Powered by GREYCORTEX Mendel
Deep Network Intelligence for Advanced Threat Detection
The GREYCORTEX Mendel NDR platform delivers advanced network detection capabilities based on full traffic analysis, machine learning, and behavioral analytics. It is designed to identify sophisticated cyber threats that evade traditional security controls, including firewalls, IDS/IPS, and endpoint-based solutions.
At iS Group, Mendel is deployed as part of a Managed NDR service or integrated into a broader SOC / XDR ecosystem, ensuring not only detection but also operational response.
Technology Foundation
GREYCORTEX Mendel is built on a combination of:
- Full packet capture and metadata analysis (L2–L7 visibility)
- Advanced behavioral analytics (NBA – Network Behavior Analysis)
- Machine learning models for anomaly detection
- Deep packet inspection (DPI) with protocol decoding
- Threat intelligence correlation and signature-based detection
Unlike traditional monitoring tools, Mendel provides context-aware detection, combining traffic analysis with behavioral profiling.
Key Technical Capabilities
Full-Fidelity Network Visibility
- Continuous monitoring of north-south and east-west traffic
- Support for SPAN/TAP-based traffic ingestion
- Visibility across on-premise, virtualized, and cloud environments
- Asset discovery including unmanaged and shadow IT devices
Behavioral Analytics Engine (NBA)
- Baselines normal network behavior for:
- Users
- Devices
- Applications
- Detects anomalies such as:
- Lateral movement
- Privilege misuse
- Unusual communication patterns
Mendel’s ML models continuously adapt to network conditions, improving detection
accuracy over time.
Advanced Threat Detection
Detection capabilities include:
- Command-and-Control (C2) communication
- Data exfiltration attempts
- Malware communication patterns
- DNS tunneling and covert channels
- Fileless and zero-day attack indicators
Detection combines heuristics, ML, and signature-based methods, minimizing false
positives while maintaining high sensitivity.
Encrypted Traffic Analysis
- Detection within encrypted traffic (SSL/TLS) without requiring decryption
- Analysis based on:
- Traffic patterns
- Session metadata
- Behavioral anomalies
Forensics & Incident Investigation
- Full packet capture (PCAP) for retrospective analysis
- “Back-in-time” investigation of incidents
- Visual attack reconstruction and timeline analysis
- Detailed session-level inspection
Threat Intelligence Integration
- Correlation with global threat intelligence feeds
- IOC matching (IPs, domains, hashes)
- Continuous update of detection logic
Architecture Overview
GREYCORTEX Mendel architecture consists of:
Network Sensors / Collectors
- Passive monitoring via TAP/SPAN
- High-throughput packet processing
Central Analysis Engine
- ML-based detection
- Behavioral analytics
- Threat correlation
Management & Visualization Console
- Real-time dashboards
- Incident investigation tools
- Network topology and communication maps
Integration with Security Ecosystem
Mendel is designed for interoperability within enterprise security environments:
- SIEM integration (log forwarding, correlation)
- SOAR platforms (automated response workflows)
- XDR ecosystems (endpoint + network correlation)
- REST API for third-party integrations
iS Group Managed NDR Service
iS Group delivers GREYCORTEX Mendel as a fully managed service, ensuring operational value beyond technology deployment.
Service Scope
- 24/7 monitoring and alert triage
- Threat hunting using network telemetry
- Incident validation and escalation
- Forensic analysis and reporting
- Continuous tuning of detection models
- Integration into customer SOC or iS Group SOC
Role within XDR and SOC Architecture
NDR (Mendel) complements other security layers:
- Endpoint (XDR) → detects host-level activity
- Network (NDR – Mendel) → detects communication and lateral movement
- SIEM/SOC → central correlation and response
This layered approach provides high-confidence detection across the entire attack surface.
Business Impact
- Detection of threats invisible to endpoint-only solutions
- Visibility into unmanaged and IoT devices
- Reduction of attacker dwell time
- Faster incident investigation using packet-level data
- Improved overall security posture
Typical Enterprise Use Cases
- Advanced Persistent Threat (APT) detection
- Lateral movement identification in data centers
- Insider threat detection
- Data exfiltration monitoring
- Hybrid and cloud network visibility
Why iS Group + GREYCORTEX
- Proven expertise with Mendel NDR deployments
- Strong integration into SIEM and XDR environments
- MSP delivery model aligned with enterprise operations
- Focus on measurable detection and response outcomes