Progress Flowmon
Network detection and response platform, born as Czech spin-off Flowmon Networks, now sold and developed as Progress Flowmon after passing through Kemp Technologies to Progress Software.
Visit Website ↗ + Add to CompareOverview
Progress Flowmon is a network detection and response (NDR) platform that analyzes network flow data and full packet traffic to surface threats and anomalies that endpoint and log-based tools can miss, such as lateral movement, DDoS activity, and command-and-control traffic hidden inside otherwise normal-looking connections. It maps detected behavior to MITRE ATT&CK tactics and techniques, giving analysts a standardized way to triage severity and likely attacker intent, and integrates with SIEM platforms to feed automated response workflows.
The product traces back to Flowmon Networks, a 2007 spin-off of Masaryk University, Brno University of Technology, and network engineering firm UNIS in the Czech Republic, building on flow-monitoring research that started at CESNET in 2002. Flowmon built a reputation in Central Europe as a fast-growing network performance and security monitoring vendor before being acquired by application-delivery vendor Kemp Technologies in November 2020 to fold NDR capability into Kemp’s load-balancing and network stack. Kemp was itself acquired by Progress Software in September 2021, and Flowmon now operates as the Progress Flowmon product line within Progress’s broader infrastructure software portfolio.
For network security teams, Flowmon’s value is largely unchanged by the ownership changes: it remains a purpose-built NDR tool with a long operating history and real MITRE ATT&CK-mapped detection logic, now backed by a larger, publicly traded parent (Progress Software, Nasdaq: PRGS) with more resources for integration and support than the original Czech startup had on its own.
Innovation Matrix Assessment
As a product line inside a large public software company, Flowmon's release cadence is steady and integration-focused (SIEM connectors, ATT&CK mapping updates) rather than fast-moving startup-style iteration.
Flow-based NDR is lightweight to deploy relative to full packet-capture alternatives, and the product has over 15 years of field deployment history refining its detection engine and SIEM integrations.
Two acquisitions in under a year (Kemp in 2020, then Kemp itself by Progress in 2021 for $258M) confirm real strategic value was recognized in the market, though Flowmon itself is now a smaller line item within a much larger public company's results rather than a standalone growth story.
NDR via flow analysis is a mature, well-established category; Flowmon is a solid long-standing incumbent in that category rather than a category-redefining technology.
Explicit MITRE ATT&CK tactic/technique mapping in its detection output and a long operating history with enterprise customers across Europe and the US support reasonable confidence in real-world detection efficacy, though no independent third-party detection test (e.g., MITRE ATT&CK Evaluations) results were found.
Network-layer visibility remains a relevant complement to endpoint-centric detection, particularly for unmanaged/IoT devices and lateral-movement detection, keeping NDR broadly relevant to security operations.
Why CISOs Should Care
Gives security teams network-layer visibility and MITRE ATT&CK-mapped detection for threats that endpoint agents and log-based SIEM rules alone can miss, backed by a financially stable public-company parent.
What Makes It Different
A long-running, purpose-built NDR engine with explicit ATT&CK mapping, now bundled with Progress's broader infrastructure and application-delivery portfolio rather than sold as a narrow point product.
The Matrix Verdict
53/100 — INCREMENTAL INNOVATOR
A mature, credible NDR option with real detection depth and staying power thanks to Progress Software's backing, appropriately scored as a steady incumbent rather than a disruptive newcomer.
Editorial Note: Claims vs. Verified Findings
Acquisition dates and the $258M Kemp/Progress deal value are independently reported in industry press; detection-quality and ATT&CK-mapping descriptions are drawn from vendor product pages and have not been independently benchmarked.
Sources
Alternatives to Progress Flowmon
Forward
CISO ReviewedBuilds a mathematically accurate 'digital twin' of enterprise networks, letting teams verify network and security changes before they…
Zscaler
A cloud-native security-service-edge pioneer that routes all user traffic through a global proxy cloud instead of backhauling it…
Claroty
Cyber-physical systems protection platform securing industrial, healthcare and enterprise IoT devices for critical infrastructure operators.
Tailscale
A zero-configuration mesh VPN built on WireGuard that applies Google's BeyondCorp zero-trust model to make secure networking accessible…
TXOne Networks Inc.
OT and industrial control system cybersecurity built for zero operational disruption, protecting legacy manufacturing and critical infrastructure devices…
secunet Security Networks
Germany's largest independent IT security company and the federal government's primary cybersecurity partner, best known for its SINA…