It commonly uses packet data, flow records, protocol metadata, traffic patterns, or a combination of these sources.
NDR can reveal activity across systems that do not support endpoint agents, making it useful in data centers, cloud networks, and operational technology environments. It can also help analysts follow lateral movement or command-and-control traffic, provided sensors are positioned where the relevant communications are visible.
Its limits are structural: pervasive encryption hides payload content and forces reliance on metadata, timing, and destination reputation; cloud and software-defined networking can move traffic past fixed sensors; and behavioral baselines need time to learn what “normal” means in each environment — and will flag the unusual-but-legitimate alongside the malicious.
Key points
Primary purposeDetect and investigate malicious or anomalous activity from network evidence.
Typical methodsProtocol analysis, behavioral baselining, signatures, threat-intelligence matching, and traffic correlation.
Design dependencySensor placement, network topology, east–west visibility, time synchronization, and retained evidence materially affect results.
Important limitationEncryption, asymmetric routing, cloud architecture, high traffic volume, and activity confined to a host can reduce visibility.