Skip to content

Claroty Continuous Threat Detection

You can integrate Claroty Continuous Threat Detection (CTD) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Claroty CTD product overview

Claroty Continuous Threat Detection (CTD) is an on-premises cyber-physical systems (CPS) protection platform for industrial environments, providing OT, ICS, and XIoT asset discovery and visibility; threat detection; exposure and vulnerability management; and network segmentation.

What we ingest

Sophos XDR collects Claroty CTD data by listening for CEF messages your CTD deployment forwards to a Sophos XDR data collector. The following log categories are collected:

  • Security alerts: Claroty CTD alerts and events (all alert categories and types).
  • Network communications1: Connection detail associated with alerts and events.

Event and data types

We ingest the following event and data types from Claroty CTD:

  • Security alerts: Claroty CTD alerts and events for OT and ICS threats, anomalies, and policy violations, including the alert type, category, severity, and affected assets. Normalized to third-party security alert telemetry.
  • Network communications1: The network connections associated with CTD alerts and events, including source and destination and protocol. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Claroty CTD gets normalized to the following schemas:

  • netflow 1
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview