Security Stack Logo
Gatewatcher NDR Platform logo

Network & Infrastructure Security

Gatewatcher NDR Platform

Multi-engine NDR pairing passive capture with contextual decision support and automated response.

Gatewatcher NDR Platform Overview

What it does

Gatewatcher NDR Platform is a multi-engine Network Detection and Response (NDR) platform that detects known, unknown, and hidden threats across IT, OT, and cloud networks, covering zero-days, encrypted traffic threats, and past compromises through retro-hunt analysis. Its architecture pairs passive multi-source network capture with a decision layer that evaluates each threat on context, adversary intent, and business impact, and its preconfigured engines detect from the moment of deployment without requiring a learning baseline. An ANSSI-qualified Trackwatch range serves restricted and classified French environments.

How it works

Three components form the platform: Sensor captures traffic passively through deep packet inspection on hardware or virtual appliances, with no agents; Detection Center runs static, heuristic, and machine learning engines over network metadata, maintaining a live asset inventory with contextual risk scoring; and Decision Center correlates alerts with Endpoint Detection and Response (EDR), firewall, and data lake sources, qualifies indicators of compromise, filters false positives, and produces explainable action plans validated by analysts. Reflex automates response orchestration, Cockpit prioritizes incident handling, the LastInfoSec threat intelligence feed enriches detections, and GTAP taps with the Deep Visibility appliance extend coverage.

Credentials and traction

The Trackwatch certified range holds an ANSSI Visa de Sécurité qualification, first granted in 2019 and renewed in 2024, including a first-level security certification (CSPN). Gatewatcher was named a Niche Player in the 2026 Gartner Magic Quadrant for Network Detection and Response, after being the sole Visionary of the inaugural 2025 edition, and won TEISS Awards for Best AI/ML and Best Network plus a Computing Security Award in 2024. Named customers include KNDS France, Lynred, GHT Vaucluse, and Leeds United.

Key Capabilities

mapped to solution categories
Network Detection and Response (NDR)

Discovers and inventories cyber-physical system assets (OT, ICS, IoT, and medical devices) and their communication channels from the same sensors that monitor IT traffic, baselines normal CPS activity and alerts on deviations, and parses industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC UA) for deep inspection, so IT and CPS attacks are detected and correlated in one NDR console. Protocol depth and CPS asset detail vary widely across NDR products.

Executes containment automatically on confirmed detections: isolating infected hosts, blocking malicious traffic, or disabling compromised accounts, either natively (for example through the vendor's own switches, firewalls, or inline sensors) or through integrations with firewalls, NAC, EDR, SASE or SSE, and SOAR platforms. Whether enforcement is native or integration-dependent is the primary buying distinction.

Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.

Detects threats inside TLS-encrypted sessions either without decryption, through JA3, JA4, and certificate fingerprinting plus behavioral analysis of encrypted flows, or through on-appliance decryption where keys are available for full payload inspection. Fingerprint-only analysis is now standard across NDR; on-appliance decryption, JA4 support, and detection quality on encrypted command-and-control are the differentiators.

Learns per-entity baselines of normal network behavior for devices, users, and applications, typically with unsupervised or self-learning models that need little manual tuning, and detects deviations that reveal insider threats, external attacks, and advanced persistent threats, including novel command-and-control, data staging, and lateral movement. Detection quality separates products: self-learning models with minimal tuning versus rule-primary engines with limited machine learning.

Aggregates related network alerts into structured incidents that link the hosts, accounts, and detections of one attack, reducing alert volume and giving analysts one case to investigate and respond to instead of disconnected events.

Runs traditional detection alongside behavioral analytics: intrusion-detection signatures (Suricata or Zeek rule sets and vendor IPS signatures), rule-based heuristics, and threshold alerts, with support for importing community rules and authoring custom rules, so known exploits and indicators are caught deterministically and analysts can codify their own detections.

Matches observed traffic against continuously updated threat-intelligence feeds, both the vendor's global intelligence and customer-imported internal or third-party feeds, to recognize malicious infrastructure, command-and-control patterns, and known indicators, and enriches detections with the matching intelligence context.

Captures and retains full packets (PCAP) at scale alongside flow and metadata records, with long-term retention and session reconstruction or replay, so analysts can pivot from an alert to the exact underlying packets and run retroactive investigations against historical traffic. Metadata-only products that retain no packets do not qualify.

Extracts files and payloads from network sessions and analyzes them in a built-in sandbox and layered malware engines, combining static and dynamic analysis, so suspicious downloads and attachments are classified inside the NDR platform without handing them to a separate third-party sandbox.

Uses an AI assistant to qualify and triage network detections inside the NDR console, explaining each anomaly in plain language, assembling related detections into an incident narrative, and recommending the next investigation or response step, so analysts spend less time on first-pass triage of network alerts.

Runs behavioral detection, machine-learning models, and AI assistance entirely on local sensors and management appliances, with no cloud-tethered analysis or external data sharing, so detection quality is undiminished in air-gapped, sovereign, or disconnected environments.

Renders the network events, entities, and detections of an incident on an interactive timeline or attack graph, so analysts can reconstruct the sequence of an intrusion across hosts and time and see the path an attacker took through the environment.

Assigns a risk score to each detection and affected entity from threat severity, detection certainty, and asset or account importance, with adjustable scoring, so response effort goes to the highest-risk hosts and accounts first rather than to the newest alert.

Parses raw traffic with deep packet inspection into structured, protocol-level metadata records, such as Zeek-style connection, DNS, HTTP, and TLS logs, and enriches them at collection or analysis time with asset, user, geolocation, and threat-intelligence context, producing hunt-ready evidence that is retained far longer than packets and exportable to a SIEM or data lake.

Discovers every device communicating on the network and assembles a continuously updated inventory with device type, role, protocols in use, and communication paths, grouping and tracking entities across address changes (for example through a knowledge graph) and tagging criticality and exposure, so risk scoring and investigations start from an accurate map of what is on the network.

Compliance

certifications
ANSSI CSPNGDPRNIS2 Directive

Integrations

compatible tools
AnomaliAzure ADFortinetGigamonGlimpsHarfangLabIBM QRadarKeysightNozomi NetworksO365OpenCTIOrion MalwarePalo Alto NetworksPradeoSekoiaSentinelOneSplunkVadeWallix

Implementation & support

Deployment model
Air-GappedCloudHybridNetwork ApplianceOn-Premises
Support channels
Email SupportTicketing Portal

Info last updated on September 7, 2026

Buyers

Start a shortlist with Gatewatcher NDR Platform

Compare options, add your notes, and run informed evaluations.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.