NDR vs EDR: What Each Sensor Cannot See

A coverage map of endpoint and network telemetry, built from what each sensor collects and where each one goes dark.

A watchtower island with a radar dish shining a beam onto one snowy island while three faded islands sit outside the light

NDR and EDR fail in different places, and the gap between them is where intrusions live. EDR reads process, command line and driver activity on hosts that run its agent. NDR reads flow and protocol metadata for traffic its sensors receive. This is a coverage map of both, technique by technique, so you can see which parts of an intrusion neither product is watching today.

What each sensor actually collects

Product categories describe packaging. Telemetry describes what you can detect. MITRE ATT&CK separates the two feeds into distinct data sources, and the split is a useful starting point.

EDR telemetry

EDR agents produce host-level events: Process (DS0009), Command (DS0017), Driver (DS0027), Module (DS0011) and WMI (DS0005). That gives you execution lineage. You can see which parent spawned which child, what arguments were passed, what was loaded into memory, and which driver was installed.

No other sensor produces this. If a detection depends on a command line argument or a parent-child chain, it depends on an agent.

NDR telemetry

NDR sensors produce Network Traffic (DS0029) and, where file transfers are visible, Network Share (DS0033) events. That gives you relationships: who talked to whom, on which port, with what protocol behaviour, at what volume and cadence.

Network telemetry is device-agnostic. It observes a printer, a firewall and a domain controller through the same lens, and none of them has to cooperate.

Where EDR goes dark

Three classes of host produce no endpoint telemetry. They are not the same problem and they need different answers.

Hosts that cannot run an agent

Network appliances run stripped-down or proprietary firmware and do not accept third-party software. CISA named these device classes in Binding Operational Directive 26-02, issued February 5, 2026. The list runs from load balancers, firewalls and routers to switches, wireless access points, network security appliances, IoT edge devices and software defined networks.

Attackers picked up on this. Mandiant's M-Trends 2026 reports that threat clusters including UNC6201 and UNC5807 deliberately target edge and core network devices. VPNs and routers are named, and both typically lack standard EDR telemetry. The same report puts BRICKSTORM dwell times at nearly 400 days. A 90-day log retention policy hides the initial access vector completely at that timescale.

The economics point the same way. Verizon's 2026 Data Breach Investigations Report finds 31% of breaches now start with a software vulnerability. watchTowr's reading of the same report puts the remote access and network device category at 5% of breaches, up from 1.5%. Median remediation time for a known-exploited vulnerability moved from 32 days to 43 days.

An agent-based sensor cannot watch the device class that is growing fastest as an entry point.

Hosts that should have an agent and do not

Coverage on managed fleets is never complete. The 2026 Axonius Actionability Report ran with the Ponemon Institute across 662 IT and security professionals. It found 12.7% of devices missing an expected security agent, in a median inventory of 298,000 devices.

Contractor laptops, forgotten test VMs, freshly imaged machines and systems where the agent crashed all fall into this group. Your EDR console reports on what it can see, so the gap does not surface as an alert. It surfaces as silence.

Hosts where the agent is switched off

Kernel-level tampering is now routine. Huntress documented an intrusion in February 2026 that began with compromised SonicWall SSLVPN credentials. The attackers then deployed an EDR killer. It abused a legitimate Guidance Software forensic driver whose signing certificate had been revoked.

Read that chain again. Entry through a device with no agent, then removal of the agent on the devices that had one. Both halves of the intrusion are invisible to endpoint telemetry alone.

Where NDR goes dark

Network sensors have their own three failure classes, and vendors are quieter about them.

Encrypted payloads

TLS 1.3 changed what a passive sensor can recover. NIST published SP 1800-37 in September 2025 to address this. The approach used to achieve forward secrecy in TLS 1.3 may interfere with passive decryption. What survives is the shape of the conversation: timing, volume, certificate characteristics and client fingerprints such as JA3 and JA4.

That is enough to detect beaconing and unusual destinations. It stops short of reading a command, recovering a dropped binary or confirming what an operator typed.

Activity that never crosses the wire

Several technique families run entirely inside a single host. Local privilege escalation, credential access from LSASS memory, in-memory execution, local persistence and defence evasion all qualify. Nothing traverses a link, so nothing reaches a sensor.

These are the techniques EDR was built for, and no amount of packet capture substitutes for them.

Traffic the sensor never receives

NDR sees what its collection points carry. A sensor on the data centre core misses two cloud workloads talking inside a VPC. It also misses two containers on the same node, and a laptop reaching a SaaS tenant from a home network. East-west coverage depends on tap placement, and tap placement rarely matches the topology you have now.

The coverage map

Intrusion stepEDRNDR
Exploitation of an internet-facing VPN or firewallNo agent possibleAnomalous inbound session, post-exploit callback
Credential theft from process memoryFull process and handle detailNothing
Malicious driver load or EDR tamperingVisible until the agent is killedSecondary signal only
Lateral movement over SMB or RDPBoth sides, if both run agentsVisible regardless of agent coverage
Command and control over TLSProcess, parent and destinationDestination, cadence, fingerprint, not payload
Persistence on a router or load balancerNo agent possibleConfig-change traffic, unexpected outbound sessions
Staging and exfiltration to cloud storageFile writes, process attributionVolume, destination, timing
Discovery inside a cloud VPCOnly on instances with agentsOnly where flow collection exists

Read each row on its own. Every row with a gap on both sides is a detection you do not currently have.

What to ask vendors

Coverage questions beat feature questions. Both lists below take about ten minutes on a call.

For the EDR vendor

  • What percentage of our asset inventory can run your agent, by operating system and device class?
  • How do you report hosts that should have an agent and do not?
  • What happens to telemetry when an attacker unloads your kernel callbacks?
  • Which ATT&CK techniques in our threat model does your telemetry not cover at all?

For the NDR vendor

  • Which collection points are required for east-west coverage in our topology, including cloud?
  • What do you detect on a TLS 1.3 session with ECH enabled, without decryption?
  • What is the storage and retention cost at our observed traffic volume?
  • Which detections degrade when we cannot deploy a sensor at a given site?

Joining the two feeds

Buying both sensors leaves the merge work to analysts. They do it by hand, in the middle of an investigation, which is where the time goes. An alert from one console needs the other console to become a verdict, and the correlation work stays manual.

A different approach exists. Query both telemetry sets where they already sit, then correlate host and network evidence into one graph. The correlation happens before a human opens the alert. Port0 takes that route, and our honest comparison with traditional NDR sets out the trade-offs. It includes the cases where sensor-based products still do better. Our sensorless network signal fusion reads flow data your firewalls, proxies and cloud logs already produce. Our detection authoring with replay against historical data applies the same logic across both feeds.

The map above is the useful artefact either way. Fill in your own rows, mark the cells where neither sensor reports, and treat those cells as your detection backlog. Mandiant's data gives one reason to move quickly. Global median dwell time rose to 14 days in 2025, up from 11 days in 2024. That is two weeks inside your blind spots before the average investigation starts.

See Port0 on your own data.

Bring your noisiest alert queue. Watch Soc0 investigate it live.

Book a Demo

Never Miss an Insight

Subscribe to get the latest posts delivered to your inbox.