Logpoint NDR

Logpoint NDR (Network Detection and Response) analyzes network traffic and behavioral patterns to identify anomalies and detect and respond to potential threats in real time. Logpoint NDR provides detailed analysis of notifications, also known as detections, network traffic, assets, topology, statistics, metadata, and raw network packet data.

How Logpoint NDR Works

1

Monitors Network Traffic

Once you deploy Logpoint NDR on a network, it starts to monitor its traffic. It captures network packets and extracts related metadata. A packet is a small unit of data, and metadata is the descriptive information about the raw data within the packet, including IP addresses, timestamps, and packet size.

2

Learns Normal Network Behavior

Logpoint NDR uses machine learning and threat intelligence to learn normal network behavior.

3

Detects Anomalies

If an event does not match normal network behavior, it analyzes whether it resembles a known security threat.

4

Sends a Notification

Logpoint NDR notifies you of detected threats.

Notifications include key information to investigate a potential threat, such as source and destination IP addresses, severity level, affected assets, timestamps, and relevant metadata. You can further explore these notifications in great detail by leveraging both the metadata and raw data that Logpoint NDR stores and provides, and by using its search functionality to conduct threat hunting, forensic investigation, and other relevant activities.

Logpoint NDR contains two components:

  1. AI Detect

    Logpoint NDR AI Detect is a product module that provides organizations with visibility into attack indicators and network anomalies, leveraging machine learning and network behavior analysis. Logpoint NDR AI Detect also provides organizations with visibility into the usage of insecure or unsanctioned applications and protocols, including weak encryption.

  2. AI Prevent

    Logpoint NDR AI Prevent enables organizations to go beyond detecting potential security risks and threats. With Logpoint NDR AI Prevent, customers can automatically respond to risks and threats. When an activity is identified as malicious, Logpoint NDR can, in real time, natively act or orchestrate the response actions across other platforms (depending on configured integrations), like containment of a rogue or compromised endpoint or by blocking specific IOCs at the perimeter firewall, thus mitigating or preventing potential security risks from further escalation.

circle-info

This product includes GeoLite2 data created by MaxMindarrow-up-right. The world map is powered by Leafletarrow-up-right.

Last updated

Was this helpful?