100% of network flows inspected continuously. Wybot's NDR detects intrusions and advanced threats where EDRs, firewalls and antivirus have no visibility.
Every cyberattack, to succeed, must communicate: reconnaissance, lateral movements, contact with a command server, exfiltration. These exchanges inevitably leave a trace in network traffic.
Wybot's NDR (Network Detection & Response) inspects all of this traffic, north-south and east-west, to reveal the malicious behaviour that perimeter defences let through, then alert and block.
North-south (Internet) and east-west (internal) traffic analysed continuously, with no blind spot.
The nDPI engine identifies applications and protocols, including hidden or suspiciously encrypted flows.
Detection of connections to illegitimate IP addresses and domain names, including the Darknet.
Spots an attacker spreading from one machine to another within the network.
Recognition of known attack patterns and abnormal network behaviour.
Blocking of illegitimate flows and instant alert: notification, e-mail & mobile app.
The probe receives a copy of the traffic via the switch or firewall, with no outage and no added latency.
The 8 engines analyse flows continuously; a few GB/day is enough, without affecting performance.
Physical appliance (up to 10,000 devices) or virtualised version with no device limit.
An NDR demonstration on your environment, in a few minutes of installation.