East-west tension: Are NDR vendors monitoring the wrong traffic?
ID: 9293409d-38d5-5f2f-8b5f-2d018ebd4854
STIX ID: report--9293409d-38d5-5f2f-8b5f-2d018ebd4854
Feed Name: Group-IB Blog
This report argues that many organizations over-rely on EDR and perimeter-only NDR, leaving critical internal (east-west) activity—such as lateral movement, credential theft, and data exfiltration—unseen; it explains how hardware economics and the use of legitimate protocols for C2 drive these blind spots, leading to prolonged dwell time and higher risk. It promotes Group-IB’s NDR within Managed XDR as a remedy, emphasizing behavioral analytics across internal traffic, automatic asset context, covert channel detection, internal file extraction with sandboxing, multi-protocol (including OT) visibility, integrated threat intelligence, and 24/7 managed operations to speed detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
