See inside the network. Attackers move east-west after a foothold — LinkShadow Intelligent NDR inspects mirrored traffic to surface the lateral movement, beaconing and data staging that never crosses your perimeter — with a Master that can stay on-premises.
Buy through TechBag
Same software. Better outcome — at a lower cost.
How it’s rated
Full scoreboard ↓Quick answer
This page covers Intelligent NDR — the flagship. The rest of the platform:
Most product pages skip this. We start here — so you buy a capability, not a buzzword.
Detection on traffic inside your network — sensors inspect mirrored traffic with deep packet inspection and behavioural analytics to surface lateral movement, C2 beaconing and data staging that never crosses the perimeter, so a firewall never sees it.
What consolidation actually replaces, dimension by dimension.
| Dimension | Perimeter inspection only | Intelligent NDR (LinkShadow) |
|---|---|---|
| What it inspects | Traffic crossing the perimeter | Traffic moving inside the network |
| Detection basis | Signatures and policy | Behavioural baseline and deviation |
| Blind spot | East-west movement after a foothold | Whatever you do not mirror |
| Action | Blocks in line | Detects; something else acts |
| Data location | Your own appliance | Your choice — on-prem Master or cloud |
| Deployment effort | Rack, cable, policy | Traffic mirroring across the segments that matter |
NDR detects; it never enforces — budget for a SOC, an MDR service or an XDR workflow to consume the detections. And remember coverage equals mirroring: you see exactly the segments you mirror.
Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.
Sensors receive traffic from a SPAN port, a network TAP or a virtual mirror and perform deep packet inspection. You get visibility exactly where you mirror and nowhere else, so deciding which segments matter is the real deployment work — network engineering with change windows.
Sensors feed a Master that correlates, stores and analyses. It may run ON-PREMISES or in the cloud. For a regulated Indian estate that is the whole conversation: on-premises keeps traffic and metadata in country by architecture. LinkShadow offers no India residency for its cloud.
Models learn what normal looks like for each host and user, then surface deviation: beaconing, a workstation talking to twenty internal hosts, staging before exfiltration. This catches what signatures miss — and needs a baseline period before its detections are precise.
LinkShadow surfaces a finding; it does not block or enforce. That is the category, not a shortcoming — which is also why no inspected-throughput figure applies. You need a consumer for detections: a SOC, an MDR service or an XDR workflow. An unwatched console is a log.
Traffic metadata accumulates fast, and the retention window sets both the storage bill and how far back an investigation reaches. Decide it before sizing the Master — on-premises, this is your capacity to plan, a real cost line a cloud quote hides.
One telemetry fabric across endpoint, cloud, and network — threats correlated once, not chased console to console.
LinkShadow Intelligent NDR watches the traffic inside your network — behavioural detection on what the portfolio, and paired with the human firewall.
Sensors parse mirrored traffic rather than sampling flow records, so detection works on protocol behaviour and content patterns rather than on volume statistics alone. This is what separates NDR from NetFlow analysis.
Most attacker activity after an initial foothold is east-west — host to host, inside the perimeter. That traffic never reaches the firewall, so it is invisible to perimeter inspection no matter how good the firewall is.
Compromised hosts call home on an interval. Behavioural models surface that periodicity even when the destination is unknown and the traffic is encrypted, because the pattern is the signal rather than the payload.
Models baseline each host and user, then surface what departs from it. Expect a tuning period: precision improves as the baseline matures, and teams that judge NDR on week one are judging an untrained model.
Collection and staging happen inside the network before anything is sent out. Surfacing the staging is the difference between an incident you contain and a breach you disclose.
If you also run LinkShadow DSPM or ITDR, findings correlate in one console: an anomalous identity, on a beaconing host, reaching data it has never touched. Compound detections are far higher-confidence than any single signal — but this only pays off across multiple modules.
The Gartner placement, the NDR argument, and where the platform is going.
On the Magic Quadrant placement — Visionaries.
Where NDR is heading, from the MQ 2026 vantage.
The thinking behind the NDR product.
Why east-west visibility shows up in audits.
The company and the platform, in its own words.
Want a live, India-context walkthrough for your environment?
Book a guided demo →Here’s what genuinely sets LinkShadow iNDR apart — and where it honestly does not.
The single strongest reason to deploy NDR is that perimeter inspection has a blind spot it cannot engineer away. A firewall inspects what crosses the boundary. Once an attacker has a foothold — a phished credential, a vulnerable edge device, a contractor’s laptop — almost everything they do next is east-west: enumerating shares, moving host to host, escalating privilege, staging data. None of it crosses the perimeter, so none of it reaches the firewall, no matter how good the firewall is or how many subscriptions are enabled on it. LinkShadow’s sensors sit on mirrored internal traffic and inspect it directly, so that activity becomes visible as behaviour rather than as a signature. This is the argument for the category as a whole, and it is the reason NDR shows up in incident post-mortems: the detections that matter are usually of things that had already been happening inside the network for weeks.
LinkShadow does NOT offer India data residency. Its privacy policy states plainly that data may be used, processed or stored anywhere in the world, and the company makes no DPDP Act, RBI, SEBI, IRDAI or CERT-In claim anywhere in its documentation. An India office in Kochi and a Truvisor distribution agreement are real, and neither is residency. What LinkShadow does offer is better than a promise for estates that need in-country handling: the Master appliance may run ENTIRELY ON-PREMISES. Traffic and metadata then stay inside your data centre by architecture, with no vendor cloud in the path to make a claim about. For BFSI, insurance and government buyers this is the deployment to specify from the first design conversation rather than the last, because it changes the sizing, the hardware and the price. TechBag will put it in writing rather than represent an office address as a residency commitment.
Gartner positioned LinkShadow in the Visionaries quadrant of the 2026 Magic Quadrant for Network Detection and Response, announced in May 2026. That is genuine recognition in a category where an MQ now exists, and it deserves to be stated precisely rather than upgraded. Visionaries indicates strong vision with less proven execution than Leaders. Vectra AI, Darktrace and ExtraHop are the Leaders on that Magic Quadrant and sit above LinkShadow on Ability to Execute. If your first requirement is the most-proven NDR and the budget supports it, shortlist those three — TechBag will tell you that in the first meeting. LinkShadow’s case is architectural flexibility, the on-premises option and price-performance. Keep three separate recognitions distinct as well: the 2026 Magic Quadrant, the older 2024 Gartner Market Guide (where LinkShadow was a Representative Vendor, a non-evaluative listing), and the 2024 Frost Radar from Frost & Sullivan, a different firm entirely. Conflating them is the fastest way to lose credibility in a technical evaluation.
Two things are true about every NDR deployment and both are better understood before the purchase order. First, NDR detects and does not enforce. LinkShadow surfaces findings; a firewall, an EDR agent or a human blocks. No inspected-throughput figure applies because nothing is being inspected in line. That means you need a consumer for detections — a SOC, an MDR service or an XDR workflow — and an NDR console nobody watches is an expensive log rather than a control. Second, coverage equals mirroring. You see exactly the segments you mirror to the sensors, so a design that mirrors the data-centre core but not the user VLANs will miss lateral movement between workstations. Arranging SPAN ports, TAPs or virtual mirrors across the segments that matter is real network engineering with change windows and sometimes hardware. Teams that scope NDR as a software purchase discover the gaps after go-live, which is the worst time.
Which segments are genuinely dark today, and what would you do with a detection if you got one? TechBag scopes whether NDR is the right control now, and says plainly if an MQ Leader fits your risk appetite better than LinkShadow.
If data must stay in India, the answer is the on-premises Master — LinkShadow offers no India data residency for its cloud. This decision changes sizing, hardware and price, so it belongs at the start rather than after a quote.
Coverage equals mirroring. Map the segments that matter, then plan SPAN ports, TAPs or virtual mirrors for each — with change windows, and sometimes a switch upgrade. This is the real deployment work.
Sensors go in, the Master correlates, and the behavioural models start learning your network. Expect the tuning period: precision improves as the baseline matures, and judging detections in week one is judging an untrained model.
Decide who watches and what happens next — your SOC, an MDR provider, or an XDR workflow. TechBag helps design the handoff, because an NDR console nobody watches delivers nothing.
Re-check mirroring as the network changes, and evaluate whether DSPM or ITDR earns its place on your numbers. TechBag prices modules separately so consolidation has to prove itself rather than being assumed.
Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.
“Our firewall was clean and we still had an incident. NDR showed us the lateral movement that had been running for weeks — none of it ever crossed the perimeter, so nothing at the edge was ever going to see it.”
“The on-premises Master is why this cleared our review at all. Traffic never leaves our data centre, so residency stopped being a contract argument and became an architecture fact.”
“Good value and the detections are solid once tuned. Be realistic about the first month — the models need a baseline, and we judged it too early.”
“The mirroring design was the actual project. Sensors and licences were straightforward; getting SPAN across the segments we cared about took change windows and a switch upgrade.”
“We could not get a named reference from the vendor, which slowed our procurement badly. The technology held up in the PoC; the paperwork was the hard part.”
Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the NDR market — tap any vendor to see why it sits where it does.
Execution strength vs product vision — the classic market map, minus the paywall.
Visionaries on the 2026 MQ; flexible on-prem or cloud.
The grid nobody publishes — detection depth vs how proven the vendor is at scale, with published references.
Strong on deployment flexibility; less proven at scale.
Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.
The NDR Leaders and the honest gaps — Visionaries is a real placement, and it is not the top right.
| Dimension | LinkShadow iNDR | Vectra AI | Darktrace | ExtraHop |
|---|---|---|---|---|
| 2026 Gartner MQ for NDR | Visionaries | Leader | Leader | Leader |
| On-premises deployment option | Yes — Master on-prem | Varies by product | Yes, appliance-led | Yes, sensor + appliance |
| India data residency | Not offered | Confirm | Confirm | Confirm |
| Published pricing | None at all | Quote-only | Quote-only | Quote-only |
| Named public customers | None published | Published | Published | Published |
| Enforcement | None — by design | None — by design | Autonomous response option | None — by design |
| Deployment effort | Traffic mirroring | Traffic mirroring | Traffic mirroring | Traffic mirroring |
| India commercial presence | Kochi office + Truvisor | Channel + regional presence | Channel + regional presence | Channel + regional presence |
Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.
Intelligent NDR is one of 13 firewall & network security products TechBag carries. The Firewall & Network Security guide narrows them to a shortlist and shows the reasoning. →
Drag the sliders (endpoints on the segments you would mirror; IT-hour cost as loaded incident rate). Estimates model analyst time spent investigating internal activity without east-west visibility — the avoided-breach value of catching lateral movement early is the larger, unpriced win. Illustrative.
Loaded cost = salary + overheads per productive hour. Illustrative only — your TechBag quote models your actual environment and modules.
LinkShadow publishes NO price — its marketplace listings are bring-your-own-licence. TechBag scopes sensors, Master placement and retention, then quotes in INR with GST.
Best for east-west visibility
Best for a broader rollout
Best if you add DSPM or ITDR
Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.
Tell us your requirements and current tools — we’ll model it against what you spend today.
Take this into your next vendor call — including ours.
Which internal segments are dark today? NDR sees exactly what you mirror to it — list the segments that matter before sizing anything.
Must traffic and metadata stay in India? LinkShadow offers NO cloud residency here — specify the ON-PREMISES Master and get it in writing.
Can you deliver SPAN, TAP or virtual mirrors on those segments? This is the real deployment work, and it needs change windows.
Where do detections land — your SOC, an MDR service, or an XDR workflow? An unwatched NDR console is an expensive log.
Is Visionaries defensible internally, or does your board expect a Leader? Vectra, Darktrace and ExtraHop sit above LinkShadow on the 2026 MQ.
Does procurement require named customers? LinkShadow publishes none — raise it in week one, not at final approval.
Can you approve without a list price? LinkShadow publishes no pricing at all; TechBag returns a scoped INR quote with GST.
Would DSPM or ITDR earn their place later? Price each on its own merits — consolidation only pays across multiple modules.
Scope the traffic-mirroring design, decide on-premises vs cloud for residency, or let a TechBag advisor compare it honestly against Vectra, Darktrace and ExtraHop.
Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.