NDR Network Detection & Response
Behavioral monitoring of network traffic via passive sensors. Catches lateral movement, C2 channels and unmanaged device behavior that endpoint tools cannot see.
NDR watches traffic rather than hosts. Sensors collect from a network TAP or SPAN port on premises and from flow logs in cloud environments, which means nothing is installed on the machines being observed. The system learns what normal conversation looks like for each segment, then flags the deviations: a workstation that suddenly speaks to a domain controller it has never contacted, a server reaching outbound on a schedule no human would keep, a burst of internal scanning.
Its value is the coverage gap it fills. Endpoint tooling can only report on devices that can run an agent, and a real network is full of devices that cannot: printers, IP cameras, building controllers, medical and industrial equipment, guest laptops, personal phones and anything shipped by a vendor as a sealed appliance. Those devices are frequently the softest target and the quietest foothold, and to an endpoint product they simply do not exist.
Encryption is less of an obstacle than people expect, because NDR reads metadata rather than payload. Connection timing, packet sizing, destination reputation, certificate details and TLS handshake fingerprints are all visible without decrypting anything, and beaconing to a command-and-control server has a rhythm that survives encryption. Vijilan folds network detections into the same investigation queue as endpoint and identity signals through Managed NDR.
Common questions
What does NDR stand for?
NDR stands for Network Detection and Response. It is a security capability that monitors network traffic for malicious behavior, using passive sensors rather than software installed on individual devices, and supports investigation and response when something is found.
What is the difference between NDR and EDR?
EDR runs as an agent on a host and sees that host in detail: processes, files, registry and memory. NDR watches traffic between hosts and sees relationships and movement. EDR gives depth on managed machines, NDR gives breadth across everything on the wire including devices that can never run an agent. They answer different questions and mature programmes run both.
Can NDR detect threats in encrypted traffic?
Yes, without decrypting it. Encryption hides the contents of a connection but not its shape. Who is talking to whom, how often, in what volume, with what certificate and what TLS fingerprint are all still observable, and command-and-control beaconing has a regularity that content encryption does not conceal.
NDR is one signal.
We watch the rest.
Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.