Ransomware on the Network: How NDR Stops Lateral Movement Before the Damage Is Done

Stefan Röthlisberger
Founder & CEO, IRONATE
Ransomware attacks have changed fundamentally in recent years. While earlier variants relied primarily on mass distribution, modern ransomware groups such as LockBit, BlackCat (ALPHV) and Cl0p operate on the "big game hunting" principle: targeted attacks on organizations with high extortion potential. Lateral movement through the network is the decisive factor that separates an isolated incident from a company-wide catastrophe.
The Anatomy of Modern Ransomware Attacks
According to the IBM X-Force Threat Intelligence Index 2024, the average dwell time of an attacker in the network before ransomware detonation is 24 days. During this time, the actors move laterally through the network, escalate privileges and exfiltrate data, often completely undetected by traditional endpoint solutions.
The typical attack sequence follows the MITRE ATT&CK Framework and comprises several phases: initial access via phishing or exploited vulnerabilities, followed by credential harvesting with tools such as Mimikatz, then lateral movement via SMB, RDP or WMI, data exfiltration as leverage for double extortion, and finally ransomware detonation and encryption.
Why Endpoint Security Alone Is Not Enough
According to the Verizon Data Breach Investigations Report (DBIR) 2024, 68% of breaches were only discovered after weeks or months. Endpoint Detection & Response (EDR) is an important component, but it has a fundamental blind spot: it only sees what happens on the individual endpoint.
Lateral movement in east-west traffic, meaning communication between internal systems, remains largely invisible to EDR. This is exactly where Network Detection & Response (NDR) comes in. NDR analyzes network traffic on layers 2 through 7 and detects anomalous communication patterns that indicate lateral movement.
NDR as a Line of Defense: How Detection Works
Modern NDR systems such as Ironate NDR rely on a combination of deep packet inspection (DPI), machine learning and threat intelligence. Detection happens in real time and comprises several mechanisms.
First, baseline analysis: the system creates a digital fingerprint of normal network behavior. Any deviation, such as an accounting server suddenly communicating with dozens of other systems, is immediately flagged as an anomaly.
Second, protocol analysis: C2 beaconing (command & control) has characteristic patterns in timing and payload size. NDR detects these patterns even in encrypted traffic through JA3/JA3S fingerprinting, without having to decrypt the traffic.
Third, automated response: for critical threats, the system can automatically isolate the affected endpoint, in under one second, through direct API integration with the firewall and EDR solution.
Practical Example: Detecting Cobalt Strike Beaconing
Cobalt Strike is one of the most frequently abused tools in ransomware attacks. According to the Recorded Future Adversary Infrastructure Report 2024, Cobalt Strike was used in over 30% of all identified C2 infrastructures. NDR detects Cobalt Strike beaconing by analyzing interval jittering and HTTP header anomalies, even when the communication is encrypted over HTTPS.
Conclusion: Defense in Depth Requires NDR
Ransomware defense is not a single product, it is an architecture decision. NDR closes the critical gap between endpoint and perimeter security and delivers the network visibility that is essential for detecting lateral movement. For Swiss companies that must meet the strict requirements of the revised Swiss Data Protection Act (revDSG) and ISO 27001, NDR is no longer an option, it is a necessity.
summarize Summary / Key Takeaways
- check_circleModern ransomware groups operate on the "big game hunting" principle: the average dwell time in the network is 24 days before detonation (IBM X-Force 2024).
- check_circle68% of all breaches are only discovered after weeks or months (Verizon DBIR 2024). Endpoint security alone cannot detect lateral movement in east-west traffic.
- check_circleNDR analyzes network traffic on layers 2–7 and detects C2 beaconing, lateral movement and data exfiltration in real time, even in encrypted traffic.
- check_circleCobalt Strike was used in over 30% of all identified C2 infrastructures (Recorded Future 2024). NDR detects it through JA3/JA3S fingerprinting.
- check_circleFor Swiss companies subject to the revised Swiss Data Protection Act (revDSG) and ISO 27001, NDR is a necessary component of a defense-in-depth strategy.
Sources & References
- • IBM X-Force Threat Intelligence Index 2024 (ibm.com/reports/threat-intelligence)
- • Verizon Data Breach Investigations Report (DBIR) 2024 (verizon.com/dbir)
- • MITRE ATT&CK Framework (attack.mitre.org)
- • Recorded Future: Adversary Infrastructure Report 2024 (recordedfuture.com)
- • NCSC Switzerland: Ransomware situation reports (ncsc.admin.ch)
Want to strengthen your security strategy?
Our experts will show you, with no obligation, how to protect your network against modern ransomware attacks with NDR monitoring.
Request a free consultation arrow_forward