Investigate

Console route · /investigation

NDR investigation

Internal network investigation: site and cluster topology, entity relationship graphs, and time-scoped playback for lateral movement context. This is not the geographic Infrastructure Map.

Job of this workbench

NDR investigation helps operators reason about east-west and north-south movement inside the environment: which sites and clusters talk to each other, which entities sit on a path, and how relationships change over a time window. It is a specialized view over projected graph and telemetry bundles — not a separate NDR product with its own alert lake.

Tabs and controls

Network covers topology and force-directed graph views. Entities focuses relationship inspection for selected nodes. Playback walks time-scoped steps so operators can see sequence, not only a static map. Traffic scope filters distinguish east-west versus north-south emphasis. Asset drawers show overview, relationships, and exposure. URL parameters can scope the graph to an incident or entity when deep-linking from a case.

Data loading and actions

The page loads an NDR bundle from the API when available. Evaluation mode can provide a labeled fallback for walkthroughs. Operators can rebuild graph views client-side from the returned bundle. Containment requests use the shared approval workflow.

When the question is geographic placement of company endpoints or arcs to observed malicious remote contacts, use Infrastructure Map (/infrastructure-map) instead. NDR is internal topology; the map is geo and external contact context.

Graph depth depends on worker projection and available telemetry. The UI renders what the control plane returns and does not invent edges to look complete.

Privacy controls

Your visit should be as controlled as your telemetry.

We use necessary cookies to keep the site working. Optional analytics help us understand which product pages are useful. Marketing cookies stay off unless you allow them.