NDR · network detection and response

Network detection (NDR)
without a SPAN port

Aegis NDR needs no SPAN port, TAP or traffic mirroring. An agent on each node watches outbound connections and detects C2 channels, data exfiltration and suspicious DNS directly at the source — where the attack actually happens.

No traffic rerouting Visibility both in the cloud and on VMs Connection tied to a process and user
What Aegis NDR does

The network gives an attack away — before it reaches your data

A compromised system almost always has to call out somewhere: to pull a tool, check in with a command server or exfiltrate data. Aegis NDR puts exactly that outbound traffic under watch.

Outbound connections

Every outbound connection under watch — with the process and user that opened it, not just an IP and port.

C2 detection

Recognition of command-and-control channels toward known and reputationally suspicious destinations.

Exfiltration

Unusual data-egress patterns — large or periodic transfers to the outside.

Suspicious DNS

DNS tunneling and algorithmically generated domains (DGA) as an early signal of compromise.

Connection per process

A connection tied to a specific process and user — the investigation starts with context, not a bare IP.

Auto-block and geo

A risky destination is blocked at the firewall; geo rules stop traffic toward undesirable regions.

Differentiator

Why agent-based rather than a SPAN port

Classic NDR requires you to mirror network traffic to a probe (SPAN/TAP). That means hardware, configuration on every switch and blind spots wherever there is no physical network — in the cloud, for example. Aegis observes traffic from an agent on the host.

CRITERIONAegis NDR (agent)Classic NDR (SPAN / TAP probe)
Network hardware required✓ Not requiredSPAN port, TAP, probe
Visibility in the cloud and on VMs✓ Yes, the agent runs everywhereDifficult — no physical port
Encrypted trafficSees the destination, process and intentSees only flow metadata
Attribution to process and user✓ Which application opened the connection✗ Only IP and port
DeploymentAgent installation, minutesA network project, days
Aegis NDR focuses on outbound connections, DNS queries and their attribution to a process and user. For full-packet capture of an entire segment, a dedicated probe still makes sense — the two techniques complement each other, and the agent removes the biggest blind spot: traffic that never passes through your measurement port.
HOW IT WORKS

From connection to block

1
The agent records the connectionEvery outbound connection and DNS query is tied to the process that initiated it and to the user in whose context it runs.
2
Threat enrichmentThe destination IP and domain are checked against threat intelligence (reputation, known C2, DGA patterns).
3
Correlation in the SIEMThe suspicious connection is joined with other events from the host into a single incident, with a MITRE ATT&CK label.
4
ResponseA risky destination can be blocked at the firewall (auto-block), and the host isolated or flagged for investigation.
Aggregate metrics illustration

The measure of network visibility

6,7M
process events
280.000+
automatic blocks
98.000+
TI indicators
13.000+
detection rules

Aggregated, anonymised and illustratively rounded production metrics from the Aegis network.

Basics

What NDR is and why outbound traffic matters

NDR (Network Detection and Response) is a discipline that detects attacks by observing network traffic, not just application logs. The idea is simple: an attacker may bypass defenses at one layer, but can hardly hide communication with the outside world.

North-south and east-west

Traffic entering and leaving the organization is called north-south, while traffic between internal systems east-west. The Aegis agent sees both sides from each host's perspective, so an attacker's lateral movement isn't hidden behind a single network hop.

Why the outbound connection matters so much

Almost every serious attack opens an outbound connection at some point — a command & control channel, downloading a second-stage tool or data exfiltration. Monitoring outbound connections therefore catches the attack even when the initial entry slipped through.

NDR works best paired with SIEM correlation i WAF protection: the WAF guards the entrance to web applications, SIEM joins events together, and NDR covers what goes out.

Frequently asked questions

NDR — frequently asked questions

Does Aegis NDR need a SPAN port or TAP? +
No. Aegis NDR runs via an agent on each node and observes outbound connections and DNS directly on the host, so no SPAN port, TAP or rerouting of network traffic is required.
Does it work in the cloud and on VMs? +
Yes. Because it is agent-based, it works the same in your data center, on virtual machines and in the public cloud, where classic network probes often have no access to the traffic.
Does NDR see which application opened the connection? +
Yes. Every connection is attributed to a process and user, which speeds up the investigation because you immediately know which application communicated and with whom.
Does NDR replace a firewall? +
No. A firewall sets rules, while NDR detects suspicious behavior within permitted traffic and can trigger an auto-block. They complement each other.
RELATED

Keep exploring the platform

Find out what your network is actually sending out

A demo on your traffic shows outbound connections, suspicious domains and the processes that open them — without deploying a SPAN port.

Odgovaramo isti radni dan · info@aegis.hr