Security Stack Logo
Exeon.NDR logo

Network & Infrastructure Security

Exeon.NDR

Hardware-free network detection with metadata analysis for encrypted traffic visibility.

Exeon.NDR Overview

What it does

Exeon.NDR (ExeonTrace until July 2025) is a Network Detection and Response (NDR) platform that finds attackers already inside IT, OT, and cloud networks by analyzing network metadata instead of mirrored packets. Its distinctive mechanism is sensor-free collection: flow and log records exported from existing switches, firewalls, DNS servers, proxies, and cloud platforms feed supervised and unsupervised machine learning models, so detection is unaffected by TLS encryption and needs no appliances, agents, or traffic mirroring. The analytics originated in research at ETH Zürich.

How it works

The pipeline runs in four stages: log collection from routers, switches, firewalls, DNS and proxy servers, and cloud flow logs (AWS, Azure, Google Cloud); processing that normalizes and enriches the metadata into a communication map held in a graph database; detection layered from pretrained supervised models, on-site unsupervised baselining, static expert rules, and indicator-of-compromise matching; and risk-based alerting that stitches related alerts into one incident storyline with user, asset, and location context. Alerts flow through REST and syslog APIs into SIEM and SOAR tooling, where playbooks quarantine hosts or block flows. Customers include PostFinance, SWISS International Airlines, WinGD, and Planzer.

Credentials and traction

ISO 27001 certified, with metadata-only analytics built for GDPR-compliant, locally retained data and reporting templates for NIS2 and DORA evidence. Exeon.NDR supported the joint blue team that placed second at NATO Locked Shields 2026, and Exeon ranked among Switzerland's top three high-tech companies at the Swiss Economic Forum in 2021. Named customers include PostFinance, SWISS International Airlines, Swisscom, WinGD, Mobiliar, the University of St. Gallen, Klinikum Dortmund, and LGT across European finance, aviation, manufacturing, healthcare, and government.

Key Capabilities

mapped to solution categories
Network Detection and Response (NDR)

Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.

Detects threats inside TLS-encrypted sessions either without decryption, through JA3, JA4, and certificate fingerprinting plus behavioral analysis of encrypted flows, or through on-appliance decryption where keys are available for full payload inspection. Fingerprint-only analysis is now standard across NDR; on-appliance decryption, JA4 support, and detection quality on encrypted command-and-control are the differentiators.

Learns per-entity baselines of normal network behavior for devices, users, and applications, typically with unsupervised or self-learning models that need little manual tuning, and detects deviations that reveal insider threats, external attacks, and advanced persistent threats, including novel command-and-control, data staging, and lateral movement. Detection quality separates products: self-learning models with minimal tuning versus rule-primary engines with limited machine learning.

Executes containment automatically on confirmed detections: isolating infected hosts, blocking malicious traffic, or disabling compromised accounts, either natively (for example through the vendor's own switches, firewalls, or inline sensors) or through integrations with firewalls, NAC, EDR, SASE or SSE, and SOAR platforms. Whether enforcement is native or integration-dependent is the primary buying distinction.

Aggregates related network alerts into structured incidents that link the hosts, accounts, and detections of one attack, reducing alert volume and giving analysts one case to investigate and respond to instead of disconnected events.

Attributes network activity and detections to users and accounts by ingesting identity provider, directory, and SSE or SASE telemetry, correlating network anomalies with user behavior and distinguishing on-premises users from remote workers, so lateral movement and insider activity are traced to an identity rather than only to an IP address.

Assigns a risk score to each detection and affected entity from threat severity, detection certainty, and asset or account importance, with adjustable scoring, so response effort goes to the highest-risk hosts and accounts first rather than to the newest alert.

Learns from analyst dispositions and confirmed benign patterns to suppress recurring false positives and adjust detection thresholds automatically after the initial learning period, keeping the alert stream trustworthy enough to drive automated response.

Discovers every device communicating on the network and assembles a continuously updated inventory with device type, role, protocols in use, and communication paths, grouping and tracking entities across address changes (for example through a knowledge graph) and tagging criticality and exposure, so risk scoring and investigations start from an accurate map of what is on the network.

Compliance

certifications
GDPRHIPAAISO 27001NIS2 Directive

Integrations

compatible tools
AWSAzureDNS ServersEDR PlatformsFirewall SystemsGoogle Cloud PlatformIPS SystemsNetwork Infrastructure (Routers, Switches)Proxy ServersSecure Web GatewaysSIEM PlatformsSOAR PlatformsXDR Platforms

Implementation & support

Deployment model
Air-GappedCloudHybridOn-PremisesPrivate Cloud
Support channels
Email SupportTicketing Portal

Info last updated on September 7, 2026

Buyers

Start a shortlist with Exeon.NDR

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.