Al momento questa pagina è disponibile solo in inglese.

Torna al blog

NDR vs EDR vs SIEM for teams without a SOC

NetSenX Team3 min di lettura
ndredrsiembuyers-guidemid-market

EDR protects the devices you can install an agent on, a SIEM collects and correlates logs from everything that produces them, and NDR watches the network traffic between all devices — including the ones that run no agent at all. For an IT team without a security operations centre (SOC), the practical order is usually EDR on every managed endpoint first, then NDR for the traffic and devices EDR cannot see, and a SIEM once someone has the time to write rules and read logs every day.

What each tool watches

EDRSIEMNDR
WatchesProcesses, files and memory on managed endpointsLogs from servers, firewalls, cloud services and applicationsNetwork traffic between hosts, inside and out
Catches wellMalware executing on a laptop or server; ransomware behaviour on the hostCorrelations across many systems; long-term retention; audit reportingCommand-and-control beaconing, scanning, lateral movement, unusual outbound data
Blind spotsDevices without an agent: printers, cameras, IoT, OT controllers, unmanaged laptopsAnything that does not write a log, or writes one nobody collectsWhat happens inside a host without touching the network; encrypted payload content
Effort to runLow to mediumHigh: parsing, rules and tuning never stopLow to medium
Usual pricing basisPer endpointPer volume of data ingestedPer monitored device, sensor or bandwidth

The three overlap less than it may seem. An attacker who lands on an unmanaged device is invisible to EDR, and a SIEM only sees it if something logs the activity. The same attacker still has to talk over the network — to a command-and-control server, to other hosts, to wherever the data goes — and that is what NDR sees. The MITRE ATT&CK framework lists lateral movement and command and control as distinct attacker tactics for exactly this reason: they happen between machines.

What to add first without a SOC

  1. EDR on every endpoint you manage. It blocks and records malicious activity on the host, and needs little daily attention once deployed.
  2. NDR for the network. It covers the devices EDR cannot, shows lateral movement between hosts, and gives you the incident timeline NIS2 reporting needs. Choose one whose alerts explain themselves: without analysts, an alert with no reason attached is an alert nobody acts on.
  3. A SIEM when you can staff it. A SIEM pays off when someone owns it — writing correlation rules, keeping parsers working and reviewing logs every day. Until then, the logs your regulator requires can often be kept without a full SIEM deployment.
  4. Consider MDR if you need 24/7 eyes. A managed detection and response service is people, not a tool: a provider watches your EDR, NDR or SIEM alerts around the clock.

Questions to ask before you buy an NDR

  • Does every alert say, in plain language, why it fired?
  • Is there a stated false-positive bound, and can you verify it on your own data?
  • Is the price list published, or is every deployment quoted?
  • Where is the monitoring data stored, and under which data processing agreement?
  • Can it read OT protocols passively, without probing controllers?

Our NDR vendor comparisons apply these questions to Darktrace, Vectra AI, ExtraHop and Nozomi Networks, with sources for every statement.

Where NetSenX fits

NetSenX is a Network Detection and Response (NDR) platform for EU mid-market organisations that detects attacks from network behaviour, explains every alert in plain language and keeps customer data in the EU. It works alongside EDR and SIEM, not instead of them: from the Business plan, alerts can be exported to the SIEM you already run. The Free plan covers up to 3 devices with no time limit, so you can see what it finds before deciding. Details are on the pricing page and in the FAQ. If NIS2 applies to you, the NIS2 network monitoring checklist is the next read.

Sources


Written by the NetSenX Team at TriStiX S.L. Questions: [email protected].

NetSenX Team

TriStiX S.L.