QRadar NDR
- Home
- QRadar NDR
Why NDR is so important
Networks are the foundation of today’s connected world, making them a prime target of cyber attackers looking to cause disruption and a key source of data for threat detection and analysis. IBM Security® QRadar® Network Detection and Response (NDR) helps your security teams by analyzing network activity in real time. It combines depth and breadth of visibility with high-quality data and analytics to fuel actionable insights and response.
How it's Used
Detect Lateral Movement
Gain visibility into unusual activity
Given the high volume of data traveling across your network, it’s easy for threats to go unnoticed. Detect reconnaissance, pivoting and transfers between devices — which are indicative of malicious lateral movement — in real time.
Stop Data Exfiltration
Reduce dwell time with quick detection
Discover Compromised Devices
Automatically update assets to stay ahead of attackers
Preform Threat Hunting
Shift from reactive to proactive
Benefits
Features
Threats hide within the volume of normal traffic on your network. Get a broad network view across a wide range of network devices.
Analyze and correlate network data in real time. Network insights provides for session reconstruction, full packet capture, extraction of key metadata, and application analysis.
Detect slight changes in user or system behavior that might have gone unnoticed by baselining for normal network activity, scouting for anomalies, and identifying suspicious behavior.
Get insights into your local DNS traffic by identifying malicious activity and enabling your security team to detect Domain Generated Algorithm (DGA), Tunneling, or Squatting domains that are being accessed from within your network.
Retrace the step-by-step actions of cyber criminals by rebuilding data and retracing actions. Captures, reconstructs, and replays the entire event chain.
Delivers an optional appliance to store and manage data used by QRadar Incident Forensics when no other network packet capture (Network PCAP) device is deployed.