As ransomware actors increasingly evade traditional defenses, Sophos has introduced a Network Detection and Response (NDR) module designed to illuminate the internal shadows most tools miss. Integrated with the company’s existing XDR and MDR offerings, the NDR platform monitors east-west traffic across networks and flags anomalous behavior in environments often beyond the reach of firewalls and endpoint agents.Unlike traditional perimeter-focused tools, Sophos NDR is deployed as a virtual appliance on platforms such as VMware, Hyper-V, and AWS. It connects directly to network switches via SPAN port mirroring, enabling visibility into unmanaged devices, rogue endpoints, and encrypted traffic patterns without decrypting payloads or exposing PII.Key use cases include identifying compromised IoT/OT assets, detecting suspicious off-hours network activity, and surfacing new or zero-day command-and-control traffic. According to Sophos, the engine inspects encrypted flows using behavioral analytics—rather than relying solely on known IOCs or signatures—to detect bespoke or emerging threats in real time.
NDR, Network Security, Ransomware
New NDR tool targets blind spots inside the network

An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



