WireTraceWIRETRACEDeep Protocol & Asset Intelligence
WireTrace Integrations Overview

Connects to the tools you already run, in formats they already understand

What WireTrace sends, what it receives and what your tools can request from it, organised by direction and purpose, with each integration stated exactly as it works.

01Networkcommunication02Deep protocolintelligence03Asset & entityidentity04Classification& context05Behaviouralbaseline06Risk & threatintelligence07Policy &segmentation08Integratedcontrol
For: Security architects, SOC engineering, network and identity teams

WireTrace is the intelligence and decision layer in your security stack, not a replacement for it. Its value reaches people through the tools they already run: alerts into the SIEM, data into automation, rule proposals to firewall teams and asset context to network access control. This overview lists every integration by direction (what WireTrace receives, sends, or lets your tools request) and by purpose.

01Principles

Open formats first

Syslog, JSON, SNMP, STIX 2.1, CSV and plain-text rule syntax. Any tool that understands the format can consume WireTrace without a vendor-specific app.

On your appliance

Integrations, including the REST API, run on your WireTrace platform. Nothing is relayed through a vendor service.

Your controls enforce

WireTrace supplies identity, risk, intent and proposed rules. Your firewalls, NAC and switches remain the enforcement points.

INBOUND: CONTEXT, SIGN-IN, INTELLIGENCE OUTBOUND: ALERTS, DATA, HAND-OFF Switches and routers SNMP v1/v2c/v3, LLDP, CDP read-only polling Network devices device syslog and SNMP traps received Directory and SSO LDAP / Active Directory, OpenID Connect, one-time code Threat indicators STIX 2.1, CSV, commercial feed with your own key Vulnerability data NVD, CISA KEV, FIRST EPSS, ICS, OT vendor, end-of-life data SIEM syslog CEF, LEEF, RFC 5424/3164 Splunk HTTP Event Collector Automation and SOAR JSON webhooks plus the read-only REST API Notifications email to people, SNMP traps to your NMS Firewall teams rule text to apply, blocklists to pull NAC identity, classification and risk retrieved through the API Data and reporting tools read-only REST API, CEF detection exports WireTrace platform on your server or virtual machine Inventory and identity Alerts and investigations Vulnerabilities and risk Rules, violations, policies Activity log API Access (off until enabled) Sensors feed it from SPAN, TAP or ERSPAN received by WireTrace sent by WireTrace requested by your tool (pull)
WireTrace integration map. Inbound integrations add context, sign-in and intelligence; outbound integrations deliver alerts and decisions, or answer requests from your tools. Every integration runs from your own WireTrace platform.

02Security operations: alerts and notifications out

IntegrationWhat it doesFormats and transport
SIEM over syslogForwards alerts to any SIEM, filtered by alert type and minimum severity.CEF, LEEF, RFC 5424, RFC 3164; UDP, TCP or TLS
Splunk HTTP Event CollectorNative Splunk HTTP Event Collector output.HTTP Event Collector
IBM QRadarIngests WireTrace alerts through standard syslog formats.LEEF over syslog
Microsoft SentinelIngests WireTrace alerts through standard syslog formats.CEF over syslog
WebhooksSends events to automation and SOAR workflows. SOAR platforms consume WireTrace through webhooks and the REST API.JSON
EmailAlerts, policy notifications and user invitations.SMTP
SNMP trapsTrap notifications to your network management system.SNMP traps

03Data access: what your tools can request

API Access is a read-only REST API that exposes assets, changes, risk, vulnerabilities, alerts, threat matches and exports. It is designed to be safe to switch on:

  • OAuth 2.0 client credentials: each consuming application has its own client.
  • Scoped tokens: a client is granted only the data areas it needs.
  • Per-client rate limits and IP allowlists.
  • Read-only: the API cannot change anything in WireTrace.
  • On your appliance: it runs on your WireTrace platform, not a vendor service.
  • Off until enabled by an administrator.

IP, domain and URL blocklists and CEF detection exports are available for tools to pull on their own schedule.

04Enforcement hand-off

WireTrace provides the intelligence, policy intent and continuous validation layer for segmentation; your existing firewalls, NAC and switches enforce it. The hand-off is explicit and reviewable:

ToWhat WireTrace providesHow
Firewall teamsProposed block rules derived from traffic rules and violations, for review and application by your team.Text in iptables, nftables, Cisco IOS or pf syntax
FirewallsIP, domain and URL blocklists from threat-indicator matches.Pulled by the firewall through the API
Network access controlAsset identity, classification and risk, so a NAC can enrich its own policy decisions.Retrieved by the NAC through the REST API

What WireTrace does not do. It does not push configuration to firewalls, NAC or switches. Rules leave as text for your team to review and apply, and blocklists and context are pulled by the receiving system. Changes stay under your existing change control.

05Network enrichment in

What WireTrace receives

  • SNMP v1, v2c and v3 from switches and routers, read-only
  • LLDP and CDP neighbour information
  • Device syslog and SNMP traps sent to WireTrace

What it adds

  • Port-level connectivity: which device is on which switch port
  • Neighbour relationships between network devices
  • Hardware details of switches and routers

Polling needs SNMP targets and read-only credentials configured by an administrator, and runs from the platform's management interface. WireTrace never writes configuration over SNMP.

06Identity and access

Users sign in through LDAP/Active Directory (over LDAPS or STARTTLS), OpenID Connect single sign-on with your identity provider, for example Microsoft Entra ID or Google Workspace, or an email one-time passcode. Whichever method is used, role-based access control in WireTrace decides what each user can see and do, and tenants on a multi-tenant platform keep their own users and permissions.

07Intelligence inputs

InputSourcesUsed for
Threat indicatorsPublic threat-intelligence feeds; STIX 2.1 import and export; CSV indicator lists; commercial feeds using your own key.Matching observed IPs, ranges, domains, URLs, file hashes and TLS fingerprints.
Vulnerability intelligenceNVD, CISA KEV, FIRST EPSS, CISA ICS advisories, OT vendor advisories, and end-of-life data that also works offline.Matching device software, firmware and OT products, prioritised by exploitation.

Connected appliances refresh automatically; air-gapped sites import a checksummed offline bundle.

08Integration classes

The class states what is built into WireTrace and what relies on a standard format or the API.

ClassMeaningIntegrations
SupportedBuilt in, configured in the console.Syslog, Splunk HEC, webhooks, email, SNMP traps, inbound syslog, SNMP/LLDP/CDP, LDAP/AD, OIDC SSO, one-time passcode, STIX 2.1, CSV and commercial feeds, vulnerability sources, REST API, rule-text export
Via standard formatsIngests a standard format; no dedicated connector.IBM QRadar (LEEF over syslog), Microsoft Sentinel (CEF over syslog), other SIEMs over syslog
Through the APIRequests data from the REST API or consumes webhooks.SOAR platforms (webhooks and API), network access control (identity, classification and risk), firewalls and security tools pulling blocklists and CEF exports

Limits, stated plainly

Map WireTrace onto your tooling

A technical session maps your SIEM, automation, firewall, NAC and identity tooling to WireTrace integration points, and an evaluation shows the alerts and data your teams would receive.

Book a demo at wiretrace.io/request-demo or email [email protected]