Claroty Continuous Threat Detection
You can integrate Claroty Continuous Threat Detection (CTD) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Claroty CTD product overview
Claroty Continuous Threat Detection (CTD) is an on-premises cyber-physical systems (CPS) protection platform for industrial environments, providing OT, ICS, and XIoT asset discovery and visibility; threat detection; exposure and vulnerability management; and network segmentation.
What we ingest
Sophos XDR collects Claroty CTD data by listening for CEF messages your CTD deployment forwards to a Sophos XDR data collector. The following log categories are collected:
- Security alerts: Claroty CTD alerts and events (all alert categories and types).
- Network communications1: Connection detail associated with alerts and events.
Event and data types
We ingest the following event and data types from Claroty CTD:
- Security alerts: Claroty CTD alerts and events for OT and ICS threats, anomalies, and policy violations, including the alert type, category, severity, and affected assets. Normalized to third-party security alert telemetry.
- Network communications1: The network connections associated with CTD alerts and events, including source and destination and protocol. Normalized to netflow telemetry.
Data provided by this integration
Data provided by Claroty CTD gets normalized to the following schemas:
netflow1thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.
Vendor documentation
-
Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview. ↩↩↩