Skip to main content

Vectra

Vectra is a network detection and response (NDR) and extended detection and response (XDR) platform that uses artificial intelligence and machine learning to detect, investigate, and respond to cybersecurity threats across enterprise networks, cloud environments, and SaaS applications. The platform provides continuous monitoring and threat detection capabilities to identify attackers and malicious behavior in real-time.

CategoryNDR
DirectionQuery source
Sign-inNone
Query languagesSTIX
Websitevectra.ai

Before you start​

warning

The setup page can't take credentials for Vectra yet. Create the connection, then contact Huntbase support to finish signing it in.

For the vendor's own instructions, see Vectra API token quick start.

Connect Vectra​

  1. Go to Connections and click New connection, or click New connection on the Vectra product page.
  2. On Product, pick Vectra and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Vectra lives:

FieldRequiredNotes
Server AddressYesThe hostname or IP address of your Vectra Brain.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.

Query it​

Once connected, Vectra can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​