Network Detection and Response (NDR) is a new product category with an unexpectedly rich history. In this talk, Greg Bell traces the open source heritage of NDR, explains its growing prominence in the ‘SOC triad’, and shines a light on community models for network defense - using the recent SolarWinds / SUNBURST compromise as a case study.