What is WatchGuard Network Detection and Response?
ThreatSync+ Network Detection and Response (NDR) from WatchGuard (formerly CyGlass) is a cloud-native, open-network threat detection and response solution. It delivers enterprise-wide network monitoring, detection, and response focused on finding threats, including ransomware, supply chain, and vulnerability-based attacks.
Running a multi-tier neural network, operating flow-based unsupervised and semi-supervised machine learning, ThreatSync+ NDR ingests NetFlow and quickly detects attacks that have bypassed perimeter defenses and are actively expanding in the network. The AI engine identifies C&C, lateral movement, unusual access, unusual data movement, beaconing, scanning, and other traffic-based attack processes.
ThreatSync+ NDR continuously monitors the entire protected network for changes and applies intelligent risk scoring to focus cybersecurity's efforts on what is essential. From identifying all the devices operating on the network to alerting with rogue devices, new IoT devices, or known vulnerabilities are discovered, ThreatSync+ NDR can be used to take control of network activity.
ThreatSync+ NDR reduces detection times to minutes and identifies attacks early enough to take action to prevent their damage. This includes identifying ransomware attacks early enough to block encryption and prevent internal network penetration from reaching partner networks. Working with ThreatSync remediation workflows, IT teams will reduce dwell times from weeks to hours.
Categories & Use Cases
Technical Details
| Deployment Types | SaaS |
|---|---|
| Operating Systems | Web-Based |
| Mobile Application | No |





