Security Stack Logo
Gatewatcher NDR Platform logo

Network & Infrastructure Security

Gatewatcher NDR Platform

Multi-engine NDR pairing passive capture with contextual decision support and automated response.

Gatewatcher NDR Platform Overview

What it does

Gatewatcher NDR Platform is a multi-engine Network Detection and Response (NDR) platform that detects known, unknown, and hidden threats across IT, OT, and cloud networks, covering zero-days, encrypted traffic threats, and past compromises through retro-hunt analysis. Its architecture pairs passive multi-source network capture with a decision layer that evaluates each threat on context, adversary intent, and business impact, and its preconfigured engines detect from the moment of deployment without requiring a learning baseline. An ANSSI-qualified Trackwatch range serves restricted and classified French environments.

How it works

Three components form the platform: Sensor captures traffic passively through deep packet inspection on hardware or virtual appliances, with no agents; Detection Center runs static, heuristic, and machine learning engines over network metadata, maintaining a live asset inventory with contextual risk scoring; and Decision Center correlates alerts with Endpoint Detection and Response (EDR), firewall, and data lake sources, qualifies indicators of compromise, filters false positives, and produces explainable action plans validated by analysts. Reflex automates response orchestration, Cockpit prioritizes incident handling, the LastInfoSec threat intelligence feed enriches detections, and GTAP taps with the Deep Visibility appliance extend coverage.

Credentials and traction

The Trackwatch certified range holds an ANSSI Visa de Sécurité qualification, first granted in 2019 and renewed in 2024, including a first-level security certification (CSPN). Gatewatcher was named a Niche Player in the 2026 Gartner Magic Quadrant for Network Detection and Response, after being the sole Visionary of the inaugural 2025 edition, and won TEISS Awards for Best AI/ML and Best Network plus a Computing Security Award in 2024. Named customers include KNDS France, Lynred, GHT Vaucluse, and Leeds United.

Key Capabilities

mapped to solution categories
Network Detection and Response (NDR)

Performs retroactive and forensic analysis using network flow data and scalable full-packet capture with long-term retention.

Includes traditional detection such as IDPS signatures, rule-based heuristics and threshold alerts alongside behavioral analytics.

Performs deep packet inspection on industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC-UA), for behavioral monitoring of OT environments alongside IT network analysis.

Integrates with firewalls, NAC platforms, and switches to automatically block or quarantine hosts and traffic flows in response to confirmed detections, without requiring analyst-initiated action.

Uses an AI-based search assistant to accelerate threat hunting and surface actionable insights.

Groups related network alerts into structured incidents that reconstruct an attack across hosts and time, reducing alert volume and giving analysts a single investigation timeline instead of disconnected events.

Detects threats using intelligence feeds from internal and external sources.

Detects threats in TLS-encrypted traffic using JA3/JA3S fingerprinting, certificate anomaly detection, and traffic behavioral analysis, without requiring decryption.

Monitors lateral movement traffic between internal network segments and hosts, distinct from perimeter monitoring. Requires network tap or span port placement on internal switch infrastructure.

Builds per-device and per-application baselines of normal network communication patterns and detects deviations, enabling detection of novel C2 channels, data staging, and lateral movement.

Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.

Compliance

certifications
ANSSI CSPNGDPRNIS2 Directive

Integrations

compatible tools
AnomaliAzure ADFortinetGigamonGlimpsHarfangLabIBM QRadarKeysightNozomi NetworksO365OpenCTIOrion MalwarePalo Alto NetworksPradeoSekoiaSentinelOneSplunkVadeWallix

Implementation & support

Deployment model
Air-GappedCloudHybridNetwork ApplianceOn-Premises
Support channels
Email SupportTicketing Portal

Info last updated on August 23, 2026

Buyers

See how Gatewatcher NDR Platform fits your stack

Add Gatewatcher NDR Platform to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.