Integrations

WireTrace understands. Existing controls enforce.

WireTrace adds device identity, risk and decoded evidence to the tools you already run. It does not replace your firewalls, NAC or switches: it tells them what is on the network, what it is doing, and what should change.

CONTEXT IN · FINDINGS OUTYOUR CONTROLS ACTSIEM / SOARsyslog · CEF · LEEF · webhooksThreat intelligenceSTIX 2.1 · CSV · feedsNetwork infrastructureSNMP · LLDP/CDP · syslog inWireTraceunderstandsdecides · validatesFirewallsrule proposals · blocklistsNACidentity & risk via APIAPIs & automationREST · OAuth 2.0 · webhooks
At a glance

What connects, and how.

IntegrationDirectionHow
Any SIEMOutSyslog over UDP, TCP or TLS in CEF, LEEF, RFC 5424 or RFC 3164, filtered by type and severity
SplunkOutNative Splunk HTTP Event Collector output
IBM QRadar / Microsoft SentinelOutIngest WireTrace alerts through standard syslog formats (LEEF / CEF)
SOAR and automationOutJSON webhooks and the REST API
Email, SNMP trapsOutAlerts and policy notifications
NACPullAsset identity, classification and risk through the read-only REST API
FirewallsPull / exportIP, domain and URL blocklists; rule proposals in iptables, nftables, Cisco IOS and pf syntax
Switches and routersInRead-only SNMP v1/v2c/v3, LLDP/CDP; inbound syslog and SNMP traps
Threat intelligenceInSTIX 2.1 import/export, CSV, custom feed URLs, commercial feeds with your key
Identity providersInLDAP/Active Directory and OpenID Connect single sign-on

Ticketing actions are available as early access. Ask us about the integration you need.

Bring your stack to the demo.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.