Skip to content
  • There are no suggestions because the search field is empty.
PROTECTING OVER $1B IN DAILY TRADES
DEFENDING ENERGY FOR 32+M U.S. USERS
SECURING NETWORKS FOR 52K+ TRANSPORT VEHICLES
PROTECTING OVER $10T IN MANAGED ASSETS
SECURING 16+M ANNUAL PATIENT VISITS
Home/Podcasts/Episode 20 - NDR Essentials:...
Episode 20 - NDR Essentials: Why Network Data Still Defines Detection
Guest Speaker: Vince Stoffer
July 30, 2026

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection
0:00 / 0:00

About the episode

Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment. Richard also reflects on the writing process, the pressure of creating technical material while doing the work, and why the future of NDR depends on trustworthy data, clear investigation paths, and analysts who know when to question the machine. Download the NDR Essentials book: https://corelight.com/cp/ndr-essentials

Episode transcript

Download transcript

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

Welcome to Corelight Defenders. I'm Richard Bejtlich, strategist and author in residence at Corelight. In each episode, we explore insights from the front lines of NDR, network detection and response. Today, I'm speaking with Vince Stoffer, Field CTO at Corelight, but he is here to interview me about the new NDR, book

I've written. Welcome, Vince, and thank you for serving as host today. Oh, thank you for having me, Richard. And, uh, yeah, the tables are turned.

What is this book that we're talking about, and, and what was the kind of, uh, idea behind its creation? Well, I've written. s-several books before around network security monitoring, and the natural question people might have is, what's the relationship between network security monitoring and network detection and response? And I think the easy answer is, uh, NSM is a strategy, it's a process, it also defines a certain set of data types, but NDR is a product. So you can't buy NSM, but you could buy or you could build potentially yourself, uh, an

NDR. And when you're doing that, you wanna make sure that the NDR that you are selecting or perhaps even building provides the right kind of data. Otherwise, you're just gonna be frustrated, and it'll be an exercise in futility.

So one of the major goals with the book was to talk about, if you're going to look at NDR as a product category or something that you're interested in, what should you be looking at? What type of, data should it provide? And what' can you expect to get out of this thing? And how would it work with other elements of your security infrastructure? You're never gonna be able to stop every intrusion, so you know, Kevin Mandia, who I just saw yesterday speaking, reminded the audience, uh, security breaches are inevitable.

I've framed it in the book as I've done in my previous works as prevention eventually fails. But the idea is, that you can't stop everything. You want to try to stop as many intrusions as possible, but you can't stop everything. So you have to prepare for the day when something is going to happen or potentially something has already happened, and you need to find it, and you want to identify and contain the intruder before he accomplishes his mission. Because you can' survive an intrusion, you may not survive a breach, so you want to identify that, you've had an unauthorized access to your system or your data, and you want to constrain the intruder before he accomplishes his goal, whether it's to steal your data, delete your data, or whatever they're there for.

Maybe lay out a little bit of the, uh, the organization beyond that first chapter of the paper. What, what are some of the ways that, you know, network data. can help? Overall, um, the book has five chapters. The first one is just what is NDR, and incidentally, if you're hearing this today, you' can go essen-- you' could... The easiest way to find it is just do Google Corelight NDR Essentials book, and that'll lead you' to it. We'll also have a, a link in the description for the podcast. But you can get the first chapter for free. It'll just, you know, click a link and download it. And that first chapter is what is NDR, so if you're in the market, you're trying to understand it, that'll help you right away.

Um, the other chapters are, uh, the second one is network data, and it goes through the four types of, of network, or network security monitoring data, uh, actually, full content, extracted files, transaction data, and alerts. The third chapter is investigating alerts. So there are two sort of main processes by which you can use NDR or really pretty much any sort of security data to try to find intrusions. There's investigating alerts or there's threat hunting.

So chapter three is, uh, about investigating alerts, and I give a bunch of examples, uh, provided by Corelight, uh, various detections that we have and how you investigate those and what they look like. And then the fourth chapter is threat hunting. The idea there is you come up with a hypothesis. You know, if an intruder is in my environment and they're affecting this resource, here is how that would manifest in an artifact. And the artifacts in this, this case are, you know, network artifacts. So I go through a set of examples based on the Corelight threat hunting guide. And then the final chapter, because you can't do this in twenty twenty-six without talking about those two magic letters, uh, it's artificial intelligence in NDR. So it's not the sort of thing? where I could say, "Set up this MCP server and use this model and do this and that," because I could have written that two weeks ago, and it could be completely obsolete i-in another two weeks. So instead, I sort of took a bigger picture and said,

"What can this do for you? What can agentic triage do for you? What do I expect to happen? How should you plan for that? How can you incorporate it into your, your system?" Who would be interested in downloading it, and, and why should they? If you are someone who just wants to understand what this thing is, what it can do for you, how it fits into your security program, so let's say you're a CISO, you're a CIO,

CTO, you're someone like that, the first chapter is gonna speak your language because it talks about risk, it talks about how this thing fits into the ecosystem. That's gonna be great. But honestly, if you're at any level of security organization, you should understand that stuff because if you can't connect what you're doing, say at the technical, in the trenches level, with the higher mission of your security executives all the way up to the business, uh, measure, you're gonna have issues, right, whether you're trying to get a budget for your new tool or training or whatever it is. So that first chapter is, is great for everyone. But as the, as the book goes on, I would say the middle part of the book is more for the practitioner. So if you're talking about...

I-- So the second chapter is, is about the data types. That could be more sort of for your architecture people, the people who wanna know, what is it, what's this type of data we're gonna be collecting? How are we gonna save it? How are we gonna query it? Um, but also analysts are gonna wanna know what is this and how do I use it. But then the, uh, third and fourth chapters are definitely more for the practitioners, so the person who has to investigate alerts, the person who is trying to do threat hunting. And then the fifth chapter is sort of a look-ahead chapter. I mean, it doe-it does talk about stuff that's happening today, but it's also trying to figure out where are we going with this, this AI stuff, automation.

So again, that sort of probably rolls back a little bit more into the leadership role. Do, do you think this helps orient people to kinda understand a little bit more about, uh, network data and its power? Yes. Yes. And, uh, funny enough, that is where AI can help quite a bit. I- In the process of writing the book, I encountered different sorts of activities that I hadn't really seen before because, you know, my day-to-day world is not looking at this sort of data. I mean, I do for fun, but it's not the kind of thing where, you know, back

20 years ago when I had to sit a, a watch and I had a queue and I had to deal with all that kind of stuff. It's not the same today. So there were plenty of things I came across and I said, "I don't know what that process does. I'm not familiar with this log type. I'm not familiar with this service."

Uh, a- and I wrote the book in, uh, Google Docs, and so I had access to our, our corporate Gemini instance, and I would say, "Tell me about this. What, what is this thing? What does it do? Or what vulnerability is associated with it, or how would I look for it?" And, uh, y- there's even some examples where I would feed in, um, Suricata alerts, or I would say, uh, "Write me a Suricata alert that would look for the following," and then I would, you know, validate based on my own experience whether I think it would do that. So I baked all that into the book, and, uh, that's what I think is so cool about having, uh, an AI assistant with you when you're doing this kind of work, is if you're not familiar with whatever it is you're looking at... Years ago, I would have to look in a book.

You know, I would look at- Yeah ... like the first edition of Hacking Exposed or, or Building Internet Firewalls or maybe some obscure white paper, uh, you know, published on, uh, FRAC or 2600 or something to try to find anything that would talk about this. It is true. It's an amazing resource. Well, I and many others were, uh, you know, readers of your blogs and your books to help understand these, uh, you know, uh, principles back, back many years ago. What... I guess, what, what's changed? What's the most fundamental change from, say, writing, uh, y- you know, uh, some of your earlier books to, to taking a, an approach at this one now? When I wrote my previous books, I would take big chunks of time off and just devote myself to them. So something like, uh, DOM Network Security Monitoring, where it's got, you know, dozens of chapters, it's over 800 pages, I would take off weeks at a time and just write. In fact, every major book that I had written before, I wrote the books between jobs. So I left one job, I would just surge on a book, and then I would start a new job. I couldn't do that this time. Uh- Mm-hmm ... you know, I wasn't gonna leave Corelight to write this, and this was...

I was writing this for Corelight, but that just because I'm writing the book doesn't mean I don't have other stuff to do for Corelight. So I had to find ways to, uh, write while I was doing my job.

And something that helped a lot with it was not only using our product, but using AI next to our product.

So, uh, for example, when I was doing the agentic triage section, I had sort of looked ahead to that and I learned what this thing could do for us, and it taught me quite a bit about how to use the product, 'cause the product isn't something that I use on a daily basis. It's, it's not my, my core job. But it was able. to teach me how to use it, which is really pretty amazing.

And then when I' was trying to investigate other aspects, like let's say I was looking at something in, in, um, just a raw log, or I was trying to understand an' alert better, I could drop that into Gemini and say, "I don't understand this. Can' you help me?" Or

I could say, "I need to write a script that will do the following to summarize this data. Can you do that?" And it, would produce something, and I would test it and iterate and then come up with something that, that would work.

And that, that, um, helped alleviate that pressure that I had, uh, the time pressure, because it sped up my writing process. Things that would have taken me, you know, a full day to research 20 years ago, I could research in five minutes and come up with something that I was confident was correct, 'cause

I could test it and say, "Yeah, you're wrong," or, "Yeah, this is right." So, uh, thankfully that, you know, having those automation tools and those research tools made up for the, the more constrained writing environment I had this time around. Uh, yeah. Well, how, how many people you think will, uh, in- ingest your book into AI and ask for a summary?

Oh, I think everyone will. I, I will, I will do that. I'd be interested to see what it says, and if it's... if I agree with the conclusion. You know, if, um, it... Does it... Y- 'cause when you're an author, or at least I would imagine most authors have a goal. They want to communicate certain points to an audience, and how do you know if you've done that? I suppose you could talk to a bunch of readers and see, you know, "What did you think?" Or you could try to read reviews. But, um, it would be cool to drop it into a bunch of different models and say, "Summarize this. Tell me what the most important points are."

And if it comes back with what you were hoping f- to communicate, that's great. Uh, but if it doesn't, if it... or, or if it twists it or if it emphasizes things you didn't think were that important, then maybe, you know, that's a tool that you could use in the future. I didn't do that for this.

Maybe that would be something to consider for, uh, a future project where, you know, it's sort of a... it's almost like a, a QA test, uh, like for software. Uh, well, so you've been spending a lot of time recently, y- you know, on the podcast on talking and interviewing people, uh, at Corelight and elsewhere.

Uh, what, what was it like to switch back to kind of more intensive writing? Uh, it, it can be terrifying at times. So most projects, I try to have a very detailed outline, and I do a ton of research to address each, point before

I start writing so that I'm simply addressing all of the things that I've already researched. I didn't do that as much this time. I had, I had an outline, and I said, "These are the things I wanna cover," but I was a lot more fluid in terms of what I would cover. Because

I found out in some cases there were, there were lots of dead ends where I said, "This, this is... this example's not really working," or, "I think it's boring," or, "It didn't work out the way I thought it' might, so I need to pivot to something else." Beginning each section was... it can, it can just be terrifying. Like, I don't... Like, how do

I start this? But what I found is the case with every single project I've ever done, as long as I could start, I would get the bug to say, "Oh, I c- I need to finish this," or, "Oh, I know what to say next," or whatever, and then it would just s- pull me through. But getting over that initial hump was always difficult.

Uh, you, you talked about a few things that were, you know, kind of interesting discoveries. W- was there one thing that really stood out as, uh, you know, something that surprised you or was a, an aha from this whole process?

I was surprised at how good the models were in digesting and making sense of security data.

I- Mm. I was not convinced that that would be the case. And this one example's not in the book, but it's adjacent, so I'll mention it. Um, recently I was looking at some decompilations of some source code, and I had two different people looking at different parts of this program, and they' had two... They each took screen captures of the tools they were using. One was

Rizin and one was Ghidra. And in both cases, I, I'm not that great with that kind of stuff. So I... It just occurred to me, I should take s- you know, I should download the screenshots, and I'm gonna upload them to Gemini and say, "Gemini, what's going on in these?" And in both cases, it, it identified the screenshots.

It said, "Oh, I, I see this one's Ghidra, this one's Rizin. Here's what, the code does." And then I started asking it questions like, "These two people are trying to solve this problem. What would you suggest?" And it came up with these answers, and it's been a great tool in my own troubleshooting and overclocking and undervolting, and all, the other little tinkering, uh, I do. Even, even doing things like, um, trying to get the new Windows, uh, 2023 certificates installed for secure boot, and some issues I was having with some different systems. Uh, it is remarkably good at solving these sorts of problems.

And if, and if you' provide it with a high quality log set, like every time you do something, you're, you're logging and you're providing it back the details that' it. can look at, you know, as long as you have some level of knowledge of what you're looking at, and you can guide it' along a, a good path, you can get some really great results. Yeah, and if you don't, it. will help you' learn about those things, so...

Yeah. I- if you're careful. It, it, like, it, it pays to push back sometimes. Like there's been many, many times where

I've been working with it, and it'll say something, and I'll say, "Are you sure about that?" "Oh, no, you're right. I don't need to... No, that' won't work," or whatever. One of, the things I often ask is, "What are the consequences of running this?"

Or, "If I, if I don't do this, is, is there another way I could do this?" Because sometimes I'll recognize another approach that it's taking, and I'll say, "Oh, okay, I, I know what that will do," versus some invocation that I'm like, "I don't know what that does. That, uh, you know, I'm a little scared you're trying to ask me to run this certain command." It... Yeah. I, I just had one of those yesterday where I was, like, trying to change my path, and I said, "Yeah, won't that have a bunch of other, you know, ramifications on other programs?" "Oh, yeah, you're right, it will." You know, it's just so focused on solving the problem at hand that it sometimes forgets that there are other things happening on a system. So i- i- the book's obviously sponsored by Corelight, kind of written, you know, using Corelight's time. Uh, but i- is it focused on Corelight specifically as a product?

So I don't think I even say the word Corelight in the first chapter. I think the first chapter is com- the, the word Corelight doesn't even appear. It may appear in the second chapter, um, but probably not, because I'm just talking about NSM data, types, and those have been my standard for data, types now for, you know, 25 years. Uh, by the third chapter, though, I'm using Corelight because I need an NDR to show you, uh, you know, stuff in the wild. And we have this great, uh, environment called Cyber Lab, where we're running our product and tons of other, uh, sources and e- exporters and all kinds of stuff. So we have a lot of rich traffic to look at. So I needed something to not only demonstrate what the product can do, you know, a- a

NDR, uh, product could do, but also have data to show people who were interested in seeing, you know, nitty-gritty type stuff. So yeah, by the third chapter, I'm using our investigator product to show how to, uh, investigate alerts. And then again, for the, uh, fourth chapter, I'm showing how to do threat hunting with, uh, with Corelight Investigator and also with our, our logs, uh, log scale instance. And then in the fifth chapter, um, I do talk about our agentic triage offering be- uh, that's built into Investigator because it's a great example of how I think it should be done, uh, in a good way. You know, not just, not just having the system tell you what it thinks, but being able to drill, drill down on it. You know, say, "Why did you come up with that? What is the underlying data? I need to validate what you think before I just blindly trust you." So anything we didn't talk about that you really wanted to share about the, the new book? I'm just glad that I've been able to do this again. It's, it's been a few years since I wrote anything like this. Um, during COVID, my, my big COVID project was turning about 3,000 blog posts into a four-volume series called, uh, Best of Dao Security

Blog. The reason I did that was the book is the most durable storage format I think we've ever created. There are books that you can read now that were written hundreds of years ago, and I thought that, uh, you know, although Blogger, hosted by Google, has been around for me now for

23 years, it won't always be around. So I thought it would be cool to put those, the content of those blog posts, the, the ones that I thought that were the most interesting, into, uh, a themed collected format, and also to write commentary on each one. Because if something was, had changed or was interesting or not interesting, whatever, I wanted to have some commentary for each one of those. But that was, that was, like I said, my COVID project over

2020, 2021. So it had been five years since I'd put anything out like that, and, um, uh, it had been seven years between Practice of Network Security Monitoring and the first Best of Dao Security Blog. So it was, it was nice to, to try to exercise those writing muscles again after, you know, several years. Thank you for talking about this. I got a chance to read the first chapter, and I can't wait for the rest to get published so I can check out the rest. Can you remind people where they can find the new book? Yeah. The easiest way to do it would be just to Google Corelight NDR Essentials book.

It's gonna be the first result. Also, we'll have the link to the, the book in the podcast description, so wherever you're listening, it should be there. And, uh, there's a possibility that we're gonna be expanding it as well as other topics come up, because at this point it's just in a digital format, so adding material is, is not that difficult. Uh, there should be an option for print editions because we'd like to be able to put this into people's hands if they want to. You know, if you're at a, a trade event or something and you see the Corelight booth, you know, come on up. Uh, hopefully in the next few months we'll have print editions that you can just grab and, you know, read when you're, you're flying home, and you won't have to look at it on a screen. Well, thanks for letting me talk to you, Richard, and thanks so much for writing this new book. Can't wait to s- see it. Yeah. Thank you, Vince. Thank you for being the first new host of the, uh, Network Defenders podcast. I appreciate it. Thank you for joining us on the Network Defenders podcast, sponsored by Corelight. We will see you on the network. You've been listening to Corelight Defenders.

To stay informed with expert intelligence on today's cybersecurity challenges, please subscribe to ensure you never miss an episode. We'll see you on the network.