EDR is one of the best investments you can make. But after performing thousands of hours of internal pentests I’ve come to realize, it’s just not enough.
It doesn’t matter what EDR is in place or who you have for SOC/MDR, blind spots are inevitable because they are features of those capabilities.
EDR is great for detection malicious activity on endpoints. But what if an attacker is not on one of your corporate-controlled endpoints?
MDR is great and there some really good providers out there, but unfortunatly they don’t know your environment very well.
Suzie running PowerShell? Maybe that’s normal…
Because EDR is not perfect (no product can be) and because MDR providers are not continuously tuning per-client/per-environment, it’s not unreasonable to remain undetected for several days during an internal pentest.
During that time, I’m normally making quite a bit of noise on the network. Stuff like, enumerating shares, making a bunch of LDAP requests, etc.
That’s where NDR shines and why it’s so needed. NDR will detect recon activity well before EDR captures suspicious endpoint activity.
I’ve also seen first hand where incidents were detected by NDR well before anything “malicious” happened on an endpoint. This happens because EDR is not looking at the telemetry needed to identify this activity.
So what do you do?
Well, if you’ve dismissed NDR because the ROI didn’t seem compelling, I’d encourage you to take another look. Keep in mind that it’s not a replacement for EDR. It actually compliments it really well.
I’ve see two products in action, and I can say they appear to be really solid:
Corelight and Darktrace.
This is not an ad, just my opinion and a place to start looking if you’re new to this.
Implement NDR, detect threats sooner, keep your environment safe.
All the best
Spencer
PS - NDR can be expensive and take significant time and investment and tuning. Don’t let that deter you. It’s worth it. Hard work matters.
