Orca Security
You can integrate Orca Security with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
Orca Security product overview
Orca Security is a cloud-native security platform that delivers full-stack visibility and protection for public cloud infrastructures. By tapping directly into the cloud environment, it identifies vulnerabilities, malware, misconfigurations, and lateral movement risks, ensuring that your cloud assets remain secure and compliant without the need for agents or network scanners.
What we ingest
Sophos XDR collects Orca Security data via HTTPS by polling the Orca Security API for alerts and authenticating with an Orca API token. The following data is collected:
- Cloud security alerts: Orca alerts raised across your cloud estate, each carrying the alert type and category, severity (Orca score), status, the affected cloud asset and account, and recommendation details.
Event and data types
All Orca Security alerts are normalized uniformly to third-party security alert telemetry. They include:
- Misconfigurations and compliance: Cloud and workload misconfigurations and failed compliance checks, such as CIS benchmark findings.
- Vulnerabilities: Vulnerable services and software identified on cloud assets.
- Malware: Malware detected on cloud workloads.
- Suspicious activity: Anomaly and cloud detection and response findings, such as unusual identity or cloud-service access.
- Data at risk: Exposure risks such as publicly accessible or internet-facing resources.
Data provided by this integration
Data provided by Orca Security gets normalized to the following schemas:
thirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.