Why SOCs Still Can't Answer 'What Happened?' — The Case for Network Detection
Alert-driven triage keeps missing context. NDR proponents argue packet truth is the only ground truth left.

Key points
- Alert-based triage answers whether a rule matched, not what the full chain of events looked like.
- EDR agents can't cover appliances, OT gear, IoT, or sealed vendor hardware, and attackers know it.
- Network telemetry records what happened on the wire regardless of endpoint cooperation.
- Selective flow records and triggered capture give investigators the session record endpoint data can't reconstruct after the fact.
- The real gap is correlation: NDR, EDR, and identity logs in separate consoles are three silos, not one investigation.
Ask a SOC analyst mid-investigation what actually happened on the wire and you'll usually get a pause. Not because they're bad at the job, but because the telemetry they've been handed rarely reconstructs the event end to end. It flags the symptom. The chain of custody between symptom and root cause is where investigations go to die.
Is the problem the alerts or what's behind them?
Alerts answer "something matched a rule." They don't answer what evidence exists or whether you're seeing it all in context. Those are different questions, and the second one is the one that matters when you're writing the incident report or briefing counsel.
EDR is genuinely useful: process trees, command-line capture, file hashes. But EDR depends on an agent being installed and not actively under attack by the thing you're trying to detect. The list of devices that can't run an agent keeps growing: appliances, OT gear, contractor laptops, IoT, sealed vendor hardware. Recent exploitation campaigns against Ivanti, Fortinet and Palo Alto appliances drove that point home. Our 2 June story on operationalizing EDR made a related point: detection telemetry only matters if someone is reading it, and most teams still aren't.
What does NDR actually give you?
Network telemetry doesn't care whether the endpoint cooperates. Packets traverse the wire regardless.
The pragmatic version of NDR isn't full packet capture for everything: storage economics still say no. It's selective flow records plus triggered capture tied to detection logic, Zeek-style logs combined with the ability to pull session content when an indicator fires. That gets you the record of who talked to whom and what the handshake looked like, the reconstruction that endpoint data can't provide after the fact.
Encrypted traffic complicates the metadata story. It doesn't eliminate it.
Should the silos worry you more than the tools?
The operational gap most teams hit is correlation. NDR data in its own console, EDR in another, identity logs in a third, is just worse handoffs dressed up as coverage. The value appears when the network record is queryable alongside the endpoint timeline and the auth events on the same case. Forty tools and forty-three-day dwell times are the symptom of that failure, as our 19 June story on SOCs rethinking the triage stack laid out.
Does any of this have a track record?
None of this argument is new. Richard Bejtlich has been making versions of it since his network security monitoring book in 2004, and operational reality keeps proving him right: when endpoint data is absent or manipulated, the wire is what you have left.
For defenders building 2025 budgets, the question isn't NDR versus EDR. It's whether your investigation workflow can answer the basic questions without both. The vendors will always have a pitch. The packet record doesn't negotiate.



