Trellix Network Detection and Response (NDR) is a security platform allows you to continuously monitor, detect, investigate, and contain emerging threats on your devices in real time. It also provides centralized search capabilities across connected Packet Capture appliances and can detect threats using Mandiant Threat Intelligence indicators of compromise (IOCs).
Trellix NDR allows you to continuously monitor, detect, investigate, and contain emerging threats on your devices in real time.
NDR enables you to search for Layer 7 information across an enterprise and retrieve PCAP data from selected flows captured on connected Packet Capture appliances.
Some of the key capabilities of NDR are:
Extended visibility across complex network environments — Provides comprehensive visibility, high-fidelity detection, streamlined investigation and response workflows.
Multi-layered detection aligned to MITRE ATT&CK™ mapping — Behavior-based detection results map to the MITRE ATT&CK™ framework, supporting a consistent process to prioritize response.
Artificial intelligence guided investigation — Trellix NDR uses investigation guides built by combining the experience and expertise from Trellix forensic investigators with artificial intelligence (AI). These investigation guides force–multiply the investigation process and explore many hypotheses in parallel for maximum speed and accuracy. Investigation guides dynamically adjust to the case at hand, combining different strategies and data. Trellix NDR automatically asks and answers questions to prove or disprove the hypotheses. It automatically gathers, summarizes, and visualizes evidence from multiple sources and iterates as the investigation evolves.
High-Fidelity detection — Uses advanced methods and global threat intelligence to detect all types of threats and prioritize important alerts.
Accelerates investigation and response —Streamlines incident response by correlating signals, identifying root causes, and accelerating investigations for faster containment of attacks.
Key features
NDR key features focus on enhancing the analyst experience, improving visibility, and expanding detection and integration capabilities:
Enhanced Alert Analysis: Improved workflows with new alert and user views, synchronized filtering across dashboards, and enhanced analyst springboards for prioritized threat investigation. Features risk-based severity scoring with MITRE, Tenable, and ePO integration, plus customizable severity badges.
Improved Asset display: A new Assets List view with persistent filters, CSV download, and integration with ePO and Tenable for enriched asset data. The Asset Details view now includes dedicated panels for events, alerts, and conversation graphs.
Comprehensive Integrations: A new Integration Hub manages enhanced SIEM (Splunk), Tenable Security Center, and on-premises ePO integrations.
Attack Path Discovery: Provides detailed insights into attack paths for specific assets (Enterprise License only).
Selective Packet Capture: Enables capturing network traffic around suspicious assets for closer investigations.
Expanded Threat Detection: New capabilities include detecting communication with malicious domains, DNS/ICMP tunneling, phishing, SSL anomalies, Tor activity, and suspicious URLs.
AI-Powered Alert Investigation: Integrates with Trellix WISE (GenAI) for conversational AI-assisted alert investigations, reducing false positives.
GTI Integration: Queries Global Threat Intelligence (GTI) for URL reputation to enhance detection capabilities.
DNS Tunneling Detection: CLI-configurable DNS tunneling exploit detection to monitor for malicious DNS activity.
Product Editions: Now available in Essentials, Core, and Enterprise editions.