License & Deployment Mix: 10 tools – 5 OSS, 5 commercial.
Color: Blue team.
What Is This Category?
Network Detection & Response (NDR) is the post- compromise hunting layer that lives on the wire. Where IDS / IPS look for known-bad signatures and block them, NDR records high-fidelity network metadata (Zeek logs, PCAP, Suricata EVE) and applies behaviour / ML detection to find lateral movement, beacon C2, data staging, and other in-progress attacker activity that signatures miss.
Distinct from neighbouring categories
- IDS / IPS – IDS is signature-based detection; NDR is behaviour-based hunting on top of (often) the same Suricata + Zeek substrate. The split is operational, not technical.
- SIEM & Log Analytics – SIEM aggregates events; NDR generates the rich network events that SIEM ingests
- Network Monitoring / NPM – Network monitoring is health metrics; NDR is threat detection
- Deception & Honeypots – deception waits for attackers to touch obvious-but-fake bait; NDR finds attackers in legitimate-looking traffic
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Capability Matrix
| Tool | Metadata | Alerts | Full PCAP | Hunt | ML/Behaviour |
|---|---|---|---|---|---|
| Zeek | yes (first-class) | partial | – | scripted | – |
| Suricata (EVE) | yes | yes (first-class) | partial | – | – |
| Arkime | yes | – | yes (first-class) | yes | – |
| RITA | post-process | – | – | yes (beacons / tunnels) | partial |
| Maltrail | – | yes (trail-based) | – | – | partial |
| Corelight | yes (Zeek) | yes (Suricata) | yes (Arkime) | yes | partial |
| ExtraHop Reveal(x) | yes | yes | – | yes | yes |
| Vectra AI | yes | yes | – | yes | yes (first-class) |
| Darktrace | yes | yes | – | yes | yes (unsupervised) |
| Stamus Networks | yes (Zeek) | yes (Suricata) | yes (Arkime) | yes | partial |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| Zeek | BSD-3-Clause | yes | OSS sensor |
| Suricata (EVE) | GPL-2.0-only | yes | OSS sensor |
| Arkime | Apache-2.0 | yes | OSS full-PCAP |
| RITA | GPL-3.0-only | yes | OSS post-processor |
| Maltrail | MIT | yes | OSS trail detector |
| Corelight | Proprietary | – | Commercial appliance |
| ExtraHop Reveal(x) | Proprietary | – | Commercial appliance |
| Vectra AI | Proprietary | – | Commercial NDR/XDR |
| Darktrace | Proprietary | – | Commercial NDR/XDR |
| Stamus Networks | Proprietary | – | Commercial appliance (Suricata-led) |
SSO / OIDC
| Tool | OIDC | SAML | SCIM | Authentik Notes |
|---|---|---|---|---|
| Zeek | n/a | n/a | n/a | Headless sensor |
| Suricata (EVE) | n/a | n/a | n/a | Headless sensor |
| Arkime | plugin | plugin | none | Reverse-proxy auth recommended |
| RITA | n/a | n/a | n/a | CLI analyser |
| Maltrail | plugin | plugin | none | Reverse-proxy auth |
| Corelight | paid | paid | paid | Enterprise tier |
| ExtraHop Reveal(x) | paid | paid | paid | Enterprise tier |
| Vectra AI | paid | paid | paid | Enterprise tier |
| Darktrace | paid | paid | paid | Enterprise tier |
| Stamus Networks | paid | paid | paid | Enterprise tier |
Deployment Comparison
| Tool | Deployment | Resources | Privileges |
|---|---|---|---|
| Zeek | AlmaLinux package / Docker | Bare-metal for >1 Gbps | SPAN port / tap |
| Suricata (EVE) | AlmaLinux package / Docker | Bare-metal for >1 Gbps | SPAN port / tap |
| Arkime | Native / Docker | TB-scale disk for PCAP | SPAN port / tap |
| RITA | Scheduled job + MongoDB | Modest | Reads Zeek logs |
| Maltrail | Native Python / Docker | Small VM / RPi | SPAN port / inline |
| Corelight | Hardware / virtual / cloud appliance | – | Vendor-managed |
| ExtraHop Reveal(x) | Appliance + SaaS console | – | Vendor-managed |
| Vectra AI | SaaS + cloud / on-prem sensors | – | Vendor-managed |
| Darktrace | Appliance + cloud | – | Vendor-managed |
| Stamus Networks | Appliance + SaaS console | – | Vendor-managed |
Composition Patterns
1. OSS-only NDR stack
Zeek -- protocol-aware metadata logging Suricata (EVE-mode) -- signature-based alerting Arkime -- full PCAP indexing + search RITA -- weekly beacon / DNS-tunnel hunt Maltrail (optional) -- lightweight blacklist sensor at small sites
Output: full NDR coverage at zero license cost. Standard OSS customer-network deployment.
2. Managed commercial NDR
Corelight (or Stamus Networks) -- managed Zeek + Suricata + Arkime SIEM (the customer's existing) -- alert + metadata consumer
Output: same engines as the OSS stack but managed delivery. Trade operational savings for license cost.
3. ML-led commercial NDR
Vectra AI (or Darktrace) -- ML-led detection RITA (optional, OSS hunt) -- complement with explicit beacon hunt
Output: AI-marketed detection. Worth pairing with RITA on the side for explainable beacon-hunt output that operators can verify.
Cost Tier
Approximate annual TCO for a 1-10 Gbps customer perimeter.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | Zeek + Suricata + Arkime + RITA + Maltrail | $0 + sensor hardware + operator time |
| Mid | Corelight / Stamus Networks managed appliance | $50,000-200,000 / year |
| High | ExtraHop / Vectra / Darktrace | $100,000-500,000 / year |
Tools
10 tools.
Arkime
Open-source full PCAP indexing and search platform; formerly Moloch; the analyst’s tool for diving into network packets at scale.
License: Apache-2.0 (OSS) · Kind: web · Deploy: native, docker, package · SSO: OIDC
Corelight
Commercial NDR platform built on Zeek + Suricata + Arkime; the canonical ‘Zeek appliance’ vendor (founded by Zeek creators).
License: Proprietary (proprietary) · Kind: web · Deploy: appliance, saas · SSO: OIDC, SAML
Darktrace
UK commercial NDR / XDR; unsupervised-ML ‘Enterprise Immune System’ marketing; large global customer base.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance, saas · SSO: OIDC, SAML
ExtraHop Reveal(x)
Commercial NDR with ML-driven encrypted-traffic analysis differentiator; wire-data-platform heritage.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance, saas · SSO: OIDC, SAML
Maltrail
Open-source malicious-traffic detection system; trail-based detection using curated blacklists + heuristics; lightweight footprint.
License: MIT (OSS) · Kind: service · Deploy: native, docker · SSO: none
RITA
Real Intelligence Threat Analytics from Active Countermeasures; Zeek-log post-processing for beacon / DNS-tunnel / long-connection detection.
License: GPL-3.0-only (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none
Stamus Networks
Commercial NDR built directly on Suricata + Zeek; SELKS open-source distribution heritage; France-based.
License: Proprietary (proprietary) · Kind: web · Deploy: appliance, saas · SSO: OIDC, SAML
Suricata (EVE-mode)
Open-source IDS / IPS / NSM engine from OISF; EVE JSON output is the canonical NDR feed format alongside Zeek logs.
License: GPL-2.0-only (OSS) · Kind: service · Deploy: native, docker, package · SSO: none
Vectra AI
Commercial NDR / XDR with strong AI marketing; behavioural ML for post-compromise hunting; broader XDR now.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, appliance · SSO: OIDC, SAML
Zeek
Open-source network analysis framework (formerly Bro); generates rich protocol logs and is the substrate under most commercial NDR products.
License: BSD-3-Clause (OSS) · Kind: service · Deploy: native, docker, package · SSO: none