What you are evaluating
Evaluate the NDR platform and required collection components. Campus Edition, managed services and DANZ packet-observability infrastructure have distinct scope. Existing switching equipment does not establish that every necessary telemetry path is available.
A useful evaluation context
SOCs studying entity relationships and behavioral investigations across a network.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- EntityIQ models devices, users, applications and their relationships.
- AVA supports investigation by correlating network observations.
- Adversarial modeling describes related behaviors across time, protocols and entities.
Where it fits in the work
- Verify entity attribution against known lab devices and network translations.
- Inspect a related-behavior story and follow it back to the underlying observations.
- Export a case summary with the uncertainty around any inferred relationship.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
Two lab devices share an egress address. Examine a supplied relationship graph and decide which observations can confidently be attributed to each device.
Evidence to look for
Document the distinguishing evidence and remaining ambiguity. Avoid turning a shared IP address into an unsupported user-identity claim.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which collection components are required for the proposed deployment?
- How does attribution handle shared addresses, proxies and changing device identities?
- Which features differ in Campus Edition or a managed-service package?
Names you may encounter: Awake Security. Historical names do not establish current availability or feature equivalence.