Episode 20 - NDR Essentials: Why Network Data Still Defines Detection
Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment. Richard also reflects on the writing process, the pressure of creating technical material while doing the work, and why the future of NDR depends on trustworthy data, clear investigation paths, and analysts who know when to question the machine. Download the NDR Essentials book: https://corelight.com/cp/ndr-essentials