Precursor Security
Comparison

NDR vs EDR

Watching the network versus watching the endpoint.

EDR (endpoint detection and response) monitors activity on endpoints such as laptops and servers via an agent. NDR (network detection and response) monitors network traffic to detect threats, including on devices that cannot run an agent. EDR sees what happens on a device; NDR sees what moves between them. They cover complementary blind spots.

The short answer

EDR (endpoint detection and response) monitors activity on endpoints such as laptops and servers via an agent. NDR (network detection and response) monitors network traffic to detect threats, including on devices that cannot run an agent. EDR sees what happens on a device; NDR sees what moves between them. They cover complementary blind spots.

NDR

NDR monitors network traffic, analysing patterns and metadata with behavioural analytics to detect threats such as lateral movement, command and control and data exfiltration, including on devices that cannot run an endpoint agent.

  • Sees traffic between all devices
  • Covers unmanaged, IoT and legacy devices
  • Strong at detecting lateral movement
  • Often works from metadata where traffic is encrypted
Full definition of NDR
EDR

EDR runs an agent on each endpoint, recording detailed activity and enabling detection, investigation and response on the device itself, with deep visibility that the network view cannot provide.

  • Deep visibility into each managed endpoint
  • Behavioural detection on the device
  • Response actions such as endpoint isolation
  • Blind to devices that cannot run an agent
Full definition of EDR

Key differences

Where NDR and EDR diverge, at a glance.

NDREDR
Vantage pointThe networkThe endpoint
CoversAny device that communicatesDevices running an agent
Best atMovement between systemsActivity on a system
Blind spotsWhat happens on a deviceAgentless devices
ResponseAlerting and network contextDirect action on the device

When to choose which

Choose NDR when

NDR is valuable in environments full of devices that cannot run an agent, such as operational technology, IoT and legacy systems, and for catching lateral movement between machines.

Choose EDR when

EDR is the foundation for deep visibility and response on managed endpoints, where most attacks ultimately land and act.

How they work together

NDR and EDR cover each other’s blind spots: the endpoint agent misses devices it cannot run on, and the network view misses what happens inside a device. Correlating both, alongside identity signals, is the premise of extended detection and response and of a well-run security operations centre, which treats network and endpoint as parts of one picture rather than separate feeds.

A worked example: the device with no agent

An attacker who has compromised a laptop moves laterally to an unmanaged device, an old server or an Internet of Things device that cannot run an endpoint agent, and uses it as a quiet base to explore the network. EDR is blind here, because there is no agent on that device to record what it does.

NDR sees the movement anyway, because the traffic between the laptop and the unmanaged device crosses the network, where NDR is watching. It flags the unusual internal connection and the subsequent scanning activity, giving defenders a chance to catch an attacker who has deliberately chosen a device the endpoint tools cannot see. This is the core reason the two are complementary: each covers the other’s blind spot.

Where each has blind spots, and the road to XDR

EDR cannot see devices that will not run an agent, and it can miss lateral movement to those devices. NDR cannot see what happens inside a device once traffic reaches it, such as a local process or file change. Neither is complete alone, which is why serious detection programmes run both.

Correlating network and endpoint signals, ideally alongside identity, is the premise of extended detection and response. When a network anomaly from NDR is combined with the endpoint context from EDR and an identity signal, an attack that each tool would see only partially becomes a clear, connected picture. This correlation is where much of the value of a modern detection stack lies.

Which products, and how they are operated

EDR is well established, with products from CrowdStrike, SentinelOne, Microsoft and others. NDR is a distinct category, with vendors focused on network traffic analysis. Increasingly, both feed into XDR platforms or a SIEM that correlates their signals, rather than being watched in isolation.

As with all detection technology, NDR and EDR produce alerts that need continuous human investigation. Many organisations access both, correlated and operated together, through a managed detection and response service, so that lateral movement and command and control across managed and unmanaged devices are caught and acted upon rather than generating alerts no one reviews.

Related definitions

Not sure which you need?

The right detection stack depends on your environment, your team and your risk. Precursor operates managed detection and response from a CREST-accredited security operations centre, so you get the outcome rather than another tool to run.

NDR vs EDR, answered

Common questions about how NDR and EDR differ and relate.

Neither is better; they watch different things. EDR gives deep visibility into managed endpoints, while NDR sees traffic between all devices, including unmanaged ones. They cover complementary blind spots, which is why mature detection uses both.

EDR cannot see devices that will not run an agent, such as IoT, operational technology and some legacy systems, and it can miss lateral movement to those devices. NDR fills that gap by watching the network itself, so the two together give far broader coverage.

Their signals are most powerful when correlated. A network anomaly gains meaning when combined with what is happening on the hosts involved, which is the idea behind extended detection and response and behind a security operations centre that treats network, endpoint and identity as one picture.

Neither is better; they watch different things. EDR gives deep visibility into managed endpoints, while NDR sees traffic between all devices, including unmanaged ones. They cover complementary blind spots, which is why mature detection uses both rather than choosing one.

EDR cannot see devices that will not run an agent, such as IoT, operational technology and some legacy systems, and it can miss lateral movement to those devices. NDR fills that gap by watching the network itself, so the two together give far broader coverage than either alone.

EDR detects and responds on endpoints. NDR does the same from network traffic. XDR correlates detection across several layers including endpoint and network. MDR is a managed service that operates these technologies on your behalf, so a provider’s analysts watch and respond around the clock.

No. NDR sees traffic between devices but not what happens inside a device, while EDR sees deep endpoint activity but not agentless devices. They cover different blind spots, so NDR complements EDR rather than replacing it, and strong detection programmes run both.