Request a demo
HomeNDR Solution
Detection & response ยท core module

Detection that starts with your network, not someone else's list.

NDR is the module every other part of the platform reports into. It learns the ordinary shape of your traffic, who talks to whom, how much, how often, at what hour, and raises a hand the moment that shape changes. No signature feed to chase, no rule set to maintain.

<7 daysTo a usable baseline
6 minMedian time to contain
0Signatures required
What it watches

Four planes of traffic, one model of normal.

East-west movement is where intrusions actually spread, and it is the plane most tools never see. NDR watches it alongside everything else.

01

East-west traffic

Lateral movement between internal hosts, the plane a perimeter firewall never inspects.

02

North-south egress

Every outbound conversation, matched against what this host has ever done before.

03

Service behaviour

Ports, protocols and payload volumes profiled per service rather than per policy.

04

Time-of-day rhythm

A backup at 02:00 is normal. The same transfer at 14:00 is a question worth asking.

How it decides

A deviation is only interesting in context.

Raw anomaly counts are noise. NDR scores each deviation against the host's own history, its peer group and the hour it happened in, then decides whether a human should ever hear about it.

  • Per-host historyEvery device carries its own record. A print server and a jump box are never judged by the same yardstick.
  • Peer comparisonHosts are grouped by observed behaviour, so one machine drifting from its cohort stands out immediately.
  • Confidence, not verdictsEach alert arrives with a score and the trace behind it, so your team can argue with the model.
Anomalies auto-triaged97%
Alerts that reach a human3%
Traces retained30 days
False-positive rate<1.4%
The loop

Five beats, every time.

The same sequence runs against live traffic that you can watch on the home page's simulated segment.

Observe

Flow records, DNS, TLS metadata and endpoint telemetry stream into the model continuously.

Compare

Each conversation is scored against this host's baseline and its behavioural peer group.

Trace

When something drifts, the full path is reconstructed, source, hops, destination, volume.

Contain

Segment isolation or session termination is proposed, and executed if you have pre-authorised it.

Report

The incident lands with a timeline, the evidence and a recommended next action.

Against the old way

Signatures versus behaviour.

Both approaches catch things. Only one of them catches what nobody has written a rule for yet.

Signature-based IDSNetworkFort NDR
Detects known malware
Detects novel lateral movement,
Needs a daily feed update,
Tuned to your own traffic,
Explains why it firedPartially
Works on encrypted traffic,, metadata only
Questions

What teams ask before they switch.

Straight answers, including the ones that make a sale harder.

Do you need to decrypt our traffic?
No. The model works on flow metadata, timing, volume, direction, certificate and DNS characteristics. Payload inspection is optional and off by default.
How long before it is useful?
Usable inside a week for most networks, sharper after a month. The first days are spent learning rather than alerting, which is deliberate.
What happens during the learning window?
You get visibility immediately and alerting once confidence passes threshold. We will tell you when, not guess.
Can it act on its own?
Only where you have pre-authorised it, per segment. Everything else is proposed and waits for a decision.
Request a live demo

Bring a real question about your network.

Thirty minutes against a live instance, your infrastructure or a mirrored sandbox, whichever you prefer.