Comparison

Hilt vs Vectra: Network Detection and Data Movement

April 23, 2026 Hilt 7 min

Your most valuable data leaves on access you granted on purpose. Vectra detects threats from network behavior. Where Hilt adds the data movement at the host, identity-resolved, and where NDR still owns the network signal.

Hilt vs Vectra: Network Detection and Data Movement cover image

Host A talks to host B. Some bytes move, over some port, at some hour. Vectra reads that conversation and tells you whether it looks like an attack. That is what Network Detection and Response was built to do, and Vectra does it well. The teams who come to it have endpoint agents and a firewall and still cannot see what an attacker does once inside. NDR closes that gap by watching the one place every device has to talk through.

The wire is also where the question we care about runs out of answers.

What Vectra sees

Vectra ingests traffic from cloud, data center, and identity sources, then scores it against the moves attackers make after they get a foothold. Lateral movement between hosts. Command-and-control beaconing. Reconnaissance scans, privilege escalation, account takeover. It reconstructs the chain that turns one stolen credential into a presence across your estate, and it does that without an agent on every box. You cannot install software on the contractor laptop, the unmanaged device, the printer with the firmware bug. They all show up in the traffic anyway. For catching an intruder spreading through the environment, the network is exactly the right place to stand.

If your problem is "someone is in my network and I need to catch the attack as it spreads," Vectra is built for that. Hilt does not stand in for it.

What the wire cannot resolve

The network sees flows, not the thing on the host that opened them. It records that bytes moved, how many, where to, on which port, with what timing, and it guesses intent from the shape of the conversation. It does not see the user behind the flow, the process, the job, the path being read. Encrypt the traffic, which most traffic now is, and even the content goes dark. The wire is left with volume, destination, and timing.

That catches a smash-and-grab. It does not catch the move that was supposed to happen.

A researcher copies proprietary code over two weeks. Small chunks, off-hours, through an approved transfer channel that moves data every single day. On the wire, every flow is the channel doing its job: ordinary destination, ordinary protocol, volume that never spikes high enough to notice. No beacon. No lateral movement. No intrusion signature, because there is no intruder. The credential is real. The access was granted. The channel is sanctioned. Every move is permitted. The pattern is the breach.

NDR hunts the attack. There is no attack here, only a permission used wrong.

What Hilt adds underneath

Hilt is runtime Data Movement Governance. It watches data movement at the kernel, on the host, metadata only by default and off the path. Rather than infer the host's behavior from a flow, it observes the move where the identity is still attached: this user, this process, this job, reading these paths, sending to this destination. Each move resolves to a probabilistic, source-dependent identity and gets scored against how that identity has moved data over months.

Vectra asks whether the traffic looks like an attack. Hilt asks whether this move fits the person making it, even with no rule broken and no signature firing.

Run the researcher through that question and the deviation lands on three layers at once. The job is wrong for her identity. The read is a sustained pull on high-value paths in a window she never works. The destination volume is wrong for that channel over time, though no single transfer is large. One signal alone is noise. Stacked, they are a pattern, and a pattern is a case, not an alert. Hilt writes the case, resolved to the job behind the move, and responds with host-level network isolation, quarantine from the control plane. It never sits inline. It never blocks or alters traffic. It never has to read your data to know the pattern is wrong.

The two views stack without colliding. Vectra gives you the network narrative of an intrusion crossing the estate. Hilt gives you the host-resolved identity behind a single move and whether that move fits. One watches the attacker cross the wire. The other watches the data leave on access nobody had to break.

Where Hilt does not replace Vectra

Keep the boundary sharp, because these are not substitutes.

Hilt does not detect lateral movement, beaconing, or reconnaissance as network phenomena. It is not your coverage for the unmanaged device that will never run a collector. If your threat is an intruder hopping host to host, that is NDR's job, and Hilt is not pretending to do it.

Hilt also does not sit inline. It reads no packets on the wire, gates no traffic, holds no position as a network control point. It observes movement at the kernel and isolates a host at the network when a pattern earns it. That is a different mechanism from a tool acting on flows in transit.

The honest framing is additive. Vectra owns the network signal: the attack narrative, the unmanaged surface, post-compromise behavior across the environment. Hilt owns the host-resolved data movement signal: who moved what, under which job, and whether the move fits, including the permitted moves NDR was never built to question. Small overlap. Real blind spot on each side that the other closes.

Putting them together

Ask any tool you are weighing one question. What did this specific identity's data do, resolved to the job behind it, scored against how it normally moves, between 11pm and 2am on these three dates, through a channel that was approved. NDR answers from the flow and the attack model, and it answers well. The permitted-pattern question is not the one it was designed for.

Vectra already covers the network narrative. The layer most teams find missing sits below the wire, on the host, where the identity and the job are still attached to the move. Hilt adds that layer and asks you to remove nothing you already trust.

If you want to see where the host-resolved view fits against your current NDR coverage, the fastest path is a 30-minute technical call, engineer to engineer. We will walk the moves your network signal cannot resolve and show you where the line falls.