Claroty CTD Integration with TEM
Overview
Threat Exposure Management (TEM) integrates with Claroty Continuous Threat Detection (CTD), an on‑premises solution, to provide centralized visibility into vulnerabilities across OT, IoT assets, and medical devices. The integration automatically ingests asset and vulnerability data from Claroty CTD, enabling the identification of exposed industrial systems and their associated risks within a single platform.
TEM correlates Claroty CTD insights with other exposure data to help security and operations teams prioritize remediation and reduce the risk of business disruption. The integration supports multi-site Claroty deployments, providing a consolidated view of OT, IoT, and medical device exposure across connected environments without requiring manual data collection.
Supported Capability
Vulnerability Remediation -
-
Identifies, correlates, and prioritizes vulnerabilities across your environment.
-
Provides actionable insights to remediate vulnerabilities effectively through compensating controls, such as configuration changes, access restrictions, or virtual patching.
-
Ensures that remediation actions are tracked and verified, supporting continuous risk reduction and improved security posture.
Prerequisites
Before integrating CTD with TEM, ensure that the following requirements are met.
|
Requirement |
Detail |
|---|---|
|
Claroty CTD Version |
5.1.1 or later (API compatible up to version 5.3) |
|
Credentials |
Claroty CTD username and password with API access |
|
Instance URL |
Claroty CTD base domain URL |
|
TEM Access |
Admin or Integration Manager role in Check Point TEM |
Integrating Claroty CTD with TEM
Step 1 - Collecting Claroty CTD Connection Details
Collect the following information from the Claroty CTD environment:
-
Claroty CTD base domain URL: Navigate to your Claroty CTD instance in your browser. Copy the full URL directly from the address bar.
Note - Enter only the base domain URL of the Claroty CTD server. Do not include specific pages, paths, or query parameters.
-
Retrieve your Claroty CTD username and password. These credentials must have API access permissions to allow TEM to pull asset and vulnerability data.
Use the following credentials:
-
Username - Claroty login email address
-
Password - Claroty account password
Note - A dedicated service account with Read-only access to assets and vulnerabilities is recommended for production environments.
-
Step 2 - Configuring the TEM Portal
-
Log in to the TEM portal.
-
Go to Settings > Integrations > Catalog > Continuous Threat Detection (CTD).
-
In the CTD pop-up that appears, navigate to the Connection tab and enter the following details:
-
In the Connection Name field, enter a name for this connection.
-
In the Base URL field, enter the Claroty CTD base domain URL.
-
In the Username field, enter the Claroty CTD username.
-
In the Password field, enter the corresponding password.
-
-
Click Next.
-
Select the Claroty site to ingest data from.
-
Click Connect to establish a connection.
Data Ingested from Claroty CTD
TEM ingests the following data from Claroty CTD on a scheduled basis:
|
Data Type |
Description |
|---|---|
|
Vulnerable Assets |
All OT/IoT and medical devices with active insights. |
|
CVE Details per Asset |
All CVEs associated with each asset. |
|
Multi-site data |
Assets and vulnerabilities from all connected Claroty CTD sites. |
|
|
Beta Integration Note - This integration is based on the Claroty CTD v5.1.1 API specification. Currently, no breaking API changes are known between versions v5.1.1 and v5.3. Compatibility with specific CTD deployments will be validated during pilot onboarding. |


