NDR
Network Detection and Response
NDR platforms analyze raw network traffic to detect threats that bypass endpoint and perimeter defenses. They use behavioral analytics and machine learning to identify anomalous communication patterns.
Cómo se usa en ciberseguridad
SOC analysts use NDR to detect lateral movement, command-and-control callbacks, and data exfiltration on the wire. Incident responders rely on NDR packet metadata to reconstruct attack timelines and understand attacker behavior. Threat hunters query NDR data to find covert channels and encrypted tunnels used by advanced adversaries.
Término relacionado en el glosario: network detection and response
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.