MetaDefender NDR v5.2.0 — Release Notes
Release Date: July 31, 2026
Overview
MetaDefender NDR v5.2.0 introduces six significant capability additions focused on enterprise integration, operational visibility, and deployment flexibility — particularly for air-gapped environments and organizations with mature identity and security operations infrastructure.
What’s New
Manual Threat Intelligence & Software Updates via UI
Operators can now upload threat intelligence feeds and software update packages directly through the administration interface. This eliminates dependency on automated pipelines and external connectivity, enabling organizations in air-gapped, classified, or network-restricted environments to maintain current detection coverage and software versions without external access.
Multi-Sensor Behavioral Analytics
Behavioral analytics now support multi-sensor configuration, enabling a single MetaDefender NDR deployment to correlate detections and orchestrate response across distributed sensor infrastructure. Security teams gain centralized visibility and coordinated detection across multiple network segments from a single control plane.
OpenTelemetry Observability Integration
MetaDefender NDR now natively exports metrics, traces, and logs in OpenTelemetry format, compatible with any OTel-compliant observability backend (Prometheus, Grafana, Datadog, Splunk Observability, and others). This provides standardized operational telemetry without custom integrations or proprietary agents.
Expanded Policy Administration
Policy administration has been significantly expanded to support fleet-wide policy management. Security teams can now define, version, and distribute detection and response policies across all deployed sensors from a single administrative interface, simplifying governance in large or multi-site deployments.
Enterprise Identity Integration (SAML 2.0 / Microsoft Entra ID / Okta)
MetaDefender NDR now supports single sign-on and identity federation via SAML 2.0, Microsoft Entra ID (Azure AD), and Okta. This enables seamless integration with enterprise IAM workflows, centralizes access control, and eliminates the need for local credential management for administrative users.
SIEM Integration via Syslog
Out-of-the-box syslog forwarding enables NDR alerts and event