Claroty CTD Integration
The Corsha mIDP integrates with Claroty Continuous Threat Detection (CTD) to automatically import and synchronize OT and IoT assets as machine identities. This integration enables organizations to leverage Claroty's comprehensive asset discovery capabilities while applying Corsha's zero-trust access controls.
Overview
Claroty CTD provides continuous asset discovery and threat detection for operational technology (OT), Internet of Things (IoT), and Industrial Internet of Things (IIoT) environments. Through direct integration, Corsha adds identity-based access management, microsegmentation, and policy-based enforcement to cyber-physical systems monitored by Claroty.
Key Benefits:
- Automated Asset Import: Discovered OT/IoT devices are automatically imported as machine identities in Corsha
- Continuous Synchronization: Asset inventory stays current as Claroty discovers new devices or detects changes
- Unified Visibility: View both IT and OT assets in a single machine identity platform
- Zero-Trust Enforcement: Apply connection rules and protocol enforcement to imported OT/IoT assets
- Risk-Aware Decisions: Leverage Claroty's threat intelligence for dynamic, risk-aware identity and access control
Asset Information Imported
The following information is imported from Claroty CTD:
- Device Identification: IP address, MAC address, hostname, resource ID
- Device Classification: Device type (IT/OT), category, vendor, model, class type
- Network Information: Network segments, VLANs, zones
- Operational Context: Site location, business function, criticality
- Protocol Information: Supported industrial protocols (ARP, BACnet, DHCP, ICMP, Kerberos, Modbus, OPC UA, SMB, TCP, UDP, etc.)
- Security Context: Risk level (Low/Medium/High), vulnerability status
- Last Seen Timestamp: Most recent activity detection
Viewing Claroty Assets in the Corsha Console
Once the integration is configured, Claroty-discovered assets automatically appear in the Corsha Console as a trusted identity source.
Identity Sources Dashboard
The Identity Sources page shows the Claroty integration status and provides an overview of discovered assets:

Asset Discovery Sources:
- Platform: Claroty Machines
- Assets Synced: Number of assets synchronized from Claroty
- Machine Identities Mapped: Number of identities successfully mapped
- Last Sync: Most recent synchronization timestamp
Machine Identities List View
Navigate to Machine Identities to view and manage all Claroty-mapped identities:

Features:
- Filter by Identity Source: Use the "Identity Source: Claroty CTD" filter to view only Claroty-discovered machines
- Search: Find specific machines by name, IP address, or identifier
- Status Indicator: View real-time status (Running, Halted, etc.)
- Last Activity: Track when each machine was last active
- Created On: See when the identity was first discovered
All Claroty-mapped entries display their Identity Source as "Claroty" with the distinctive Claroty icon.
Individual Machine Identity Details
Click on any machine identity to view comprehensive details and Claroty-specific attributes:

Claroty Device Attributes:
This section displays rich contextual data synchronized from Claroty CTD:
| Attribute | Description |
|---|---|
| Resource ID | Claroty's unique resource identifier |
| Asset Name | Device name from Claroty |
| Host Name | Network hostname |
| VLAN | Virtual LAN identifier |
| Class Type | IT or OT classification |
| Protocol | Supported protocols (ARP, BACnet, DHCP, ICMP, Kerberos, Modbus, OPC UA, SMB, TCP, UDP, etc.) |
| Risk Level | Claroty risk assessment (Low, Medium, High) |
Configuration
Contact your Corsha Technical Point of Contact (TPOC) for assistance configuring the Claroty CTD integration.
For best practices on using asset discovery integrations, see Asset Discovery Sources Best Practices.
Next Steps
- Asset Discovery Sources Overview for integration best practices
- Managing Machine Identities to work with imported assets
- Machine Groups to organize imported machines