Sophos Community
Site
User
Site
Search
User
Community & Product Forums
Sophos Endpoint
Sophos Firewall
Sophos Central
Sophos Factory
Sophos Mobile
Sophos Cloud Optix
Sophos Sensor
Sophos Switch
Sophos Wireless
Sophos Email
UTM Firewall
Community Blogs & Events
Sophos Community Blog
Community Security Blog
Product Documentation Blog
Application Control
Getting Started
Sophos Partners
Sophos Partners Group
Member Recognition
Community Leaderboards
More
Cancel
NDR Community Channel
NDR Queries
Announcements
Discussions
Recommended Reads
Videos & Uploads
Queries
Ideas
Online Help
More
Cancel
New
NDR Community Channel requires membership for participation - click to join
By highest score
By date
By recent status change
Descending
Ascending
All ideas
Ideas you submitted
Ideas you voted on
With any status
With any open status
With any closed status
With held votes
Currently 'Completed (Brand-new content)'
Currently 'Completed (Content Update)'
Currently 'Completed (Minor Issue)'
Currently 'Approved'
Currently 'Under Review'
Currently 'Coming Soon'
Currently 'Not Planned'
Currently 'Complete'
NDR - Top 100 most trafficked hostnames (BARS)
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Top 100 most trafficked hostnames -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the top 100 most trafficked hostnames by traffic volume -- SOURCE: Data Lake -- VARIABLE $$Destination IP Address$$ IP ADDRESS -- VARIABLE $...
28 Jan 2023 9:04 PM
NDR Report with last execution time
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- QUERY NAME: NDR Report with last execution time -- CATEGORY: All queries, NDR -- DESCRIPTION: List the available NDR reports and the most current report execution time -- SOURCE: Data Lake -- VARIABLE $$Report Name$$ STRING SELECT DISTINCT...
28 Jan 2023 9:01 PM
NDR - Protocol Report (BARS)
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Protocol Report (BARS) -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying protocols used and how often -- NOTE: avg_pcr is the Producer Consumer Ratio (PCR) (-1 Pure Push to +1 Pure Pull) -- NOTE: mac_addresses is a list of...
28 Jan 2023 8:57 PM
NDR - Devices generating most network traffic (BARS)
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Devices generating most network traffic (BARS) -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the top 100 talkers on a network. -- Fields are ip: the private IP address of the machine, total_bytes: the total number of bytes...
28 Jan 2023 8:46 PM
NDR - Top Clusters (BARS)
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Top Clusters (BARS) -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the clusters with the most traffic in bytes. -- A cluster is a group of flows defined by their shared values for src_ip, dest_ip, dest_port, protocol, app_protocol...
28 Jan 2023 9:08 PM
NDR - Top 10 hosts for each protocol seen
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Top 10 hosts for each protocol seen -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying all used application protocols on the network and the top five hosts using each -- SOURCE: Data Lake -- VARIABLE $$Application Protocol...
28 Jan 2023 9:03 PM
NDR - MAC IP correlation
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - MAC IP correlation -- DESCRIPTION: Detection for identifying all the IP addresses associated with a given MAC address -- Excludes :: and 0.0.0.0 -- The query also checks for the MAC Address in the data lakes XDR Data to determine if...
28 Jan 2023 8:50 PM
NDR - Number of Monitored Hosts
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Number of Monitored Hosts -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the number of private, public, and unknown hosts being monitored by -- SOURCE: Data Lake -- VARIABLE $$Category$$ STRING WITH NDR_Data AS ( ...
28 Jan 2023 8:53 PM
NDR - Devices generating most network traffic
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Devices generating most network traffic -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying the top 100 talkers on a network. -- Fields are ip: the private IP address of the machine, total_bytes: the total number of bytes sent...
28 Jan 2023 8:48 PM
NDR - Protocol Report
Karl_Ackerman
Approved on
28 Jan 2023
0 Comments
-- NAME: NDR - Protocol Report -- CATEGORY: NDR -- DESCRIPTION: Detection for identifying protocols used and how often -- NOTE: avg_pcr is the Producer Consumer Ratio (PCR) (-1 Pure Push to +1 Pure Pull) -- NOTE: mac_addresses is a list of the top...
28 Jan 2023 8:55 PM
>