MDR partner · Vectra AI Platform

MDR on Vectra AI Platform: NDR + ITDR with entity-based prioritisation.

The Fortgale European SOC 24·7·365 on the Vectra console. AI prioritisation per entity (host · account · identity), ~11 min median containment, response via native integrations.

~11 minMedian containment
24·7·365European SOC
Per entityAI prioritisation
Fortgale × Vectra AI
MDR · live
Vectra AI sensor activeEndpoint · cloud · identity telemetry
Vectra AI
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced by 94%
Fortgale
Native Vectra AI responseMedian host isolation ~8 s
Live
Proprietary intelligence34,000+ IoCs per week · European actors
Fortgale
MDR live — Vectra AI + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Vectra AI Platform
MITRE ATT&CK aligned
OpenCTI
Why Fortgale + Vectra AI

Network + identity AI detection, governed by senior analysts.

Vectra AI is Gartner Leader for NDR + ITDR. Particularly strong on lateral movement and identity-based attacks. Fortgale operates it with European analysts who know the European actor TTPs leveraging these vectors.

01 ·

Vectra AI · NDR + ITDR + cloud

AI-driven detection on network, identity (AD/AAD), cloud (AWS, Azure, M365). Per-entity prioritisation reduces alert volume by 80%. Strong on lateral movement, Pass-the-Hash, Golden Ticket, AAD compromise.

02 ·

European SOC 24·7·365

L2/L3 analysts specialised on identity attacks. Triage <15 min on Vectra alerts. Custom rules for European environments. 34,000+ IoCs per week applied as Watchlists.

03 ·

Cross-tool response + IR

Containment via Vectra integrations: EDR isolation, AD lockout, firewall block, AAD revocation. Direct escalation to Fortgale IR. Full NIS2 national CSIRT notification support.

How it works · architecture

Four blocks, one MDR cycle on Vectra.

From Vectra sensor ingestion to cross-tool response — all governed by Fortgale with European analysts and proprietary CTI on European markets.

01 ·
01 · Ingestion

Vectra sensors active

Network sensors (NDR), AD/AAD integrations (ITDR), cloud (AWS, Azure, M365). Telemetry on Vectra Cloud + Fortgale data fabric for cross-customer correlation.

02 ·
02 · Tier-zero

AI prioritisation per entity

Vectra AI scores risk per host, account, identity — not per alert. Fortgale tunes scoring on European context. False positives reduced by 80%.

03 ·
03 · Analysts

Our L2/L3 on the console

European SOC specialised on identity-based attacks. Triage on entities, attribution to actor (Scattered Spider, APT29, FIN12). Decisions in your business language.

04 ·
04 · Response

Cross-tool + IR

Containment via Vectra integrations: EDR isolation, AD lockout, firewall block, AAD revocation. Direct escalation to Fortgale IR for critical incidents.

Proof · service metrics

Four numbers that hold MDR on Vectra AI up.

Metrics measured on real customer telemetry — Q1 2026, updated quarterly.

~11 min
Median containment
from confirmed Vectra alert
80 %
Volume reduction
via entity prioritisation
NDR+ITDR
Network + identity
+ cloud unified
10 days
Full onboarding
Vectra AI Platform
What the service includes

MDR on Vectra AI, in detail.

Every component designed to leverage Vectra entity prioritisation with European SOC governance and proprietary CTI.

01

Managed Vectra AI Platform

Vectra licensing (or existing instance). Network sensors, AD/AAD integrations, cloud connectors managed by Fortgale. Continuous tuning per environment.

02

Identity threat detection

Vectra ITDR governed by Fortgale on AD on-prem + Entra ID + AAD. Detection of Kerberoasting, Pass-the-Hash, Golden Ticket, AAD impossible travel, OAuth abuse.

03

Network detection (NDR)

Vectra Detect on network: lateral movement, C2 beaconing, data staging, exfil. Native integration with proprietary CTI for IoC enrichment.

04

Cross-tool response

Containment orchestrated via Vectra integrations: EDR isolation (CrowdStrike, SentinelOne, Defender), AD lockout, firewall block, AAD session revocation.

05

Reporting & governance

Executive reports with MTTD, MTTR, entity risk trends, attack progression. Per-incident technical reports. NIS2/ISO 27001/GDPR audit documentation.

06

Threat hunting on Vectra

Monthly hunting on Vectra Recall using proprietary CTI + Sigma rules. Focus on identity-based attacks, lateral movement and silent C2 not caught by automatic detections.

For whom · two angles

Same MDR on Vectra AI, two angles.

The CISO decides on risk. The IT lead decides on the runbook. Fortgale MDR produces evidence for both.

For the CISO

A named runbook per actor, on the Vectra AI stack.

Each month the CISO receives the profile of the 3 most likely actors against their sector, with the Fortgale MDR runbook already mapped to the Vectra AI Platform telemetry.

  • Monthly threat briefingActors, observed TTPs, campaigns in progress on your sector.
  • Vectra AI runbookLive MITRE-mapped playbooks, executable on the Vectra AI Platform console.
  • Board-ready reportingRisk · impact · decision. No slideware technology.
Request the threat briefing →
For the IT lead

Zero translator handover. European analysts on your Vectra AI console.

When the Vectra AI alert is real, decision time is containment time. Our L2/L3 analysts know the Vectra AI Platform console and have a mandate to decide.

  • Median containment ~11 minFrom confirmed alert to remediation in production.
  • Native Vectra AI responseProcess kill, host isolation, network containment via Vectra AI Platform API.
  • End-to-end integrationVectra AI telemetry ingested into our multi-domain data fabric.
See a real runbook →
FAQ · frequently asked

Everything to know before talking to our analysts.

What is the Fortgale MDR service on Vectra AI?

Combines Vectra AI Platform (NDR + ITDR + cloud detection) with the Fortgale European SOC 24·7·365. L2/L3 analysts monitor the Vectra Recall/Detect console, leverage AI entity prioritisation and trigger response via native integrations (firewall, EDR, IAM).

What does it mean that Vectra prioritises by entity?

Vectra applies AI to score risk not per single alert but per entity (host, account, identity). It reduces alert volume to manage by grouping them around 'what matters', accelerating triage and reducing noise.

Do I need to already have Vectra?

No. Fortgale handles the full cycle: licensing, network sensor deployment, integrations configuration (cloud, identity, EDR), tuning. Available both on existing instance or as part of the service.

Is the service NIS2-compliant?

Yes. We support NIS2 transposition requirements: continuous monitoring, IoC collection for national CSIRT notification within 24 hours, technical documentation for 72-hour notifications.

Is Vectra only NDR or does it cover identity and cloud too?

Vectra AI Platform covers NDR (network detection), ITDR (identity threat detection for AAD/AD), cloud (AWS, Azure, M365). Particularly strong on detecting lateral movement and identity-based attacks (Pass-the-Hash, Golden Ticket, AAD compromise).

Talk to the outpost

One meeting. One NDA. One real runbook on Vectra AI.

We bring you the Report on your sector with the most likely actors and a concrete MDR runbook on your Vectra AI Platform console.

Tempo di risposta: < 1 giorno lavorativo.

Questo sito è protetto da reCAPTCHA e si applicano la Privacy Policy e i Termini di servizio di Google.