Home NDR Monitoring DNS Shield UEBA Analytics RECON Scanner Blog Company Deutsch (DE) Contact

Your network.
Fully visible.
Secure.

Network Detection & Response (NDR): agentless, Swiss Made

IRONATE NDR passively analyzes all of your network traffic: 55+ detection engines, 44 log types, 6 OT/ICS protocols included. Not a single agent on any device.

hubNDR Network Map - LIVE
Anomaly detected14:22:01 UTC
Source: 192.168.1.45
Target: EXTERNAL_C2 [RU]
Isolation initiated
55+Detection Engines
44Log Types Analyzed
6Native OT/ICS Protocols
0Agents on Endpoints

NDR Monitoring in Action

See how IRONATE NDR detects and isolates threats in real time.

35+ Attack Scenarios

What IRONATE NDR detects.

From C2 beaconing to OT attacks to behavior-based anomalies, IRONATE NDR covers the full threat spectrum on the network.

radar

C2 Beaconing

Detects regular communication with command-and-control servers based on timing and volume patterns: even in encrypted traffic.

sync_alt

Lateral Movement

Complete monitoring of east-west traffic detects lateral movement across the network before an attacker reaches the target.

dns

DNS Tunneling

Data exfiltration over the DNS protocol is detected by analyzing query lengths, entropy and response patterns.

travel_explore

Port Scanning & Reconnaissance

Network reconnaissance and port scans are detected in real time through connection frequency and target distribution analysis.

cloud_upload

Data Exfiltration

Anomalously high outbound data volumes, unknown destinations and unusual protocols trigger an immediate alert.

key_off

SSL/TLS Anomalies

Expired certificates, self-signed issuers, JA3 fingerprint anomalies and certificate transparency issues are detected.

rotate_right

Fast-Flux DNS

Rapid IP changes behind domains, a classic hallmark of malware infrastructure, are detected through TTL and response analysis.

phishing

Typosquatting Domains

Deceptively similar domains are detected automatically through edit distance analysis against protected domains.

terminal

SSH/SMTP Brute Force

Authentication attacks on SSH, SMTP and HTTP portals are detected immediately through connection frequency analysis.

folder_shared

SMB Mass Downloads

Anomalously high file read volumes over SMB/CIFS indicate internal data theft and are detected volumetrically.

visibility

First-Seen Connections

First-time connections to new servers, services or administrative targets are automatically flagged and scored.

factory

OT/ICS Attacks

Unauthorized control commands to industrial controllers, write access to unknown registers and IT→OT zone crossings are detected natively.

code_off

SQL Injection Detection

HTTP payload analysis detects SQL injection attempts directly in network traffic: before the attack reaches the database.

folder_open

Directory Traversal

Path traversal patterns in HTTP requests are detected to identify unauthorized file system access through web applications.

download

Executable & Script Downloads

Downloads of executables and scripts from suspicious hosts are flagged as potential payload staging activity.

inventory_2

Archive Staging

Mass archive creation (ZIP, RAR, 7z) on internal hosts ahead of data exfiltration is detected behaviorally on the network.

vpn_key_off

Kerberoasting

Service ticket requests for privileged service accounts in Kerberos traffic are checked for anomaly patterns: detectable without agents.

manage_search

LDAP Enumeration

Automated Active Directory reconnaissance over LDAP is detected on the network through unusual query frequency and breadth.

screen_lock_rotation

RDP Brute Force

High-frequency failed RDP connections are detected as credential attacks on Windows systems and reported immediately.

send_time_extension

BITS Transfer (T1197)

Abuse of the Windows Background Intelligent Transfer Service as a covert C2 channel is detected through network activity analysis.

password

Password Spraying

Low-frequency authentication attempts against many accounts (rather than many against one) are distinguished from brute force through source-target pattern analysis.

leak_remove

ICMP Tunneling

Data transport over ICMP packets is detected through payload size anomalies and request frequency analysis: even with delayed exfiltration.

Protocol Coverage

44 log types. IT and OT.

IRONATE NDR analyzes all common network protocols from layer 2 to layer 7, including specialized industrial protocols that other NDR solutions sell as an add-on license.

lanIT Network Protocols

DNS HTTP/HTTPS SSL/TLS SSH SMTP SMB FTP RDP ICMP TCP/UDP + more

precision_manufacturingOT/ICS Industrial Protocols (native)

Modbus TCP DNP3 EtherNet/IP OPC-UA Siemens S7comm BACnet

No additional sensor, no separate license: OT detection is part of every IRONATE NDR license.

file_copyFile & Metadata Analysis

File transfers including hash extraction, certificate and TLS fingerprints, HTTP headers and payload metadata are logged and analyzed for anomalies.

Data Capture

Passive. Non-intrusive. Everywhere.

IRONATE NDR is connected via mirror ports or network TAPs, without installing a single agent on endpoints. No interference with network flow, no performance impact.

swap_horiz

East-West Traffic

Lateral communication between servers, clients and segments, fully visible.

north_south

North-South Traffic

Inbound and outbound traffic to the internet, cloud services and external partners.

fence

IT/OT Zone Boundary

Prohibited connections between IT and operational technology are detected immediately.

devices

Complete Asset Inventory

Automatic discovery and classification of all network devices without manual upkeep.

Why IRONATE NDR?

What Darktrace, Vectra & ExtraHop cannot do.

Enterprise NDR has long meant a black box with US cloud dependency. IRONATE NDR breaks that pattern: explainable, extensible, Swiss sovereignty.

Feature IRONATE NDR Darktrace Vectra AI ExtraHop
Explainable alerts (no black-box AI)check_circlecancelhelphelp
OT/ICS protocols without an additional licensecheck_circlehelpcancelhelp
Custom detection rules with backtestingcheck_circlecancelcancelhelp
Complete SOC workspace built incheck_circlehelpcancelcancel
Bulk IOC sweep (up to 500 indicators)check_circlecancelcancelcancel
On-premises / no US CLOUD Actcheck_circlehelpcancelcancel
German-language interfacecheck_circlecancelcancelcancel
Sigma rule import & custom editorcheck_circlecancelcancelhelp
AI SOC agent (agentic triage) check_circle partial (black box) cancel cancel
MITRE ATT&CK Navigator exportcheck_circlehelpcheck_circlehelp
Pricing modelCHF 0.70–6.00
per entity/mo.
USD six figures/year
(minimum commit)
USD six figures/year
(minimum commit)
USD six figures/year
(minimum commit)

help = limited or requires an additional license/add-on

SOC Analyst Workspace

Everything in one platform: no external SIEM required.

IRONATE NDR is not just a detection system. It provides a complete SOC workspace, from initial detection through investigation to incident closure.

manage_search

Log Hunting & Free-Text Search

Free-text search and structured field filters across all network logs. Saved queries, a power-user query language and exports of up to 100,000 results.

checkScheduled automatic hunts
monitor_heart

Host 360° View

A consolidated view of every endpoint: CMDB data, risk score, all threat information and 24h network activity at a glance.

checkAsset inventory populated automatically
timeline

Cross-Index Timeline

A timeline per IP across all log types at once: alerts, DNS, HTTP, SSL and file transfers chronologically correlated, with zoom.

check60 interactive time windows
security

MITRE ATT&CK Integration

Interactive attack technique overview with direct export to the official MITRE Navigator. Every alert is mapped to an ATT&CK technique.

checkNavigator layers ready to import
hub

Network Graph & Sankey

Interactive topology visualization of all connections and a Sankey diagram of the top data flows between sources, protocols and destinations.

checkGeoIP world map included
code

Jupyter Notebook Integration

4 prebuilt notebook templates for alerts, log hunting, timelines and host profiles, ready to download, no separate server required.

checkLong-lived API tokens for automation
folder_supervised

Case Management

Complete incident lifecycle with SLA tracking, deadline monitoring, case templates and a gapless timeline. Alerts are grouped directly into cases.

  • checkSLA notifications before deadlines are breached
AI-Powered Triage

Your AI analyst. Transparent. Local. Explicit.

IRONATE NDR integrates two AI functions: an autonomous triage agent and an interactive chat assistant. Both run entirely on your own infrastructure, no data sent to external LLM services.

smart_toy

AI SOC Agent: Autonomous Alert Triage

The AI agent investigates alerts on its own: it pulls context from the system, assesses relevance and annotates the results. Configurable in 4 modes: off / shadow (logging only) / advisory (recommendation) / auto (autonomously closes false positives).

  • checkSupported LLM providers: OpenAI, Anthropic Claude, Ollama, vLLM (on-premises)
  • checkTool use: alert lookups, log queries, IOC checks, agentic loop with configurable tools
  • checkConfigurable minimum severity: the AI only steps in above a defined threshold
  • checkEvery AI decision fully logged in the audit trail
forum

AI Chat Assistant: Natural-Language Analysis

Ask questions about alerts, hosts and trends directly in natural language. The assistant searches your logs, correlates context and returns structured answers with recommended actions.

  • checkStreaming responses for large data volumes
  • checkContext: alert history, host 360°, timeline
  • checkPrivacy by design: all queries stay within your infrastructure
  • checkSupported providers: OpenAI, Anthropic, Ollama, vLLM
Threat Intelligence & Custom Detection

Your own rules. Real feeds. Historical analysis.

IRONATE NDR is not just a black-box detection system: you can write your own detection rules, test them historically and sweep up to 500 IOCs at the push of a button.

edit_note

Custom Detection Rule Editor

Write your own detection rules directly in the platform and validate them with the backtesting function against historical network data before they go live.

  • checkSigma rule import (community rules + your own)
  • checkBacktesting against historical logs before go-live
  • checkThree-tier whitelist system (global / per rule / manual)
  • checkNo vendor involvement needed for rule changes
  • checkAI-assisted whitelist suggestions, automatic false positive pattern detection
search_insights

Bulk IOC Sweep & Retro Analysis

After a published threat report, check up to 500 threat indicators against your historical network data at once, via CSV upload.

  • checkUp to 500 IOCs at once (IP, domain, hash, URL)
  • checkCSV/TXT upload with automatic type detection
  • checkHistorical analysis against existing logs
  • checkMISP REST API integration
feed

Threat Intelligence Feeds

Direct integration of global and internal threat intelligence sources. Automatic alert enrichment with IOC context data in real time.

  • checkTAXII 2.1 / STIX 2.x feed integration
  • checkPreconfigured open-source feeds active from day 1
  • checkMISP REST API integration
  • checkIP, domain and hash reputation lookups
  • checkAutomatic alert enrichment on matches
  • checkScheduled automatic hunt execution
account_tree

SOAR Integration & Auto-Response

Automatic response to critical alerts, directly via firewall API or through SOAR platforms with native forwarding schemas.

  • checkTheHive 5.x native integration (correct schemas)
  • checkCortex XSOAR forwarding (TLP + observable mapping)
  • checkWebhook forwarding (4 formats)
  • checkSyslog RFC 5424 forwarding (TCP/UDP), for Splunk, QRadar, Elastic and any SIEM
Ironate NDR - Core Node 01
[14:21:44] INFO: Passive analysis active, 44 log types, no agent
[14:21:58] INFO: Flow: 10.0.4.12:44561 → 185.112.x.x:443 (HTTPS)
[14:22:01] [ALERT] C2 beaconing detected, interval anomaly
[14:22:01] [ALERT] Threat score: 97/100 (Critical)
[14:22:01] [ALERT] IOC match: threat feed hit (C2 infrastructure)
[14:22:02] SOAR: Playbook "Auto-Isolation-Critical" executed
[14:22:02] SOAR: Connecting to FortiGate-01...
  Rule: DENY src 10.0.4.12 dst ANY
  Rule: DENY src ANY dst 185.112.x.x
[14:22:03] SYSTEM: Rules active. Traffic blocked.
[14:22:03] SYSTEM: Incident #77412 opened in TheHive.
[14:22:03] SYSTEM: Alert MITRE ATT&CK: T1071.001 (C2 Web Protocols)
ironate@ndr-node-01:~$

Seconds instead of hours. Automated response.

When every second counts, IRONATE NDR does not leave you hanging. The engine detects, correlates, scores and isolates, fully automated and with a complete audit trail.

  • check_circle
    Immediate firewall isolationAutomatic blocking rules pushed directly to FortiGate, Palo Alto and other perimeter firewalls via API.
  • check_circle
    MITRE ATT&CK mapping per alertEvery alert is automatically mapped to an ATT&CK technique, for structured incident response.
  • check_circle
    Native SOAR forwardingTheHive 5.x and Cortex XSOAR, with correct schemas and TLP mapping.
  • check_circle
    VMware NSX-T & generic REST APINative NSX-T Distributed Firewall integration plus a configurable REST API adapter for FortiGate, Palo Alto, Cisco and more.
Business Benefits

Why companies choose IRONATE NDR

Reduce your mean time to detect (MTTD) from days to seconds and protect your company from the financial fallout of a security incident.

savings

Cut costs

A security incident costs Swiss SMEs over CHF 500,000 on average. IRONATE NDR detects threats in real time, preventing costly data theft and business interruption.

compliance

Meet compliance

Meet the requirements of the revised Swiss Data Protection Act (revDSG), FINMA, ISO 27001 and NIS2 with complete network logging. Audit logs are retained for 2 years, and automatic reports simplify compliance evidence.

speed

Relieve your SOC

Automated triage and context-rich alerts drastically reduce false positives. Your security team focuses on real threats instead of manual alert filtering.

deployed_code

Operational in 72h

Agentless and non-intrusive. No changes to network flow, no agents on endpoints. Connect via mirror ports or network TAPs: baselining starts immediately.

shield_lock

Swiss Data Sovereignty

Your network data never leaves Switzerland. IRONATE NDR runs exclusively in your own infrastructure: no US CLOUD Act, no external dependencies.

factory

IT & OT from one platform

Six OT/ICS industrial protocols are detected natively: no separate sensor, no additional license. Ideal for manufacturing and critical infrastructure.

Transparent Pricing

NDR Monitoring Price List

Fair, volume-based pricing. The more entities you protect, the lower the price per unit.

Number of EntitiesPrice in CHF
1 – 100CHF 6.00
101 – 300CHF 5.00
301 – 500CHF 4.00
501 – 1,000CHF 2.00
1,001 – 2,000CHF 1.00
2,001 – 4,000CHF 0.90
4,001 – 8,000CHF 0.80
8,001 – 12,000CHF 0.70

Prices per entity / month, excl. VAT. Custom terms for more than 12,000 entities on request.

What is NDR (Network Detection and Response)?

NDR (Network Detection and Response) is a cybersecurity technology that passively analyzes all network traffic in real time to detect advanced threats. NDR closes the critical visibility gap left by endpoint solutions (EDR): the east-west traffic between servers, clients and segments that remains invisible to agent-based systems.

Unlike rule-based SIEM systems, NDR combines behavior-based detection with threat intelligence to also identify unknown attack patterns (zero-day). IRONATE NDR extends classic NDR with a complete SOC workspace, custom detection rules with a backtesting function and native OT/ICS protocol analysis, without an additional license.

IRONATE NDR analyzes 44 log types with 55+ detection engines and natively supports 6 OT/ICS industrial protocols. The solution is agentless, operational within 72 hours and runs entirely in your infrastructure, Swiss data sovereignty guaranteed.

How does NDR work in 4 steps?

  1. 1
    Passive capture: IRONATE NDR captures all network traffic via mirror ports or network TAPs, without agents on endpoints and without interfering with network flow.
  2. 2
    Behavioral baseline: Multiple parallel detection models automatically build a normal behavior profile of your network, per IP, segment, protocol and time window.
  3. 3
    Threat detection: 55+ detectors and threat intelligence feeds identify C2 beaconing, lateral movement, data exfiltration, OT attacks and anomalous patterns, with MITRE ATT&CK mapping.
  4. 4
    Response & forensics: Automatic isolation via firewall API, incident creation in TheHive/XSOAR, forensic timeline analysis and MITRE Navigator export for incident response.

Frequently asked questions about NDR

What is NDR and why do I need it?expand_more

NDR passively analyzes all network traffic in real time, without agents. Lateral movement, C2 beaconing, data exfiltration and OT attacks remain invisible to agent-based systems because they happen between devices, not on them. IRONATE NDR closes exactly this gap with 55+ detectors and 44 analyzed log types.

What sets IRONATE NDR apart from Darktrace, Vectra or ExtraHop?expand_more

IRONATE NDR explains every alert in plain language, no opaque black-box AI. A complete SOC workspace (log hunting, host 360°, timeline, MITRE ATT&CK, case management) is built in. OT/ICS detection for 6 industrial protocols is included without an additional license. Custom detection rules can be validated with backtesting against historical logs. And the solution runs on-premises in your infrastructure, no US CLOUD Act.

What threats does IRONATE NDR detect?expand_more

35+ attack scenarios: C2 beaconing, DNS tunneling, lateral movement, port scanning, SSH/SMTP/RDP brute force, password spraying, data exfiltration, SSL/TLS anomalies, fast-flux DNS, typosquatting domains, SMB mass downloads, SQL injection, directory traversal, executable downloads, archive staging, Kerberoasting, LDAP enumeration, BITS transfers (T1197), ICMP tunneling, first-seen connections, OT control commands on unauthorized systems, IT→OT zone crossings and behavior-based anomalies without writing a single rule.

How long does implementation take?expand_more

IRONATE NDR is agentless and operational within 72 hours. The sensors are connected via mirror ports or network TAPs: no changes to network flow, no agents on endpoints. The AI starts building the baseline immediately.

Does IRONATE NDR support OT/ICS networks?expand_more

Yes, without an additional sensor and without an additional license. IRONATE NDR natively detects attacks on Modbus TCP, DNP3, EtherNet/IP, OPC-UA, Siemens S7comm and BACnet (building automation). Unauthorized control commands, write access to unknown registers and IT→OT zone crossings are detected immediately.

Can I write my own detection rules?expand_more

Yes. The built-in custom detection rule editor lets you write your own rules, including Sigma rule imports from the community. A backtesting function validates new rules against historical logs before they go live. No vendor involvement needed for rule changes.

What is the bulk IOC sweep?expand_more

The bulk IOC sweep matches up to 500 threat indicators (IPs, domains, hashes, URLs) against your historical network data at once, via CSV upload with automatic type detection. After a published threat report, you can immediately check whether your infrastructure is affected.

Is IRONATE NDR compliant with the FADP, GDPR and NIS2?expand_more

Yes. IRONATE NDR runs entirely in your infrastructure: no US CLOUD Act, no external dependencies. Complete audit trail (2-year retention by default), role-based access (admin/analyst), SSO integration with Microsoft 365 and MFA enforcement. Automatic compliance reports for the revised Swiss Data Protection Act (revDSG), FINMA, ISO 27001 and NIS2.

Which SOAR platforms are supported?expand_more

IRONATE NDR integrates natively with TheHive 5.x (correct schemas including TLP and observable mapping) and Cortex XSOAR. Webhook forwarding in 4 formats is also available, for any SOAR or SIEM platform.

Is there an AI assistant?expand_more

Yes. IRONATE NDR includes two AI functions: an autonomous triage agent (shadow/advisory/auto mode) and an interactive chat assistant for natural-language log queries; both run entirely on your own infrastructure. Supported LLM providers: OpenAI, Anthropic Claude, Ollama and vLLM (on-premises, no cloud required).

Which SSO providers are supported?expand_more

IRONATE NDR supports four SSO providers: Microsoft 365 (PKCE, no client secret required), Azure AD OAuth2, Google OAuth2 and SAML 2.0 (for any identity provider such as ADFS, Okta or Keycloak). MFA enforcement is available in all variants.

What company sizes is IRONATE NDR suitable for?expand_more

IRONATE NDR fits SMEs from 20 employees up to large enterprises with several thousand endpoints. Volume-based pricing starting at CHF 6.00 per entity/month makes the solution economically attractive for smaller companies as well.