LogoLogo
⌘Ctrlk
  • Documentation
  • Release Notes
  • API Reference
  • Help Center
AI Assistant
Good afternoon

I'm here to help you with the docs.

⌘Ctrli
AI Based on your context
LogoLogo
  • 🏠Welcome
    • Getting started
    • IDR for Azure AD & CDR for M365
    • CDR for AWS
    • CDR for Azure
    • NDR physical appliances
    • NDR virtual / cloud appliances
    • NDR Traffic engineering and validation
    • Match
    • Stream
    • Recall (QUX only)
    • Appliance operations
    • Deprecated / Retired
    • Navigation updates in the Vectra UI
    • ACCESS
    • COVERAGE
    • RESPONSE
    • SETUP
    • TUNING
    • QUX specific
    • Response
      • Cisco AMP
      • Cisco FMC
      • Cisco ISE
      • Cisco Meraki
      • Cisco PxGrid
      • ClearPass
      • CrowdStrike
      • Cybereason
      • Endgame
      • Trellix (FireEye)
      • Fortinet Firewalls (FortiOS)
      • Harmony
      • McAfee EPO
      • Microsoft Active Directory
      • Microsoft Azure AD (Entra ID) (RUX)
      • Microsoft Defender for Endpoint
      • Palo Alto Network Cortex
      • Palo Alto Networks Firewalls (Panorama or not)
      • Pulse Secure NAC
      • SentinelOne
      • Sophos Firewall
      • Static destination IP blocking
      • Trend Micro Apex One
      • Trend Micro Cloud One
      • Trend Micro Vision One
      • VMware Carbon Black Cloud Endpoint
      • VMware Carbon Black Response
      • VMware vSphere
      • WatchGuard
      • Windows (direct PowerShell commands to shutdown host)
      • WithSecure Elements
    • SOAR
    • ITSM
    • Coverage
    • Context
    • SIEM
    • Access / Authentication
    • Notifications / Data Export
    • Analyst Guidance
    • Updates
    • Dashboards and Reports
    • Detection specific guidance
    • Licensing
    • Backup / Restore / DR
    • Investigate
    • General
    • AI and ML terminology
    • Vectra AI prioritization and scoring factors
    • Appliance support and EOS / EOL policy
    • Bandwidth used between Sensor and Brain
    • How detection PCAPs are generated
    • In-App support
    • Metadata attributes
    • Product Security
    • RSPAN and ERSPAN support
    • Host ID best practices and functionality
    • Vectra's coverage of MITRE ATT&CK and D3FEND
    • Vectra UI supported browsers
    • Why is metadata sharing important
For the complete documentation index, see llms.txt. This page is also available as Markdown.
  1. Documentation
  2. Integrations

Response

Response integration resources for actions, lockdown workflows, endpoint controls, and network controls connected to Vectra AI.

Cisco AMPCisco FMCCisco ISECisco MerakiCisco PxGridClearPassCrowdStrikeCybereasonEndgameTrellix (FireEye)Fortinet Firewalls (FortiOS)HarmonyMcAfee EPOMicrosoft Active DirectoryMicrosoft Azure AD (Entra ID) (RUX)Microsoft Defender for EndpointPalo Alto Network CortexPalo Alto Networks Firewalls (Panorama or not)Pulse Secure NACSentinelOneSophos FirewallStatic destination IP blockingTrend Micro Apex OneTrend Micro Cloud OneTrend Micro Vision OneVMware Carbon Black Cloud EndpointVMware Carbon Black ResponseVMware vSphereWatchGuardWindows (direct PowerShell commands to shutdown host)WithSecure Elements
PreviousSMTP configuration (QUX)NextCisco AMP

Last updated 10 days ago

Was this helpful?

LogoLogo
linkedinx-twitterfacebookyoutubeinstagramreddit

© 2026 Vectra AI, Inc. All rights reserved.

Was this helpful?