MNX is an AI-native NDR that analyzes full-packet network traffic and connects scattered detection events into a single attack narrative, helping security teams detect, investigate, and respond to threats faster.
What security teams need isn't more alerts — it's better context.
Today’s attackers can blend into legitimate account activity, hide within encrypted traffic, and move quietly through internal networks. Security teams must distinguish real threats from a flood of events and respond quickly.
Hiding behind encrypted traffic.
As encrypted traffic becomes the norm, relying on payloads and logs alone can leave gaps in network visibility.
Moving quietly through the network after initial access.
After gaining initial access, attackers move laterally between assets using internal network traffic that existing security tools may not fully observe.
Threats emerge before signatures exist.
Zero-days, novel threats, and low-and-slow attacks are difficult to detect with signature-based methods alone.
Important attacks get lost in a flood of alerts.
Security teams can’t investigate every event that comes in—they need to prioritize the events most likely to represent real threats.
MNX turns network traffic into actionable threat context.
A single DNS request, TLS session, or file transfer can’t tell you the full context of an attack. MNX connects traffic, sessions, assets, files, and threat intelligence to reconstruct attack behavior in context.
Traffic Collection & Normalization
Collects and normalizes network traffic.
Session Reconstruction & Asset Mapping
Reconstructs sessions and maps relationships between assets.
Behavior Pattern Analysis
Analyzes behavior patterns and anomalies to identify attacker intent.
Investigation & Response Support
Provides the context and insight needed for investigation and response.
Correlated detections reveal a single attack narrative.
MNX’s AI doesn’t simply surface more events. It selects meaningful network events, connects related activity, prioritizes them by risk, and presents them as a single, explainable attack narrative.
Identifying events most likely to represent real threats
Distinguishes routine activity from events most likely to indicate a real threat.
Connecting related activity into a single attack flow
Connects multiple sessions, assets, files, and threat data into a single attack context.
Highest-risk attacks first
Prioritizes investigation targets based on assessed risk.
Explaining why an attack is considered risky
Provides the detection rationale and supporting evidence so analysts can understand the attack flow.
From known attacks to previously unseen threats.
MNX combines supervised-learning detection with unsupervised behavioral analysis. Known attacks are identified using learned threat patterns and multiple detection layers, while unknown threats are detected by analyzing deviations from your network’s own behavioral baseline.
Detecting known attack patterns
Identifies known attack activity—including C2 communication, data exfiltration, exploits, malware, and DB reconnaissance—using supervised learning and multiple detection layers such as signatures, threat intelligence, AV + AI file detection, YARA, and blacklists.
Unsupervised Behavioral Analysis
Detects new or low-frequency communication, low-and-slow attacks, abnormal lateral movement, and other deviations from a behavioral baseline built from your network’s own traffic.
Make hidden network activity visible —and ready for analysis.
MNX identifies and structures network traffic, sessions, assets, and files, giving security teams the visibility needed to trace internal activity and threat progression.
Comprehensive Traffic Visibility
Collects and analyzes traffic between the internet and the internal network using an out-of-band deployment.
Protocol & Application Identification
Identifies 500+ protocols and 2,500+ applications, providing Layer 7 visibility into network activity.
Encrypted Traffic Behavioral Analysis
Analyzes application and behavioral patterns even when traffic is encrypted with TLS, using metadata and communication characteristics.
In-Depth Session Analysis
Reconstructs sessions and analyzes asset relationships and anomalous communication flows.
Internal Asset Identification
Identifies asset information—including IP address, MAC address, OS, and browser—to help trace the asset from which a threat originated.
Incident Tracing & Evidence Collection
Uses searchable metadata and historical raw data to quickly trace past communications based on specified conditions and collect evidence for breach investigations.
MNX goes beyond detection — supporting investigation and response.
Automated Response
Runs a playbook-based response process based on the detection scenario.
Integration with Existing SOC Systems
Connects with existing SOC systems through Syslog and other supported methods.
Blocking Policy Integration
Integrates with IP- or domain-based blocking policy enforcement.
Alert Delivery
Delivers alerts via email, messaging platforms, and other supported channels.
External System Integration
Supports API-based connections to external systems.
Ask in natural language. Get answers grounded in attack context.
MNX uses SANDS Lab’s own LLM to investigate detected threats and support analyst decision-making. Deployment options and LLM usage scope are configured based on your environment and operational policies.
Natural-Language Queries
Investigate detected threats by asking questions in natural language.
Risk Summary
Summarizes the risk level and key details of a detected threat.
MITRE ATT&CK Mapping
Maps detected attacks to the MITRE ATT&CK framework for easier investigation and analysis.
Response Recommendations
Generates response recommendations based on the analysis results.
Deploy where you need visibility— without redesigning your network.
Passive Deployment
Receives mirrored traffic via SPAN/TAP in an out-of-band deployment, minimizing impact on your production network.
Supports Diverse Network Environments
Supports traffic monitoring and centralized analysis across on-premises, closed networks, multi-site, and IT/OT environments, as well as cloud and hybrid infrastructures.
Scales with Your Network
Available in 500 Mbps, 1 Gbps, 5 Gbps, and 10 Gbps configurations to match your network requirements.
Integrates with Your Existing Security Stack
Connects with SIEM, SOAR, EDR, firewalls, WAFs, and other security systems through REST APIs, Syslog, email, webhooks, messaging platforms, and other supported methods.
Environments change. Network visibility still matters.
Public institutions, manufacturing/OT, media & broadcasting, education & healthcare, and cloud environments all have different infrastructure, but security teams need the same fundamentals: visibility into internal traffic, scattered detections connected into a single attack context, and the highest-risk threats prioritized first.

Internal Visibility for On-Premises, Isolated, and Air-Gapped Environments
Provides internal visibility and evidence-backed analysis across on-premises, isolated, and air-gapped environments, supporting security operations and compliance.

Passive Monitoring Without Operational Impact
Detects anomalous communications and internal activity across IT/OT environments through SPAN/TAP-based passive monitoring, without disrupting operations.

Fast Anomaly Detection in High-Volume Traffic Environments
Helps quickly identify anomalous communications and hidden security risks even in high-volume traffic environments.

Asset & Behavioral Analysis for Mixed Networks
Analyzes assets and behavioral patterns across mixed networks where personal devices and unmanaged endpoints coexist.

Centralized Monitoring for Hybrid, Multi-Site Environments
Supports centralized monitoring and AI-assisted threat investigation across hybrid and multi-site environments.
An NDR proven across real-world environments.
Deployed across diverse network environments—from the public sector to manufacturing, education, healthcare, and cloud. More than 20 years of attack-response technology and accumulated threat data form the foundation of MNX’s AI analysis.
Packet-Based Deep Analysis & APT Response
Built on SIMBA-HV deep packet analysis technology to detect C2 communications and respond to APT attacks.
Threat Intelligence Built Over Time
Continuously accumulates IoCs, campaign data, and other threat intelligence through malwares.com, CTX, and related services.
Evolved into an AI-Native NDR
This foundation evolved into MNX, bringing together AI-based detection, behavioral analysis, attack narrative, and LLM-assisted investigation.
Frequently asked questions about MNX.
We already have firewalls, IPS, EDR, and SIEM — why do we need an NDR?
Existing security tools each cover specific areas, including access control, signature-based detection, endpoint activity, and logs/events. MNX adds network-level visibility by analyzing network traffic and activity between assets that these tools may not fully capture, then connecting related events into a single attack context.
Can it analyze encrypted traffic?
MNX provides visibility into network behavior even when traffic is encrypted by analyzing communication metadata and session/application characteristics. Whether decryption is used, and how it is implemented, depends on your network environment.
How does it detect unknown attacks?
MNX combines unsupervised behavioral analysis with supervised detection. It identifies unknown threats by analyzing statistical and time-series deviations from your network’s normal baseline, including anomalies such as new or low-frequency communications.
Can it integrate with our existing security stack?
MNX integrates with existing security systems, including SIEM, SOAR, EDR, firewalls, and WAFs, through REST APIs, Syslog, and other supported methods.
Can it be deployed in isolated or air-gapped environments?
MNX supports on-premises deployment, including isolated and air-gapped environments. Deployment architecture and the scope of LLM and external threat intelligence usage are configured based on your environment and operational policies.
What network sizes does MNX support?
MNX is available in 500 Mbps, 1 Gbps, 5 Gbps, and 10 Gbps configurations to match different network requirements. In multi-site environments, collection sensors can be deployed with centralized analysis and management.
Not more alerts — see the full attack context.
MNX gives you visibility into behavior across your network, helping you prioritize threats for investigation and understand how an attack unfolded—faster.
How does this product behave in your environment?
Whether you're exploring, evaluating, or rolling out, you connect directly with a SANDS Lab solutions engineer. Clear every question before contract — that's the point.
Product evaluation & PoC
Real-data PoCs, technical deep-dive sessions, and custom integration scoping. Everything you'd need to validate technical fit before the paperwork starts.
Technical collaboration & licensing
If you want to use the product in an academic benchmark or co-authored paper, we support research licenses and the underlying datasets. Co-authorship is on the table.