Title
Create new category
Edit page index title
Edit category
Edit link
Overview
Overview
MetaDefender NDR gives security analysts one interface to detect network threats. Analysts use it to investigate and respond to those threats. This guide covers the core workflows and pages that analysts use each day.
Key analyst workflows
Triage alerts -- Review detections on the Dashboard and Detection Overview pages. Set the priority for each detection.
Investigate threats -- Use the Hunt page to inspect flows, alerts, and extracted files.
Manage runbooks -- Follow structured Investigation Runbooks for common attack patterns, such as C2, data exfiltration, tunneling, and malicious files.
Monitor sensor health -- Use Health and Monitoring to make sure sensors are online and capture traffic.
Navigation
The operating guide contains these sections:
Section | Description |
|---|---|
Dashboard | Alert summary, sensor status, and threat activity over time |
Hunt Page | Interactive investigation across all event types |
Detection Overview | Summary of active detections by type and severity |
Investigation Runbooks | Steps for common threat scenarios |
Daily Operations | Analyst workflows for shift handoff and triage |
Administration | Sensor management, user roles, integrations, and system configuration |
Get started
If you are new to MetaDefender NDR, start with Get started. Then continue to the Dashboard overview.