Title
Page icon
Create new category
Edit page index title
Edit category
Edit link
Third Party Integrations
MetaDefender NDR connects to other security tools in your environment. These integrations extend detection, response, and context. The platform supports these integration types:
SIEM: Syslog (UDP 514 / TLS) forwards all events, alerts, and analytics.
SOAR: REST API and webhook triggers start automated playbooks.
EDR/XDR: Correlation through API or syslog adds endpoint context enrichment.
Sandboxes: Automatic file submission sends extracted files to an external sandbox.
Identity solutions: Active Directory, LDAP, and Okta integration adds user context.
Access control: Dynamic block through firewall or Network Access Control (NAC) APIs acts on threat verdicts.
For the response integrations that stop an attack, the platform uses the firewall and NAC APIs. A threat verdict triggers a block action at the enforcement point. The sensor stays passive and does not sit inline.
See also
Network services and external dependencies
Communication ports and protocols