Network · NDR
North-south and east-west traffic, with detections ranked by entity through Attack Signal Intelligence: command and control, reconnaissance, lateral movement, exfiltration.
For teams running Vectra with nobody to turn a lateral movement detection into a decision at night, or a provider that forwards it without looking at the endpoint. The Fortgale MDR service works on your Vectra platform and the tools connected to it, at a median TTC of <30 minutes.
The surfaces the Vectra platform observes and the SOC takes on: network, identity and cloud. If Vectra is not in place yet, licensing and sensors are part of the service.
North-south and east-west traffic, with detections ranked by entity through Attack Signal Intelligence: command and control, reconnaissance, lateral movement, exfiltration.
Active Directory and Entra ID: privilege abuse, anomalous sign-ins and suspicious use of service accounts, tied to the hosts where they appear.
AWS, Azure and Microsoft 365 in the same entity view, to follow an attacker from the network into the tenant.
Network metadata kept in Recall for investigations, with saved searches turned into detections as Custom Models.
Fortgale indicators loaded as a STIX threat feed: every match raises a Threat Intelligence Match detection on the entity.
A network detection tells you something is moving; it does not tell you who it is or what to do. Fortgale adds the missing part: every network detection is read by an analyst against 287 tracked adversary groups and attack tools and correlated with endpoint and identity activity, so lateral movement becomes an attribution and a decision. Noise drops by more than 90% by day 30, and containment runs through the controls your environment already has: median TTD <15 minutes, median TTC <30 minutes.
On Vectra, response runs through 360 Response, with time-limited blocks from 1 to 24 hours. Account Lockdown disables the account in Active Directory; on Entra ID it revokes sessions, disables the account or forces a password reset together with revocation.
Host Lockdown does not isolate the host by itself: it asks the integrated EDR to do it, for example Microsoft Defender, CrowdStrike or SentinelOne. Killing a process, quarantining a file or pulling an email from a mailbox are not Vectra actions: the SOC runs them on the EDR or the mail tenant, with the permissions agreed at onboarding.
Fortgale CTI indicators, 34,000 IOCs a week, reach Vectra as STIX feeds uploaded through the API, because the platform does not pull TAXII feeds on its own. Read next to behavioural detections, they push to the top of the queue a host already moving laterally that contacts attributed infrastructure.
On a Vectra platform already in production, sensors and entity scores stay where they are: the SOC joins with the agreed users and roles, without touching the deployment.
Technical onboarding closes in one week: integrations with EDR and identity provider, thresholds for automatic lockdown and the cases where your confirmation is needed.
On your side: permissions for the lockdown integrations, the accounts and hosts to keep out of automatic blocking, and the escalation list.
In June 2026 Fortgale CTI analysed Kali365, a phishing as a service platform sold for 250 dollars that abuses the Microsoft OAuth device code flow: the victim enters a code on microsoft.com/devicelogin, completes MFA, and the operator receives valid access and refresh tokens. Of the 800 domains analysed, 85.8% were hosted on Cloudflare Workers.
The article is not about Vectra, but it points to the response that matters: spotting the session anomaly and revoking tokens, because a changed password does not close a refresh token already issued. On Entra ID that is what Vectra Account Lockdown does when it revokes sessions, and if the action is pre-authorised the analyst who sees the anomalous sign-in runs it without waiting for the tenant administrator.
No. Vectra MXDR is the vendor's managed service. Fortgale works independently on the Vectra platform you already have, from a SOC in Milan, and brings proprietary CTI and analysts with the mandate to contain to the same detections.
Vectra ties detections to an entity, host or account, and ranks it. The Fortgale analyst opens the same entity in the EDR and in identity logs: if a process on the host explains the traffic, the decision to isolate rests on evidence from both sides and not on a single score.
The risk is real and it is why thresholds are agreed. Vectra blocks last from 1 to 24 hours and start manually or automatically above a score threshold: at onboarding we decide which accounts and hosts are never blocked automatically and where the analyst asks for your confirmation first.
Sensors and detection history stay on the platform: only users and response integrations change hands. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.
Both models work: Fortgale operates the Vectra platform you already own, or provides licensing and sensors as part of the service. Some features, such as Recall and Match, are licensed separately: at onboarding we check what is active.
We walk through a lateral movement detection step by step: the entity Vectra ranked first, the check on the EDR, the account lockdown and the isolation requested from the endpoint. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.