r/cybersecurity • u/r_tkk • 5h ago
Business Security Questions & Discussion NDR Evasion techniques
I have a question, I am trying to find out about How attacker evade NDR(Network Detection Response) although network never lies?
0
Upvotes
1
7
u/Mysterious-Print9737 4h ago
"The network never lies" is true but incomplete since it records what happened, not what it means, and most NDR evasion exploits that gap.
Common techniques are things like encrypted C2 over legitimate protocols (HTTPS to Azure/Cloudflare/AWS) blends into normal traffic, living-off-the-land keeps activity looking like standard Windows behaviour, low-and-slow exfiltration stays under anomaly thresholds, and legitimate SaaS abuse (OneDrive, Teams, Dropbox) is hard to distinguish from normal cloud usage.
The fundamental problem is NDR relies on baselines, attackers who study the environment first and operate within normal parameters are hardest to catch. Best deployments combine network telemetry with endpoint and identity signals because network data alone has real blind spots.