For the complete documentation index, see llms.txt. This page is also available as Markdown.

Overview

ThreatDefence provides two types of appliances to collect and forward data to the SecOps platform: the Network Sensor for network detection and response (NDR), and the Syslog Forwarder for log collection from your existing infrastructure. Both are available as virtual appliances, with the Network Sensor also offered as a physical hardware option for larger environments.


Network Sensor (NDR)

The ThreatDefence Network Sensor provides passive monitoring of network traffic for visibility, intrusion detection, and behavioural analytics. It is available as a physical appliance for enterprise and data-centre environments, or as a virtual appliance for smaller or cloud-only deployments.

  • Overview — Deployment architecture, SPAN/port mirroring setup, and connectivity requirements

  • Physical Sensor — Hardware specifications and installation

  • Virtual Sensor — Virtual appliance setup and configuration


Syslog Forwarder

The ThreatDefence Syslog Forwarder (TD-SYSLOG-VM) is a lightweight Linux virtual appliance that collects logs from your environment and forwards them securely over an encrypted TLS channel to the ThreatDefence platform. It runs on any common hypervisor or cloud provider, including VMware, Hyper-V, and AWS.

Last updated