LogLM vs. NDR

Evaluating Vectra, Darktrace or ExtraHop? Compare the architecture first.

NDR products differ in features, but many share one design: sensors in your network, a model tuned to each environment, and analytics that often run in the vendor's cloud. LogLM inverts that design. It is a foundation model pretrained across diverse security telemetry, so your team detects concerning sequences zero-shot in the logs and network data you already collect, inside your own boundary.

No baselining period

Pretrained across diverse environments and telemetry types. 99% zero-shot, with no learning period in yours.

No special-purpose hardware

Runs on infrastructure you already operate: your data lake, your Cribl pipeline, your Kubernetes clusters.

Nothing leaves

Weights, verdicts and learning stay inside your environment: on premises, air-gapped or in your own cloud.

Side by side

Conventional NDR and LogLM differ in where the intelligence comes from.

Dimension
Conventional NDR
LogLM
Source of detection
Conventional NDR:Signatures and models built for each environment over network traffic
LogLM:Encoder-only foundation model pretrained across diverse security telemetry including Zeek logs
Time to trusted detections
Conventional NDR:Often a baselining or tuning period per environment
LogLM:99% zero-shot, with no baselining period
Telemetry scope
Conventional NDR:Primarily network traffic, sometimes extended to identity and cloud
LogLM:Logs and telemetry across network, endpoint, identity, cloud, application and OT
Hardware
Conventional NDR:Physical or virtual sensors at collection points
LogLM:No special-purpose hardware
Where analysis runs
Conventional NDR:Frequently in vendor-hosted analytics
LogLM:Inside your environment: on premises, air-gapped, your own cloud or Kubernetes
Investigation
Conventional NDR:The vendor's console
LogLM:Vigil, the open source AI SOC, or the SIEM and SOAR you already run
Improvement
Conventional NDR:Tuning inside each tenant
LogLM:Classifiers adapted to your environment, in a learning loop you own

The left column describes common NDR architectures as vendors publicly present them. Individual products vary; confirm current capabilities with each vendor.

Evaluation results

Measured in production, not in a lab.

Security teams at BNY, Deutsche Telekom, a top-four global bank and the Technology Advancement Center evaluated LogLM on their own telemetry.

99% zero-shot detection

Without training on the customer's environment.

1% or fewer false positives

Analysts spend their time on incidents, not noise.

0.7% false negatives

Measured at a top-four global bank.

0.9% false negatives

Measured at BNY.

Evaluating a vendor

Questions to ask any NDR vendor.

The answers expose the architecture you will live with long after the evaluation ends: where analysis runs, what leaves your environment, and how long before your team can trust a detection.

Vectra AI

Vectra publicly describes attack signal intelligence across network, identity and cloud. Ask where the analysis runs, and what telemetry leaves your environment to reach it.

Darktrace

Darktrace publicly describes Self-Learning AI that learns each organization's normal patterns. Ask how long before detections are trusted, and what happens when your environment changes.

ExtraHop RevealX

ExtraHop publicly describes wire data analysis from network sensors. Ask which physical or virtual sensors are required, and what coverage extends beyond the wire.

Corelight

Corelight builds on Zeek network evidence. Ask who writes and maintains the detections that run on that evidence.

How teams start

From historical logs to a proof of value inside your boundary.

1

Send telemetry

Share historical logs or flow data from one environment. No agents, no disruption.

2

Review findings

Receive detections mapped to MITRE ATT&CK, with the evidence behind each one.

3

Prove value in place

Run LogLM and Vigil inside your environment on live telemetry, beside your current detection layer.

See what your current detection layer misses.

Send historical logs or flow telemetry. The team runs LogLM against them and returns findings mapped to MITRE ATT&CK, with the evidence behind each one.