# Best Network Detection and Response (NDR) Software - Page 5

## How Many Network Detection and Response (NDR) Software Products Does G2 Track?

**Total Products under this Category:** 70

### Category Stats (Aug 2026)

- **Average Rating:** 4.39/5 The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** BluSapphire OnePlatform (+0.96%) - Among all products in this category, BluSapphire OnePlatform recorded the largest rating increase compared to last month

_Last updated: August 05, 2026_

## How Does G2 Rank Network Detection and Response (NDR) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 1,600+ Authentic Reviews
- 70+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

## G2 Grid® for Network Detection and Response (NDR) Software
 ![G2 Grid® for Network Detection and Response (NDR) Software plotting products by satisfaction and market presence](https://www.g2.com/categories/network-detection-and-response-ndr/grids.png?focus%5B%5D=19387&focus%5B%5D=1405921&focus%5B%5D=130021&focus%5B%5D=27617&focus%5B%5D=129114&focus%5B%5D=1293&focus%5B%5D=5691&focus%5B%5D=30501)

Highlighted products: Progress WhatsUp Gold, Sophos NDR, TrendAI Vision One, Cortex XDR, Darktrace / NETWORK, ExtraHop, ManageEngine ADAudit Plus, and Rapid7 Next-Gen SIEM.

Underlying data: [Grid® JSON](https://www.g2.com/categories/network-detection-and-response-ndr/grids.json?focus%5B%5D=progress-whatsup-gold&focus%5B%5D=sophos-ndr&focus%5B%5D=trendai-vision-one&focus%5B%5D=palo-alto-networks-cortex-xdr&focus%5B%5D=darktrace-network&focus%5B%5D=extrahop&focus%5B%5D=manageengine-adaudit-plus&focus%5B%5D=rapid7-next-gen-siem)

**Sponsored**

### ManageEngine ADAudit Plus

ADAudit Plus is a UBA-driven auditor that helps keep your AD, Azure AD, file systems (including Windows, NetApp, EMC, Synology, Hitachi, and Huawei), Windows servers, and workstations secure and compliant. ADAudit Plus transforms raw and noisy event log data into real-time reports and alerts, enabling you to get full visibility into activities happening across your Windows Server ecosystem in just a few clicks. More than 10,000 organizations across the world trust ADAudit Plus to: 1. Instantly notify them about changes in their Windows Server environments. 2. Continuously track Windows user logon activity. 3. Monitor the active and idle time spent by employees at their workstations. 4. Detect and troubleshoot AD account lockouts. 5. Provide a consolidated audit trail of privileged user activities across their domains. 6. Track changes and sign-ins in Azure AD. 7. Audit file accesses across Windows, NetApp, EMC, Synology, Hitachi, and Huawei file systems. 8. Monitor file integrity across local files residing on Windows systems. 9. Mitigate insider threats by leveraging UBA and response automation. 10. Generate audit-ready compliance reports for SOX, the GDPR, and other IT mandates.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=2380&secure%5Bchosen_at%5D=2026-08-07T13%3A30%3A24Z&secure%5Bdisplayable_resource_id%5D=2380&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=page_category&secure%5Bplacement_resource_ids%5D%5B%5D=2380&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=5691&secure%5Bresource_id%5D=2380&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fnetwork-detection-and-response-ndr%3FlinkId%3D653835293%26page%3D5&secure%5Btoken%5D=bb6db14f9e80bbdabb8d7f639dad51691748825c60eddf6b315d278546efe318&secure%5Burl%5D=https%3A%2F%2Fwww.manageengine.com%2Fproducts%2Factive-directory-audit%2F%3Futm_source%3DG2%26utm_medium%3Dtpac%26utm_campaign%3DADAP-network-detection-response&secure%5Burl_type%5D=custom_url)

### [MixMode](https://www.g2.com/products/mixmode/reviews)

MixMode is a cybersecurity anomaly detection platform that combines the functionality of SIEM, NDR, NTA and UEBA in a single purpose built platform for the modern SOC. MixMode is focused on solving three primary issues for the Security Operations Center: providing next-generation threat and anomaly detection, surfacing zero-day attacks and improving false-positive alert fatigue. MixMode allows security teams to dramatically increase productivity and efficiency while significantly decreasing the wasted time, effort, and resources associated with legacy cybersecurity tools. The platform is equipped patented self-learning unsupervised AI that is uniquely adaptable to the environment it monitors, can evolve on its own, and predict what’s coming before it happens. This advanced AI requires zero written rules to function and removes the need for constant human oversight of the AI and enables faster and more accurate detections, ultimately reducing cost and improving SOC efficiency. MixMode’s AI intelligently creates and updates the network baseline, then provides security teams with sophisticated functionality like zero-day no signature attack identification, predictive threat detection, 95% false-positive alert reduction, and all the tools necessary to investigate a threat. SOC teams can easily integrate MixMode into their security stack to dramatically reduce the investigation time, cost, and expertise required to respond to persistent threats, malware, insider attacks, and nation-state espionage efforts. MixMode’s core AI algorithm is patented and was utilized over the past 20 years on projects for DARPA and the DoD.

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### Who Is the Company Behind MixMode?

- **Seller:** [MixMode](https://www.g2.com/sellers/mixmode-073e4a6e-a2a1-44cc-88eb-596bec4929c6)
- **Year Founded:** 2020
- **HQ Location:** Santa Barbara, US
- **Twitter:** @MixModeAI  
3,441 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=cb7a57e872bd46a8de4e613e565ce3568ae8a3092c9107fbfdbac39d1f7bea32&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fmixmode%2F&secure%5Burl_type%5D=linkedin_company_website)  
61 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Medium

#### What Are Recent G2 Reviews of MixMode?

**["Excellent SIEM Platform"](https://www.g2.com/survey_responses/mixmode-review-7279408)**

**Rating:** 5.0/5.0 stars

_— Verified User in Computer Software_

[Read full review](https://www.g2.com/survey_responses/mixmode-review-7279408)

### [Netography Fusion](https://www.g2.com/es/products/netography-fusion/reviews)

Netography Fusion identifica actividad que nunca debería ocurrir en ninguna parte de una red multi-nube o híbrida, en tiempo real y a gran escala. Fusion proporciona a los equipos de seguridad, nube y operaciones de red información procesable sobre actividades que sus otras herramientas pasan por alto sin la carga de dispositivos, agentes, sondas o taps. Recolección de Datos La plataforma 100% SaaS Netography Fusion comienza recolectando metadatos de redes multi-nube o híbridas. Los metadatos proporcionan una descripción en tiempo real de la actividad de la red en cualquier entorno, y la arquitectura sin fricciones de Fusion elimina la carga de desplegar sensores, taps o agentes para recolectar los datos. Los clientes simplemente identifican una ubicación de sus registros de flujo en la nube y proporcionan credenciales para que la plataforma Fusion ingiera los registros, o envían los registros directamente a Fusion desde su red local. Los metadatos que Fusion puede ingerir incluyen: - Registros de flujo en la nube de los cinco principales proveedores de nube (Amazon Web Services, Microsoft Azure, Google Cloud, IBM Cloud y Oracle Cloud Infrastructure) - Datos DNS de AWS y GCP - Datos de flujo (NetFlow, sFlow e IPFIX) de routers, switches y otros dispositivos físicos o virtuales. La arquitectura sin fricciones de Fusion permite a una organización comenzar a monitorear la actividad de la red en cualquier parte de su red, y en menos de una hora. Orquestar y Enriquecer Fusion luego orquesta los registros de flujo en la nube, registros de flujo y datos DNS en un solo conjunto de datos, eliminando la necesidad de gastar recursos de ingeniería para agregar y normalizar las fuentes de datos dispares. Y, dado que los metadatos representan la "única fuente de verdad" para la red, la orquestación asegura que los equipos de SecOps, CloudOps y NetOps puedan aprovechar el mismo conjunto de datos. Enriquece los metadatos con atributos de contexto de aplicaciones y servicios en el stack tecnológico de la organización, incluyendo sistemas de gestión de activos, CMDB, EDR, XDR y gestión de vulnerabilidades. El contexto puede incluir docenas de atributos, incluyendo riesgo de activos, entorno, último usuario conocido, región, puntuación de riesgo, grupo de trabajo de seguridad, tipo de entidad y conteo de vulnerabilidades. El contexto transforma los metadatos en una red de una tabla de direcciones IP, puertos y protocolos en descripciones ricas en contexto de las actividades de usuarios, aplicaciones, datos y dispositivos. Los metadatos enriquecidos aceleran la capacidad de cualquier equipo de operaciones para detectar y responder a actividades anómalas o comprometidas al eliminar la necesidad de consultar otras herramientas o equipos para entender la importancia de cualquier actividad. Análisis Impulsado por IA Fusion luego utiliza su motor de análisis avanzado para detectar actividades anómalas y maliciosas usando Modelos de Detección de Netography (NDMs). Creados por el equipo de Ingeniería de Detección de Netography, los NDMs funcionan continuamente y buscan datos entrantes. Fusion genera una alerta cuando detecta excepciones de umbral. Los clientes tienen completa flexibilidad para personalizar los modelos de detección preconfigurados de Fusion, así como crear sus propios modelos para satisfacer sus requisitos. Investigar Los analistas e investigadores pueden realizar un análisis forense detallado de la actividad Este/Oeste y Norte/Sur entre y dentro de plataformas en la nube y de la nube a local para ver toda la actividad relacionada con una detección. Pueden cambiar rápidamente entre paneles dentro de Fusion para mapear el alcance e impacto de un incidente de seguridad (incluyendo cargas de trabajo y conjuntos de datos accedidos) o buscar actividad anómala en el tráfico de red para exponer la línea de tiempo de eventos. Fusion también les permite "mirar hacia atrás" para ver actividad histórica de hasta 12 meses, para entender el alcance y duración de la actividad antes de la detección. Responder La plataforma Fusion también permite a los clientes implementar rápidamente una gama de flujos de trabajo de respuesta desde dentro de la plataforma Fusion directamente o a través de integraciones incorporadas con una variedad de socios tecnológicos, incluyendo sistemas EDR y XDR, y plataformas SIEM/SOAR. Los clientes también pueden usar las API de Fusion para automatizar flujos de trabajo con su stack tecnológico.

#### Who Is the Company Behind Netography Fusion?

- **Vendedor:** [Netography](https://www.g2.com/es/sellers/netography)
- **Año de fundación:** 2018
- **Ubicación de la sede:** Annapolis, US
- **Página de LinkedIn®:** [www.linkedin.com](https://www.g2.com/es/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=0949c60cb1e48e993731a5d802e2b4a683ec9828ec98449b37594ca4c5e60366&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnetography&secure%5Burl_type%5D=linkedin_company_website)  
35 empleados en LinkedIn®

### [NetworkFort](https://www.g2.com/products/networkfort/reviews)

NetworkFort is an AI-powered cybersecurity solution that identifies and stops critical cyber threats before they cause damage. Using machine learning and autonomous response, NetworkFort protects networks across healthcare, finance, government, and enterprise sectors — detecting threats up to 45 days earlier than traditional security systems.

#### Who Is the Company Behind NetworkFort?

- **Seller:** [NetworkFort](https://www.g2.com/sellers/networkfort)
- **Year Founded:** 2020
- **HQ Location:** Reston, US
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=62df7fd8961de64a0efd3590799f28e079e83f778f86fe2977e5e0e0a9812fa1&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnetworkfort%2F&secure%5Burl_type%5D=linkedin_company_website)  
10 employees on LinkedIn®

### [NextRay NDR](https://www.g2.com/es/products/nextray-ndr/reviews)

NextRay AI proporciona una solución integral de Detección y Respuesta de Red (NextRay NDR) para ayudar a las empresas a detectar y responder a ciberataques en redes de nube, PaaS, SaaS, centro de datos, correo electrónico, endpoint, TI e IoT. Su solución, NextRay NDR, utiliza tecnologías avanzadas de aprendizaje automático e inteligencia artificial para potenciar a los equipos de seguridad al automatizar el proceso de seguimiento, detección, priorización y respuesta. Además, la plataforma NextRay AI ofrece investigaciones detalladas de vulnerabilidades de red para evaluar y asegurar su red.

#### Who Is the Company Behind NextRay NDR?

- **Vendedor:** [NextRay AI](https://www.g2.com/es/sellers/nextray-ai)
- **Ubicación de la sede:** 2880 Zanker Rd, Suite 203, San Jose, CA 95134, US
- **Página de LinkedIn®:** [www.linkedin.com](https://www.g2.com/es/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=992a20d024bafcdacc784c6257548ddefd281c4ceedf65595edda249028ce3ca&secure%5Burl%5D=http%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnextray-ai-detection-response-inc&secure%5Burl_type%5D=linkedin_company_website)  
11 empleados en LinkedIn®

### [NovaCommand](https://www.g2.com/products/novacommand/reviews)

Businesses currently rely on multiple tools and consoles to correlate events, and to detect a range of threats and attacks. NovaCommand changes that by providing a unified command center that works with existing solutions to provide a single view across the security landscape. Detect the full spectrum of threats, get instant alerts on common attacks, and use behavioral detection backed by thousands of network signals and 800+ AI models to validate, triage, and establish root cause in minutes or hours instead of days.

#### Who Is the Company Behind NovaCommand?

- **Seller:** [ForeNova Technologies B.V.](https://www.g2.com/sellers/forenova-technologies-b-v)
- **Year Founded:** 2021
- **HQ Location:** Amsterdam, NL
- **Twitter:** @forenovasec  
578 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=87f9567dec120c2efb6571e5975fa0176a03a9e41a486737a9d2f463f36fe518&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fforenova&secure%5Burl_type%5D=linkedin_company_website)  
44 employees on LinkedIn®

### [Nozomi Networks Platform](https://www.g2.com/products/nozomi-networks-platform/reviews)

Nozomi Networks offers highly accurate, actionable intelligence and protection for integrated cybersecurity at scale. The detailed visibility and in-depth insight provided by Nozomi Networks lets users: • See all the OT, IoT, IT, edge and cloud assets on your networks • Pinpoint the cyber threats and vulnerabilities that matter most • Respond quickly to incidents with forensic analysis tools • Manage asset, security and network data in a single platform • Scale cyber and operational resilience across your entire infrastructure

**Average Rating:** 5.0/5.0

**Total Reviews:** 1

#### How Do G2 Users Rate Nozomi Networks Platform?

- **Quality of Support:** 10.0/10 (Category avg: 8.9/10)

#### Who Is the Company Behind Nozomi Networks Platform?

- **Seller:** [Nozomi Networks](https://www.g2.com/sellers/nozomi-networks)
- **Year Founded:** 2013
- **HQ Location:** San Francisco, California, United States
- **Twitter:** @nozominetworks  
4,238 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5226e5108a484b8d31b538c85ee5d2c460e909ca0f9b37ab7aee5e6e97ff318d&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fnozomi-networks-sa%2F&secure%5Burl_type%5D=linkedin_company_website)  
365 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 100% Large

#### What Do G2 Reviewers Say About Nozomi Networks Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users praise the **customization options** of Nozomi Networks Platform, enhancing their ability to monitor network traffic effectively.
- Users praise the **detection algorithms** for identifying OT network intrusions and displaying traffic patterns effectively.
- Users commend the **detection efficiency** of Nozomi Networks Platform, effectively identifying intrusions and malicious traffic.
- Users value the **effective detection algorithms** in Nozomi, enhancing security with clear visibility of traffic patterns.
- Users value the **effective threat detection** capabilities of Nozomi Networks, noting its superb user-friendly interface for traffic monitoring.

##### Cons

- Users find Nozomi Networks Platform to be **expensive** , though it aligns with cyber security budget constraints.

#### What Are Recent G2 Reviews of Nozomi Networks Platform?

**["Nozomi offers excellent OT IDS"](https://www.g2.com/survey_responses/nozomi-networks-platform-review-8632385)**

**Rating:** 5.0/5.0 stars

_— Verified User in Oil & Energy_

[Read full review](https://www.g2.com/survey_responses/nozomi-networks-platform-review-8632385)

### [OpenText Network Detection & Response](https://www.g2.com/products/opentext-network-detection-response/reviews)

OpenText™ Network Detection & Response (NDR) is a comprehensive security solution designed to provide organizations with full visibility into their network traffic, enabling rapid detection and response to both known and emerging cyber threats. By integrating detection, forensic analysis, and proactive threat-hunting capabilities, OpenText NDR empowers security teams to effectively monitor and protect their network environments. Key Features and Functionality: - Immediate Deployment: The solution can be operational within minutes using a single, software-based sensor appliance that self-configures, simplifying the setup process. - Real-Time Detection and Response: Utilizes a multi-faceted suite of threat detection tools, including signature inspection, stateful anomaly detection, and machine-learning-powered malware conviction, to inspect network traffic from all angles and respond promptly to threats. - Comprehensive Network Visibility: Employs high-fidelity metadata and SmartPCAP to eliminate blind spots, ensuring complete visibility across the network. - Advanced Threat Hunting: Allows for retrospective network traffic analyses and historical data testing to identify threats that may have infiltrated the environment before known indicators were available. - Seamless Integration: Exports data in standard formats to existing Security Information and Event Management (SIEM) or Security Orchestration, Automation, and Response (SOAR) systems, facilitating integration into current security infrastructures. Primary Value and Problem Solved: OpenText NDR addresses the critical need for organizations to have real-time, comprehensive visibility into their network traffic to detect and respond to cyber threats effectively. By combining multiple detection engines and advanced analytics, it reduces false positives and enhances the accuracy of threat detection. The solution's scalability and ease of deployment ensure that organizations can maintain robust network security without significant operational overhead, thereby safeguarding sensitive data and maintaining business continuity.

#### Who Is the Company Behind OpenText Network Detection & Response?

- **Seller:** [OpenText](https://www.g2.com/sellers/opentext)
- **Year Founded:** 1991
- **HQ Location:** Waterloo, ON
- **Twitter:** @OpenText  
21,565 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=6c339a6555764b5ffce77c3df08d6ed9c9b1cb1ee1baeebac8435f0485b7cca5&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F2709%2F&secure%5Burl_type%5D=linkedin_company_website)  
23,048 employees on LinkedIn®
- **Ownership:** NASDAQ:OTEX

### [SpyLore](https://www.g2.com/products/spylore/reviews)

SpyLore is the all-in-one growth platform built exclusively for Teachers Pay Teachers sellers. Find high-demand, low-competition keywords tied to your exact niche and grade level. Track competitor shops, monitor rank positions, and catch seasonal trends before the market gets crowded. Optimize titles, tags, and descriptions with guided SEO recommendations. Generate AI-powered listing videos and visuals without external tools. One clear weekly workflow instead of five disconnected tools. Free tier available, no credit card required.

#### Who Is the Company Behind SpyLore?

- **Seller:** [SpyLore](https://www.g2.com/sellers/spylore)
- **HQ Location:** N/A
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=7886df2ed926834e5eb248c77dcfa8e5c815d3ab1f0fe3132ced0dba45868834&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2FNo-Linkedin-Presence-Added-Intentionally-By-DataOps&secure%5Burl_type%5D=linkedin_company_website)  
1 employees on LinkedIn®

### [Sycope](https://www.g2.com/products/sycope/reviews)

Sycope was created and developed by engineers who have been working in the fields of network performance, application efficiency, and IT security for over 20 years. Our mission is to provide intelligent tools that automate network monitoring, ensuring the stability, security, and performance of IT infrastructures worldwide. Sycope is a real-time network traffic monitoring and security tool. It addresses the challenges posed by limited visibility, unpredictable network and application performance, and increasing cybersecurity threats, using four smart modules: Visibility, Performance, Security, and Asset Discovery. What differentiates Sycope? Collecting data from sources that others cannot Automatic alerting based on multiple data sources Customizable without development Scalable data retention – compliance, security, performance Business continuity – constant high performance 24/7

#### Who Is the Company Behind Sycope?

- **Seller:** [Sycope](https://www.g2.com/sellers/sycope)
- **Year Founded:** 2019
- **HQ Location:** Warszawa, PL
- **Twitter:** @SycopeIT  
17 Twitter followers
- **LinkedIn® Page:** [pl.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=934ec72887329c05e6a70a4913004192dddf6d0aa88b1e11ace1dfb3248b88af&secure%5Burl%5D=https%3A%2F%2Fpl.linkedin.com%2Fcompany%2Fsycope&secure%5Burl_type%5D=linkedin_company_website)  
23 employees on LinkedIn®
- **Phone:** +48 691 512 219

### [XTEND](https://www.g2.com/products/xtend-xtend/reviews)

XTEND is a developer of AI-assisted tactical Unmanned Aerial Systems (UAS) designed to enhance military operations by enabling remote operators to perform complex missions safely and effectively. Their mission is to revolutionize military operations and ensure combatant safety using advanced technology.

#### Who Is the Company Behind XTEND?

- **Seller:** [XTEND](https://www.g2.com/sellers/xtend-c06a6666-cdda-4543-925d-f87d6a679585)
- **Year Founded:** 2018
- **HQ Location:** Tel Aviv, IL
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=fffda71bdae211edcbca94a92b497ecb5a82428400b7834bd7aa9ccbf5f2b21c&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fxtend-xr%2F&secure%5Burl_type%5D=linkedin_company_website)  
140 employees on LinkedIn®

- [&lsaquo; Prev‹ Prev](/categories/network-detection-and-response-ndr?linkId=653835293&order=g2_score&page=4#product-list)
- [1](/categories/network-detection-and-response-ndr?linkId=653835293&order=g2_score#product-list)
- [2](/categories/network-detection-and-response-ndr?linkId=653835293&order=g2_score&page=2#product-list)
- [3](/categories/network-detection-and-response-ndr?linkId=653835293&order=g2_score&page=3#product-list)
- [4](/categories/network-detection-and-response-ndr?linkId=653835293&order=g2_score&page=4#product-list)
- 5
- Next &rsaquo;Next ›

Spotlight Categories

[Virtual Event Platforms](https://www.g2.com/categories/virtual-event-platforms)

[Purchasing Software](https://www.g2.com/categories/purchasing-software)

[Sales Compensation Software](https://www.g2.com/categories/sales-compensation)

[Quality Management Systems (QMS)](https://www.g2.com/categories/quality-management-qms)

[Sales Enablement Software](https://www.g2.com/categories/sales-enablement)

Similar Categories

- [Business VPN](/categories/business-vpn)
- [DNS Security Solutions](/categories/dns-security-solutions)
- [Firewall Software](/categories/firewall-software)
- [Intrusion Detection and Prevention Systems (IDPS)](/categories/intrusion-detection-and-prevention-systems-idps)

- [Microsegmentation](/categories/microsegmentation)
- [Network Access Control (NAC)](/categories/network-access-control-nac)
- [Network Sandboxing](/categories/network-sandboxing)
- [Network Security Policy Management (NSPM)](/categories/network-security-policy-management-nspm)

- [Network Traffic Analysis (NTA)](/categories/network-traffic-analysis-nta)
- [Software-Defined Perimeter (SDP)](/categories/software-defined-perimeter-sdp)
- [Unified Threat Management (UTM)](/categories/unified-threat-management-utm)

[Browse Network Detection and Response (NDR) Themes](/categories/network-detection-and-response-ndr/themes)

 ![Brandon Summers-Miller](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Brandon Summers-Miller")
BS

Researched and written by [Brandon Summers-Miller](https://research.g2.com/insights/author/brandon-summers-miller)

Updated October 3, 2024

Network detection and response (NDR) software is used to document business network activity for security threats and alert relevant parties or automate threat remediation. These tools work by monitoring east-west traffic and comparing them to established baselines. When traffic behavior deviates from normal functionality, the solution will detect the issue and assist in forensic investigation. Many tools include or integrate with other solutions that automate incident response processes to minimize the threat’s impact.

These tools are used by security professionals and IT staff to observe network traffic and detect anomalies related to user behavior. Other, older technologies may offer one component of network threat detection or incident response, but NDR combines the functionality of numerous security solutions. These tools use artificial intelligence and machine learning to analyze user behavior as well as existing security data; security professionals can then use that data to develop streamlined discovery and response workflows.

[Network traffic analysis (NTA)](https://www.g2.com/categories/network-traffic-analysis-nta) is a similar emerging technology related to NDR. NTA is the core technology behind NDR; it refers to the analytical and monitoring capabilities used to develop baselines and response frameworks as NDR. But NTA solutions do not have the same level of response automation and end-user, behavioral anomaly detection used to trigger incident response. [Endpoint detection and response (EDR)](https://www.g2.com/categories/endpoint-detection-response-edr) has a similar name, but products within that category only detect issues at the device level while NDR provides visibility to threats across the entire network.

To qualify for inclusion in the Network Detection and Response (NDR) category, a product must:

- Analyze network traffic in real time
- Utilize AI or ML to develop baselines for network behavior 
- Automate threat and anomaly detection across the network
- Deploy network forensics upon detection for investigation and remediation

Show More