Integrations · APIs & Automation

Automate on trusted data.

A read-only REST API (OAuth 2.0 client credentials, scoped tokens, per-client rate limits and IP allowlists) exposes assets, changes, risk, vulnerabilities, alerts, threat matches and exports. It runs on your appliance and is off until an administrator enables it.

CONTEXT IN · FINDINGS OUTYOUR CONTROLS ACTSIEM / SOARsyslog · CEF · LEEF · webhooksThreat intelligenceSTIX 2.1 · CSV · feedsNetwork infrastructureSNMP · LLDP/CDP · syslog inWireTraceunderstandsdecides · validatesFirewallsrule proposals · blocklistsNACidentity & risk via APIAPIs & automationREST · OAuth 2.0 · webhooks
Policies

Automation with guardrails.

Define what WireTrace does when conditions become true: asset attributes, groups, sites, zones, risk, vulnerabilities (including known-exploited), alerts, protocol and communication behaviour, and baseline deviations. Each policy runs as monitor only, recommend, require approval or automatic.

  • Notify by email, syslog, webhook, SNMP trap or in-app
  • Label assets and record compliance evidence
  • Four-eyes approvals, emergency stop, change freeze and maintenance windows
  • An append-only activity log of every decision and action
WireTraceintelligence · intentvalidationMAPwho talks to whomBASELINEapprove normalPROPOSEsegmentation intentVALIDATEtest against trafficENFORCEvia your controlsMONITORviolations · driftENFORCEMENT STAYS WITH YOUR FIREWALL, NAC AND NETWORK TEAMS
Access

Sign-in and roles.

Single sign-on

LDAP/Active Directory or OpenID Connect single sign-on (for example Microsoft Entra ID or Google Workspace).

Roles and audit

Role-based access control and an audit trail of administrative and automation actions.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.