Network Detection and Response (NDR) is a security approach that analyzes actual network traffic to detect suspicious activity — including attacks that log-based systems miss.
In detail
Unlike tools that rely on logs from connected systems, NDR observes the communication itself: which systems talk to which, what volumes and destinations are normal, and what deviates. It combines behavioral analysis with threat intelligence to surface lateral movement, command-and-control traffic, and unusual data flows.
NDR doesn't depend on every system being correctly logged, which is why it catches activity other layers don't.
AEGYS Pulse is a passive NDR solution — analyzed where you choose.
Related terms
Last updated: 5 June 2026 · 4 min read
