Agentic NDR Detection Capability Published

更新时间: 2026-05-08 10:29:44

Through security events, security alerts, and ATT&CK attack matrices, it enables threat detection and analysis during an incident, as well as post-incident tracing and handling.

Content

Applicable customers: Suitable for complex scenarios such as APT attacks, major event support, and sensitive data protection.
New Feature/Specification:
1. ATT&CK Matrix maps attack techniques and tactics based on the MITRE framework, visually rendering intrusion paths and attack phases;
2. The intelligent event capability automatically aggregates and generates attack event reports using large language models, enabling one-click handling by linking traceability graphs with entity views.
3. The alerting module integrates multiple engines, including intrusion detection, threat intelligence, sandbox, and behavior analytics. It supports payload decoding, PCAP backtracking, and AI interpretation, significantly reducing false positives and improving analysis efficiency.

上一篇: Agentic NDR Adds Sensitive Data Fraud Detection Capability 下一篇: Detection and Response capability optimization
阿里云首页 云防火墙 相关技术圈