Your network.
Fully visible.
Secure.
Network Detection & Response (NDR): agentless, Swiss Made
IRONATE NDR passively analyzes all of your network traffic: 55+ detection engines, 44 log types, 6 OT/ICS protocols included. Not a single agent on any device.
NDR Monitoring in Action
See how IRONATE NDR detects and isolates threats in real time.
What IRONATE NDR detects.
From C2 beaconing to OT attacks to behavior-based anomalies, IRONATE NDR covers the full threat spectrum on the network.
C2 Beaconing
Detects regular communication with command-and-control servers based on timing and volume patterns: even in encrypted traffic.
Lateral Movement
Complete monitoring of east-west traffic detects lateral movement across the network before an attacker reaches the target.
DNS Tunneling
Data exfiltration over the DNS protocol is detected by analyzing query lengths, entropy and response patterns.
Port Scanning & Reconnaissance
Network reconnaissance and port scans are detected in real time through connection frequency and target distribution analysis.
Data Exfiltration
Anomalously high outbound data volumes, unknown destinations and unusual protocols trigger an immediate alert.
SSL/TLS Anomalies
Expired certificates, self-signed issuers, JA3 fingerprint anomalies and certificate transparency issues are detected.
Fast-Flux DNS
Rapid IP changes behind domains, a classic hallmark of malware infrastructure, are detected through TTL and response analysis.
Typosquatting Domains
Deceptively similar domains are detected automatically through edit distance analysis against protected domains.
SSH/SMTP Brute Force
Authentication attacks on SSH, SMTP and HTTP portals are detected immediately through connection frequency analysis.
SMB Mass Downloads
Anomalously high file read volumes over SMB/CIFS indicate internal data theft and are detected volumetrically.
First-Seen Connections
First-time connections to new servers, services or administrative targets are automatically flagged and scored.
OT/ICS Attacks
Unauthorized control commands to industrial controllers, write access to unknown registers and IT→OT zone crossings are detected natively.
SQL Injection Detection
HTTP payload analysis detects SQL injection attempts directly in network traffic: before the attack reaches the database.
Directory Traversal
Path traversal patterns in HTTP requests are detected to identify unauthorized file system access through web applications.
Executable & Script Downloads
Downloads of executables and scripts from suspicious hosts are flagged as potential payload staging activity.
Archive Staging
Mass archive creation (ZIP, RAR, 7z) on internal hosts ahead of data exfiltration is detected behaviorally on the network.
Kerberoasting
Service ticket requests for privileged service accounts in Kerberos traffic are checked for anomaly patterns: detectable without agents.
LDAP Enumeration
Automated Active Directory reconnaissance over LDAP is detected on the network through unusual query frequency and breadth.
RDP Brute Force
High-frequency failed RDP connections are detected as credential attacks on Windows systems and reported immediately.
BITS Transfer (T1197)
Abuse of the Windows Background Intelligent Transfer Service as a covert C2 channel is detected through network activity analysis.
Password Spraying
Low-frequency authentication attempts against many accounts (rather than many against one) are distinguished from brute force through source-target pattern analysis.
ICMP Tunneling
Data transport over ICMP packets is detected through payload size anomalies and request frequency analysis: even with delayed exfiltration.
44 log types. IT and OT.
IRONATE NDR analyzes all common network protocols from layer 2 to layer 7, including specialized industrial protocols that other NDR solutions sell as an add-on license.
lanIT Network Protocols
precision_manufacturingOT/ICS Industrial Protocols (native)
No additional sensor, no separate license: OT detection is part of every IRONATE NDR license.
file_copyFile & Metadata Analysis
File transfers including hash extraction, certificate and TLS fingerprints, HTTP headers and payload metadata are logged and analyzed for anomalies.
Passive. Non-intrusive. Everywhere.
IRONATE NDR is connected via mirror ports or network TAPs, without installing a single agent on endpoints. No interference with network flow, no performance impact.
East-West Traffic
Lateral communication between servers, clients and segments, fully visible.
North-South Traffic
Inbound and outbound traffic to the internet, cloud services and external partners.
IT/OT Zone Boundary
Prohibited connections between IT and operational technology are detected immediately.
Complete Asset Inventory
Automatic discovery and classification of all network devices without manual upkeep.
What Darktrace, Vectra & ExtraHop cannot do.
Enterprise NDR has long meant a black box with US cloud dependency. IRONATE NDR breaks that pattern: explainable, extensible, Swiss sovereignty.
| Feature | IRONATE NDR | Darktrace | Vectra AI | ExtraHop |
|---|---|---|---|---|
| Explainable alerts (no black-box AI) | check_circle | cancel | help | help |
| OT/ICS protocols without an additional license | check_circle | help | cancel | help |
| Custom detection rules with backtesting | check_circle | cancel | cancel | help |
| Complete SOC workspace built in | check_circle | help | cancel | cancel |
| Bulk IOC sweep (up to 500 indicators) | check_circle | cancel | cancel | cancel |
| On-premises / no US CLOUD Act | check_circle | help | cancel | cancel |
| German-language interface | check_circle | cancel | cancel | cancel |
| Sigma rule import & custom editor | check_circle | cancel | cancel | help |
| AI SOC agent (agentic triage) | check_circle | partial (black box) | cancel | cancel |
| MITRE ATT&CK Navigator export | check_circle | help | check_circle | help |
| Pricing model | CHF 0.70–6.00 per entity/mo. | USD six figures/year (minimum commit) | USD six figures/year (minimum commit) | USD six figures/year (minimum commit) |
help = limited or requires an additional license/add-on
Everything in one platform: no external SIEM required.
IRONATE NDR is not just a detection system. It provides a complete SOC workspace, from initial detection through investigation to incident closure.
Log Hunting & Free-Text Search
Free-text search and structured field filters across all network logs. Saved queries, a power-user query language and exports of up to 100,000 results.
Host 360° View
A consolidated view of every endpoint: CMDB data, risk score, all threat information and 24h network activity at a glance.
Cross-Index Timeline
A timeline per IP across all log types at once: alerts, DNS, HTTP, SSL and file transfers chronologically correlated, with zoom.
MITRE ATT&CK Integration
Interactive attack technique overview with direct export to the official MITRE Navigator. Every alert is mapped to an ATT&CK technique.
Network Graph & Sankey
Interactive topology visualization of all connections and a Sankey diagram of the top data flows between sources, protocols and destinations.
Jupyter Notebook Integration
4 prebuilt notebook templates for alerts, log hunting, timelines and host profiles, ready to download, no separate server required.
Case Management
Complete incident lifecycle with SLA tracking, deadline monitoring, case templates and a gapless timeline. Alerts are grouped directly into cases.
- checkSLA notifications before deadlines are breached
Your AI analyst. Transparent. Local. Explicit.
IRONATE NDR integrates two AI functions: an autonomous triage agent and an interactive chat assistant. Both run entirely on your own infrastructure, no data sent to external LLM services.
AI SOC Agent: Autonomous Alert Triage
The AI agent investigates alerts on its own: it pulls context from the system, assesses relevance and annotates the results. Configurable in 4 modes: off / shadow (logging only) / advisory (recommendation) / auto (autonomously closes false positives).
- checkSupported LLM providers: OpenAI, Anthropic Claude, Ollama, vLLM (on-premises)
- checkTool use: alert lookups, log queries, IOC checks, agentic loop with configurable tools
- checkConfigurable minimum severity: the AI only steps in above a defined threshold
- checkEvery AI decision fully logged in the audit trail
AI Chat Assistant: Natural-Language Analysis
Ask questions about alerts, hosts and trends directly in natural language. The assistant searches your logs, correlates context and returns structured answers with recommended actions.
- checkStreaming responses for large data volumes
- checkContext: alert history, host 360°, timeline
- checkPrivacy by design: all queries stay within your infrastructure
- checkSupported providers: OpenAI, Anthropic, Ollama, vLLM
Your own rules. Real feeds. Historical analysis.
IRONATE NDR is not just a black-box detection system: you can write your own detection rules, test them historically and sweep up to 500 IOCs at the push of a button.
Custom Detection Rule Editor
Write your own detection rules directly in the platform and validate them with the backtesting function against historical network data before they go live.
- checkSigma rule import (community rules + your own)
- checkBacktesting against historical logs before go-live
- checkThree-tier whitelist system (global / per rule / manual)
- checkNo vendor involvement needed for rule changes
- checkAI-assisted whitelist suggestions, automatic false positive pattern detection
Bulk IOC Sweep & Retro Analysis
After a published threat report, check up to 500 threat indicators against your historical network data at once, via CSV upload.
- checkUp to 500 IOCs at once (IP, domain, hash, URL)
- checkCSV/TXT upload with automatic type detection
- checkHistorical analysis against existing logs
- checkMISP REST API integration
Threat Intelligence Feeds
Direct integration of global and internal threat intelligence sources. Automatic alert enrichment with IOC context data in real time.
- checkTAXII 2.1 / STIX 2.x feed integration
- checkPreconfigured open-source feeds active from day 1
- checkMISP REST API integration
- checkIP, domain and hash reputation lookups
- checkAutomatic alert enrichment on matches
- checkScheduled automatic hunt execution
SOAR Integration & Auto-Response
Automatic response to critical alerts, directly via firewall API or through SOAR platforms with native forwarding schemas.
- checkTheHive 5.x native integration (correct schemas)
- checkCortex XSOAR forwarding (TLP + observable mapping)
- checkWebhook forwarding (4 formats)
- checkSyslog RFC 5424 forwarding (TCP/UDP), for Splunk, QRadar, Elastic and any SIEM
Seconds instead of hours. Automated response.
When every second counts, IRONATE NDR does not leave you hanging. The engine detects, correlates, scores and isolates, fully automated and with a complete audit trail.
- check_circleImmediate firewall isolationAutomatic blocking rules pushed directly to FortiGate, Palo Alto and other perimeter firewalls via API.
- check_circleMITRE ATT&CK mapping per alertEvery alert is automatically mapped to an ATT&CK technique, for structured incident response.
- check_circleNative SOAR forwardingTheHive 5.x and Cortex XSOAR, with correct schemas and TLP mapping.
- check_circleVMware NSX-T & generic REST APINative NSX-T Distributed Firewall integration plus a configurable REST API adapter for FortiGate, Palo Alto, Cisco and more.
Why companies choose IRONATE NDR
Reduce your mean time to detect (MTTD) from days to seconds and protect your company from the financial fallout of a security incident.
Cut costs
A security incident costs Swiss SMEs over CHF 500,000 on average. IRONATE NDR detects threats in real time, preventing costly data theft and business interruption.
Meet compliance
Meet the requirements of the revised Swiss Data Protection Act (revDSG), FINMA, ISO 27001 and NIS2 with complete network logging. Audit logs are retained for 2 years, and automatic reports simplify compliance evidence.
Relieve your SOC
Automated triage and context-rich alerts drastically reduce false positives. Your security team focuses on real threats instead of manual alert filtering.
Operational in 72h
Agentless and non-intrusive. No changes to network flow, no agents on endpoints. Connect via mirror ports or network TAPs: baselining starts immediately.
Swiss Data Sovereignty
Your network data never leaves Switzerland. IRONATE NDR runs exclusively in your own infrastructure: no US CLOUD Act, no external dependencies.
IT & OT from one platform
Six OT/ICS industrial protocols are detected natively: no separate sensor, no additional license. Ideal for manufacturing and critical infrastructure.
NDR Monitoring Price List
Fair, volume-based pricing. The more entities you protect, the lower the price per unit.
| Number of Entities | Price in CHF |
|---|---|
| 1 – 100 | CHF 6.00 |
| 101 – 300 | CHF 5.00 |
| 301 – 500 | CHF 4.00 |
| 501 – 1,000 | CHF 2.00 |
| 1,001 – 2,000 | CHF 1.00 |
| 2,001 – 4,000 | CHF 0.90 |
| 4,001 – 8,000 | CHF 0.80 |
| 8,001 – 12,000 | CHF 0.70 |
Prices per entity / month, excl. VAT. Custom terms for more than 12,000 entities on request.
What is NDR (Network Detection and Response)?
NDR (Network Detection and Response) is a cybersecurity technology that passively analyzes all network traffic in real time to detect advanced threats. NDR closes the critical visibility gap left by endpoint solutions (EDR): the east-west traffic between servers, clients and segments that remains invisible to agent-based systems.
Unlike rule-based SIEM systems, NDR combines behavior-based detection with threat intelligence to also identify unknown attack patterns (zero-day). IRONATE NDR extends classic NDR with a complete SOC workspace, custom detection rules with a backtesting function and native OT/ICS protocol analysis, without an additional license.
IRONATE NDR analyzes 44 log types with 55+ detection engines and natively supports 6 OT/ICS industrial protocols. The solution is agentless, operational within 72 hours and runs entirely in your infrastructure, Swiss data sovereignty guaranteed.
How does NDR work in 4 steps?
- 1Passive capture: IRONATE NDR captures all network traffic via mirror ports or network TAPs, without agents on endpoints and without interfering with network flow.
- 2Behavioral baseline: Multiple parallel detection models automatically build a normal behavior profile of your network, per IP, segment, protocol and time window.
- 3Threat detection: 55+ detectors and threat intelligence feeds identify C2 beaconing, lateral movement, data exfiltration, OT attacks and anomalous patterns, with MITRE ATT&CK mapping.
- 4Response & forensics: Automatic isolation via firewall API, incident creation in TheHive/XSOAR, forensic timeline analysis and MITRE Navigator export for incident response.
Frequently asked questions about NDR
What is NDR and why do I need it?expand_more
NDR passively analyzes all network traffic in real time, without agents. Lateral movement, C2 beaconing, data exfiltration and OT attacks remain invisible to agent-based systems because they happen between devices, not on them. IRONATE NDR closes exactly this gap with 55+ detectors and 44 analyzed log types.
What sets IRONATE NDR apart from Darktrace, Vectra or ExtraHop?expand_more
IRONATE NDR explains every alert in plain language, no opaque black-box AI. A complete SOC workspace (log hunting, host 360°, timeline, MITRE ATT&CK, case management) is built in. OT/ICS detection for 6 industrial protocols is included without an additional license. Custom detection rules can be validated with backtesting against historical logs. And the solution runs on-premises in your infrastructure, no US CLOUD Act.
What threats does IRONATE NDR detect?expand_more
35+ attack scenarios: C2 beaconing, DNS tunneling, lateral movement, port scanning, SSH/SMTP/RDP brute force, password spraying, data exfiltration, SSL/TLS anomalies, fast-flux DNS, typosquatting domains, SMB mass downloads, SQL injection, directory traversal, executable downloads, archive staging, Kerberoasting, LDAP enumeration, BITS transfers (T1197), ICMP tunneling, first-seen connections, OT control commands on unauthorized systems, IT→OT zone crossings and behavior-based anomalies without writing a single rule.
How long does implementation take?expand_more
IRONATE NDR is agentless and operational within 72 hours. The sensors are connected via mirror ports or network TAPs: no changes to network flow, no agents on endpoints. The AI starts building the baseline immediately.
Does IRONATE NDR support OT/ICS networks?expand_more
Yes, without an additional sensor and without an additional license. IRONATE NDR natively detects attacks on Modbus TCP, DNP3, EtherNet/IP, OPC-UA, Siemens S7comm and BACnet (building automation). Unauthorized control commands, write access to unknown registers and IT→OT zone crossings are detected immediately.
Can I write my own detection rules?expand_more
Yes. The built-in custom detection rule editor lets you write your own rules, including Sigma rule imports from the community. A backtesting function validates new rules against historical logs before they go live. No vendor involvement needed for rule changes.
What is the bulk IOC sweep?expand_more
The bulk IOC sweep matches up to 500 threat indicators (IPs, domains, hashes, URLs) against your historical network data at once, via CSV upload with automatic type detection. After a published threat report, you can immediately check whether your infrastructure is affected.
Is IRONATE NDR compliant with the FADP, GDPR and NIS2?expand_more
Yes. IRONATE NDR runs entirely in your infrastructure: no US CLOUD Act, no external dependencies. Complete audit trail (2-year retention by default), role-based access (admin/analyst), SSO integration with Microsoft 365 and MFA enforcement. Automatic compliance reports for the revised Swiss Data Protection Act (revDSG), FINMA, ISO 27001 and NIS2.
Which SOAR platforms are supported?expand_more
IRONATE NDR integrates natively with TheHive 5.x (correct schemas including TLP and observable mapping) and Cortex XSOAR. Webhook forwarding in 4 formats is also available, for any SOAR or SIEM platform.
Is there an AI assistant?expand_more
Yes. IRONATE NDR includes two AI functions: an autonomous triage agent (shadow/advisory/auto mode) and an interactive chat assistant for natural-language log queries; both run entirely on your own infrastructure. Supported LLM providers: OpenAI, Anthropic Claude, Ollama and vLLM (on-premises, no cloud required).
Which SSO providers are supported?expand_more
IRONATE NDR supports four SSO providers: Microsoft 365 (PKCE, no client secret required), Azure AD OAuth2, Google OAuth2 and SAML 2.0 (for any identity provider such as ADFS, Okta or Keycloak). MFA enforcement is available in all variants.
What company sizes is IRONATE NDR suitable for?expand_more
IRONATE NDR fits SMEs from 20 employees up to large enterprises with several thousand endpoints. Volume-based pricing starting at CHF 6.00 per entity/month makes the solution economically attractive for smaller companies as well.