Overview

Overview

MetaDefender NDR provides security analysts with a unified interface for detecting, investigating, and responding to network-based threats. This guide covers the core workflows and pages analysts interact with daily.

Key Analyst Workflows

  • Triage alerts -- Review and prioritize detections on the Dashboard and Detection Overview pages

  • Investigate threats -- Use the Hunt Page for deep-dive investigation across flows, alerts, and extracted files

  • Manage runbooks -- Follow structured Investigation Runbooks for common attack patterns (C2, data exfiltration, tunneling, malicious files)

  • Monitor sensor health -- Ensure sensors are online and capturing traffic via Health and Monitoring

The operating guide is organized into the following sections:

Section

Description

Dashboard

High-level alert summary, sensor status, and threat activity over time

Hunt Page

Interactive investigation across all event types

Detection Overview

Breakdown of all active detections by type and severity

Investigation Runbooks

Step-by-step guides for common threat scenarios

Daily Operations

Recommended analyst workflows for shift handoff and triage

Administration

Sensor management, user roles, integrations, and system configuration

Getting Started

New to MetaDefender NDR? Start with the Getting Started guide, then proceed to the Dashboard overview.