Third Party Integrations
MetaDefender NDR connects to other security tools in your environment. These integrations extend detection, response, and context. The platform supports these integration types:
SIEM: Syslog (UDP 514 / TLS) forwards all events, alerts, and analytics.
SOAR: REST API and webhook triggers start automated playbooks.
EDR/XDR: Correlation through API or syslog adds endpoint context enrichment.
Sandboxes: Automatic file submission sends extracted files to an external sandbox.
Identity solutions: Active Directory, LDAP, and Okta integration adds user context.
Access control: Dynamic block through firewall or Network Access Control (NAC) APIs acts on threat verdicts.
For the response integrations that stop an attack, the platform uses the firewall and NAC APIs. A threat verdict triggers a block action at the enforcement point. The sensor stays passive and does not sit inline.
See also
Network services and external dependencies
Communication ports and protocols