
Next-Gen Network Detection & Response by Exeon
With Exeon.NDR, you benefit from a leading network security solution that helps you meet legal compliance requirements. With NetDescribe and Exeon Analytics.
“Protect your IT/OT infrastructure through immediate detection of potential cyber threats and rapid, efficient responses.”
Kevin Neumann | Exeon Analytics Expert at NetDescribe

The Challenge
Cyber incidents such as ransomware attacks, data breaches, and IT disruptions, as well as the associated risks of business interruptions in a dynamic IT/OT landscape, are putting companies on high alert.
Distributed and hybrid networks are difficult to analyse and monitor. Added to this are new compliance regulations such as the NIS2 directive and the Digital Operational Resilience Act (DORA), which hold management accountable in cases of insufficient IT security measures. Selecting the right security solutions, conducting thorough risk assessments and ensuring continuous training are essential.

Exeon Analytics – the Solution from NetDescribe
Exeon Analytics’ solutions offer powerful Network Detection & Response (NDR) and User and Entity Behavior Analytics (UEBA) for the early detection of modern cyberattacks. By analyzing network metadata and log data from identity, cloud, and enterprise applications, the platform detects suspicious activity in real time.
Using AI-powered behavioral analytics, Exeon identifies compromised user accounts, insider threats, unusual access, and data exfiltration even in complex IT and cloud environments. The solution efficiently processes large volumes of data, reduces log volume, and integrates seamlessly with existing SIEM, SOAR, and SOC platforms.
Exeon can be flexibly deployed on-premises, in the cloud, or in hybrid environments and meets stringent requirements for data protection, compliance, and data sovereignty.
Protect your corporate networks quickly, reliably, and completely free of hardware.
How Exeon.NDR works:
Exeon NDR (Network Detection & Response) continuously analyzes network metadata such as NetFlow, IPFIX, and firewall logs to detect suspicious activity—even in encrypted traffic. AI-powered algorithms identify anomalies, prioritize critical incidents, and reduce false positives. Since the solution is purely software-based and leverages existing infrastructure, it can be quickly implemented, is scalable, and operates without additional hardware or agents.
Source: www.exeon.com
The most advanced NDR (Network Detection and Response)
Exeon.NDR’s forward-looking approach is based entirely on metadata analysis without any resource-intensive traffic mirroring. Modern AI algorithms are specifically trained to evaluate even encrypted network traffic that conventional NDR solutions cannot see. Exeon.NDR processes data from a wide variety of sources, ranging from on-premises infrastructures to hybrid setups and native cloud environments, making it ideally suited for highly virtualized and distributed networks.
Because the majority of today’s network traffic is encrypted, traffic mirroring quickly reaches its technical and economic limits, especially as bandwidths increase. Exeon circumvents this limitation by exporting the required metadata directly from existing network devices and cloud services.
This metadata is mapped as specific network actions and aggregated into traces – that is, chains of actions that can be attributed to individual users or systems. Every attacker thus leaves an unavoidable trail. Using machine learning models, Exeon.NDR detects anomalies and potentially malicious behavior in these traces – accurately, quickly, and in real time.
Exeon achieves significant data reduction before uploading to the SIEM by processing and forwarding only relevant and enriched metadata instead of complete raw data or traffic mirroring dumps. Through the intelligent correlation, aggregation, and filtering of security-relevant events, Exeon reduces the data volume by a factor of many, often up to 50 times less than with raw log data alone. This means lower storage requirements, reduced bandwidth load, and thus significantly lower licensing costs in the SIEM system
Compliance and Zero Trust
Today, organizations must strengthen their cyber resilience while meeting strict regulatory requirements, ideally through a seamless, integrated approach. Exeon.NDR combines state-of-the-art zero-trust strategies with compliance and cybersecurity standards such as NIS2, HIPAA, GDPR, and ISO 27001. The solution supports core zero-trust principles such as microsegmentation, least privilege, and end-to-end encryption without compromising performance or scalability.
It can also be operated entirely on-premises and air-gapped, without any external connections, wherever regulatory requirements demand it.
By continuously monitoring and analyzing network activity, Exeon.NDR detects suspicious patterns and anomalies early on, even in heavily encrypted and distributed environments. This not only ensures compliance with data protection and security requirements but also enables rapid incident response.
Learn how NetDescribe and Exeon can help you establish a secure, transparent, and compliant foundation to effectively implement Zero Trust and take your cyber defense to the next level.
Exeon.NDR – The Platform

With the modular design of Exeon.NDR, you can tailor the advanced NDR solution precisely to your needs. As the central “brain,” the platform correlates events from a wide variety of sources, detects complex attack patterns, and provides a comprehensive overview of the situation in real time and across all network environments.
Correlation Engine
Combines and correlates security-related data from all systems to enable maximum transparency, precise detection, and efficient response.
SecurityDB
A high-performance graph database with up to 50 times less data volume than traditional logs, ideal for long event histories and unlimited scalability.
Alerting System
Intelligent alerting with REST API integration into ticketing, SIEM, SOC, or SOAR systems to seamlessly integrate incidents into existing workflows.
Incident Handling & Assessment
An intuitive user interface for handling incidents, along with AI-powered prioritization to minimize false alarms and focus attention on critical events.
Dashboard & Reporting
Customizable dashboards with clear reports, KPI overviews, and guided threat hunting.
Visualizations
Scenario-specific, interactive visualizations for quick analysis and informed decisions.
AI-Detection & Analysis
Pre-built AI models and use cases for specific threat scenarios, continuously optimized.
Data Lake (Option)
Integration of existing data lakes such as Splunk or Elasticsearch or use of the high-performance, cost-effective Exeon Data Lake.
With this flexible architecture, Exeon.NDR provides everything modern businesses need to detect threats faster, respond effectively, and optimize security processes without unnecessary complexity.
Exeon.NDR – The Modules
The Exeon.NDR modules provide specialized AI capabilities for collecting, processing, analyzing, and visualizing security-related data without the need for additional hardware or software sensors. Powerful software collectors efficiently capture log data from existing infrastructures, while AI algorithms reliably detect and investigate threats from specific data sources.

The modules make your network more secure and smarter – whether used together or individually:
Network Module: Monitors internal and external network traffic (NetFlow, IPFIX, Corelight, DNS).
- Detection of Advanced Persistent Threats (APTs)
- Complete network visibility
- Analysis of access patterns to internal services
- Detection of internal shadow IT
- Blacklist matching for suspicious connections
Web Module: Analyzes web activity on internal devices using proxy logs from SSL/TLS-inspecting secure web gateways.
- Detection of APTs and data breaches
- Identification of external shadow IT
- Identification of unauthorized or outdated devices
- Blacklist matching for compromised domains
Xlog Module: Cross-source threat detection using additional security-related log data.
- Better Events: Enriched, aggregated, and efficiently stored events
- Better Detection: Correlation of network events with host log data
- Better Alerts: Consolidated, high-quality alerts achieved by filtering out false positives
- Better Response: Targeted, rapid responses to confirmed incidents
Exeon.NDR – On Prem or On Cloud
Cloud-based cybersecurity solutions offer high scalability, a usage-based pricing model, and minimal maintenance requirements including automatic updates, security patches, and the ability to monitor systems remotely. They are ideal for dynamically growing infrastructures and enable rapid deployment without significant upfront investments.
On-premises solutions, on the other hand, offer maximum control over data and infrastructure, minimal latency for real-time detection, and maximum adaptability. This is particularly relevant for organizations with strict data protection and compliance requirements. They reduce reliance on internet connections, offer stable performance, and can be better secured physically.
Exeon.NDR combines the best of both worlds: The platform can be flexibly operated in the cloud, on-premises, or in hybrid environments. It analyzes network metadata without costly traffic mirroring or decryption, is easy to implement and scale, and adapts precisely to individual business requirements.
Exeon.Visibility
Exeon.Visibility provides companies with comprehensive and in-depth insight into their network activities regardless of the complexity of their IT environment. The solution collects and analyzes network metadata from a wide variety of sources to provide complete transparency into internal and external communication flows. This enables the rapid detection of hidden risks such as shadow IT, unusual access patterns, or unknown devices. Exeon.Visibility thus supports effective security monitoring, facilitates compliance with regulatory requirements, and forms the basis for preventive measures against cyber threats.
Exeon.UEBA
Exeon.UEBA is a User and Entity Behavior Analytics (UEBA) security solution that detects suspicious behavior by users, applications, and systems. The platform analyzes log data from various sources and creates behavioral profiles to identify anomalies and potential attacks at an early stage.
Exeon.UEBA uses behavioral analytics and AI-based models to detect unusual activity in IT environments, such as compromised user accounts, insider threats, or unauthorized access to applications and data. The solution processes logs from SaaS, cloud, on-premises, and custom applications in real time and detects anomalies based on patterns in user and system behavior.
- Analysis of user and system behavior across users and administrators, SaaS and custom applications, APIs, service accounts, and access systems.
- Real-time anomaly detection via streaming analytics.
- A combination of predefined security use cases and AI-powered models ensures highly accurate detection rather than false alarms. Behavioral correlation delivers precise, context-aware alerts instead of a flood of isolated events.
- Integration with SIEM, SOAR, and IAM systems for automated response. Lower SIEM costs and faster SOC workflows. Intelligent data processing reduces log volume while accelerating investigations and responses.
- Holistic visibility across critical enterprise systems. Monitor the behavior of identities within critical applications such as SAP, in-house developments, and legacy applications containing sensitive data.
- Data protection and data sovereignty by design. GDPR-compliant analysis thanks to anonymization, and deployable on-premises, in public/private clouds, and air-gapped environments.
In short: Exeon.UEBA helps security teams detect attacks carried out using valid credentials or legitimate user accounts by identifying unusual behavior patterns in log and activity data.
Exeon.NDR – Business Benefits
Quick Deployment
Up and running in just a few hours without any additional sensors or agents.
Comprehensive Visibility
A unified view of distributed networks, endpoints, and applications for complete control.
Holistic IT and OT Monitoring
Identify malicious attack patterns and vulnerabilities (compromised services, shadow IT, etc.) in real time.
Encryption Is No Obstacle
Analysis is based on metadata, not deep packet inspection, so encrypted data remains untouched.
Efficient Data Collection
Utilizes lightweight log data directly from existing network sources (switches, firewalls, etc.) without traffic mirroring or hardware sensors.
Smart threat detection
Powerful AI and proven algorithms for precise and reliable detection.
Intelligent data handling
Minimal storage requirements with full data control, flexibly on-premises or in the cloud.
Powerful response
Automated prioritization, easy investigation, and effective incident response.
Future-proof and scalable
Designed for increasing data volumes and growing encryption, even as network complexity rises.
Lower licensing costs
Significant data reduction before uploading to the SIEM through intelligent correlation, aggregation, and filtering of security-relevant events means less storage requirements and lower bandwidth load.
Book your personal consultation now
Put your IT performance to the test now. What requirement have you always been looking for a solution for? NetDescribe will get you to your goal – through independent advice, reliable support and proven use cases.
Blog
Interesting Facts from the IT World
-
NetDescribe Use Case – End-to-end network visibility and automated troubleshooting in complex MPLS environments
Can you handle complex MPLS networks? A regional telecommunications provider faced exactly this challenge.
-
ISO 27001 certification and TISAX® assessment
Information security is more than compliance The Xantaro Group’s integrated approach highlights the interplay between network, observability, and certification. A look at current best practices…
-
Combined Splunk expertise within the Xantaro Group: greater transparency, security, and efficiency for our customers
NetDescribe and anykey are pooling their Splunk expertise within the Xantaro Group. Customers benefit from greater transparency, security, and efficient observability and SIEM solutions from…








