Best Network Detection and Response (NDR) Software - Page 5

How Many Network Detection and Response (NDR) Software Products Does G2 Track?

Total Products under this Category: 78

Category Stats (Sep 2026)

  • Average Rating: 4.39/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: BluSapphire OnePlatform (+1.05%) - Among all products in this category, BluSapphire OnePlatform recorded the largest rating increase compared to last month

Last updated: September 01, 2026

How Does G2 Rank Network Detection and Response (NDR) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 1,600+ Authentic Reviews
  • 78+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Network Detection and Response (NDR) Software

G2 Grid® for Network Detection and Response (NDR) Software plotting products by satisfaction and market presence

Highlighted products: Progress WhatsUp Gold, Sophos NDR, TrendAI Vision One, Cortex XDR, Darktrace / NETWORK, ExtraHop, Rapid7 Next-Gen SIEM, and ManageEngine ADAudit Plus.

Underlying data: [Grid® JSON](https://www.g2.com/categories/network-detection-and-response-ndr/grids.json?focus%5B%5D=progress-whatsup-gold&focus%5B%5D=sophos-ndr&focus%5B%5D=trendai-vision-one&focus%5B%5D=palo-alto-networks-cortex-xdr&focus%5B%5D=darktrace-network&focus%5B%5D=extrahop&focus%5B%5D=rapid7-next-gen-siem&focus%5B%5D=manageengine-adaudit-plus)

Intrusion Shield OnPremise

With today’s ever-expanding attack surface, visibility and speed are critical to protecting your organization’s most valuable data. Shield OnPremise is a physical appliance that sits behind your firewall and analyzes all traffic entering and exiting your network. Known malicious or unknown IPs are blocked, trusted IPs are permitted – all without impeding everyday business or network speeds. See all inbound and outbound blocks See the real-time list of all blocked connections. Drill down on an individual connection to see more details like why it was blocked, risk level, etc. Find out where connections are coming from An interactive map shows you what countries your business is communicating with the most. Identify the top offending devices Quickly see which devices have the most malicious connection attempts to prioritize remediation efforts. Get informed threat intelligence No wasted time sifting through intelligence feeds.Only look at the intelligence relevant to your current network activity.

Who Is the Company Behind Intrusion Shield OnPremise?

  • Seller: Intrusion
  • Year Founded: 1983
  • HQ Location: Plano, Texas, United States
  • Twitter: @IntrusionShield
    16,860 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    58 employees on LinkedIn®
  • Ownership: NASDAQ: INTZ

IronWiFi

IronWiFi is a cloud-based WiFi authentication and access management platform that eliminates the complexity of on-premises RADIUS servers. Trusted by 1,000+ organizations across 108 countries, IronWiFi provides enterprise-grade network security with a setup time under 30 minutes. The platform offers captive portal solutions for guest WiFi with customizable login pages, social login, email collection, and payment processing. For employee networks, IronWiFi delivers cloud-hosted WPA-Enterprise 802.1X RADIUS authentication with certificate-based security and SAML SSO integration. Additional capabilities include OpenRoaming for seamless connectivity across 3M+ global hotspots, Passpoint (Hotspot 2.0), and SCEP for automatic device certificate provisioning. IronWiFi works with existing WiFi infrastructure from 45+ vendors including Cisco, Aruba, Ubiquiti, Meraki, Ruckus, and Fortinet. Organizations across hospitality, education, healthcare, retail, coworking, and enterprise use IronWiFi to secure network access, collect visitor analytics, and manage multi-site deployments from a single cloud console — all backed by 99.9% uptime SLA and 24/7 human support.

Who Is the Company Behind IronWiFi?

  • Seller: IronWifi
  • Year Founded: 2014
  • HQ Location: Orlando, FL
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®

Jizô

Jizô is a network observability platform that enables decision-makers to anticipate, identify and block cyber-attacks, thanks to unique and innovative AI. Jizô has proved to be highly effective on a number of critical networks used by major companies and public authorities. Sesame*it, the publisher of Jizô, is one of the Representative Vendors in the Gartner® Market Guide 2024 for Network Detection and Response Solutions.

Who Is the Company Behind Jizô?

MixMode

MixMode is a cybersecurity anomaly detection platform that combines the functionality of SIEM, NDR, NTA and UEBA in a single purpose built platform for the modern SOC. MixMode is focused on solving three primary issues for the Security Operations Center: providing next-generation threat and anomaly detection, surfacing zero-day attacks and improving false-positive alert fatigue. MixMode allows security teams to dramatically increase productivity and efficiency while significantly decreasing the wasted time, effort, and resources associated with legacy cybersecurity tools. The platform is equipped patented self-learning unsupervised AI that is uniquely adaptable to the environment it monitors, can evolve on its own, and predict what’s coming before it happens. This advanced AI requires zero written rules to function and removes the need for constant human oversight of the AI and enables faster and more accurate detections, ultimately reducing cost and improving SOC efficiency. MixMode’s AI intelligently creates and updates the network baseline, then provides security teams with sophisticated functionality like zero-day no signature attack identification, predictive threat detection, 95% false-positive alert reduction, and all the tools necessary to investigate a threat. SOC teams can easily integrate MixMode into their security stack to dramatically reduce the investigation time, cost, and expertise required to respond to persistent threats, malware, insider attacks, and nation-state espionage efforts. MixMode’s core AI algorithm is patented and was utilized over the past 20 years on projects for DARPA and the DoD.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind MixMode?

  • Seller: MixMode
  • Year Founded: 2020
  • HQ Location: Santa Barbara, US
  • Twitter: @MixModeAI
    3,441 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    61 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of MixMode?

Netography Fusion

Netography Fusion delivers a holistic view of all network activity across your multi-cloud or hybrid network, in real-time and at scale. It detects malicious and anomalous activity, such as lateral movement, data harvesting and exfiltration from ransomware without the burden of sensors or agents. Fusion is the fastest way for you to see all network activity. In less than an hour, your cloudops, netops, and secops teams can start seeing all network activity in to, between, and out of your multi-cloud or hybrid network. Data Collection The 100% SaaS Netography Fusion platform begins by collecting VPC flow logs, VNet flow logs, on-prem flow logs, and DNS logs from your multi-cloud or hybrid networks. Fusion’s frictionless architecture eliminates the burden of deploying sensors or agents to collect the data. You simply identify a location of your cloud flow logs and provide credentials for the Fusion platform to ingest the logs, or you can send the logs directly to Fusion from your on-prem network. The metadata Fusion can ingest includes: - Cloud flow logs from all five major cloud providers (Amazon Web Services, Microsoft Azure, Google Cloud, IBM Cloud, and Oracle Cloud Infrastructure) - DNS data from AWS and GCP - Flow data (NetFlow, sFlow, and IPFIX) from routers, switches, and other physical or virtual devices. Orchestrate and Enrich Fusion then orchestrates the cloud flow logs, flow logs, and DNS data into a single dataset, eliminating the need to spend engineering resources to aggregate and normalize the disparate data sources. And, because the metadata represents the “one source of truth” for the network, orchestration ensures that SecOps, CloudOps, and NetOps teams can all take advantage of the same dataset. It enriches the metadata with context attributes from applications and services in the organization’s tech stack, including asset management, CMDB, EDR, XDR, and vulnerability management systems. The context can include dozens of attributes, including asset risk, environment, last known user, region, risk score, security workgroup, type of entity, and vulnerability count. Context transforms the metadata in a network from a table of IP addresses, ports, and protocols into context-rich descriptions of the activities of users, applications, data, and devices. Enriched metadata accelerates any operations teams’ ability to detect and respond to anomalous or compromise activity by eliminating the need to consult other tools or teams to understand the significance of any activity. AI-Driven Analytics Fusion then uses its advanced analytics engine to detect anomalous and malicious activity using Netography Detection Models (NDMs). Created by the Netography Detection Engineering team, NDMs run continuously and search incoming data. Fusion generates an alert when it detects threshold exceptions. Customers have complete flexibility to customize Fusion’s preconfigured detection models as well as create their own models to meet their requirements. Investigate Analysts and investigators can conduct detailed forensic analysis of East/West and North/South activity between and within cloud platforms and cloud to on-prem to see all activity related to a detection. They can quickly pivot between dashboards within Fusion to map the scope and impact of a security incident (including workloads and data sets accessed) or hunt anomalous activity in network traffic to expose the timeline of events. Fusion also enables them to “look back” to see historical activity for up to 12 months, to understand the scope and duration of the activity before detection. Respond The Fusion platform also enables customers to implement a range of response workflows quickly from within the Fusion platform directly or via built-in integrations with a range of technology partners, including EDR and XDR systems, and SIEM/SOAR platforms. Customers can also use Fusion’s APIs to automate workflows with their tech stack as well.

Who Is the Company Behind Netography Fusion?

NetworkFort

NetworkFort is an AI-powered cybersecurity solution that identifies and stops critical cyber threats before they cause damage. Using machine learning and autonomous response, NetworkFort protects networks across healthcare, finance, government, and enterprise sectors — detecting threats up to 45 days earlier than traditional security systems.

Who Is the Company Behind NetworkFort?

NeXafe

Who Is the Company Behind NeXafe?

  • Seller: NeXafe Solutions
  • Year Founded: 2018
  • HQ Location: Vancouver - Calgary - Toronto - Montréal - Sherbrooke, CA
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®

NextRay NDR

NextRay AI provides a comprehensive Network Detection & Response solution (NextRay NDR) to help enterprises detect and respond to cyberattacks across cloud, PaaS, SaaS, data center, email, endpoint, IT, and IoT networks. Its solution, NextRay NDR uses advanced machine learning and AI technologies to empower security teams by automating the tracking, detection, prioritization, and response process. Additionally, NextRay AI platform offers detailed investigations of network vulnerabilities to assess and secure your network.

Who Is the Company Behind NextRay NDR?

  • Seller: NextRay AI
  • HQ Location: 2880 Zanker Rd, Suite 203, San Jose, CA 95134, US
  • LinkedIn® Page: www.linkedin.com
    11 employees on LinkedIn®

NovaCommand

Businesses currently rely on multiple tools and consoles to correlate events, and to detect a range of threats and attacks. NovaCommand changes that by providing a unified command center that works with existing solutions to provide a single view across the security landscape. Detect the full spectrum of threats, get instant alerts on common attacks, and use behavioral detection backed by thousands of network signals and 800+ AI models to validate, triage, and establish root cause in minutes or hours instead of days.

Who Is the Company Behind NovaCommand?

Nozomi Networks Platform

Nozomi Networks offers highly accurate, actionable intelligence and protection for integrated cybersecurity at scale. The detailed visibility and in-depth insight provided by Nozomi Networks lets users: • See all the OT, IoT, IT, edge and cloud assets on your networks • Pinpoint the cyber threats and vulnerabilities that matter most • Respond quickly to incidents with forensic analysis tools • Manage asset, security and network data in a single platform • Scale cyber and operational resilience across your entire infrastructure

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate Nozomi Networks Platform?

  • Quality of Support: 10.0/10 (Category avg: 8.9/10)

Who Is the Company Behind Nozomi Networks Platform?

  • Seller: Nozomi Networks
  • Year Founded: 2013
  • HQ Location: San Francisco, California, United States
  • Twitter: @nozominetworks
    4,238 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    365 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Do G2 Reviewers Say About Nozomi Networks Platform?

AI-generated summary from verified user reviews

Pros
  • Users highlight the customization features of Nozomi Networks Platform, enhancing their ability to monitor network activities effectively.
  • Users value the effective detection algorithms of Nozomi Networks Platform, which accurately identify intrusions and malicious traffic.
  • Users commend the detection efficiency of Nozomi Networks Platform, effectively identifying intrusions and analyzing traffic patterns.
  • Users value Nozomi's detection algorithms for identifying intrusions and its excellent interface for traffic pattern visualization.
  • Users value the advanced threat detection capabilities of Nozomi Networks, identifying intrusions and malicious traffic effectively.
Cons
  • Users find the Nozomi Networks Platform expensive, yet it aligns with cybersecurity budget constraints against competitors.

What Are Recent G2 Reviews of Nozomi Networks Platform?

OpenText Network Detection & Response

OpenText™ Network Detection & Response (NDR) is a comprehensive security solution designed to provide organizations with full visibility into their network traffic, enabling rapid detection and response to both known and emerging cyber threats. By integrating detection, forensic analysis, and proactive threat-hunting capabilities, OpenText NDR empowers security teams to effectively monitor and protect their network environments. Key Features and Functionality: - Immediate Deployment: The solution can be operational within minutes using a single, software-based sensor appliance that self-configures, simplifying the setup process. - Real-Time Detection and Response: Utilizes a multi-faceted suite of threat detection tools, including signature inspection, stateful anomaly detection, and machine-learning-powered malware conviction, to inspect network traffic from all angles and respond promptly to threats. - Comprehensive Network Visibility: Employs high-fidelity metadata and SmartPCAP to eliminate blind spots, ensuring complete visibility across the network. - Advanced Threat Hunting: Allows for retrospective network traffic analyses and historical data testing to identify threats that may have infiltrated the environment before known indicators were available. - Seamless Integration: Exports data in standard formats to existing Security Information and Event Management (SIEM) or Security Orchestration, Automation, and Response (SOAR) systems, facilitating integration into current security infrastructures. Primary Value and Problem Solved: OpenText NDR addresses the critical need for organizations to have real-time, comprehensive visibility into their network traffic to detect and respond to cyber threats effectively. By combining multiple detection engines and advanced analytics, it reduces false positives and enhances the accuracy of threat detection. The solution's scalability and ease of deployment ensure that organizations can maintain robust network security without significant operational overhead, thereby safeguarding sensitive data and maintaining business continuity.

Who Is the Company Behind OpenText Network Detection & Response?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Redborder

Redborder provides bespoke NDR & NPM services, these combine the use of AI (ML) and Next Gen IPS. The product is customizable and scalable making it accessible to smaller organizations and larger ones alike. NDR: Network : Monitors 24/7. Detection: Unusual user behaviour, lateral movement, unauthorised requests. Response: Triage made easy. NPM- Monitors the health and performance of all assets in real time. IT & OT.

Who Is the Company Behind Redborder?

SpyLore

SpyLore is the all-in-one growth platform built exclusively for Teachers Pay Teachers sellers. Find high-demand, low-competition keywords tied to your exact niche and grade level. Track competitor shops, monitor rank positions, and catch seasonal trends before the market gets crowded. Optimize titles, tags, and descriptions with guided SEO recommendations. Generate AI-powered listing videos and visuals without external tools. One clear weekly workflow instead of five disconnected tools. Free tier available, no credit card required.

Who Is the Company Behind SpyLore?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024