Trellix Network Detection and Response (NDR) is a security platform allows you to continuously monitor, detect, investigate, and contain emerging threats on your devices in real time. It also provides centralized search capabilities across connected Packet Capture appliances and can detect threats using Mandiant Threat Intelligence indicators of compromise (IOCs).
Trellix NDR allows you to continuously monitor, detect, investigate, and contain emerging threats on your devices in real time.
NDR enables you to search for Layer 7 information across an enterprise and retrieve PCAP data from selected flows captured on connected Packet Capture appliances.
Some of the key capabilities of NDR are:
Extended visibility across complex network environments — Provides comprehensive visibility, high-fidelity detection, streamlined investigation and response workflows.
Multi-layered detection aligned to MITRE ATT&CK™ mapping — Behavior-based detection results map to the MITRE ATT&CK™ framework, supporting a consistent process to prioritize response.
Artificial intelligence guided investigation — Trellix NDR uses investigation guides built by combining the experience and expertise from Trellix forensic investigators with artificial intelligence (AI). These investigation guides force–multiply the investigation process and explore many hypotheses in parallel for maximum speed and accuracy. Investigation guides dynamically adjust to the case at hand, combining different strategies and data. Trellix NDR automatically asks and answers questions to prove or disprove the hypotheses. It automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves.
High-Fidelity detection — Uses advanced methods and global threat intelligence to detect all types of threats and prioritize important alerts.
Accelerates investigation and response —Streamlines incident response by correlating signals, identifying root causes, and accelerating investigations for faster containment of attacks.