December 1, 2024

This November brings each the second anniversary and 1,000 buyer milestone for Sophos Network Detection and Response (NDR). Such phenomenal progress in two quick years displays the ability of Sophos NDR in addition to rising consciousness of the significance of community detection and response within the safety stack.

Adversaries go to nice lengths to keep away from being detected earlier than they will full their assault. However nonetheless good they’re at hiding their tracks, they all the time must cross the community. The excellent news is that with Sophos NDR adversaries merely can’t conceal – there isn’t a spot that the answer can’t shine a lightweight on.

Sophos NDR sits deep on the community, monitoring all community visitors from managed and unmanaged gadgets and detecting suspicious actions which will in any other case go unnoticed till it’s too late. In depth response capabilities allow analysts – each within the Sophos MDR crew and the in-house analysts of our clients and companions – to shortly examine and neutralize threats.

Watch this quick video to see Sophos NDR in motion stopping a Cobalt Strike assault.

Combining AI and 5 real-time detection engines

Sophos NDR frequently displays your community visitors, utilizing 5 real-time menace detection engines to determine indicators of malicious or suspicious exercise. Leveraging a mix of AI-powered machine studying, superior analytics, and rule-based matching strategies, it identifies threats that usually go undetected till it’s too late, together with:

  • Threats on unprotected gadgets like point-of-sale methods, IoT and OT gadgets, and legacy working methods
  • Rogue belongings that adversaries exploit to launch assaults
  • Insider threats similar to delicate knowledge uploads to an offsite location
  • Zero-day assaults, and extra

Plus, when mixed with different safety telemetry, Sophos NDR permits menace analysts to color a extra full, correct image of the whole assault path and development, enabling a quicker, extra complete response.

Dive deep with the highly effective Investigation Console

The Sophos NDR Investigation Console deploys on the native community, offering wealthy evaluation instruments to speed up the identification of potential points and threats, together with the timing of occasions, the variety of occurrences, their severity, and their geo places. It additionally permits evaluation of utility visitors to determine undesirable or suspicious utility exercise and potential knowledge loss incidents, in addition to evaluation of dangerous session knowledge to make sure the community is working effectively and securely.

Acknowledged as a Main Participant

Sophos is acknowledged as a Main Participant within the IDC MarketScape: Worldwide Community Detection and Response 2024 Vendor Evaluation (November 2024, IDC #US51752324). The IDC MarketScape famous that “a strong function that companies profit from when working inside a Sophos devoted ecosystem is Lively Menace Response.” The report additionally famous that “pricing is aggressive for midsize firms.”

Versatile deployment, most influence

Sophos NDR deploys as a digital equipment on VMware or Microsoft Hyper-V, within the cloud on AWS, or on a spread of licensed {hardware} home equipment.

Licensing relies on the variety of customers and servers on the community. There are not any restrictions or extra prices to deploy a number of NDR sensors and a single sensor can help as much as 40Gbps of community visitors.

Sophos NDR is obtainable with each our managed detection and response service, Sophos MDR, and our self-managed Sophos XDR resolution. Whether or not you need to conduct community detection and response your self or have our crew do it for you, Sophos NDR may help.

Get began as we speak

To be taught extra about Sophos NDR, visit our website or communicate to your Sophos accomplice or consultant. Present Sophos clients can even activate a free 30-day trial straight inside their Sophos Central console.