Security Stack Logo
RevealX NDR logo

Network & Infrastructure Security

RevealX NDR

Wire-data NDR with out-of-band decryption, full packet capture, and cloud-scale ML detection.

Network Detection and Response (NDR)

RevealX NDR Overview

What it does

RevealX NDR is a network detection and response (NDR) platform built on wire data, the reconstruction and analysis of network packets and transactions rather than logs or endpoint agents. Its differentiator is out-of-band decryption: RevealX decrypts traffic at up to 100 Gbps across more than 90 network and application protocols without operating inline, exposing credential abuse, privilege escalation, and lateral movement that stay hidden inside encrypted sessions for metadata-only sensors.

How it works

Passive sensors in physical, virtual, cloud, and container form factors tap traffic out of band and feed a cloud-scale machine learning pipeline that baselines behavior and maps detections to the MITRE ATT&CK framework. An integrated intrusion detection system adds curated signatures, STIX and TAXII feeds match threat-intelligence indicators, and a Packet Forensics store retains full packets for retrospective investigation. An AI Search Assistant turns natural-language questions into queries, while coverage spans data center, AWS, Azure, Google Cloud, and industrial protocols including DNP3 and Modbus. RevealX is delivered as the RevealX 360 cloud service or self-managed.

Credentials and traction

RevealX holds FedRAMP Moderate authorization for RevealX Federal (2025) and maintains SOC 2 Type II, SOC 3, and HIPAA attestations. ExtraHop is a Leader in the 2026 Gartner Magic Quadrant for Network Detection and Response, its second consecutive year, and a Leader in the Forrester Wave for Network Analysis and Visibility Solutions (Q4 2025). Its customers include government agencies, financial institutions, healthcare providers, and energy and utilities operators.

Key Capabilities

mapped to solution categories
Network Detection and Response (NDR)

Performs retroactive and forensic analysis using network flow data and scalable full-packet capture with long-term retention.

Includes traditional detection such as IDPS signatures, rule-based heuristics and threshold alerts alongside behavioral analytics.

Performs deep packet inspection on industrial protocols (Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC-UA), for behavioral monitoring of OT environments alongside IT network analysis.

Integrates with firewalls, NAC platforms, and switches to automatically block or quarantine hosts and traffic flows in response to confirmed detections, without requiring analyst-initiated action.

Uses an AI-based search assistant to accelerate threat hunting and surface actionable insights.

Groups related network alerts into structured incidents that reconstruct an attack across hosts and time, reducing alert volume and giving analysts a single investigation timeline instead of disconnected events.

Detects threats using intelligence feeds from internal and external sources.

Detects threats in TLS-encrypted traffic using JA3/JA3S fingerprinting, certificate anomaly detection, and traffic behavioral analysis, without requiring decryption.

Monitors lateral movement traffic between internal network segments and hosts, distinct from perimeter monitoring. Requires network tap or span port placement on internal switch infrastructure.

Builds per-device and per-application baselines of normal network communication patterns and detects deviations, enabling detection of novel C2 channels, data staging, and lateral movement.

Extends network detection to cloud VPC traffic using VPC flow log analysis, cloud-native sensors, or mirroring, covering east-west traffic between cloud workloads.

Compliance

certifications
CSA STAR Level 1FedRAMP ModerateHIPAASOC 2 Type IISOC 3

Integrations

compatible tools
AWS Security LakeCheck PointCrowdStrikeFortinetGoogle Security OperationsIBM QRadarMicrosoft Defender for EndpointMicrosoft SentinelPalo Alto Cortex XSOARPalo Alto PanoramaSentinelOneServiceNowSplunkZscaler

Implementation & support

Deployment model
Air-GappedHybridNetwork ApplianceOn-PremisesSaaS
Support channels
DocumentationProfessional ServicesTicketing PortalTraining

Info last updated on August 12, 2026

Buyers

See how RevealX NDR fits your stack

Add RevealX NDR to your shortlist and unlock all evaluation tools.

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

Resources

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.