Greycortex: Why Firewalls and EDR Are Not Enough
News | 30.07.2026
Firewalls and endpoint agents are foundational security controls, but each one sees only a slice of the network. Everything that happens between them — lateral traffic, IoT devices, printers, cameras, BYOD laptops — sits in a blind spot that attackers actively exploit. Network Detection and Response (NDR) closes that gap by watching every internal connection and flagging behavior that firewalls and EDR were never designed to catch.
What was announced
GREYCORTEX explains why a modern security stack cannot rely solely on perimeter firewalls and endpoint agents. Firewalls inspect traffic entering and leaving the network. EDR watches processes on devices where an agent is installed. Between them lies east-west traffic, agentless assets, and credential-based activity that neither tool can fully observe.
The vendor positions GREYCORTEX Mendel as the NDR layer that sees every device, every connection, and every deviation from normal behavior, working alongside existing firewalls and EDR without adding load to endpoints.
Why this matters
For CIOs, CISOs, IT directors and procurement leaders, the message is direct: treating firewalls and EDR as a complete strategy leaves too many questions unanswered after an incident. Attackers now use legitimate credentials, encrypted channels and AI-driven techniques so their traffic looks normal at the perimeter and on the host.
Both the NIST Cybersecurity Framework and MITRE ATT&CK are built on layered detection — perimeter, endpoint, and internal network. Regulations such as NIS2 and DORA also require organizations to provide forensic evidence after an incident, which is difficult without retained network metadata.
A firewall and an endpoint agent cover two important layers, and network monitoring covers what they cannot see
Technical details
- Lateral movement detection: monitors east-west traffic that never crosses the firewall and flags anomalous device behavior even if EDR is disabled.
- Agentless device visibility: covers IoT, OT, printers, cameras, medical devices and PLCs by analyzing how they communicate.
- Insider threat and credential misuse: spots valid logins accessing systems the account has never touched or transferring data to unusual destinations.
- Incident reconstruction: retains network metadata and captures full traffic from suspicious events for forensic investigation aligned with NIS2 and DORA.
- Shadow IT discovery: identifies unauthorized 4G routers, rogue access points, personal laptops and forgotten test servers.
- Configuration hygiene: surfaces legacy protocols, expired certificates, services on non-standard ports and firewall rules that no longer match policy.
Softprom and Greycortex
Softprom is the official distributor of Greycortex. Our engineering team helps customers deploy GREYCORTEX Mendel NDR alongside existing firewalls and EDR to build a layered, NIS2- and DORA-ready detection strategy.
Request a network security audit and demo of Greycortex Mendel with Softprom experts.
This content was prepared as part of the Softprom DistriFlow project — an automated system for monitoring and adapting vendor news. Original source: original article.