Vectra AI · NDR + ITDR + cloud
AI-driven detection on network, identity (AD/AAD), cloud (AWS, Azure, M365). Per-entity prioritisation reduces alert volume by 80%. Strong on lateral movement, Pass-the-Hash, Golden Ticket, AAD compromise.
The Fortgale European SOC 24·7·365 on the Vectra console. AI prioritisation per entity (host · account · identity), ~11 min median containment, response via native integrations.
Vectra AI is Gartner Leader for NDR + ITDR. Particularly strong on lateral movement and identity-based attacks. Fortgale operates it with European analysts who know the European actor TTPs leveraging these vectors.
AI-driven detection on network, identity (AD/AAD), cloud (AWS, Azure, M365). Per-entity prioritisation reduces alert volume by 80%. Strong on lateral movement, Pass-the-Hash, Golden Ticket, AAD compromise.
L2/L3 analysts specialised on identity attacks. Triage <15 min on Vectra alerts. Custom rules for European environments. 34,000+ IoCs per week applied as Watchlists.
Containment via Vectra integrations: EDR isolation, AD lockout, firewall block, AAD revocation. Direct escalation to Fortgale IR. Full NIS2 national CSIRT notification support.
From Vectra sensor ingestion to cross-tool response — all governed by Fortgale with European analysts and proprietary CTI on European markets.
Network sensors (NDR), AD/AAD integrations (ITDR), cloud (AWS, Azure, M365). Telemetry on Vectra Cloud + Fortgale data fabric for cross-customer correlation.
Vectra AI scores risk per host, account, identity — not per alert. Fortgale tunes scoring on European context. False positives reduced by 80%.
European SOC specialised on identity-based attacks. Triage on entities, attribution to actor (Scattered Spider, APT29, FIN12). Decisions in your business language.
Containment via Vectra integrations: EDR isolation, AD lockout, firewall block, AAD revocation. Direct escalation to Fortgale IR for critical incidents.
Metrics measured on real customer telemetry — Q1 2026, updated quarterly.
Every component designed to leverage Vectra entity prioritisation with European SOC governance and proprietary CTI.
Vectra licensing (or existing instance). Network sensors, AD/AAD integrations, cloud connectors managed by Fortgale. Continuous tuning per environment.
Vectra ITDR governed by Fortgale on AD on-prem + Entra ID + AAD. Detection of Kerberoasting, Pass-the-Hash, Golden Ticket, AAD impossible travel, OAuth abuse.
Vectra Detect on network: lateral movement, C2 beaconing, data staging, exfil. Native integration with proprietary CTI for IoC enrichment.
Containment orchestrated via Vectra integrations: EDR isolation (CrowdStrike, SentinelOne, Defender), AD lockout, firewall block, AAD session revocation.
Executive reports with MTTD, MTTR, entity risk trends, attack progression. Per-incident technical reports. NIS2/ISO 27001/GDPR audit documentation.
Monthly hunting on Vectra Recall using proprietary CTI + Sigma rules. Focus on identity-based attacks, lateral movement and silent C2 not caught by automatic detections.
The CISO decides on risk. The IT lead decides on the runbook. Fortgale MDR produces evidence for both.
Each month the CISO receives the profile of the 3 most likely actors against their sector, with the Fortgale MDR runbook already mapped to the Vectra AI Platform telemetry.
When the Vectra AI alert is real, decision time is containment time. Our L2/L3 analysts know the Vectra AI Platform console and have a mandate to decide.
Combines Vectra AI Platform (NDR + ITDR + cloud detection) with the Fortgale European SOC 24·7·365. L2/L3 analysts monitor the Vectra Recall/Detect console, leverage AI entity prioritisation and trigger response via native integrations (firewall, EDR, IAM).
Vectra applies AI to score risk not per single alert but per entity (host, account, identity). It reduces alert volume to manage by grouping them around 'what matters', accelerating triage and reducing noise.
No. Fortgale handles the full cycle: licensing, network sensor deployment, integrations configuration (cloud, identity, EDR), tuning. Available both on existing instance or as part of the service.
Yes. We support NIS2 transposition requirements: continuous monitoring, IoC collection for national CSIRT notification within 24 hours, technical documentation for 72-hour notifications.
Vectra AI Platform covers NDR (network detection), ITDR (identity threat detection for AAD/AD), cloud (AWS, Azure, M365). Particularly strong on detecting lateral movement and identity-based attacks (Pass-the-Hash, Golden Ticket, AAD compromise).
We bring you the Report on your sector with the most likely actors and a concrete MDR runbook on your Vectra AI Platform console.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.