Title
Create new category
Edit page index title
Edit category
Edit link
Overview
Overview
MetaDefender NDR provides security analysts with a unified interface for detecting, investigating, and responding to network-based threats. This guide covers the core workflows and pages analysts interact with daily.
Key Analyst Workflows
Triage alerts -- Review and prioritize detections on the Dashboard and Detection Overview pages
Investigate threats -- Use the Hunt Page for deep-dive investigation across flows, alerts, and extracted files
Manage runbooks -- Follow structured Investigation Runbooks for common attack patterns (C2, data exfiltration, tunneling, malicious files)
Monitor sensor health -- Ensure sensors are online and capturing traffic via Health and Monitoring
Navigation
The operating guide is organized into the following sections:
Section | Description |
|---|---|
Dashboard | High-level alert summary, sensor status, and threat activity over time |
Hunt Page | Interactive investigation across all event types |
Detection Overview | Breakdown of all active detections by type and severity |
Investigation Runbooks | Step-by-step guides for common threat scenarios |
Daily Operations | Recommended analyst workflows for shift handoff and triage |
Administration | Sensor management, user roles, integrations, and system configuration |
Getting Started
New to MetaDefender NDR? Start with the Getting Started guide, then proceed to the Dashboard overview.