Detect, investigate, and respond to network threats in real time. AI-driven analysis with SHAP explainability, encrypted traffic inspection, and automated compliance.
EU-based network detection and response. SOC 2 Type I in preparation, GDPR: privacy by design.
// What NetSenX does today
Detects what signatures miss — and shows its work
Every capability below is in the product today. Where the plan matters, we say so.
01
Behavioural detection
Behaviour, not signatures
The engine scores how each host behaves on the network, so a new malware variant without a signature still leaves a trail. NetSenX works alongside your EDR and SIEM — it does not replace them.
Command-and-control (C2) beaconing
Scanning and lateral movement
Unusual outbound data volume
02
Explainable · SHAP
Every alert explains itself
Each alert lists, in plain language, the network features that drove its score (SHAP values). On every plan, Free included.
03
Calibrated · conformal
A false-positive bound you can check
A split-conformal layer bounds the false-positive rate of the alerts the engine surfaces, at a confidence level you set, using benign traffic your analysts have labelled on your own network. The bound appears only once your calibration data supports it; until then, the dashboard says so instead of showing a number.
04
OT / ICS · Pro plan and up
Industrial protocols, observed passively
Modbus/TCP, DNP3, BACnet/IP, EtherNet/IP and S7comm are read from passive capture. Devices classified as OT are never actively probed — no risk to PLCs or SCADA.
05
Shadow AI · Pro plan and up
See which AI services your network uses
Flags traffic to external AI services and to locally run language-model runtimes, so unapproved AI use becomes visible before it turns into a data-protection issue.
06
NIS2 · GDPR
Reporting deadlines, tracked
Incidents are tracked against the NIS2 Art. 23 deadlines — early warning within 24 hours, notification within 72 hours, final report within one month — and a GDPR Art. 33 breach notification is prepared for your DPO. Submitting it stays with you. PDF reports from the Starter plan.
07
MITRE ATT&CK
Mapped to ATT&CK
Where a detection corresponds to an ATT&CK technique, the alert names it, and a coverage view shows which techniques your enabled detections address.
08
Agent
Runs as a system service
The agent installs as a system service on Linux, macOS and Windows and keeps monitoring across reboots. Your data is stored in the EU.
// How detection works
From packet to evidence, in five layers
Hover over a layer, or select it with the keyboard, to see what happens there.
Capture
The agent observes network flows on the host: metadata and a few protocol fields. Encrypted traffic is never decrypted.
Behaviour
Flows are scored against what is normal for your network — timing, volume, fan-out and protocol use.
Explanation
Every alert carries SHAP values: which features pushed the score, and by how much.
Calibration
A conformal layer bounds the false-positive rate once your labelled benign traffic supports it — and says so while it does not yet.
Evidence
Alerts, analyst decisions and configuration changes are written to an audit log you can hand to your auditor.
01 · Capture
02 · Behaviour
03 · Explanation
04 · Calibration
05 · Evidence
// A detection, up close
Follow one attack through a network
Select a host, in the list or on the map, to see what NetSenX observed there and how the alert explains its score.
Finance workstationAlert
Alert: likely command-and-control (C2) beaconing, followed by lateral movement.
What NetSenX observed
Small outbound connections to one external address, repeating at a near-regular rhythm. Soon after, connections to two internal servers this workstation has no history with.
Why the score moved
Raised the scoreOutbound connections repeat at near-regular intervals, typical of an implant checking in with its server.
Raised the scoreThe external address has never been seen on this network before.
Raised the scoreIt reached internal servers it has never talked to.
Lowered the scoreEach connection carries a small, ordinary amount of data.
What happens next
An analyst reviews the alert and its reasons, then isolates the workstation or marks the alert as a false positive. Either decision is written to the audit log.
File serverAlert
Alert: unusual outbound data volume.
What NetSenX observed
Right after the workstation's first connection, the file server sent it far more data than it sends any single client on a normal day.
Why the score moved
Raised the scoreThe volume of data sent is far above this server's usual level.
Raised the scoreThe receiving workstation rarely fetches files from this server.
Lowered the scoreThe file-sharing protocol and port are the ones it uses every day.
What happens next
An analyst reviews it together with the workstation's alert. The decision, to isolate the server or mark the alert as a false positive, is written to the audit log.
Directory serverContacted
Contacted during the attack, no alert of its own.
What NetSenX observed
The workstation connected to it while reaching out to other servers. The directory server's own behaviour did not change.
What happens next
The workstation's alert names it as a contacted host, so an analyst can check it even though it raised no alert itself.
DatabaseNo alert
No alert.
What NetSenX observed
Its traffic stayed within what is normal for this host.
What happens next
Nothing to review. A quiet host stays quiet: alerts come from behaviour that changes, not from every connection.
LaptopNo alert
No alert.
What NetSenX observed
It sits on the same network as the finance workstation, but its behaviour did not change.
What happens next
Nothing to review. Being close to a compromised host is not, on its own, a reason to alert.
PrinterNo alert
No alert.
What NetSenX observed
It talks on the same few ports as always; nothing new appeared.
What happens next
Nothing to review.
GatewayNo alert
No alert.
What NetSenX observed
It forwarded the workstation's traffic to the internet, as it does for every host.
What happens next
Nothing to review: the behaviour that matters is on the host that started the connections.
External addressExternal
Outside your network.
What NetSenX observed
It is not one of your hosts, so NetSenX sees it only as the other end of your hosts' flows.
What happens next
Being new to your network is one of the reasons the workstation's alert gives. Blocking it at the firewall is a decision the analyst can take after reviewing the alert.
Illustrative scenario on a made-up network, not customer data. Each reason shows which way it pushed the score; in the product, every reason also carries its SHAP value.
// Who it is for
Built for specific teams, not for everyone
Who gets the most out of NetSenX today — and who is better served by another tool.
Manufacturing · Energy · Utilities
Essential or important entities under NIS2 that run OT networks with Modbus, DNP3 or BACnet and need visibility without touching PLCs or SCADA.
Best fit:Pro plan — OT/ICS detection included
Healthcare · Pharma · Medical devices
Organisations that process health data on networks full of connected medical devices. The DPO wants explainable alerts and a breach timeline, not black-box verdicts.
Best fit:Starter plan and up — PDF reports, including the GDPR Art. 33 breach notification
Finance · Fintech · Insurance
Small security teams in regulated finance that need behavioural network detection and a clean incident record — without drowning in alerts.
Best fit:Business plan — SIEM export into the tools you already run
IT manager · Network administrator
No dedicated SOC: security and compliance sit in one role. You need alerts that explain themselves and reports you can take to the board.
Best fit:Free plan to start — up to 3 devices
MSSPs · Security integrators
You run security for several clients and need strict separation per client and reports under your own brand.
Best fit:Enterprise plan — multi-tenant deployment and white-label, by contract
Not for you if…
You need endpoint protection (EDR), antivirus, a SIEM for log aggregation or a fully managed detection service (MDR).
NetSenX complements these tools — it does not replace them.
Transparent Pricing
Start free, scale as you grow. No hidden fees, no per-device licensing traps.
Short, direct answers to what buyers ask about NDR, NIS2, pricing and data residency.
What is NDR (Network Detection and Response)?
NDR is security software that watches network traffic, flags behaviour that looks like an attack and gives you the evidence to respond. Firewalls and endpoint agents each see their own device; NDR sees how hosts talk to each other — command-and-control beaconing, scanning, lateral movement and unusual outbound data. NetSenX is a Network Detection and Response (NDR) platform for EU mid-market organisations that detects attacks from network behaviour, explains every alert in plain language and keeps customer data in the EU.
Do I need NDR for NIS2?
NIS2 does not name NDR, but it does require you to detect and handle incidents and to report significant ones on a fixed timeline. Article 21 lists incident handling among the required risk-management measures; Article 23 sets an early warning within 24 hours, a notification within 72 hours and a final report within one month. Network monitoring is one practical way to detect incidents in time and keep the evidence those reports need, and NetSenX tracks the Article 23 deadlines for each incident. The duties sit with your organisation: no tool fulfils them on its own.
How much does NDR cost for a 200-person company?
With NetSenX the price depends on the number of devices you monitor, not on headcount: Starter costs €49 per month for up to 10 devices, Pro €99 for up to 25, Business €249 for up to 100, and Enterprise starts at €999 per month (prices exclude VAT; the Free plan costs €0). A device is a host running the NetSenX agent, and one agent on a SPAN or TAP port watches a whole network segment, so a 200-person company does not need 200 devices. Many enterprise NDR vendors publish no price list and quote each deployment individually.
How does NetSenX handle GDPR, and where is my data stored?
Customer data is stored in the EU: the database in Ireland (AWS eu-west-1) and the API in Frankfurt, Germany. NetSenX analyses network metadata and never decrypts encrypted traffic; a data processing agreement under GDPR Article 28 and the sub-processor list are published, and the DPO is reachable at [email protected]. Payment and e-mail sub-processors operate under EU Standard Contractual Clauses, and some AI Analyst capabilities use a provider outside the EU only with your explicit consent. GDPR is assessed for your processing as a whole, so we do not claim a certificate for it.
Can NetSenX monitor OT and industrial networks?
Yes, from the Pro plan. NetSenX reads Modbus/TCP, DNP3, BACnet/IP, EtherNet/IP and S7comm from passive capture on a SPAN or TAP port. Devices classified as OT are never actively probed, so there is no risk to PLCs or SCADA systems.
How is NetSenX different from a signature-based IDS?
A signature-based IDS matches traffic against known attack patterns; NetSenX scores how each host behaves, so a new malware variant without a signature still leaves a trail. Every alert lists, in plain language, the network features that drove its score (SHAP values). NetSenX works alongside your IDS, EDR and SIEM — it does not replace them.
Can NetSenX detect threats in encrypted traffic?
Yes, from metadata: encrypted traffic is never decrypted. NetSenX looks at flow metadata and a few protocol fields — timing, volume, destinations and the TLS handshake — so beaconing and unusual data transfers stay visible without breaking encryption or reading content.
How is NetSenX deployed?
You choose: connect one agent to a SPAN or TAP port to watch a whole network segment, or install the agent on the hosts you want to monitor. The agent runs as a system service on Linux, macOS and Windows; on Linux the installer accepts only a package signed with the NetSenX release key, and Windows and macOS agents are set up together with NetSenX support. The dashboard is a service hosted in the EU; an on-premises option is available on the Enterprise plan.
Does NetSenX replace my EDR or SIEM?
No. NetSenX adds the network view that endpoint and log tools do not have; it does not replace endpoint protection (EDR), antivirus, log aggregation (SIEM) or a managed detection service (MDR). From the Business plan, alerts can be exported to the SIEM you already run.
What is the NetSenX Math Guarantee?
It is a verifiable false-positive bound among engine-surfaced alerts, derived with split-conformal prediction from benign traffic your analysts have labelled on your own network, at a confidence level you set. The dashboard shows the bound only once your calibration data supports it; until then it says so instead of showing a number. It describes a method and what your data currently supports, not a fixed rate. It is included on every plan.
Can NetSenX detect shadow AI on my network?
Yes, from the Pro plan. NetSenX flags traffic to external AI services and to locally run language-model runtimes, so unapproved AI use becomes visible before it turns into a data-protection issue.
Is there a free plan?
Yes. The Free plan covers up to 3 devices, keeps 30 days of alert history and includes the plain-language explanation on every alert and the NetSenX Math Guarantee. There is no time limit and no credit card is required.
Secure Your Network Today
Detect and respond to network threats in real time with EU-native NDR.