Claroty CTD Integration with TEM

Overview

Threat Exposure Management (TEM) integrates with Claroty Continuous Threat Detection (CTD), an on‑premises solution, to provide centralized visibility into vulnerabilities across OT, IoT assets, and medical devices. The integration automatically ingests asset and vulnerability data from Claroty CTD, enabling the identification of exposed industrial systems and their associated risks within a single platform.

TEM correlates Claroty CTD insights with other exposure data to help security and operations teams prioritize remediation and reduce the risk of business disruption. The integration supports multi-site Claroty deployments, providing a consolidated view of OT, IoT, and medical device exposure across connected environments without requiring manual data collection.

Supported Capability

Vulnerability Remediation -

  • Identifies, correlates, and prioritizes vulnerabilities across your environment.

  • Provides actionable insights to remediate vulnerabilities effectively through compensating controls, such as configuration changes, access restrictions, or virtual patching.

  • Ensures that remediation actions are tracked and verified, supporting continuous risk reduction and improved security posture.

Prerequisites

Before integrating CTD with TEM, ensure that the following requirements are met.

Requirement

Detail

Claroty CTD Version

5.1.1 or later (API compatible up to version 5.3)

Credentials

Claroty CTD username and password with API access

Instance URL

Claroty CTD base domain URL

TEM Access

Admin or Integration Manager role in Check Point TEM

Integrating Claroty CTD with TEM

Step 1 - Collecting Claroty CTD Connection Details

Collect the following information from the Claroty CTD environment:

  • Claroty CTD base domain URL: Navigate to your Claroty CTD instance in your browser. Copy the full URL directly from the address bar.

    Note - Enter only the base domain URL of the Claroty CTD server. Do not include specific pages, paths, or query parameters.

  • Retrieve your Claroty CTD username and password. These credentials must have API access permissions to allow TEM to pull asset and vulnerability data.

    Use the following credentials:

    • Username - Claroty login email address

    • Password - Claroty account password

    Note - A dedicated service account with Read-only access to assets and vulnerabilities is recommended for production environments.

Step 2 - Configuring the TEM Portal

  1. Log in to the TEM portal.

  2. Go to Settings > Integrations > Catalog > Continuous Threat Detection (CTD).

  3. In the CTD pop-up that appears, navigate to the Connection tab and enter the following details:

    1. In the Connection Name field, enter a name for this connection.

    2. In the Base URL field, enter the Claroty CTD base domain URL.

    3. In the Username field, enter the Claroty CTD username.

    4. In the Password field, enter the corresponding password.

  4. Click Next.

  5. Select the Claroty site to ingest data from.

  6. Click Connect to establish a connection.

Data Ingested from Claroty CTD

TEM ingests the following data from Claroty CTD on a scheduled basis:

Data Type

Description

Vulnerable Assets

All OT/IoT and medical devices with active insights.

CVE Details per Asset

All CVEs associated with each asset.

Multi-site data

Assets and vulnerabilities from all connected Claroty CTD sites.

Beta Integration Note - This integration is based on the Claroty CTD v5.1.1 API specification. Currently, no breaking API changes are known between versions v5.1.1 and v5.3. Compatibility with specific CTD deployments will be validated during pilot onboarding.