Note: For essential security configurations and best practices for deploying NDR, see article 000015495.
New Features
This section describes new features in NDR Console 4.1.x release.
Trellix Hyperautomation
NDR Console integrates with Trellix Hyperautomation to streamline incident response and automate manual security tasks. Trellix Hyperautomation orchestrates security workflows. It lets you automate, schedule, or manually run response actions for NDR alerts.
Nozomi Guardian integration
NDR Console now integrates with Nozomi Guardian to enhance your ability to monitor and protect Operational Technology (OT) and Industrial Control Systems (ICSs) environments. This integration allows NDR Console to receive security alerts generated by Nozomi Guardian and visualize your OT and IoT assets.
Amazon S3 Integration (VPC Flow Logs)
AWS is configured to deliver VPC Flow Logs to an Amazon S3 bucket. The S3 bucket is set up with event notifications that send new log-object events to a configured Amazon SQS queue. A Lambda function is deployed to read messages from the SQS queue, retrieve the corresponding log objects from S3, and ingest the Flow-Log data into NDR Console.
Enable Direct Pivot from SIEM to NDR Console
Enables seamless pivoting directly from SIEM alert back into the NDR Console. This allows system administrators to quickly transition from high-level SIEM monitoring to detailed, original detection data.
Full support for IPv6 environments
NDR Console introduces full support for IPv6 environments, ensuring comprehensive network detection and response capabilities for all supported features. This support allows the NDR Console to function effectively using IPv6 addresses.
Note: The following specific features and integrations do not currently support IPv6 addresses.
TLC integration
Hyperautomation
VPC Flow Logs
Detailed Alert Descriptions and guided Next Steps
The Alert Details page has been significantly enhanced to provide rich context and step-by-step guidance for each alert, enabling users to quickly assess threats and take effective actions to investigate or remediate issues.
Policy violation alert suppression for Trellix IPS devices
Enables administrators to manage alert noise by suppressing policy violation alerts generated by Trellix IPS Sensors. This helps to focus on high-priority alerts and enables a decision on whether the NDR Console should suppress or retain alerts based on the criticality of the target asset.
Anomaly detection
Provides specialized detection capabilities for identifying DNS anomalies and attacks, which are subtle and advanced threats often missed by traditional signature-based systems.
Shared Plugin Docker
ICMP Tunnel Plugin – Detects covert ICMP tunneling patterns.
NRD Plugin – Identifies newly registered domains often used in malicious campaigns.
SSL Anomalies Plugin – Flags suspicious SSL behaviors associated with DNS misuse.
TOR Plugin – Detects DNS traffic indicative of TOR network usage.
Phishing Exfiltration Plugin – Identifies DNS-based data exfiltration attempts.
DNS Hijacking Detection – Alerts on unauthorized modification of DNS resolution paths.
DNS Poisoning Detection – Detects cache poisoning attempts and manipulated DNS responses.
DNS Rebinding Detection – Identifies attacks leveraging DNS rebinding techniques.
DNS Fast Flux Detection – Flags flux-based evasion techniques used by botnets.
DCSync - Detection of DCSync attacks targeting Active Directory.
DCShadow - Detection of DCShadow attacks manipulating Active Directory replication.
DNST Container: Includes the DNS tunneling plugin for advanced identification of tunneling behaviors used for covert communication or data leakage.
DGA Container: Incorporates the DGA plugin to detect Domain Generation Algorithm–based command-and-control domains used by modern malware.
NeURL Images Integration: Includes the NeURL plugin, extending anomaly detection through neural-based analysis of DNS traffic patterns.
MITRE ATT&CK Matrix Filter for Enterprise and IoT/ICS
The NDR Console now provides MITRE ATT&CK data for both Enterprise and IoT/ICS assets, showing tactics, techniques, and sub-techniques across these environments. This feature gives comprehensive visibility into threats targeting enterprise networks and operational technology (OT), helping users identify and respond to relevant alerts more effectively.
Use the Matrix filter to view alert counts by Enterprise, IoT/ICS, or a combined matrix.
Support on Microsoft Hyper-V
Expands deployment flexibility and ensures the NDR Console can be deployed seamlessly into Hyper-V based infrastructures.
Enhancements
The Alert Status filter has been enhanced. The “Suppress” option has been moved from Alert Status filter to Type filter. This update streamlines the filtering experience and ensures only active, user-actionable alert states are displayed.
Alerts generated by DGA and DNS Tunneling will now be categorized as anomalies.
Improved Attack Path Discovery (APD) for risk exposure capability that gives customers a proactive view of how attackers may move inside customers' environments.
Known Issues
The following issues are known in the NDR Console 4.1.0 release.
Tracking number | Summary |
|---|---|
NETFIM-7829 | NDR Console is unable to establish connections with Trellix WISE and Trellix GTI in network environments that requires the use of an explicit proxy server for external traffic. |
NETFIM-7826, NDR-1749 | A failure in the database cleanup and purging mechanism caused the PostgreSQL partition ( |
NDR-2384 | The process for handling CVE data has been simplified and enhanced in this release. The system now retrieves the complete list of relevant CVEs, automatically sorts them by severity or risk score, and displays the top five most critical CVEs. |
NDR-2170 | The automatic resizing functionality for the conversation map within the Asset Details view has been resolved. |
NDR-2091 | The Follow Stream function from initiating session reconstruction when triggered from the Alert List page has been resolved. |
NDR-1742 | The |
NDR-1696 | The |
NETFIM-7039 | The Network Anomalies chart does not display the hostname. The Hosts page displays both the IP address and hostname for the same host. |
NETFIM-6808 | Session reconstruction of NX events does not work in a certain scenario. Workaround: When PX release 6.1.x connected to NDR Console release 2.2.0 is upgraded, remove PX from metadata menu and add it back for session reconstruction of NX events to work (when using the client group workflow). |
NETFIM-5968 | Lists, saved queries, and scheduled searches are not shown in the UI after the cluster name is changed. |
NETFIM-5488 | DTI proxy authorization types "ntlm" and "none" are not supported. |
NETFIM-5427 | On virtual NDR Console appliances, the |
NETFIM-5181 | In a virtual NDR Console primary-secondary set up in ESXi, the cluster health may fail if the gateway recovery count is not set correctly. The Gateway Recovery Count must be set to the total number of non-director instances in the cluster. For example, if there are 2 instances in a cluster, the gateway recovery count must be set to 2. Use the show cluster command in KLISH to determine the number of instances in a cluster, and ignore any director node included in the |
NETFIM-4932 | Restarting a virtual NDR Console environment set up in AWS may cause the instance's IP address to change, which may cause the NDR Console-PX or NDR Console-Director connection to fail. |
NETFIM-4712 | If a virtual NDR Console OVA is deployed with only one hard disk as data storage, Elasticsearch may fail at startup. |
NDR-3060 | The DCRPC protocol is currently missing from the supported protocol list within the Packet Capture (PX) metadata export configuration. |
NDR-3000 | Attempting to download an alert list as a CSV file from the UI, the exported file contains only the alerts displayed on the first page of the results, rather than displaying the complete, unfiltered list of alerts. |
NDR-2922 | Disk mirroring is failing |
NDR-2879 | Discrepancy has been observed in the total number of events or alerts reported for the same asset when comparing different pages within the UI. |
NDR-2816 | Clicking a severity segment (Critical, Major, or Low) within the alert visualization pie chart on a dashboard breaks the layout of the resulting Alert List Page. |
NDR-2798 | An hyperlink on the Alert Details page added to map to multiple MITRE TTPs does not function correctly when clicked. |
NDR-2788 | The Source IP and Destination IP columns on the Alert List pageare truncated incase of IPv6 addresses. |
NDR-2191 | All Critical-severity alerts generated in an integrated Nozomi system are incorrectly displayed with a Medium severity classification on the Alert List page. |
NDR-2257 | The NDR Console reports an inflated asset count compared to the actual deployed asset inventory. |
Additional Information
Upgrade support
Note: Configure DNS server before you upgrade the NDR Console appliance.
You can upgrade your NDR Console appliance to release 4.1.0 from release 4.0.0. For upgrade instructions, see NDR Console Product Guide.
Product compatibility
This release supports Packet Capture Series versions 6.2 and later.