About This Architecture
Phased risk-based Vectra NDR rollout on AWS uses a six-stage deployment strategy prioritizing critical production workloads before expanding to non-prod environments. Traffic mirroring via VXLAN UDP/4789 sends network flows from EC2 ENIs and EKS workloads to a central Vectra Brain and Sensor Pool in a dedicated Security Tooling VPC, with automation via Terraform, CloudFormation, EventBridge, and Lambda orchestrating tag-based onboarding. This approach reduces blast radius, validates routing and cost per phase, and scales dedicated local Sensors for high-volume platforms like multi-tenant and container environments. Fork this diagram to customize phase sequencing, adjust mirror filters, or integrate with your SIEM and SOC tooling. The Transit Gateway routes metadata and management traffic over HTTPS/SSH while keeping inspection traffic isolated, enabling teams to prove NDR value incrementally before full-scale deployment.