configuration/access/saml-sso-rux/any-idp-saml-rux","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"extrahop-revealx","cohort":"network-detection-platforms","edition":"ExtraHop RevealX NDR with network sensor; records/packets credited only as documented conditional workflows, separate IDS/NPM and packet-forensics entitlements excluded","asOf":"2026-09-21","status":"research-preview","summary":"Detection documentation explicitly ties investigations to collection and storage prerequisites. Conditional evidence access is useful, but must not be mistaken for evidence included in every deployment.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Sensors and detections establish stage 2; participants, related detections and record/packet pivots add investigation-context credit (+0.4). The reviewed sources did not establish the complete disposition and tuning-control procedure for stage 3.","sourceIds":["extrahop","extrahop-detect"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"Detection cards link participants and related records or packets when their prerequisite stores are configured.","sourceIds":["extrahop-detect"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Rules, machine learning, related detections and investigation views meet the current network baseline. Optional IDS and packet-forensics modules are not treated as extra shipped innovation in the NDR-only scope.","sourceIds":["extrahop","extrahop-detect"]},"breadth":{"score":3,"confidence":"medium","rationale":"The documented platform offers sensor-based network detection and investigation in more than one deployment environment. Record/packet pivots are conditional; a complete in-scope identity-enrichment and constraint matrix was not established for stage 4.","sourceIds":["extrahop","extrahop-detect","extrahop-guide"]},"ecosystem":{"score":3,"confidence":"low","rationale":"RevealX integration documentation describes built-in export and a bidirectional REST API, plus named transfers such as detection events to Google Security Operations and detections and metrics to Splunk. This establishes stages 1–3. Connector configuration, authentication, operational limits and exact entitlements need verification before stage 4 can be credited.","sourceIds":["extrahop-integrations"]},"governance":{"score":null,"confidence":"low","rationale":"Detection viewing requires privileges, but the exact authentication and differentiated role matrix were not established in the reviewed sources. An inaccessible audit page is not evidence of absent auditing.","sourceIds":["extrahop-detect"]},"operations":{"score":2,"confidence":"medium","rationale":"Detection documentation supplies concrete navigation and evidence-pivot tasks, with recordstore and packet-capture prerequisites. Full detection-handling adjustment procedures were not reviewed, so stage 3 is withheld.","sourceIds":["extrahop-detect"]}},"constraints":["Viewing transactions requires a configured recordstore; downloading packets requires capture and storage.","IDS requires its own licensed module and sensor; no IDS API credit is transferred to NDR.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"extrahop","title":"ExtraHop RevealX platform","url":"https://www.extrahop.com/platform/revealx","accessedAt":"2026-09-21","kind":"product"},{"id":"extrahop-detect","title":"ExtraHop detections and evidence prerequisites","url":"https://docs.extrahop.com/current/detections-overview/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"extrahop-guide","title":"ExtraHop system user guide","url":"https://docs.extrahop.com/current/eh-system-user-guide/","accessedAt":"2026-09-21","kind":"documentation"},{"id":"extrahop-integrations","title":"ExtraHop RevealX integration partners and data flows","url":"https://www.extrahop.com/partners/integrations","accessedAt":"2026-09-21","kind":"product"}]},{"vendor":"corelight-investigator","cohort":"network-detection-platforms","edition":"Corelight network sensors plus Investigator SaaS; exact sensor, retention and optional capability entitlements must be verified","asOf":"2026-09-21","status":"research-preview","summary":"The commercial bundle links network evidence to entity investigations. Current assisted-triage and response descriptions are product evidence, without independently verified operating controls or efficacy.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Network evidence collection and detection are documented. Entity cases and links to supporting observations earn 0.4; concrete disposition and tuning controls were not verified from the public product/data-sheet material.","sourceIds":["corelight","corelight-ds"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"Investigator connects an entity-oriented case to its underlying network observations.","sourceIds":["corelight","corelight-ds"]}]}},"innovation":{"score":3.7,"confidence":"medium","rationale":"Beyond the baseline, natural-language investigation exposes generated LQL queries (+0.4), which analysts can inspect and modify before execution (+0.3). Exact prerequisites and limitations for this mechanism remain insufficiently documented for the remaining credit.","sourceIds":["corelight","corelight-ds"],"refinement":{"base":3,"evidence":[{"criterion":"inspectable-output","rationale":"The data sheet describes converting plain-language investigation questions into visible LQL queries.","sourceIds":["corelight-ds"]},{"criterion":"analyst-controls","rationale":"The data sheet describes inspecting and modifying generated LQL queries before execution, preserving analyst control over the assisted investigation.","sourceIds":["corelight-ds"]}]}},"breadth":{"score":3,"confidence":"medium","rationale":"The product and data sheet establish network detections, evidence-led investigation and hybrid/multicloud scope. A complete capability/collection constraint matrix for the precise sensor bundle was not verified for stage 4.","sourceIds":["corelight","corelight-ds"]},"ecosystem":{"score":2,"confidence":"medium","rationale":"Current product material describes export of triage verdicts and supporting context to a SIEM. A named connector’s mapped fields and configuration requirements were not verified, so stage 3 is withheld.","sourceIds":["corelight"]},"governance":{"score":null,"confidence":"low","rationale":"Claims of transparent reasoning do not establish interface authentication, differentiated role permissions or audit controls. Those procedures were not available in the reviewed product material.","sourceIds":["corelight","corelight-ds"]},"operations":{"score":2,"confidence":"medium","rationale":"The data sheet identifies concrete analyst controls: inspect and modify a generated query before execution, then pivot to raw evidence. Complete investigation-disposition and detection-adjustment procedures were not verified as a stage-3 package.","sourceIds":["corelight-ds"]}},"constraints":["Open-source Zeek alone is outside this commercial bundle and receives no inherited scoring.","Assisted triage and integrated response need explicit availability, permissions and license validation.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"corelight","title":"Corelight Investigator","url":"https://corelight.com/platform/investigator","accessedAt":"2026-09-21","kind":"product"},{"id":"corelight-ds","title":"Corelight Investigator data sheet","url":"https://corelight.com/hubfs/resources/product-data-sheets/corelight-investigator-ds.pdf","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"cisco-secure-network-analytics","cohort":"network-detection-platforms","edition":"Cisco Secure Network Analytics Manager and Flow Collector with flow licensing; optional Flow Sensor, ISE, XDR and Secure Cloud Analytics excluded unless stated as integration boundaries","asOf":"2026-09-21","status":"research-preview","summary":"A flow-oriented investigation option with explicit component and licensing boundaries. Metadata evidence is useful but does not imply retained packet contents.","dimensions":{"maturity":{"score":2.4,"confidence":"medium","rationale":"Flow collection and alerts establish stage 2. Context including devices, users and timestamps earns investigation-context credit (+0.4); concrete disposition and tuning procedures were not verified in the product/data-sheet scope.","sourceIds":["cisco-ndr","cisco-ndr-ds"],"refinement":{"base":2,"evidence":[{"criterion":"investigation-context","rationale":"The product description connects alerts with user, device, location, timestamp and application context.","sourceIds":["cisco-ndr"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Behavioral network analysis, flow context and incident investigation meet the ordinary cohort baseline. Encrypted-traffic analytics and machine-learning descriptions alone do not establish a new operator mechanism with documented controls and limits.","sourceIds":["cisco-ndr","cisco-ndr-ds"]},"breadth":{"score":3,"confidence":"medium","rationale":"The data sheet describes network investigation across on-premises and cloud environments, with physical and virtual components. Optional sensors and ISE are not included as assumed raw-packet or identity-enrichment entitlements for stage 4.","sourceIds":["cisco-ndr-ds"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"The published ISE integration describes identity/context use for segmentation policy and alerts, establishing a named data-sharing path. Full connector authentication and operational procedures were not verified for stage 4.","sourceIds":["cisco-ndr","cisco-ndr-ds"]},"governance":{"score":null,"confidence":"low","rationale":"The selected product and component sources do not establish the console authentication, differentiated role and audit procedures. The deployment’s local management model is not a substitute for governance evidence.","sourceIds":["cisco-ndr-ds"]},"operations":{"score":1,"confidence":"medium","rationale":"Public material explains components and investigation use cases but a concrete user procedure was not successfully retrieved in this review. No higher operator-documentation stage is inferred from a self-guided demo link.","sourceIds":["cisco-ndr","cisco-ndr-ds"]}},"constraints":["The component data sheet is dated January 2024 and is still linked by the current product page; exact supported versions require procurement verification.","Flow sampling, exporter coverage and retention limit investigation; encrypted metadata is not decrypted payload.","Public documentation review only; no licensed-console, efficacy, reliability or performance testing. Scores represent evidenced rubric stages, not market leadership."],"sources":[{"id":"cisco-ndr","title":"Cisco Secure Network Analytics","url":"https://www.cisco.com/site/us/en/products/security/security-analytics/secure-network-analytics/index.html","accessedAt":"2026-09-21","kind":"product"},{"id":"cisco-ndr-ds","title":"Cisco Secure Network Analytics components and licensing","url":"https://www.cisco.com/c/en/us/products/collateral/security/stealthwatch/datasheet-c78-739398.html","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"unmanaged-device","name":"Unmanaged device investigation","description":"A SOC must investigate a device without a usable endpoint agent.","priorities":["breadth","operations","ecosystem"],"questions":["Which traffic from this device is actually observed?","Can the alert be tied to retained evidence and a stable device identity?","Which separately authorized tool can contain it if needed?"]},{"id":"privacy-sensitive","name":"Privacy-sensitive network","description":"A team needs enough evidence to investigate while limiting access to sensitive traffic.","priorities":["governance","maturity","breadth"],"questions":["Which decisions need payload access rather than metadata?","Who can export packets and how is the action audited?","What do encryption and retention gaps prevent the analyst from proving?"]}],"researchNotes":["This first review is a dated baseline. Momentum begins only after a second comparable review; no trend is inferred from naming or scoring changes.","Scores reflect publicly evidenced stages, not observed efficacy, market share or maturity inferred from company age. Public documentation confidence is at most medium.","Ordinary network baselines include rules or behavioral detections, context and investigation. Additional innovation credit needs inspectable output, operator controls and explicit limits.","Equivalent scores are acceptable. Decimal credits apply shared criteria totaling ten tenths and are not graph jitter.","Zeek is an educational telemetry alternative, not a scored commercial platform. Darktrace, Fortinet and Arista remain substantive catalog profiles awaiting equivalent scoped assessments.","Some operator and audit sources could not be retrieved; unverified controls remain unknown instead of being scored as absent.","Packet- and flow-based architectures differ. A comparison must retain collection, encryption, sampling and licensing constraints."]},"changes":[]}]},"unassessed":[{"slug":"darktrace-network","name":"Darktrace / NETWORK","company":"Darktrace","profileUrl":"/landscape/vendors/darktrace-network/"},{"slug":"fortindr","name":"FortiNDR","company":"Fortinet","profileUrl":"/landscape/vendors/fortindr/"},{"slug":"arista-ndr","name":"Arista NDR","company":"Arista Networks","profileUrl":"/landscape/vendors/arista-ndr/"},{"slug":"zeek","name":"Zeek","company":"Zeek Project","profileUrl":"/landscape/vendors/zeek/"}]}