FasooNDR by FASOO detects anomalies through network traffic analysis. Network Detection and Response (NDR) solutions provide advanced threat detection and response through in-depth analysis of network traffic. The integration of IT and OT systems due to digital transformation has exposed organizations to new types of cyber threats. Cyber incidents continue to occur in major domestic companies and public institutions due to national cyber attacks, highlighting the need for strong protection measures for critical national infrastructure. The global increase in data traffic has also raised the demand for network security, particularly network forensics. Network forensics solutions analyze network traffic data from various sources and devices to collect evidence, aiming to enhance overall cybersecurity measures through attack detection, attacker behavior analysis, and intrusion pattern identification. The core of emerging network forensics as a leading solution is establishing a system to detect and respond to network threats. It must track and analyze all actions related to breaches and attacks that are not detected by conventional security solutions. This requires comprehensive monitoring and real-time detection across the entire network, including internet, DMZ, internal, and remote networks. FasooNDR offers real-time monitoring and visibility into all incoming and outgoing traffic, enhancing threat detection capabilities. It detects threat activities in real-time through patented traffic processing architecture, analyzes the root causes of breaches, and supports the establishment of response systems. Real-time alerts are generated through correlation analysis using various threat indicators and metadata, allowing for scenario-based risk warnings and management of threat priorities linked to internal assets. Provides a method to analyze threats based on original traffic from actual users, reproducing various forms such as files, strings, web, mail, Hex, and packets.