Detection that starts with your network, not someone else's list.
NDR is the module every other part of the platform reports into. It learns the ordinary shape of your traffic, who talks to whom, how much, how often, at what hour, and raises a hand the moment that shape changes. No signature feed to chase, no rule set to maintain.
Four planes of traffic, one model of normal.
East-west movement is where intrusions actually spread, and it is the plane most tools never see. NDR watches it alongside everything else.
East-west traffic
Lateral movement between internal hosts, the plane a perimeter firewall never inspects.
North-south egress
Every outbound conversation, matched against what this host has ever done before.
Service behaviour
Ports, protocols and payload volumes profiled per service rather than per policy.
Time-of-day rhythm
A backup at 02:00 is normal. The same transfer at 14:00 is a question worth asking.
A deviation is only interesting in context.
Raw anomaly counts are noise. NDR scores each deviation against the host's own history, its peer group and the hour it happened in, then decides whether a human should ever hear about it.
- Per-host historyEvery device carries its own record. A print server and a jump box are never judged by the same yardstick.
- Peer comparisonHosts are grouped by observed behaviour, so one machine drifting from its cohort stands out immediately.
- Confidence, not verdictsEach alert arrives with a score and the trace behind it, so your team can argue with the model.
Five beats, every time.
The same sequence runs against live traffic that you can watch on the home page's simulated segment.
Observe
Flow records, DNS, TLS metadata and endpoint telemetry stream into the model continuously.
Compare
Each conversation is scored against this host's baseline and its behavioural peer group.
Trace
When something drifts, the full path is reconstructed, source, hops, destination, volume.
Contain
Segment isolation or session termination is proposed, and executed if you have pre-authorised it.
Report
The incident lands with a timeline, the evidence and a recommended next action.
Signatures versus behaviour.
Both approaches catch things. Only one of them catches what nobody has written a rule for yet.
| Signature-based IDS | NetworkFort NDR | |
|---|---|---|
| Detects known malware | ✓ | ✓ |
| Detects novel lateral movement | , | ✓ |
| Needs a daily feed update | ✓ | , |
| Tuned to your own traffic | , | ✓ |
| Explains why it fired | Partially | ✓ |
| Works on encrypted traffic | , | ✓, metadata only |
What teams ask before they switch.
Straight answers, including the ones that make a sale harder.
Do you need to decrypt our traffic?
How long before it is useful?
What happens during the learning window?
Can it act on its own?
Bring a real question about your network.
Thirty minutes against a live instance, your infrastructure or a mirrored sandbox, whichever you prefer.