NDR (Network Detection and Response)
Network detection and response (NDR) is a security technology that monitors network traffic to detect suspicious activity, lateral movement and threats that endpoint tools may miss. NDR analyses traffic patterns and metadata using behavioural analytics, providing visibility into activity across the network, including devices that cannot run an endpoint agent.
Network detection and response is a category of technology that watches the traffic flowing across an organisation’s network to identify threats. Rather than sitting on individual devices, NDR observes communications between them, analysing traffic patterns, connection metadata and, where possible, content to spot activity that indicates an intrusion, such as command and control, data exfiltration or lateral movement between systems.
NDR fills a gap left by endpoint tools. Not every device on a network can run an endpoint agent: unmanaged devices, Internet of Things and operational technology, printers, and legacy systems often cannot. Attackers know this and use such devices as footholds. Because NDR sees the network itself, it provides visibility into the behaviour of every device that communicates, agent or not, and it can observe the lateral movement between machines that an endpoint-only view might miss.
Modern NDR relies heavily on behavioural analytics rather than signatures alone. It builds a baseline of what normal traffic looks like for an environment and flags deviations, such as an internal host suddenly scanning others, an unusual volume of data leaving the network, or communication with known-malicious infrastructure. Because so much traffic is now encrypted, NDR often works from metadata and traffic patterns rather than inspecting content, using the shape of communications to infer intent.
NDR is particularly valuable for detecting the middle stages of an attack. Once an attacker has an initial foothold, they typically move laterally, escalate privilege and locate data, all of which generate network activity. An endpoint tool might miss movement to a device it does not cover, but the network traffic between machines is visible to NDR, making it a strong complement to endpoint and identity detection.
Like other detection technologies, NDR produces signals that require human investigation and response, and it is most effective when its output is correlated with endpoint and identity telemetry rather than viewed alone. That correlation is the core idea behind extended detection and response and behind a well-run security operations centre, which treats network, endpoint and identity as parts of one picture.
NDR is particularly valuable in environments full of devices that cannot run an endpoint agent, such as operational technology, Internet of Things devices and legacy systems, which attackers often target precisely because they are poorly monitored. Because the network sees the traffic between machines regardless of what runs on them, NDR provides visibility into exactly the movement and communication that an endpoint-only view would miss, which is why it complements rather than duplicates endpoint detection.
Network detection is most powerful when its signals are correlated with endpoint and identity telemetry rather than viewed in isolation, because a single network anomaly gains meaning when combined with what is happening on the hosts involved. This correlation across sources is the premise of extended detection and response and of a well-run security operations centre, which treats network, endpoint and identity as parts of one picture rather than separate feeds.
Precursor incorporates network visibility alongside endpoint and identity signals in its managed SOC, so lateral movement and command and control that an endpoint-only view would miss are caught and investigated by analysts.