WhatsApp us

Network Detection and Response

Powered by GREYCORTEX Mendel

Deep Network Intelligence for Advanced Threat Detection

The GREYCORTEX Mendel NDR platform delivers advanced network detection capabilities based on full traffic analysis, machine learning, and behavioral analytics. It is designed to identify sophisticated cyber threats that evade traditional security controls, including firewalls, IDS/IPS, and endpoint-based solutions.

At iS Group, Mendel is deployed as part of a Managed NDR service or integrated into a broader SOC / XDR ecosystem, ensuring not only detection but also operational response.

Technology Foundation

GREYCORTEX Mendel is built on a combination of:

  • Full packet capture and metadata analysis (L2–L7 visibility)
  • Advanced behavioral analytics (NBA – Network Behavior Analysis)
  • Machine learning models for anomaly detection
  • Deep packet inspection (DPI) with protocol decoding
  • Threat intelligence correlation and signature-based detection


Unlike traditional monitoring tools, Mendel provides context-aware detection, combining traffic analysis with behavioral profiling.

Key Technical Capabilities

Full-Fidelity Network Visibility

  • Continuous monitoring of north-south and east-west traffic
  • Support for SPAN/TAP-based traffic ingestion
  • Visibility across on-premise, virtualized, and cloud environments
  • Asset discovery including unmanaged and shadow IT devices

Behavioral Analytics Engine (NBA)

  • Baselines normal network behavior for:
    • Users
    • Devices
    • Applications
  • Detects anomalies such as:
    • Lateral movement
    • Privilege misuse
    • Unusual communication patterns

Mendel’s ML models continuously adapt to network conditions, improving detection
accuracy over time.

Advanced Threat Detection

Detection capabilities include:

  • Command-and-Control (C2) communication
  • Data exfiltration attempts
  • Malware communication patterns
  • DNS tunneling and covert channels
  • Fileless and zero-day attack indicators

Detection combines heuristics, ML, and signature-based methods, minimizing false
positives while maintaining high sensitivity.

Encrypted Traffic Analysis

  • Detection within encrypted traffic (SSL/TLS) without requiring decryption
  • Analysis based on:
    • Traffic patterns
    • Session metadata
    • Behavioral anomalies

Forensics & Incident Investigation

  • Full packet capture (PCAP) for retrospective analysis
  • “Back-in-time” investigation of incidents
  • Visual attack reconstruction and timeline analysis
  • Detailed session-level inspection

Threat Intelligence Integration

  • Correlation with global threat intelligence feeds
  • IOC matching (IPs, domains, hashes)
  • Continuous update of detection logic
Years of proven track record
in cybersecurity
0 +
Number of endpoints with the XDR platform deployed
0 +
Attacks, incidents, requests,
 changes handled in the past year
0 +
Successfully implemented cybersecurity projects
0 +

Architecture Overview

GREYCORTEX Mendel architecture consists of:

Network Sensors / Collectors

  • Passive monitoring via TAP/SPAN
  • High-throughput packet processing

Central Analysis Engine

  • ML-based detection
  • Behavioral analytics
  • Threat correlation

Management & Visualization Console

  • Real-time dashboards
  • Incident investigation tools
  • Network topology and communication maps

Integration with Security Ecosystem

Mendel is designed for interoperability within enterprise security environments:

  • SIEM integration (log forwarding, correlation)
  • SOAR platforms (automated response workflows)
  • XDR ecosystems (endpoint + network correlation)
  • REST API for third-party integrations

iS Group Managed NDR Service

iS Group delivers GREYCORTEX Mendel as a fully managed service, ensuring operational value beyond technology deployment.

Service Scope

  • 24/7 monitoring and alert triage
  • Threat hunting using network telemetry
  • Incident validation and escalation
  • Forensic analysis and reporting
  • Continuous tuning of detection models
  • Integration into customer SOC or iS Group SOC

Role within XDR and SOC Architecture

NDR (Mendel) complements other security layers:

  • Endpoint (XDR) → detects host-level activity
  • Network (NDR – Mendel) → detects communication and lateral movement
  • SIEM/SOC → central correlation and response


This layered approach provides high-confidence detection across the entire attack surface.

Business Impact

  • Detection of threats invisible to endpoint-only solutions
  • Visibility into unmanaged and IoT devices
  • Reduction of attacker dwell time
  • Faster incident investigation using packet-level data
  • Improved overall security posture

Typical Enterprise Use Cases

  • Advanced Persistent Threat (APT) detection
  • Lateral movement identification in data centers
  • Insider threat detection
  • Data exfiltration monitoring
  • Hybrid and cloud network visibility

Why iS Group + GREYCORTEX

  • Proven expertise with Mendel NDR deployments
  • Strong integration into SIEM and XDR environments
  • MSP delivery model aligned with enterprise operations
  • Focus on measurable detection and response outcomes

Contact us today

Request a free consultation or readiness audit—fill out a short form and we will get back to you no later than the next business day. Request a consultation