Detection and monitoring EU-developed
Guardsix NDR
Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments.
By Guardsix · Denmark
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- Guardsix
- Recorded country
- Denmark
- Product model
- Commercial
- Deployment
- Self-hosted
- Software license
- Proprietary
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteGuardsix NDR continues a product line acquired from Danish Muninn; current engineering distribution and ultimate control require separate verification.
Reported capabilities
- Analyzes network telemetry for suspicious behavior.
- Presents correlated activity as attack chains.
- The vendor describes on-premises and hybrid deployment.
Scope and limits
Guardsix promotes SIEM integration; the public pages do not establish whether NDR can operate without any other Guardsix license.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
The current NDR product page describes network telemetry analysis, chain-of-events investigation, on-premises/hybrid deployment, and a commercial demo path.
Read sourceorigin / country
The vendor support note identifies Danish Muninn as the NDR predecessor acquired by Logpoint in 2024.
Read sourcelicense
The Guardsix EULA covers its network-monitoring software, retains source and intellectual-property rights, and grants a paid nontransferable use right.
Read sourcemaintenance
The vendor dated the NDR 2.33 release 18 August 2026 and describes licensed on-premises network sensors.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection