logo

East-west tension: Are NDR vendors monitoring the wrong traffic?

ID: 9293409d-38d5-5f2f-8b5f-2d018ebd4854

STIX ID: report--9293409d-38d5-5f2f-8b5f-2d018ebd4854

Feed Name: Group-IB Blog

Date Published: 2025-10-17

Date Updated: 2026-04-28

...
...

This report argues that many organizations over-rely on EDR and perimeter-only NDR, leaving critical internal (east-west) activity—such as lateral movement, credential theft, and data exfiltration—unseen; it explains how hardware economics and the use of legitimate protocols for C2 drive these blind spots, leading to prolonged dwell time and higher risk. It promotes Group-IB’s NDR within Managed XDR as a remedy, emphasizing behavioral analytics across internal traffic, automatic asset context, covert channel detection, internal file extraction with sandboxing, multi-protocol (including OT) visibility, integrated threat intelligence, and 24/7 managed operations to speed detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.