The job to be done
Reconstruct a suspicious network sequence and connect it to the systems, identities and actions that need investigation.
Network detection and response examines traffic or network metadata to identify suspicious behavior and support investigation. It helps when a device lacks an endpoint agent or an analyst needs to follow communications between systems. Its usefulness depends on collection: an unmirrored segment, sampled flow or encrypted payload changes what can be established. Compare products against an explicit evidence question, such as whether an unmanaged host communicated with an unexpected service, and test how that observation reaches an authorized response.
What goes in
- Packets, flow records and supported cloud network logs
- Sensor placement and network topology
- Asset and identity enrichment
What should come out
- Network detections and investigation context
- Communication timelines and retained evidence
- Scoped response requests to connected controls
Inside the segment
These capabilities answer different questions. Use the distinction to define the work before assembling a shortlist.
Packet-derived detection
Analyze observed network traffic and protocol behavior for investigation.
Boundary: Mirror coverage, encryption, packet loss and storage affect which evidence is available.
Flow-based detection
Use connection metadata to investigate communication patterns across networks.
Boundary: Flows describe communication; they do not automatically preserve payloads or application commands.
Investigation and response
Correlate observations, preserve context and hand off an approved containment action.
Boundary: An external EDR, firewall or identity tool may perform the actual enforcement.
Open-source telemetry
Build evidence pipelines and learn protocol analysis using tools such as Zeek.
Boundary: A telemetry engine is not comparable to a fully operated commercial NDR platform.
How the work flows
Define the question
Choose a realistic scenario and list the network facts needed to distinguish benign from suspicious activity.
Validate collection
Record observed segments, exporter settings, mirror capacity, encryption limits and retention.
Investigate the evidence
Connect the detection to time, device identity, flows, records or packets. Mark uncertain attribution.
Tune deliberately
Use narrow, reviewed exceptions for known activity and retain visibility of evidence needed later.
Verify the handoff
Test the case export or approved response in a lab, including permissions, auditability and reversal.
The environment changes the question
Use these scenarios to adapt the evaluation to your organization. They describe operational concerns, not a determination of compliance.
Finance ↗
A workstation makes a new connection to a payment-administration subnet after an approved software rollout.
Evaluate: Reconcile network timing with identity and change records before authorizing a block.
Utilities ↗
An unmanaged device appears at the IT/OT boundary and exchanges traffic with a historian.
Evaluate: Identify the process owner and involve OT specialists before testing containment.
Manufacturing ↗
A contractor laptop communicates with several internal servers during a maintenance visit.
Evaluate: Distinguish the authorized maintenance workflow from unexplained lateral movement.
Healthcare ↗
A shared clinical device contacts an unfamiliar external service.
Evaluate: Protect patient operations and avoid copying sensitive packet content into general training material.
What drives the operating cost
- Monitored bandwidth, flow rate, sensor count and cloud traffic-mirroring charges.
- Record and packet retention, storage tiers, search capacity and optional analysis modules.
- Collection engineering, tuning, integration maintenance and any separately contracted managed service.
Questions worth asking
- Which network paths and encrypted sessions remain observable?
- Can analysts move from an alert to the underlying evidence?
- Who approves response actions and how are they reversed?
Common assumptions to check
Encrypted-traffic analysis reveals every encrypted payload.
Behavior and metadata may remain useful while message contents stay unavailable. Inspect the actual decryption and collection prerequisites.
An NDR alert automatically blocks the attacker.
Detection and enforcement are different steps; response may require another product, permission and an approved action.
A quiet dashboard proves the network is clean.
Missing telemetry, narrow coverage or tuning can also produce silence. Validate visibility before interpreting the lack of detections.
APPLY THE IDEA / EVALUATION PLAN
Make the outcome observable.
Generate a benign beacon-like sequence between lab hosts, inspect the resulting network evidence, and document what the sensor cannot determine.
Measure collection gaps
A coverage diagram and sample observations showing what each sensor or exporter can and cannot see.
Reproduce an investigation
A harmless lab sequence traced from collection to alert, supporting evidence and analyst disposition.
Test a controlled handoff
A case or response request preserving identity and timestamps, with documented approval and reversal.
Use synthetic data and an authorized test environment. Record scope, product edition, permissions, results, and recovery behavior.
Vendors & products
8 profilesAn editorial selection of relevant offerings, with documented scope and practical evaluation questions. Atlas Fold provides a separate provisional documentation assessment for selected offerings; inclusion in this directory is not a ranking.
Vectra AI / Commercial network detection and investigation
Vectra AI Platform (Network)
The scored scope is Network detections in Respond UX with the documented network investigation workflow. Identity and cloud-log detection surfaces, Match, Stream, extended search and staffed MDR require an explicit entitlement check; do not assume the whole platform is one license.
ExtraHop / Commercial network detection and investigation
RevealX NDR
This profile evaluates the NDR workflow with an explicitly configured sensor and evidence-storage design. RevealX 360 and Enterprise differ in management; IDS, packet forensics and performance monitoring are separate modules or components that need license verification.
Corelight / Commercial network detection and investigation
Open NDR with Investigator
The evaluated bundle is Corelight network sensors plus Investigator, not the open-source Zeek engine alone. Sensor type, collection licenses, retention, assisted-triage availability and downstream response integrations must be itemized.
Darktrace / Commercial network detection and response
Darktrace / NETWORK
Scope Network separately from email, cloud and other Darktrace products. Detection, autonomous response, retention and integration entitlements should be confirmed for the selected deployment; a behavioral alert alone does not authorize disruption.
Cisco / Commercial flow-based network detection
Cisco Secure Network Analytics
This is Secure Network Analytics, formerly Stealthwatch Enterprise. Evaluate Manager, Flow Collector, flow licensing and any Data Store or optional Flow Sensor explicitly. Secure Cloud Analytics and Cisco XDR are separate scope decisions.
Fortinet / Commercial network detection and response
FortiNDR
FortiNDR on-premises and FortiNDR Cloud have different architectures and capabilities. Compare the quoted deployment, retention and analysis functions directly; FortiGate, FortiEDR, FortiSOAR and other response products are not implied entitlements.
Arista Networks / Commercial network detection and investigation
Arista NDR
Evaluate the NDR platform and required collection components. Campus Edition, managed services and DANZ packet-observability infrastructure have distinct scope. Existing switching equipment does not establish that every necessary telemetry path is available.
Zeek Project / Open-source network telemetry engine
Zeek
Zeek alone is not a staffed service or a complete commercial NDR console. Operators supply deployment, storage, search, detection content, access controls and case handling. Corelight’s commercial products are separate from the open-source project.