<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>News Portal &#45; NetWitness</title>
<link>https://www.albuquerquenewstimes.com/rss/author/netwitness</link>
<description>News Portal &#45; NetWitness</description>
<dc:language>en</dc:language>
<dc:rights>Copyright 2025 albuquerquenewstimes.com &#45; All Rights Reserved.</dc:rights>

<item>
<title>Collaborative Threat Detection with Network Detection and Response (NDR)</title>
<link>https://www.albuquerquenewstimes.com/collaborative-threat-detection-with-network-detection-and-response-ndr</link>
<guid>https://www.albuquerquenewstimes.com/collaborative-threat-detection-with-network-detection-and-response-ndr</guid>
<description><![CDATA[ Collaborative Threat Detection with NDR refers to how teams and technologies work together using Network Detection and Response (NDR). ]]></description>
<enclosure url="https://www.albuquerquenewstimes.com/uploads/images/202507/image_870x580_68775ff66fa94.jpg" length="68959" type="image/jpeg"/>
<pubDate>Wed, 16 Jul 2025 23:21:22 +0600</pubDate>
<dc:creator>NetWitness</dc:creator>
<media:keywords>network detection and response, ndr, ndr solutions, ndr platforms</media:keywords>
<content:encoded><![CDATA[<p>Collaborative Threat Detection with NDR refers to how teams and technologies work together using Network Detection and Response (NDR) to identify threats faster, more accurately, and in context.</p>
<p></p>
<h2 data-start="217" data-end="262"><strong>What Is Collaborative Threat Detection?</strong></h2>
<p data-start="264" data-end="335">Its the <strong data-start="273" data-end="331">joint effort of cybersecurity tools and human analysts</strong> to:</p>
<ul data-start="337" data-end="516">
<li data-start="337" data-end="377">
<p data-start="339" data-end="377">Detect anomalies or malicious activity</p>
</li>
<li data-start="378" data-end="439">
<p data-start="380" data-end="439">Correlate signals across systems (network, endpoint, cloud)</p>
</li>
<li data-start="440" data-end="481">
<p data-start="442" data-end="481">Share insights and escalate efficiently</p>
</li>
<li data-start="482" data-end="516">
<p data-start="484" data-end="516">Prioritize real threats vs noise</p>
</li>
</ul>
<p data-start="518" data-end="665">When <strong data-start="523" data-end="541"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR solutions</a> </strong>is central to this, it becomes the core of network-based visibility and detection, powering collaboration across people and tools.</p>
<p data-start="518" data-end="665"></p>
<h2 data-start="672" data-end="709"><strong>What Does NDR Do in This Model?</strong></h2>
<p data-start="711" data-end="772">NDR acts as a <strong data-start="725" data-end="747">sensor and analyst</strong> within your environment.</p>
<div class="_tableContainer_80l1q_1">
<div class="_tableWrapper_80l1q_14 group flex w-fit flex-col-reverse" tabindex="-1">
<table data-start="774" data-end="1357" class="w-fit min-w-(--thread-content-width)" style="width: 101.578%;">
<thead data-start="774" data-end="809">
<tr data-start="774" data-end="809">
<th data-start="774" data-end="784" data-col-size="sm" style="width: 34.9874%;">Feature</th>
<th data-start="784" data-end="809" data-col-size="md" style="width: 64.9547%;">Role in Collaboration</th>
</tr>
</thead>
<tbody data-start="846" data-end="1357">
<tr data-start="846" data-end="957">
<td data-start="846" data-end="873" data-col-size="sm" style="width: 34.9874%;"><strong data-start="848" data-end="872">Deep Packet Analysis</strong></td>
<td data-start="873" data-end="957" data-col-size="md" style="width: 64.9547%;">Gives analysts detailed context (e.g., DNS lookups, encrypted traffic behaviors)</td>
</tr>
<tr data-start="958" data-end="1055">
<td data-start="958" data-end="992" data-col-size="sm" style="width: 34.9874%;"><strong data-start="960" data-end="991">Anomaly Detection via AI/ML</strong></td>
<td data-col-size="md" data-start="992" data-end="1055" style="width: 64.9547%;">Flags patterns humans might miss  shared with SOC/IR teams</td>
</tr>
<tr data-start="1056" data-end="1144">
<td data-start="1056" data-end="1089" data-col-size="sm" style="width: 34.9874%;"><strong data-start="1058" data-end="1088">Lateral Movement Detection</strong></td>
<td data-start="1089" data-end="1144" data-col-size="md" style="width: 64.9547%;">Enables IT teams to isolate infected systems faster</td>
</tr>
<tr data-start="1145" data-end="1240">
<td data-start="1145" data-end="1182" data-col-size="sm" style="width: 34.9874%;"><strong data-start="1147" data-end="1181">Integration with SIEM/EDR/SOAR</strong></td>
<td data-start="1182" data-end="1240" data-col-size="md" style="width: 64.9547%;">Allows real-time alert sharing and automated playbooks</td>
</tr>
<tr data-start="1241" data-end="1357">
<td data-start="1241" data-end="1278" data-col-size="sm" style="width: 34.9874%;"><strong data-start="1243" data-end="1277">Threat Intelligence Enrichment</strong></td>
<td data-start="1278" data-end="1357" data-col-size="md" style="width: 64.9547%;">Adds value to analyst decisions with IOCs, risk scores, and behavioral tags</td>
</tr>
</tbody>
</table>
</div>
</div>
<p data-start="518" data-end="665"></p>
<h2 data-start="1364" data-end="1420"><strong>Collaborative Threat Detection Ecosystem (Example)</strong></h2>
<h3 data-start="1422" data-end="1461">Flow of Detection Collaboration:</h3>
<ol data-start="1463" data-end="1954">
<li data-start="1463" data-end="1546">
<p data-start="1466" data-end="1546"><strong data-start="1466" data-end="1481"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR platforms</a> detects</strong> unusual internal traffic (e.g., beaconing or data exfiltration).</p>
</li>
<li data-start="1547" data-end="1622">
<p data-start="1550" data-end="1622"><strong data-start="1550" data-end="1569">SIEM Correlates</strong> with other signals (failed logins, endpoint alerts).</p>
</li>
<li data-start="1623" data-end="1699">
<p data-start="1626" data-end="1699"><strong data-start="1626" data-end="1647">SOAR Orchestrates</strong> enrichment (threat intel, geolocation, asset data).</p>
</li>
<li data-start="1700" data-end="1811">
<p data-start="1703" data-end="1811"><strong data-start="1703" data-end="1727">Analysts Collaborate</strong> using dashboards, chat tools (e.g. Slack, Microsoft Teams), or ticketing platforms.</p>
</li>
<li data-start="1812" data-end="1880">
<p data-start="1815" data-end="1880"><strong data-start="1815" data-end="1832">EDR Validates</strong> if the endpoint also shows compromise behavior.</p>
</li>
<li data-start="1881" data-end="1954">
<p data-start="1884" data-end="1954"><strong data-start="1884" data-end="1915"><a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">Incident Response</a> Escalates</strong> or automates based on shared findings.</p>
</li>
</ol>
<p data-start="518" data-end="665"></p>
<h2 data-start="1961" data-end="1986"><strong>Real-World Use Case</strong></h2>
<p data-start="1988" data-end="2040"><strong data-start="1988" data-end="2040">Scenario: Ransomware Propagation Detected by NDR</strong></p>
<ul data-start="2042" data-end="2457">
<li data-start="2042" data-end="2107">
<p data-start="2044" data-end="2107"><a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR solutions</a> identifies suspicious SMB write behavior to multiple hosts.</p>
</li>
<li data-start="2108" data-end="2170">
<p data-start="2110" data-end="2170">SOC analysts are alerted and use packet captures to confirm.</p>
</li>
<li data-start="2171" data-end="2241">
<p data-start="2173" data-end="2241">EDR tools are queried for process execution and encryption attempts.</p>
</li>
<li data-start="2242" data-end="2302">
<p data-start="2244" data-end="2302">The SOAR system isolates affected devices and notifies IT.</p>
</li>
<li data-start="2303" data-end="2379">
<p data-start="2305" data-end="2379">The <a href="https://www.netwitness.com/services/incident-response/" rel="nofollow">incident response</a> (IR) team uses historical NDR logs to trace the initial infection point.</p>
</li>
<li data-start="2380" data-end="2457">
<p data-start="2382" data-end="2457">Lessons learned are fed into detection rule updates and tabletop exercises.</p>
</li>
</ul>
<p data-start="518" data-end="665"></p>
<h2 data-start="2464" data-end="2521"><strong>Benefits of Collaborative Threat Detection with NDR</strong></h2>
<ul data-start="2523" data-end="2752">
<li data-start="2523" data-end="2577">
<p data-start="2525" data-end="2577">Fewer false positives (thanks to shared context)</p>
</li>
<li data-start="2578" data-end="2617">
<p data-start="2580" data-end="2617">Faster mean time to detect (MTTD)</p>
</li>
<li data-start="2618" data-end="2656">
<p data-start="2620" data-end="2656">Greater organizational alignment</p>
</li>
<li data-start="2657" data-end="2692">
<p data-start="2659" data-end="2692">More effective threat hunting</p>
</li>
<li data-start="2693" data-end="2752">
<p data-start="2695" data-end="2752">Resilience across hybrid environments (cloud/on-prem)</p>
</li>
</ul>
<p data-start="518" data-end="665"></p>
<h2 data-start="2759" data-end="2775">Want More?</h2>
<ul data-start="2792" data-end="2979">
<li data-start="2792" data-end="2849">
<p data-start="2794" data-end="2849">A <strong data-start="2796" data-end="2849">diagram of a collaborative detection architecture</strong></p>
</li>
<li data-start="2850" data-end="2904">
<p data-start="2852" data-end="2904">A <strong data-start="2854" data-end="2873">sample playbook</strong> for NDR-based threat detection</p>
</li>
<li data-start="2905" data-end="2979">
<p data-start="2907" data-end="2979">A <strong data-start="2909" data-end="2923">comparison</strong> of top <a href="https://www.netwitness.com/modules/network-detection-and-response-ndr/" rel="nofollow">NDR solutions</a> (e.g. NetWitness, Vectra, Darktrace, ExtraHop)</p>
</li>
</ul>
<p data-start="518" data-end="665"></p>]]> </content:encoded>
</item>

</channel>
</rss>