Skip to content
Newsroom

Explore coverage of SANDS Lab’s technology, products, business performance, and key developments—all in one place. We’ve gathered major stories about SANDS Lab from media outlets in Korea and around the world.

SANDS Lab unveils 'agentic NDR' to counter advanced AI-driven attacks — CTI integration and MDR expansion for MNX

Apr 21, 2026Press Coverage

SANDS Lab unveiled an agent-based NDR architecture for its MNX solution, integrating cyber threat intelligence and credential-breach alerts into security operations.

AI security firm SANDS Lab (KOSDAQ 411080, CEO Kim Ki-hong) unveiled an agent-based NDR architecture for its AI-powered network detection and response (NDR) solution 'MNX,' integrating cyber threat intelligence and credential-breach alerts to support judgment and prioritization in security operations. The strategy reshapes the traditionally detection-only NDR market toward interpreting the full flow and context of a threat.

As encrypted traffic grows and AI-powered attacks become more sophisticated, the ability to identify anomalies early and quickly trace intrusion paths, spread, and the timing and scope of data leaks has become increasingly critical. How efficiently a system delivers the analysis needed for response — beyond simple detection — is emerging as the key competitive edge.

In line with this, SANDS Lab said it is upgrading MNX into an NDR centered on supporting operational decisions. It combines AI-based anomaly and abnormal-session detection, file extraction with AV/AI analysis, drill-down attack-flow tracing, and automated Playbook integration, helping real-world security operators reach the judgments they need faster.

MNX also holds a security function verification certificate, giving it both reliability and deployment stability — meeting the validation bar required by enterprises and public institutions alike. Its quantum-resistant cryptography assessment capability also lets it flag whether network communications are quantum-resistant, laying groundwork for a future shift to quantum-safe security.

The solution further combines SANDS Lab's own cyber threat intelligence service 'CTX' with its credential-leak alert service 'IDPW' to broaden its analytical scope. Real-time threat data collected and analyzed by CTX feeds into MNX's traffic analysis, helping it identify unknown anomaly patterns, attacker infrastructure, and new C2 communication indicators faster.

A SANDS Lab representative said that despite being a later entrant to the NDR market, MNX has already accumulated diverse deployment experience — including large-scale 10G environments and distributed environments such as DMZ segments — addressing scenarios like unauthorized data exfiltration detection, identifying internally infected PCs, and visualizing anomalies in encrypted traffic.

CEO Kim Ki-hong said, "NDR must now evolve beyond simply detecting more anomalies into an operational system that visualizes the entire distributed network and turns that visibility into actionable judgment. By linking CTX and IDPW into MNX's agent-based NDR architecture, which interprets the flow and context of threats, we will help customers respond to hacking threats faster and more accurately."