Network Detection and Response 4.1.0 Release Notes

Prev Next

Note: For essential security configurations and best practices for deploying NDR, see article 000015495.

New Features

This section describes new features in NDR Console 4.1.x release.

  • Trellix Hyperautomation

    NDR Console integrates with Trellix Hyperautomation to streamline incident response and automate manual security tasks. Trellix Hyperautomation orchestrates security workflows. It lets you automate, schedule, or manually run response actions for NDR alerts.

  • Nozomi Guardian integration

    NDR Console now integrates with Nozomi Guardian to enhance your ability to monitor and protect Operational Technology (OT) and Industrial Control Systems (ICSs) environments. This integration allows NDR Console to receive security alerts generated by Nozomi Guardian and visualize your OT and IoT assets.

  • Amazon S3 Integration (VPC Flow Logs)

    AWS is configured to deliver VPC Flow Logs to an Amazon S3 bucket. The S3 bucket is set up with event notifications that send new log-object events to a configured Amazon SQS queue. A Lambda function is deployed to read messages from the SQS queue, retrieve the corresponding log objects from S3, and ingest the Flow-Log data into NDR Console.

  • Enable Direct Pivot from SIEM to NDR Console

    Enables seamless pivoting directly from SIEM alert back into the NDR Console. This allows system administrators to quickly transition from high-level SIEM monitoring to detailed, original detection data.

  • Full support for IPv6 environments

    NDR Console introduces full support for IPv6 environments, ensuring comprehensive network detection and response capabilities for all supported features. This support allows the NDR Console to function effectively using IPv6 addresses.

    Note: The following specific features and integrations do not currently support IPv6 addresses.

    • TLC integration

    • Hyperautomation

    • VPC Flow Logs

  • Detailed Alert Descriptions and guided Next Steps

    The Alert Details page has been significantly enhanced to provide rich context and step-by-step guidance for each alert, enabling users to quickly assess threats and take effective actions to investigate or remediate issues.

  • Policy violation alert suppression for Trellix IPS devices

    Enables administrators to manage alert noise by suppressing policy violation alerts generated by Trellix IPS Sensors. This helps to focus on high-priority alerts and enables a decision on whether the NDR Console should suppress or retain alerts based on the criticality of the target asset.

  • Anomaly detection

    Provides specialized detection capabilities for identifying DNS anomalies and attacks, which are subtle and advanced threats often missed by traditional signature-based systems.

    • Shared Plugin Docker

      • ICMP Tunnel Plugin – Detects covert ICMP tunneling patterns.

      • NRD Plugin – Identifies newly registered domains often used in malicious campaigns.

      • SSL Anomalies Plugin – Flags suspicious SSL behaviors associated with DNS misuse.

      • TOR Plugin – Detects DNS traffic indicative of TOR network usage.

      • Phishing Exfiltration Plugin – Identifies DNS-based data exfiltration attempts.

      • DNS Hijacking Detection – Alerts on unauthorized modification of DNS resolution paths.

      • DNS Poisoning Detection – Detects cache poisoning attempts and manipulated DNS responses.

      • DNS Rebinding Detection – Identifies attacks leveraging DNS rebinding techniques.

      • DNS Fast Flux Detection – Flags flux-based evasion techniques used by botnets.

      • DCSync - Detection of DCSync attacks targeting Active Directory.

      • DCShadow - Detection of DCShadow attacks manipulating Active Directory replication.

    • DNST Container: Includes the DNS tunneling plugin for advanced identification of tunneling behaviors used for covert communication or data leakage.

    • DGA Container: Incorporates the DGA plugin to detect Domain Generation Algorithm–based command-and-control domains used by modern malware.

    • NeURL Images Integration: Includes the NeURL plugin, extending anomaly detection through neural-based analysis of DNS traffic patterns.

  • MITRE ATT&CK Matrix Filter for Enterprise and IoT/ICS

    The NDR Console now provides MITRE ATT&CK data for both Enterprise and IoT/ICS assets, showing tactics, techniques, and sub-techniques across these environments. This feature gives comprehensive visibility into threats targeting enterprise networks and operational technology (OT), helping users identify and respond to relevant alerts more effectively.

    Use the Matrix filter to view alert counts by Enterprise, IoT/ICS, or a combined matrix.

  • Support on Microsoft Hyper-V

    Expands deployment flexibility and ensures the NDR Console can be deployed seamlessly into Hyper-V based infrastructures.

Enhancements

  • The Alert Status filter has been enhanced. The “Suppress” option has been moved from Alert Status filter to Type filter. This update streamlines the filtering experience and ensures only active, user-actionable alert states are displayed.

  • Alerts generated by DGA and DNS Tunneling will now be categorized as anomalies.

  • Improved Attack Path Discovery (APD) for risk exposure capability that gives customers a proactive view of how attackers may move inside customers' environments.

Known Issues

The following issues are known in the NDR Console 4.1.0 release.

Tracking number

Summary

NETFIM-7829

NDR Console is unable to establish connections with Trellix WISE and Trellix GTI in network environments that requires the use of an explicit proxy server for external traffic.

NETFIM-7826, NDR-1749

A failure in the database cleanup and purging mechanism caused the PostgreSQL partition (/data/ia/db) to run out of disk space. The resulting database process failure cascaded, leading to the shutdown of several dependent services.

NDR-2384

The process for handling CVE data has been simplified and enhanced in this release. The system now retrieves the complete list of relevant CVEs, automatically sorts them by severity or risk score, and displays the top five most critical CVEs.

NDR-2170

The automatic resizing functionality for the conversation map within the Asset Details view has been resolved.

NDR-2091

The Follow Stream function from initiating session reconstruction when triggered from the Alert List page has been resolved.

NDR-1742

The epo-configure command has been updated to prevent the administrative password from being displayed in plain text upon execution.

NDR-1696

The /var partition is running out of disk space, leading to the shutdown of multiple critical processes.

NETFIM-7039

The Network Anomalies chart does not display the hostname. The Hosts page displays both the IP address and hostname for the same host.

NETFIM-6808

Session reconstruction of NX events does not work in a certain scenario.

Workaround:

When PX release 6.1.x connected to NDR Console release 2.2.0 is upgraded, remove PX from metadata menu and add it back for session reconstruction of NX events to work (when using the client group workflow).

NETFIM-5968

Lists, saved queries, and scheduled searches are not shown in the UI after the cluster name is changed.

NETFIM-5488

DTI proxy authorization types "ntlm" and "none" are not supported.

NETFIM-5427

On virtual NDR Console appliances, the show nxstatus command only outputs metadata received from a paired Network Security Series appliance within the last 60 minutes.

NETFIM-5181

In a virtual NDR Console primary-secondary set up in ESXi, the cluster health may fail if the gateway recovery count is not set correctly. The Gateway Recovery Count must be set to the total number of non-director instances in the cluster. For example, if there are 2 instances in a cluster, the gateway recovery count must be set to 2. Use the show cluster command in KLISH to determine the number of instances in a cluster, and ignore any director node included in the show cluster output.

NETFIM-4932

Restarting a virtual NDR Console environment set up in AWS may cause the instance's IP address to change, which may cause the NDR Console-PX or NDR Console-Director connection to fail.

NETFIM-4712

If a virtual NDR Console OVA is deployed with only one hard disk as data storage, Elasticsearch may fail at startup.

NDR-3060

The DCRPC protocol is currently missing from the supported protocol list within the Packet Capture (PX) metadata export configuration.

NDR-3000

Attempting to download an alert list as a CSV file from the UI, the exported file contains only the alerts displayed on the first page of the results, rather than displaying the complete, unfiltered list of alerts.

NDR-2922

Disk mirroring is failing

NDR-2879

Discrepancy has been observed in the total number of events or alerts reported for the same asset when comparing different pages within the UI.

NDR-2816

Clicking a severity segment (Critical, Major, or Low) within the alert visualization pie chart on a dashboard breaks the layout of the resulting Alert List Page.

NDR-2798

An hyperlink on the Alert Details page added to map to multiple MITRE TTPs does not function correctly when clicked.

NDR-2788

The Source IP and Destination IP columns on the Alert List pageare  truncated incase of IPv6 addresses.

NDR-2191

All Critical-severity alerts generated in an integrated Nozomi system are incorrectly displayed with a Medium severity classification on the Alert List page.

NDR-2257

The NDR Console reports an inflated asset count compared to the actual deployed asset inventory.

Additional Information

Upgrade support

Note: Configure DNS server before you upgrade the NDR Console appliance.

You can upgrade your NDR Console appliance to release 4.1.0 from release 4.0.0. For upgrade instructions, see NDR Console Product Guide.

Product compatibility

This release supports Packet Capture Series versions 6.2 and later.