ExtraHop named a Leader in the 2025 Forrester Wave™: Network Analysis And Visibility Solutions

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

NDR & NPM Detections

How ExtraHop Modern NDR and NPM Expose the Truth in Your Traffic

Network traffic is the ground truth. ExtraHop unifies NPM and NDR to eliminate blind spots. Our stream processor decodes traffic at line-rate for immediate performance insights, while cloud-scale ML establishes behavioral baselines to detect anomalous threats.

  • NPM: Resolve outages and latency 12x faster.
  • NDR: Stop evasive attacks like lateral movement and exfiltration.

See the truth across hybrid-cloud environments before business disruption.

Detection Platforms

Filters

Tags

Category

AAA Authentication Errors
Authorization & Access Control
AD Credential Theft with ntdsutil
ExploitationIdentity
AD Database File Transfer over SMB
Actions on ObjectiveIdentity
AD Explorer Snapshot Activity
Reconnaissance
AS-REP Roasting LDAP Reconnaissance Activity
ReconnaissanceIdentity
AWS Cloud Service Enumeration
Reconnaissance
AWS Instance Metadata Service (IMDS) Proxy
Exploitation
Active Directory Domain Services Exploit Attempt - CVE-2022-26923
Lateral Movement
AdFind Activity
Reconnaissance
Adobe ColdFusion Exploit Attempt - CVE-2018-15961
Exploitation
Alias Member Enumeration Attempt
Reconnaissance
Anonymous FTP Login
Hardening
Apache APISIX Exploit Attempt - CVE-2022-24112
Exploitation
Apache ActiveMQ Exploit - CVE-2023-46604
Exploitation
Apache CouchDB Exploit Attempt - CVE-2017-12635
Exploitation
Apache HTTP Server Path Traversal Exploit - [Multiple CVEs]
Exploitation
Apache Solr Exploit - CVE-2019-17558
Exploitation
Apache Solr Exploit Attempt - CVE-2019-0193
Exploitation
Apache Spark Exploit Attempt - CVE-2022-33891
Exploitation
Apache Struts 2 Exploit Attempt - CVE-2017-9805
Exploitation
Apache Struts 2 Exploit Attempt - [Multiple CVEs]
Exploitation
Apache Tomcat JSP Exploit Attempt - [Multiple CVEs]
Exploitation
Atlassian Bitbucket Server and Data Center Exploit - CVE-2022-36804
Exploitation
Atlassian Confluence Exploit - CVE-2021-26084
Exploitation
Atlassian Confluence Exploit - CVE-2022-26134
Exploitation
Atlassian Confluence Exploit - CVE-2023-22518
Exploitation
Atlassian Confluence Exploit Attempt - CVE-2023-22518
Exploitation
Atlassian Crowd Exploit - CVE-2019-11580
Exploitation
Attempted Connections Dropped
Network Infrastructure
BITS Download
Actions on Objective

Showing 30 of 522 detections