Security Stack Logo
Open NDR Platform logo

Network & Infrastructure Security

Open NDR Platform

Open, Zeek-based NDR turning raw network traffic into structured forensic evidence.

Open NDR Platform Overview

What it does

Open NDR Platform is a Network Detection and Response (NDR) platform built on the open-source Zeek monitoring engine, generating structured forensic evidence from raw network traffic instead of relying on opaque, black-box alerts. It combines Zeek network security monitoring, Suricata intrusion-detection signatures, YARA file analysis, and transparent AI and machine-learning detections, so analysts see inspectable evidence and detection logic rather than an unexplained verdict. The open architecture avoids proprietary lock-in and interoperates with a customer's existing security stack.

How it works

Sensors deploy as physical appliances, virtual machines, cloud sensors across AWS, Azure, and GCP, or flow-log sensors, tapping traffic out of band and transforming it into structured Zeek logs, Suricata intrusion-detection alerts, YARA file detections, and Smart PCAP capture for retrospective forensics. Fleet Manager orchestrates machine-learning detection collections across the sensor fleet, while the Investigator module adds agentic triage and natural-language investigation that correlates related detections into incident timelines. Pre-correlated evidence and prioritized alerts feed native integrations with CrowdStrike Falcon, Microsoft Sentinel, and Splunk across Security Information and Event Management (SIEM), Extended Detection and Response (XDR), and orchestration platforms.

Credentials and traction

Named a Leader in the inaugural 2025 Gartner Magic Quadrant for Network Detection and Response and in The Forrester Wave: Network Analysis and Visibility Solutions, Q4 2025. The platform has reached FedRAMP Moderate In Process status on the FedRAMP Marketplace. Built on Zeek, the open-source network security monitoring standard created by co-founder Vern Paxson, it gives buyers inspectable, non-proprietary detection logic, and protects government agencies and large regulated enterprises across financial services, energy, healthcare, and transportation.

Key Capabilities

mapped to solution categories
Network Detection and Response (NDR)

Lets an AI agent investigate a confirmed network threat and propose or execute containment actions, such as isolating a host or blocking a flow, under configurable human approval gates that move response from manual sign-off toward conditional autonomy, rather than only firing fixed playbooks.

Detects employee and workload use of unsanctioned AI services, agents, and Model Context Protocol connections from network traffic, and exposes which assets are sending data to which AI endpoints, so shadow AI use and risky agent-to-tool traffic are visible without endpoint agents.

Captures and retains full packets (PCAP) at scale alongside flow and metadata records, with long-term retention and session reconstruction or replay, so analysts can pivot from an alert to the exact underlying packets and run retroactive investigations against historical traffic. Metadata-only products that retain no packets do not qualify.

Runs traditional detection alongside behavioral analytics: intrusion-detection signatures (Suricata or Zeek rule sets and vendor IPS signatures), rule-based heuristics, and threshold alerts, with support for importing community rules and authoring custom rules, so known exploits and indicators are caught deterministically and analysts can codify their own detections.

Assigns a risk score to each detection and affected entity from threat severity, detection certainty, and asset or account importance, with adjustable scoring, so response effort goes to the highest-risk hosts and accounts first rather than to the newest alert.

Discovers every device communicating on the network and assembles a continuously updated inventory with device type, role, protocols in use, and communication paths, grouping and tracking entities across address changes (for example through a knowledge graph) and tagging criticality and exposure, so risk scoring and investigations start from an accurate map of what is on the network.

Discovers and inventories cyber-physical system assets (OT, ICS, IoT, and medical devices) and their communication channels from the same sensors that monitor IT traffic, baselines normal CPS activity and alerts on deviations, and parses industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC UA) for deep inspection, so IT and CPS attacks are detected and correlated in one NDR console. Protocol depth and CPS asset detail vary widely across NDR products.

Identifies weak, outdated, or deprecated cryptographic algorithms and protocols observed in network traffic, such as legacy TLS versions, cipher suites, and hashing algorithms, and separately flags algorithms susceptible to being broken by quantum computers, so security teams can inventory cryptographic exposure per asset and plan post-quantum migration.

Uses an AI assistant to qualify and triage network detections inside the NDR console, explaining each anomaly in plain language, assembling related detections into an incident narrative, and recommending the next investigation or response step, so analysts spend less time on first-pass triage of network alerts.

Provides a natural-language search assistant over network metadata, detections, and entities, so analysts can ask hunting questions in plain language, receive generated queries and summarized results, and pivot across hosts, accounts, and sessions without writing query syntax. Distinct from AI-assisted triage, which qualifies detections rather than answering analyst queries.

Aggregates related network alerts into structured incidents that link the hosts, accounts, and detections of one attack, reducing alert volume and giving analysts one case to investigate and respond to instead of disconnected events.

Matches observed traffic against continuously updated threat-intelligence feeds, both the vendor's global intelligence and customer-imported internal or third-party feeds, to recognize malicious infrastructure, command-and-control patterns, and known indicators, and enriches detections with the matching intelligence context.

Detects threats inside TLS-encrypted sessions either without decryption, through JA3, JA4, and certificate fingerprinting plus behavioral analysis of encrypted flows, or through on-appliance decryption where keys are available for full payload inspection. Fingerprint-only analysis is now standard across NDR; on-appliance decryption, JA4 support, and detection quality on encrypted command-and-control are the differentiators.

Shows analysts the reasoning behind each machine-learning or behavioral detection, such as the baseline deviated from, the contributing signals, and the model's confidence, so alerts can be validated and tuned rather than trusted as opaque outputs.

Parses raw traffic with deep packet inspection into structured, protocol-level metadata records, such as Zeek-style connection, DNS, HTTP, and TLS logs, and enriches them at collection or analysis time with asset, user, geolocation, and threat-intelligence context, producing hunt-ready evidence that is retained far longer than packets and exportable to a SIEM or data lake.

Learns per-entity baselines of normal network behavior for devices, users, and applications, typically with unsupervised or self-learning models that need little manual tuning, and detects deviations that reveal insider threats, external attacks, and advanced persistent threats, including novel command-and-control, data staging, and lateral movement. Detection quality separates products: self-learning models with minimal tuning versus rule-primary engines with limited machine learning.

Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.

Compliance

certifications
FedRAMP ModerateFIPS 140-2

Integrations

compatible tools
CriblCrowdStrike FalconDevoElastic SecurityExabeamGreyNoiseMicrosoft DefenderMicrosoft SentinelPalo Alto NetworksReversingLabsSecuronixSentinelOneServiceNowSplunk Enterprise SecuritySplunk SOARStellar CyberSumo LogicTenable

Implementation & support

Deployment model
Air-GappedCloudHybridNetwork ApplianceOn-PremisesSaaS
Support channels
24/7 SupportDocumentationEmail SupportKnowledge BasePhone SupportTechnical Account Manager (TAM)Ticketing Portal

Info last updated on September 7, 2026

Buyers

See how Open NDR Platform fits your stack

Add Open NDR Platform to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.