Overview

Overview

MetaDefender NDR gives security analysts one interface to detect network threats. Analysts use it to investigate and respond to those threats. This guide covers the core workflows and pages that analysts use each day.

Key analyst workflows

  • Triage alerts -- Review detections on the Dashboard and Detection Overview pages. Set the priority for each detection.

  • Investigate threats -- Use the Hunt page to inspect flows, alerts, and extracted files.

  • Manage runbooks -- Follow structured Investigation Runbooks for common attack patterns, such as C2, data exfiltration, tunneling, and malicious files.

  • Monitor sensor health -- Use Health and Monitoring to make sure sensors are online and capture traffic.

The operating guide contains these sections:

Section

Description

Dashboard

Alert summary, sensor status, and threat activity over time

Hunt Page

Interactive investigation across all event types

Detection Overview

Summary of active detections by type and severity

Investigation Runbooks

Steps for common threat scenarios

Daily Operations

Analyst workflows for shift handoff and triage

Administration

Sensor management, user roles, integrations, and system configuration

Get started

If you are new to MetaDefender NDR, start with Get started. Then continue to the Dashboard overview.