MDR partner · Vectra AI Platform

MDR for Vectra AI: network and identity detections, with analysts who decide.

For teams running Vectra with nobody to turn a lateral movement detection into a decision at night, or a provider that forwards it without looking at the endpoint. The Fortgale MDR service works on your Vectra platform and the tools connected to it, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × Vectra AI
MDR · live
Vectra AI sensor activeEndpoint · cloud · identity telemetry
Vectra AI
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native Vectra AI responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, Vectra AI + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
Vectra AI Platform
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on Vectra AI.

The surfaces the Vectra platform observes and the SOC takes on: network, identity and cloud. If Vectra is not in place yet, licensing and sensors are part of the service.

01

Network · NDR

North-south and east-west traffic, with detections ranked by entity through Attack Signal Intelligence: command and control, reconnaissance, lateral movement, exfiltration.

02

Identity

Active Directory and Entra ID: privilege abuse, anomalous sign-ins and suspicious use of service accounts, tied to the hosts where they appear.

03

Cloud and Microsoft 365

AWS, Azure and Microsoft 365 in the same entity view, to follow an attacker from the network into the tenant.

04

Recall and Custom Models

Network metadata kept in Recall for investigations, with saved searches turned into detections as Custom Models.

05

Fortgale threat feed

Fortgale indicators loaded as a STIX threat feed: every match raises a Threat Intelligence Match detection on the entity.

What we add

What Fortgale adds on top of Vectra AI.

A network detection tells you something is moving; it does not tell you who it is or what to do. Fortgale adds the missing part: every network detection is read by an analyst against 287 tracked adversary groups and attack tools and correlated with endpoint and identity activity, so lateral movement becomes an attribution and a decision. Noise drops by more than 90% by day 30, and containment runs through the controls your environment already has: median TTD <15 minutes, median TTC <30 minutes.

On Vectra, response runs through 360 Response, with time-limited blocks from 1 to 24 hours. Account Lockdown disables the account in Active Directory; on Entra ID it revokes sessions, disables the account or forces a password reset together with revocation.

Host Lockdown does not isolate the host by itself: it asks the integrated EDR to do it, for example Microsoft Defender, CrowdStrike or SentinelOne. Killing a process, quarantining a file or pulling an email from a mailbox are not Vectra actions: the SOC runs them on the EDR or the mail tenant, with the permissions agreed at onboarding.

Fortgale CTI indicators, 34,000 IOCs a week, reach Vectra as STIX feeds uploaded through the API, because the platform does not pull TAXII feeds on its own. Read next to behavioural detections, they push to the top of the queue a host already moving laterally that contacts attributed infrastructure.

Takeover

How we take over your Vectra AI environment.

On a Vectra platform already in production, sensors and entity scores stay where they are: the SOC joins with the agreed users and roles, without touching the deployment.

Technical onboarding closes in one week: integrations with EDR and identity provider, thresholds for automatic lockdown and the cases where your confirmation is needed.

On your side: permissions for the lockdown integrations, the accounts and hosts to keep out of automatic blocking, and the escalation list.

From the field

Kali365: the session is the new credential.

In June 2026 Fortgale CTI analysed Kali365, a phishing as a service platform sold for 250 dollars that abuses the Microsoft OAuth device code flow: the victim enters a code on microsoft.com/devicelogin, completes MFA, and the operator receives valid access and refresh tokens. Of the 800 domains analysed, 85.8% were hosted on Cloudflare Workers.

The article is not about Vectra, but it points to the response that matters: spotting the session anomaly and revoking tokens, because a changed password does not close a refresh token already issued. On Entra ID that is what Vectra Account Lockdown does when it revokes sessions, and if the action is pre-authorised the analyst who sees the anomalous sign-in runs it without waiting for the tenant administrator.

FAQ

What buyers running Vectra AI actually ask.

Do we need Vectra MXDR to work with Fortgale?

No. Vectra MXDR is the vendor's managed service. Fortgale works independently on the Vectra platform you already have, from a SOC in Milan, and brings proprietary CTI and analysts with the mandate to contain to the same detections.

How do you correlate Vectra detections with endpoint and identity?

Vectra ties detections to an entity, host or account, and ranks it. The Fortgale analyst opens the same entity in the EDR and in identity logs: if a process on the host explains the traffic, the decision to isolate rests on evidence from both sides and not on a single score.

Can automatic lockdown block legitimate users?

The risk is real and it is why thresholds are agreed. Vectra blocks last from 1 to 24 hours and start manually or automatically above a score threshold: at onboarding we decide which accounts and hosts are never blocked automatically and where the analyst asks for your confirmation first.

How do we move from another provider without a gap in coverage?

Sensors and detection history stay on the platform: only users and response integrations change hands. Fortgale monitoring starts as soon as access is live, and the previous contract can end once technical onboarding is complete, after one week.

Do we buy the Vectra licences, or do you?

Both models work: Fortgale operates the Vectra platform you already own, or provides licensing and sensors as part of the service. Some features, such as Recall and Match, are licensed separately: at onboarding we check what is active.

See a real runbook

A real runbook on your Vectra detections.

We walk through a lateral movement detection step by step: the entity Vectra ranked first, the check on the EDR, the account lockdown and the isolation requested from the endpoint. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.