Detection and monitoring EU-developed

Guardsix NDR

Network detection and response product that analyzes network telemetry, groups related activity into attack chains, and supports investigation in on-premises environments.

By Guardsix · Denmark

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
Guardsix
Recorded country
Denmark
Product model
Commercial
Deployment
Self-hosted
Software license
Proprietary
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Guardsix NDR continues a product line acquired from Danish Muninn; current engineering distribution and ultimate control require separate verification.

Reported capabilities

  • Analyzes network telemetry for suspicious behavior.
  • Presents correlated activity as attack chains.
  • The vendor describes on-premises and hybrid deployment.

Scope and limits

Guardsix promotes SIEM integration; the public pages do not establish whether NDR can operate without any other Guardsix license.

Inspect the research evidence 4 source observations
  1. identity / capabilities / deployment

    The current NDR product page describes network telemetry analysis, chain-of-events investigation, on-premises/hybrid deployment, and a commercial demo path.

    Read source
  2. origin / country

    The vendor support note identifies Danish Muninn as the NDR predecessor acquired by Logpoint in 2024.

    Read source
  3. license

    The Guardsix EULA covers its network-monitoring software, retains source and intellectual-property rights, and grants a paid nontransferable use right.

    Read source
  4. maintenance

    The vendor dated the NDR 2.33 release 18 August 2026 and describes licensed on-premises network sensors.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection