Cyberattacks such as ransomware, fraud, credential theft, and data leaks are now routine, pushing IT teams to deploy many specialized security tools. Network Detection & Response (NDR) is positioned as a next-generation evolution of intrusion detection: it uses multiple machine learning techniques to establish baselines and identify anomalous traffic, addressing historical IDS drawbacks like labor intensity and high false-positive rates. NDR is presented as particularly valuable for uncovering unknown compromises and tracing attacker behavior that often includes lateral movement, privileged credential misuse, and data exfiltration. It also provides visibility in OT/ICS/IIoT environments where endpoint agents may be impractical, especially at network segmentation control points.
Exeon Analytics (founded 2016 in Switzerland) offers ExeonTrace, derived from ETH Zurich research, with three modules (network, web, and extended logs) licensed by active IPs and modules used. It is deployed on-premises or in private clouds only, as a Linux-based virtual appliance that passively receives telemetry (e.g., NetFlow/IPFIX, DNS, firewall, syslog, SWG logs, and varied “XLog” sources like Active Directory, VPN gateways, IDS, and EPDR). ExeonTrace analyzes flow metadata rather than packets, enabling detection even when traffic is encrypted, but it does not perform packet capture or deep packet inspection. The product combines static rules with proprietary supervised and unsupervised ML models, supports customization of detections with professional services, and typically requires two weeks or less for baselining and sensitivity tuning across different network zones. It correlates events into cases, supports threat hunting and integrations (MISP, STIX/TAXII, YARA), and exports alerts via email/APIs and multiple formats for SIEM/SOAR interoperability, though response playbooks and in-platform report creation are limited.
See All Locations
See All Locations