<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>BIP Jacksonville &#45; NetWitness</title>
<link>https://www.bipjacksonville.com/rss/author/netwitness</link>
<description>BIP Jacksonville &#45; NetWitness</description>
<dc:language>en</dc:language>
<dc:rights>Copyright 2025 BIP Jacksonville &#45; All Rights Reserved.</dc:rights>

<item>
<title>Proactive Incident Response to reduce Attack Surface</title>
<link>https://www.bipjacksonville.com/proactive-incident-response-to-reduce-attack-surface</link>
<guid>https://www.bipjacksonville.com/proactive-incident-response-to-reduce-attack-surface</guid>
<description><![CDATA[ Proactive incident response (IR) is a strategic approach focused not only on reacting to security incidents but also on anticipating and minimizing threats before they materialize. ]]></description>
<enclosure url="https://www.bipjacksonville.com/uploads/images/202507/image_870x580_68764fa628095.jpg" length="57765" type="image/jpeg"/>
<pubDate>Wed, 16 Jul 2025 04:07:04 +0600</pubDate>
<dc:creator>NetWitness</dc:creator>
<media:keywords>incident response, incident response services, incident response tools</media:keywords>
<content:encoded><![CDATA[<p data-start="58" data-end="395">Proactive incident response (IR) is a strategic approach focused not only on reacting to security incidents but also on anticipating and minimizing threats before they materialize. One of the most effective outcomes of proactive IR is<strong> </strong>attack surface reductionlimiting the number of potential entry points a threat actor can exploit.</p>
<p data-start="58" data-end="395">Reducing the attack surface with Incident Response involves leveraging IR processes not just reactively, but proactively to identify, minimize, and eliminate potential entry points that adversaries might exploit.</p>
<p data-start="58" data-end="395"></p>
<h2 data-start="296" data-end="346"><strong>How Incident Response Reduces Attack Surface</strong></h2>
<h3 data-start="348" data-end="407">1. <strong data-start="355" data-end="407">Incident Root Cause Analysis ? Surface Reduction</strong></h3>
<ul data-start="408" data-end="794">
<li data-start="408" data-end="552">
<p data-start="410" data-end="552"><strong data-start="410" data-end="420">Action</strong>: Every security incident is analyzed to uncover the initial entry point (e.g., exposed port, unpatched service, misconfigured IAM).</p>
</li>
<li data-start="553" data-end="685">
<p data-start="555" data-end="685"><strong data-start="555" data-end="565">Impact</strong>: Once identified, <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">incident response</a> teams can recommend removing or hardening the vulnerable component, permanently reducing exposure.</p>
</li>
<li data-start="686" data-end="794">
<p data-start="688" data-end="794"><strong data-start="688" data-end="699">Example</strong>: If an attacker gained access via an outdated web app, the team may retire or isolate the app.</p>
</li>
</ul>
<h3 data-start="801" data-end="849">2. <strong data-start="808" data-end="849">Feedback Loop into Hardening Policies</strong></h3>
<ul data-start="850" data-end="1192">
<li data-start="850" data-end="998">
<p data-start="852" data-end="998"><strong data-start="852" data-end="862">Action</strong>: Lessons learned from incidents feed directly into security configuration baselines, firewall rules, access controls, and patch cycles.</p>
</li>
<li data-start="999" data-end="1066">
<p data-start="1001" data-end="1066"><strong data-start="1001" data-end="1011">Impact</strong>: Future similar attack vectors are proactively closed.</p>
</li>
<li data-start="1067" data-end="1192">
<p data-start="1069" data-end="1192"><strong data-start="1069" data-end="1080">Example</strong>: An incident involving lateral movement via SMB leads to policy changes disabling SMBv1 across the environment.</p>
</li>
</ul>
<h3 data-start="1199" data-end="1261">3. <strong data-start="1206" data-end="1261">Compromise Assessments to Identify Unknown Exposure</strong></h3>
<ul data-start="1262" data-end="1486">
<li data-start="1262" data-end="1383">
<p data-start="1264" data-end="1383"><strong data-start="1264" data-end="1274">Action</strong>: After an incident, broader compromise assessments often uncover other at-risk systems or misconfigurations.</p>
</li>
<li data-start="1384" data-end="1486">
<p data-start="1386" data-end="1486"><strong data-start="1386" data-end="1396">Impact</strong>: Those systems are patched, hardened, or segmented, further shrinking the attack surface.</p>
</li>
</ul>
<h3 data-start="1493" data-end="1545">4. <strong data-start="1500" data-end="1545">Threat Hunting Leads to Surface Discovery</strong></h3>
<ul data-start="1546" data-end="1845">
<li data-start="1546" data-end="1669">
<p data-start="1548" data-end="1669"><strong data-start="1548" data-end="1558">Action</strong>: IR teams perform threat hunting based on recent TTPs (Tactics, Techniques, and Procedures) from threat intel.</p>
</li>
<li data-start="1670" data-end="1751">
<p data-start="1672" data-end="1751"><strong data-start="1672" data-end="1682">Impact</strong>: Identifies unmonitored services, shadow IT, or weak configurations.</p>
</li>
<li data-start="1752" data-end="1845">
<p data-start="1754" data-end="1845"><strong data-start="1754" data-end="1765">Example</strong>: Discovering unauthorized RDP services on internet-facing assets during a hunt.</p>
</li>
</ul>
<h3 data-start="1852" data-end="1903">5. <strong data-start="1859" data-end="1903">Automation and Orchestration of Response</strong></h3>
<ul data-start="1904" data-end="2186">
<li data-start="1904" data-end="2032">
<p data-start="1906" data-end="2032"><strong data-start="1906" data-end="1916">Action</strong>: Use SOAR platforms to auto-contain compromised endpoints, disable accounts, or remove rogue assets upon detection.</p>
</li>
<li data-start="2033" data-end="2109">
<p data-start="2035" data-end="2109"><strong data-start="2035" data-end="2045">Impact</strong>: Minimizes dwell time and rapidly shrinks the window of attack.</p>
</li>
<li data-start="2110" data-end="2186">
<p data-start="2112" data-end="2186"><strong data-start="2112" data-end="2123">Example</strong>: Auto-isolating any endpoint that triggers a ransomware alert.</p>
</li>
</ul>
<h3 data-start="469" data-end="523">6.<strong data-start="479" data-end="523">Continuous Asset Discovery and Inventory</strong></h3>
<ul data-start="524" data-end="799">
<li data-start="524" data-end="580">
<p data-start="526" data-end="580"><strong data-start="526" data-end="533">Why</strong>: You cant protect what you dont know exists.</p>
</li>
<li data-start="581" data-end="689">
<p data-start="583" data-end="689"><strong data-start="583" data-end="593">Action</strong>: Continuously scan for new devices, applications, and services. Maintain a real-time inventory.</p>
</li>
<li data-start="690" data-end="799">
<p data-start="692" data-end="799"><strong data-start="692" data-end="701">Tools</strong>: Nmap, Shodan, CMDB integrations, cloud asset discovery tools (e.g., AWS Config, Azure Defender).</p>
</li>
</ul>
<h3 data-start="806" data-end="861">7.<strong data-start="817" data-end="861">Threat Hunting and Detection Engineering</strong></h3>
<ul data-start="862" data-end="1126">
<li data-start="862" data-end="953">
<p data-start="864" data-end="953"><strong data-start="864" data-end="871">Why</strong>: Early identification of anomalies reduces the likelihood of a full-blown attack.</p>
</li>
<li data-start="954" data-end="1045">
<p data-start="956" data-end="1045"><strong data-start="956" data-end="966">Action</strong>: Hunt for indicators of compromise (IoCs) and tweak detection rules regularly.</p>
</li>
<li data-start="1046" data-end="1126">
<p data-start="1048" data-end="1126"><strong data-start="1048" data-end="1057">Tools</strong>: NetWitness <a href="https://www.netwitness.com/services/incident-response/immediate-help/" rel="nofollow">incident response services</a>, ELK stack, Splunk, Sentinel, CrowdStrike Falcon, custom YARA rules.</p>
</li>
</ul>
<h3 data-start="1133" data-end="1181">8.<strong data-start="1143" data-end="1181">Patch and Vulnerability Management</strong></h3>
<ul data-start="1182" data-end="1423">
<li data-start="1182" data-end="1243">
<p data-start="1184" data-end="1243"><strong data-start="1184" data-end="1191">Why</strong>: Unpatched software is a top initial access vector.</p>
</li>
<li data-start="1244" data-end="1339">
<p data-start="1246" data-end="1339"><strong data-start="1246" data-end="1256">Action</strong>: Conduct regular vulnerability assessments and apply critical patches within SLAs.</p>
</li>
<li data-start="1340" data-end="1423">
<p data-start="1342" data-end="1423"><strong data-start="1342" data-end="1359">Best Practice</strong>: Automate vulnerability scans with tools like Nessus or Qualys.</p>
</li>
</ul>
<h3 data-start="1430" data-end="1481">9.<strong data-start="1440" data-end="1481">Configuration Hardening and Baselines</strong></h3>
<ul data-start="1482" data-end="1717">
<li data-start="1482" data-end="1547">
<p data-start="1484" data-end="1547"><strong data-start="1484" data-end="1491">Why</strong>: Misconfigurations are low-hanging fruit for attackers.</p>
</li>
<li data-start="1548" data-end="1656">
<p data-start="1550" data-end="1656"><strong data-start="1550" data-end="1560">Action</strong>: Use secure baselines (CIS, NIST), disable unnecessary services, enforce strong configurations.</p>
</li>
<li data-start="1657" data-end="1717">
<p data-start="1659" data-end="1717"><strong data-start="1659" data-end="1668">Tools</strong>: CIS-CAT, Microsoft Security Compliance Toolkit.</p>
</li>
</ul>
<h3 data-start="1724" data-end="1763">10. <strong data-start="1734" data-end="1763">Attack Surface Monitoring</strong></h3>
<ul data-start="1764" data-end="2034">
<li data-start="1764" data-end="1817">
<p data-start="1766" data-end="1817"><strong data-start="1766" data-end="1773">Why</strong>: Your external exposure constantly changes.</p>
</li>
<li data-start="1818" data-end="1926">
<p data-start="1820" data-end="1926"><strong data-start="1820" data-end="1830">Action</strong>: Monitor internet-facing systems for open ports, exposed services, and misconfigured endpoints.</p>
</li>
<li data-start="1927" data-end="2034">
<p data-start="1929" data-end="2034"><strong data-start="1929" data-end="1938">Tools</strong>: Attack surface management (ASM) platforms like Palo Alto Cortex Xpanse, Randori, or CyCognito.</p>
</li>
</ul>
<h3 data-start="2041" data-end="2083">11. <strong data-start="2051" data-end="2083">Red Teaming &amp; Purple Teaming</strong></h3>
<ul data-start="2084" data-end="2349">
<li data-start="2084" data-end="2136">
<p data-start="2086" data-end="2136"><strong data-start="2086" data-end="2093">Why</strong>: Simulated attacks reveal real weaknesses.</p>
</li>
<li data-start="2137" data-end="2270">
<p data-start="2139" data-end="2270"><strong data-start="2139" data-end="2149">Action</strong>: Conduct regular red team assessments and coordinate with blue teams to improve detection and response (purple teaming).</p>
</li>
<li data-start="2271" data-end="2349">
<p data-start="2273" data-end="2349"><strong data-start="2273" data-end="2284">Outcome</strong>: Identifies shadow IT, weak credentials, lateral movement paths.</p>
</li>
</ul>
<h3 data-start="2356" data-end="2405">12. <strong data-start="2366" data-end="2405">Security Metrics and Feedback Loops</strong></h3>
<ul data-start="2406" data-end="2669">
<li data-start="2406" data-end="2449">
<p data-start="2408" data-end="2449"><strong data-start="2408" data-end="2415">Why</strong>: Measure what matters to improve.</p>
</li>
<li data-start="2450" data-end="2590">
<p data-start="2452" data-end="2590"><strong data-start="2452" data-end="2462">Action</strong>: Track time to detect (TTD), time to respond (TTR), and mean time to recovery (MTTR). Use these insights to fine-tune controls.</p>
</li>
<li data-start="2591" data-end="2669">
<p data-start="2593" data-end="2669"><strong data-start="2593" data-end="2602">Cycle</strong>: <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident response tools</a> feeds vulnerability management, hardening, and policy updates.</p>
</li>
</ul>
<h3 data-start="2676" data-end="2751">13. <strong data-start="2689" data-end="2751">User Behavior Analytics (UBA) and Insider Threat Detection</strong></h3>
<ul data-start="2752" data-end="2979">
<li data-start="2752" data-end="2813">
<p data-start="2754" data-end="2813"><strong data-start="2754" data-end="2761">Why</strong>: Insiders and credential misuse are rising threats.</p>
</li>
<li data-start="2814" data-end="2904">
<p data-start="2816" data-end="2904"><strong data-start="2816" data-end="2826">Action</strong>: Monitor for abnormal user behavior, impossible logins, and privilege misuse.</p>
</li>
<li data-start="2905" data-end="2979">
<p data-start="2907" data-end="2979"><strong data-start="2907" data-end="2916">Tools</strong>: UEBA platforms like Exabeam, Microsoft Defender for Identity.</p>
</li>
</ul>
<h3 data-start="2986" data-end="3041">14. <strong data-start="2996" data-end="3041">Security Awareness and Simulated Phishing</strong></h3>
<ul data-start="3042" data-end="3243">
<li data-start="3042" data-end="3087">
<p data-start="3044" data-end="3087"><strong data-start="3044" data-end="3051">Why</strong>: Humans are often the weakest link.</p>
</li>
<li data-start="3088" data-end="3200">
<p data-start="3090" data-end="3200"><strong data-start="3090" data-end="3100">Action</strong>: Run regular training and phishing simulations. Incorporate lessons learned into your <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">incident response</a> playbooks.</p>
</li>
<li data-start="3201" data-end="3243">
<p data-start="3203" data-end="3243"><strong data-start="3203" data-end="3212">Tools</strong>: KnowBe4, Cofense, Proofpoint.</p>
</li>
</ul>
<h3 data-start="3250" data-end="3310">15.<strong data-start="3261" data-end="3310">Tabletop Exercises and IR Playbook Refinement</strong></h3>
<ul data-start="3311" data-end="3514">
<li data-start="3311" data-end="3349">
<p data-start="3313" data-end="3349"><strong data-start="3313" data-end="3320">Why</strong>: Practice ensures readiness.</p>
</li>
<li data-start="3350" data-end="3464">
<p data-start="3352" data-end="3464"><strong data-start="3352" data-end="3362">Action</strong>: Run simulated incident response scenarios to test team readiness and discover policy/technical gaps.</p>
</li>
<li data-start="3465" data-end="3514">
<p data-start="3467" data-end="3514"><strong data-start="3467" data-end="3477">Update</strong>: Refine playbooks based on outcomes.</p>
</li>
</ul>
<p></p>
<h2 data-start="3952" data-end="3973"><strong>Example Workflow</strong></h2>
<ol data-start="3975" data-end="4324">
<li data-start="3975" data-end="4067">
<p data-start="3978" data-end="4067"><strong data-start="3978" data-end="3990">Incident</strong>: Malware detected on endpoint ? entry point = phishing with malicious macro.</p>
</li>
<li data-start="4068" data-end="4125">
<p data-start="4071" data-end="4125"><strong data-start="4071" data-end="4086">IR Analysis</strong>: Macro abused Word's default settings.</p>
</li>
<li data-start="4126" data-end="4239">
<p data-start="4129" data-end="4145"><strong data-start="4129" data-end="4144">Remediation</strong>:</p>
<ul data-start="4149" data-end="4239">
<li data-start="4149" data-end="4174">
<p data-start="4151" data-end="4174">Disable macros via GPO.</p>
</li>
<li data-start="4178" data-end="4206">
<p data-start="4180" data-end="4206">Remove local admin rights.</p>
</li>
<li data-start="4210" data-end="4239">
<p data-start="4212" data-end="4239">Block relevant IOC domains.</p>
</li>
</ul>
</li>
<li data-start="4240" data-end="4324">
<p data-start="4243" data-end="4324"><strong data-start="4243" data-end="4253">Result</strong>: One phishing vector permanently removed, reducing the attack surface.</p>
</li>
</ol>
<p></p>
<h3 data-start="3521" data-end="3538"><strong>Summary</strong></h3>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="3540" data-end="4223" class="w-fit min-w-(--thread-content-width)" style="width: 101.214%;">
<thead data-start="3540" data-end="3615">
<tr data-start="3540" data-end="3615">
<th data-start="3540" data-end="3575" data-col-size="sm" style="width: 42.3022%;">Strategy</th>
<th data-start="3575" data-end="3615" data-col-size="sm" style="width: 57.8735%;">Impact on Attack Surface</th>
</tr>
</thead>
<tbody data-start="3692" data-end="4223">
<tr data-start="3692" data-end="3767">
<td data-start="3692" data-end="3727" data-col-size="sm" style="width: 42.3022%;">Asset Inventory</td>
<td data-start="3727" data-end="3767" data-col-size="sm" style="width: 57.8735%;">Identifies unknown exposure</td>
</tr>
<tr data-start="3768" data-end="3843">
<td data-start="3768" data-end="3803" data-col-size="sm" style="width: 42.3022%;">Patch Management</td>
<td data-start="3803" data-end="3843" data-col-size="sm" style="width: 57.8735%;">Closes known vulnerabilities</td>
</tr>
<tr data-start="3844" data-end="3919">
<td data-start="3844" data-end="3879" data-col-size="sm" style="width: 42.3022%;">Hardening</td>
<td data-start="3879" data-end="3919" data-col-size="sm" style="width: 57.8735%;">Reduces misconfigurations</td>
</tr>
<tr data-start="3920" data-end="3995">
<td data-start="3920" data-end="3955" data-col-size="sm" style="width: 42.3022%;">Threat Hunting</td>
<td data-start="3955" data-end="3995" data-col-size="sm" style="width: 57.8735%;">Detects and removes active threats</td>
</tr>
<tr data-start="3996" data-end="4071">
<td data-start="3996" data-end="4031" data-col-size="sm" style="width: 42.3022%;">Attack Surface Monitoring</td>
<td data-start="4031" data-end="4071" data-col-size="sm" style="width: 57.8735%;">Finds public-facing weak spots</td>
</tr>
<tr data-start="4072" data-end="4147">
<td data-start="4072" data-end="4107" data-col-size="sm" style="width: 42.3022%;">Red/Purple Teaming</td>
<td data-col-size="sm" data-start="4107" data-end="4147" style="width: 57.8735%;">Reveals real-world attack paths</td>
</tr>
<tr data-start="4148" data-end="4223">
<td data-start="4148" data-end="4183" data-col-size="sm" style="width: 42.3022%;">Security Awareness</td>
<td data-col-size="sm" data-start="4183" data-end="4223" style="width: 57.8735%;">Limits social engineering risks</td>
</tr>
</tbody>
</table>
</div>
</div>
<p></p>]]> </content:encoded>
</item>

<item>
<title>NDR for Network Security Monitoring</title>
<link>https://www.bipjacksonville.com/ndr-for-network-security-monitoring</link>
<guid>https://www.bipjacksonville.com/ndr-for-network-security-monitoring</guid>
<description><![CDATA[ Network Traffic Monitoring with NDR (Network Detection and Response) is a cybersecurity approach that leverages advanced technologies to detect, investigate, and respond to threats by analyzing network traffic patterns in real time or retrospectively. ]]></description>
<enclosure url="https://www.bipjacksonville.com/uploads/images/202507/image_870x580_68764c496d508.jpg" length="68959" type="image/jpeg"/>
<pubDate>Wed, 16 Jul 2025 03:52:23 +0600</pubDate>
<dc:creator>NetWitness</dc:creator>
<media:keywords>network detection and response, ndr, ndr solutions, ndr platform</media:keywords>
<content:encoded><![CDATA[<p data-start="262" data-end="281">Network Traffic Monitoring with NDR (Network Detection and Response) is a cybersecurity approach that leverages advanced technologies to detect, investigate, and respond to threats by analyzing network traffic patterns in real time or retrospectively.</p>
<p data-start="262" data-end="281">Network Security Monitoring (NSM) with NDR is a modern approach to defending enterprise networks. While traditional NSM focuses on collecting and analyzing security-relevant data, <a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR platforms</a> enhances it with AI-driven analytics, behavior modeling, and automated threat detectionspecifically by focusing on network traffic.</p>
<p data-start="436" data-end="593">Network Security Monitoring (NSM) is the continuous collection, analysis, and escalation of indications and warnings to detect and respond to intrusions.</p>
<p data-start="595" data-end="673"><strong data-start="595" data-end="635">NDR (<a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">Network Detection and Response</a>)</strong> is an advanced component of NSM that:</p>
<ul data-start="674" data-end="869">
<li data-start="674" data-end="756">
<p data-start="676" data-end="756">Monitors traffic across the entire network (including east-west and north-south)</p>
</li>
<li data-start="757" data-end="810">
<p data-start="759" data-end="810">Detects malicious or anomalous activity using AI/ML</p>
</li>
<li data-start="811" data-end="869">
<p data-start="813" data-end="869">Enables response via alerts, integrations, or automation</p>
</li>
</ul>
<p data-start="262" data-end="281"><strong></strong></p>
<h2 data-start="262" data-end="281"><strong>What is NDR?</strong></h2>
<p data-start="283" data-end="359"><strong data-start="283" data-end="323"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">Network Detection and Response</a> (NDR)</strong> is a security solution designed to:</p>
<ul data-start="360" data-end="499">
<li data-start="360" data-end="402">
<p data-start="362" data-end="402"><strong data-start="362" data-end="402">Monitor network traffic continuously</strong></p>
</li>
<li data-start="403" data-end="448">
<p data-start="405" data-end="448"><strong data-start="405" data-end="448">Detect suspicious behavior or anomalies</strong></p>
</li>
<li data-start="449" data-end="499">
<p data-start="451" data-end="499"><strong data-start="451" data-end="499">Provide tools for investigation and response</strong></p>
</li>
</ul>
<p data-start="501" data-end="526">It uses a combination of:</p>
<ul data-start="527" data-end="633">
<li data-start="527" data-end="557">
<p data-start="529" data-end="557">Machine learning (ML) and AI</p>
</li>
<li data-start="558" data-end="580">
<p data-start="560" data-end="580">Behavioral analytics</p>
</li>
<li data-start="581" data-end="602">
<p data-start="583" data-end="602">Threat intelligence</p>
</li>
<li data-start="603" data-end="633">
<p data-start="605" data-end="633">Deep packet inspection (DPI)</p>
</li>
</ul>
<p></p>
<h2 data-start="640" data-end="690"><strong>How NDR Enhances Network Traffic Monitoring</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="692" data-end="1023" class="w-fit min-w-(--thread-content-width)" style="width: 99.9393%;">
<thead data-start="692" data-end="735">
<tr data-start="692" data-end="735">
<th data-start="692" data-end="717" data-col-size="sm" style="width: 45.585%;">Traditional Monitoring</th>
<th data-start="717" data-end="735" data-col-size="sm" style="width: 54.3543%;">NDR Monitoring</th>
</tr>
</thead>
<tbody data-start="780" data-end="1023">
<tr data-start="780" data-end="842">
<td data-start="780" data-end="805" data-col-size="sm" style="width: 45.585%;">Rule-based alerts</td>
<td data-col-size="sm" data-start="805" data-end="842" style="width: 54.3543%;">Behavioral and ML-based detection</td>
</tr>
<tr data-start="843" data-end="909">
<td data-start="843" data-end="868" data-col-size="sm" style="width: 45.585%;">Focus on known threats</td>
<td data-col-size="sm" data-start="868" data-end="909" style="width: 54.3543%;">Identifies unknown (zero-day) threats</td>
</tr>
<tr data-start="910" data-end="968">
<td data-start="910" data-end="935" data-col-size="sm" style="width: 45.585%;">Limited context</td>
<td data-col-size="sm" data-start="935" data-end="968" style="width: 54.3543%;">Full packet and flow analysis</td>
</tr>
<tr data-start="969" data-end="1023">
<td data-start="969" data-end="994" data-col-size="sm" style="width: 45.585%;">Often signature-based</td>
<td data-col-size="sm" data-start="994" data-end="1023" style="width: 54.3543%;">Anomaly + signature-based</td>
</tr>
</tbody>
</table>
<div class="sticky end-(--thread-content-margin) h-0 self-end select-none">
<div class="absolute end-0 flex items-end"><span class="" data-state="closed"><button aria-label="Copy Table" class="hover:bg-token-bg-tertiary text-token-text-secondary my-1 rounded-sm p-1 transition-opacity group-[:not(:hover):not(:focus-within)]:pointer-events-none group-[:not(:hover):not(:focus-within)]:opacity-0"><svg width="20" height="20" viewbox="0 0 20 20" fill="currentColor" xmlns="http://www.w3.org/2000/svg" class="icon"><path d="M12.668 10.667C12.668 9.95614 12.668 9.46258 12.6367 9.0791C12.6137 8.79732 12.5758 8.60761 12.5244 8.46387L12.4688 8.33399C12.3148 8.03193 12.0803 7.77885 11.793 7.60254L11.666 7.53125C11.508 7.45087 11.2963 7.39395 10.9209 7.36328C10.5374 7.33197 10.0439 7.33203 9.33301 7.33203H6.5C5.78896 7.33203 5.29563 7.33195 4.91211 7.36328C4.63016 7.38632 4.44065 7.42413 4.29688 7.47559L4.16699 7.53125C3.86488 7.68518 3.61186 7.9196 3.43555 8.20703L3.36524 8.33399C3.28478 8.49198 3.22795 8.70352 3.19727 9.0791C3.16595 9.46259 3.16504 9.95611 3.16504 10.667V13.5C3.16504 14.211 3.16593 14.7044 3.19727 15.0879C3.22797 15.4636 3.28473 15.675 3.36524 15.833L3.43555 15.959C3.61186 16.2466 3.86474 16.4807 4.16699 16.6348L4.29688 16.6914C4.44063 16.7428 4.63025 16.7797 4.91211 16.8027C5.29563 16.8341 5.78896 16.835 6.5 16.835H9.33301C10.0439 16.835 10.5374 16.8341 10.9209 16.8027C11.2965 16.772 11.508 16.7152 11.666 16.6348L11.793 16.5645C12.0804 16.3881 12.3148 16.1351 12.4688 15.833L12.5244 15.7031C12.5759 15.5594 12.6137 15.3698 12.6367 15.0879C12.6681 14.7044 12.668 14.211 12.668 13.5V10.667ZM13.998 12.665C14.4528 12.6634 14.8011 12.6602 15.0879 12.6367C15.4635 12.606 15.675 12.5492 15.833 12.4688L15.959 12.3975C16.2466 12.2211 16.4808 11.9682 16.6348 11.666L16.6914 11.5361C16.7428 11.3924 16.7797 11.2026 16.8027 10.9209C16.8341 10.5374 16.835 10.0439 16.835 9.33301V6.5C16.835 5.78896 16.8341 5.29563 16.8027 4.91211C16.7797 4.63025 16.7428 4.44063 16.6914 4.29688L16.6348 4.16699C16.4807 3.86474 16.2466 3.61186 15.959 3.43555L15.833 3.36524C15.675 3.28473 15.4636 3.22797 15.0879 3.19727C14.7044 3.16593 14.211 3.16504 13.5 3.16504H10.667C9.9561 3.16504 9.46259 3.16595 9.0791 3.19727C8.79739 3.22028 8.6076 3.2572 8.46387 3.30859L8.33399 3.36524C8.03176 3.51923 7.77886 3.75343 7.60254 4.04102L7.53125 4.16699C7.4508 4.32498 7.39397 4.53655 7.36328 4.91211C7.33985 5.19893 7.33562 5.54719 7.33399 6.00195H9.33301C10.022 6.00195 10.5791 6.00131 11.0293 6.03809C11.4873 6.07551 11.8937 6.15471 12.2705 6.34668L12.4883 6.46875C12.984 6.7728 13.3878 7.20854 13.6533 7.72949L13.7197 7.87207C13.8642 8.20859 13.9292 8.56974 13.9619 8.9707C13.9987 9.42092 13.998 9.97799 13.998 10.667V12.665ZM18.165 9.33301C18.165 10.022 18.1657 10.5791 18.1289 11.0293C18.0961 11.4302 18.0311 11.7914 17.8867 12.1279L17.8203 12.2705C17.5549 12.7914 17.1509 13.2272 16.6553 13.5313L16.4365 13.6533C16.0599 13.8452 15.6541 13.9245 15.1963 13.9619C14.8593 13.9895 14.4624 13.9935 13.9951 13.9951C13.9935 14.4624 13.9895 14.8593 13.9619 15.1963C13.9292 15.597 13.864 15.9576 13.7197 16.2939L13.6533 16.4365C13.3878 16.9576 12.9841 17.3941 12.4883 17.6982L12.2705 17.8203C11.8937 18.0123 11.4873 18.0915 11.0293 18.1289C10.5791 18.1657 10.022 18.165 9.33301 18.165H6.5C5.81091 18.165 5.25395 18.1657 4.80371 18.1289C4.40306 18.0962 4.04235 18.031 3.70606 17.8867L3.56348 17.8203C3.04244 17.5548 2.60585 17.151 2.30176 16.6553L2.17969 16.4365C1.98788 16.0599 1.90851 15.6541 1.87109 15.1963C1.83431 14.746 1.83496 14.1891 1.83496 13.5V10.667C1.83496 9.978 1.83432 9.42091 1.87109 8.9707C1.90851 8.5127 1.98772 8.10625 2.17969 7.72949L2.30176 7.51172C2.60586 7.0159 3.04236 6.6122 3.56348 6.34668L3.70606 6.28027C4.04237 6.136 4.40303 6.07083 4.80371 6.03809C5.14051 6.01057 5.53708 6.00551 6.00391 6.00391C6.00551 5.53708 6.01057 5.14051 6.03809 4.80371C6.0755 4.34588 6.15483 3.94012 6.34668 3.56348L6.46875 3.34473C6.77282 2.84912 7.20856 2.44514 7.72949 2.17969L7.87207 2.11328C8.20855 1.96886 8.56979 1.90385 8.9707 1.87109C9.42091 1.83432 9.978 1.83496 10.667 1.83496H13.5C14.1891 1.83496 14.746 1.83431 15.1963 1.87109C15.6541 1.90851 16.0599 1.98788 16.4365 2.17969L16.6553 2.30176C17.151 2.60585 17.5548 3.04244 17.8203 3.56348L17.8867 3.70606C18.031 4.04235 18.0962 4.40306 18.1289 4.80371C18.1657 5.25395 18.165 5.81091 18.165 6.5V9.33301Z"></path></svg></button></span></div>
</div>
NDR inspects east-west (internal) and north-south (external) traffic to detect lateral movement, command-and-control (C2) activity, data exfiltration, and more.</div>
</div>
<p></p>
<h2 data-start="876" data-end="912"><strong>Key Components of NSM with NDR</strong></h2>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="914" data-end="1490" class="w-fit min-w-(--thread-content-width)" style="width: 99.9393%;">
<thead data-start="914" data-end="954">
<tr data-start="914" data-end="954">
<th data-start="914" data-end="939" data-col-size="sm" style="width: 30.8142%;">Component</th>
<th data-start="939" data-end="954" data-col-size="md" style="width: 69.3073%;">Description</th>
</tr>
</thead>
<tbody data-start="996" data-end="1490">
<tr data-start="996" data-end="1072">
<td data-start="996" data-end="1021" data-col-size="sm" style="width: 30.8142%;"><strong data-start="998" data-end="1016">Sensors/Probes</strong></td>
<td data-col-size="md" data-start="1021" data-end="1072" style="width: 69.3073%;">Deployed at strategic points to capture traffic</td>
</tr>
<tr data-start="1073" data-end="1144">
<td data-start="1073" data-end="1098" data-col-size="sm" style="width: 30.8142%;"><strong data-start="1075" data-end="1094">Data Collection</strong></td>
<td data-col-size="md" data-start="1098" data-end="1144" style="width: 69.3073%;">Full packets, flows (NetFlow, IPFIX), logs</td>
</tr>
<tr data-start="1145" data-end="1228">
<td data-start="1145" data-end="1172" data-col-size="sm" style="width: 30.8142%;"><strong data-start="1147" data-end="1171">Behavioral Analytics</strong></td>
<td data-col-size="md" data-start="1172" data-end="1228" style="width: 69.3073%;">ML/AI-based profiling of normal vs abnormal behavior</td>
</tr>
<tr data-start="1229" data-end="1331">
<td data-start="1229" data-end="1254" data-col-size="sm" style="width: 30.8142%;"><strong data-start="1231" data-end="1251">Threat Detection</strong></td>
<td data-col-size="md" data-start="1254" data-end="1331" style="width: 69.3073%;">Real-time alerts based on patterns, heuristics, signatures, and anomalies</td>
</tr>
<tr data-start="1332" data-end="1406">
<td data-start="1332" data-end="1359" data-col-size="sm" style="width: 30.8142%;"><strong data-start="1334" data-end="1358">Response Integration</strong></td>
<td data-col-size="md" data-start="1359" data-end="1406" style="width: 69.3073%;">Export alerts to SIEM, SOAR, EDR for action</td>
</tr>
<tr data-start="1407" data-end="1490">
<td data-start="1407" data-end="1432" data-col-size="sm" style="width: 30.8142%;"><strong data-start="1409" data-end="1427">Threat Hunting</strong></td>
<td data-col-size="md" data-start="1432" data-end="1490" style="width: 69.3073%;">Analyst-led investigations based on enriched telemetry</td>
</tr>
</tbody>
</table>
</div>
</div>
<p></p>
<h2 data-start="1200" data-end="1248"><strong>Key Features of NDR in Network Monitoring</strong></h2>
<ol data-start="1250" data-end="2000">
<li data-start="1250" data-end="1347">
<p data-start="1253" data-end="1284"><strong data-start="1253" data-end="1284">Full Packet Capture (PCAP):</strong></p>
<ul data-start="1288" data-end="1347">
<li data-start="1288" data-end="1347">
<p data-start="1290" data-end="1347">Collects and stores raw network data for deep inspection.</p>
</li>
</ul>
</li>
<li data-start="1349" data-end="1454">
<p data-start="1352" data-end="1392"><strong data-start="1352" data-end="1392">Flow Analysis (NetFlow/IPFIX/sFlow):</strong></p>
<ul data-start="1396" data-end="1454">
<li data-start="1396" data-end="1454">
<p data-start="1398" data-end="1454">Captures metadata for performance and behavioral trends.</p>
</li>
</ul>
</li>
<li data-start="1456" data-end="1565">
<p data-start="1459" data-end="1490"><strong data-start="1459" data-end="1490">Encrypted Traffic Analysis:</strong></p>
<ul data-start="1494" data-end="1565">
<li data-start="1494" data-end="1565">
<p data-start="1496" data-end="1565">Uses metadata and ML to analyze encrypted traffic without decryption.</p>
</li>
</ul>
</li>
<li data-start="1567" data-end="1687">
<p data-start="1570" data-end="1606"><strong data-start="1570" data-end="1606">Threat Intelligence Integration:</strong></p>
<ul data-start="1610" data-end="1687">
<li data-start="1610" data-end="1687">
<p data-start="1612" data-end="1687">Enriches detection capabilities with known IOCs (Indicators of Compromise).</p>
</li>
</ul>
</li>
<li data-start="1689" data-end="1778">
<p data-start="1692" data-end="1723"><strong data-start="1692" data-end="1723">Automated Threat Detection:</strong></p>
<ul data-start="1727" data-end="1778">
<li data-start="1727" data-end="1778">
<p data-start="1729" data-end="1778">Identifies patterns of known and unknown attacks.</p>
</li>
</ul>
</li>
<li data-start="1780" data-end="1875">
<p data-start="1783" data-end="1809"><strong data-start="1783" data-end="1809">Forensic Capabilities:</strong></p>
<ul data-start="1813" data-end="1875">
<li data-start="1813" data-end="1875">
<p data-start="1815" data-end="1875">Enables in-depth investigation of historical network events.</p>
</li>
</ul>
</li>
<li data-start="1877" data-end="2000">
<p data-start="1880" data-end="1908"><strong data-start="1880" data-end="1908">Incident Response Tools:</strong></p>
<ul data-start="1912" data-end="2000">
<li data-start="1912" data-end="2000">
<p data-start="1914" data-end="2000"><a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident response tools</a> supports alert triage, mitigation, and integrations with SIEM, SOAR, or EDR platforms.</p>
</li>
</ul>
</li>
</ol>
<p></p>
<h2 data-start="2007" data-end="2030"><strong>Common NDR Use Cases</strong></h2>
<ul data-start="2032" data-end="2227">
<li data-start="2032" data-end="2068">
<p data-start="2034" data-end="2068">Detecting ransomware communication</p>
</li>
<li data-start="2069" data-end="2098">
<p data-start="2071" data-end="2098">Identifying insider threats</p>
</li>
<li data-start="2099" data-end="2132">
<p data-start="2101" data-end="2132">Spotting unusual data transfers</p>
</li>
<li data-start="2133" data-end="2181">
<p data-start="2135" data-end="2181">Monitoring lateral movement within the network</p>
</li>
<li data-start="2182" data-end="2227">
<p data-start="2184" data-end="2227">Analyzing command-and-control (C2) channels</p>
</li>
</ul>
<p></p>
<h2 data-start="2687" data-end="2701"><strong>Benefits of Using NDR</strong></h2>
<ul data-start="2703" data-end="2885">
<li data-start="2703" data-end="2746">
<p data-start="2705" data-end="2746"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR</a> improved visibility into network activity</p>
</li>
<li data-start="2747" data-end="2789">
<p data-start="2749" data-end="2789">Early detection of sophisticated threats</p>
</li>
<li data-start="2790" data-end="2810">
<p data-start="2792" data-end="2810">Reduced dwell time</p>
</li>
<li data-start="2811" data-end="2848">
<p data-start="2813" data-end="2848">Complementary to SIEM, IDS, and EDR</p>
</li>
<li data-start="2849" data-end="2885">
<p data-start="2851" data-end="2885">Cloud, hybrid, and on-prem support</p>
</li>
<li data-start="2971" data-end="3023">
<p data-start="2973" data-end="3023">Real-time visibility across all network layers</p>
</li>
<li data-start="3024" data-end="3078">
<p data-start="3026" data-end="3078">Faster detection of unknown and advanced threats</p>
</li>
<li data-start="3079" data-end="3134">
<p data-start="3081" data-end="3134">Improved triage and context for <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">incident response</a></p>
</li>
<li data-start="3135" data-end="3190">
<p data-start="3137" data-end="3190">Forensic capability through packet/flow retention</p>
</li>
<li data-start="3191" data-end="3252">
<p data-start="3193" data-end="3252">Cloud, on-prem, hybrid support for modern architectures</p>
</li>
</ul>
<p></p>
<h2 data-start="2892" data-end="2909"><strong>Common Challenges of Using NDR</strong></h2>
<ul data-start="2911" data-end="3061">
<li data-start="2911" data-end="2947">
<p data-start="2913" data-end="2947">High data volume and storage needs</p>
</li>
<li data-start="2948" data-end="2978">
<p data-start="2950" data-end="2978">False positives if not tuned</p>
</li>
<li data-start="2979" data-end="3025">
<p data-start="2981" data-end="3025">Requires skilled analysts for threat hunting</p>
</li>
<li data-start="3026" data-end="3061">
<p data-start="3028" data-end="3061">Cost and complexity of deployment</p>
</li>
</ul>
<p></p>
<h2 data-start="4567" data-end="4602"><strong>Best Practices for Deployment</strong></h2>
<ul data-start="4604" data-end="4920">
<li data-start="4604" data-end="4668">
<p data-start="4606" data-end="4668">Start with visibility mapping: where are your blind spots?</p>
</li>
<li data-start="4669" data-end="4742">
<p data-start="4671" data-end="4742">Deploy <a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR platform</a>at internal pivot points, not just the perimeter</p>
</li>
<li data-start="4743" data-end="4800">
<p data-start="4745" data-end="4800">Use baselining and tuning to reduce false positives</p>
</li>
<li data-start="4801" data-end="4863">
<p data-start="4803" data-end="4863">Integrate with SIEM/SOAR to unify detection and response</p>
</li>
<li data-start="4864" data-end="4920">
<p data-start="4866" data-end="4920">Conduct regular threat hunting using NDR telemetry</p>
</li>
</ul>
<p></p>
<h2 data-start="3068" data-end="3095"><strong>Leading NDR Vendors</strong></h2>
<ul data-start="3097" data-end="3205">
<li data-start="3097" data-end="3112">
<p data-start="3099" data-end="3112">Darktrace</p>
</li>
<li data-start="3113" data-end="3128">
<p data-start="3115" data-end="3128">Vectra AI</p>
</li>
<li data-start="3129" data-end="3143">
<p data-start="3131" data-end="3143">ExtraHop</p>
</li>
<li data-start="3144" data-end="3168">
<p data-start="3146" data-end="3168">Cisco Stealthwatch</p>
</li>
<li data-start="3169" data-end="3184">
<p data-start="3171" data-end="3184">Corelight</p>
</li>
<li data-start="3185" data-end="3205">
<p data-start="3187" data-end="3205">NetWitness <a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR Solutions</a></p>
</li>
</ul>
<p></p>]]> </content:encoded>
</item>

</channel>
</rss>