Skip to main content

Federated XDR

Overview

OneFirewall Alliance is a federated Global XDR platform. Member organizations securely share real-time threat signals through an alliance model, building a threat intelligence ecosystem that spans multiple networks, clouds, and geographies, rather than operating within a single enterprise or data center.

Key Components

World Crime Feeds Agent Listener

A modular agent that integrates with security telemetry sources, including:
  • Intrusion detection systems (IDS) such as Snort
  • SIEM platforms such as ELK Security, QRadar, and Splunk
  • Raw system events, audit logs, endpoint telemetry, and cloud logs
Feeds are aggregated, normalized, and enriched using threat intelligence from alliance members.

Global Threat Intelligence Engine

  • Curated and enriched using machine learning and human analysis
  • Sources signals from enterprise environments, public data sources, and proprietary honeypots
  • Identifies new attack vectors, zero-days, and active campaigns early

Instruction Layer – Distributed IPS Control

Once threats are detected, OneFirewall can instruct defense mechanisms through integrations with:
  • Firewalls: Checkpoint, Fortinet, Cisco
  • Endpoint and network security: Trellix, Sophos, SonicWall
  • Cloud providers: AWS Shield, Google Chronicle SOC
  • Application security: Cloudflare, web layers, proxies
  • Routers, email gateways, and more

Comparison with Traditional XDR


How It Works

Proactive Defense

Members receive threat data shared by other alliance members before a specific threat targets their organization, rather than relying solely on signature updates.

Federated Intelligence

Threats discovered in one environment inform defenses across all others, reducing mean time to detect (MTTD) and mean time to respond (MTTR).

Plug-in Ecosystem

Integrations support deployment across legacy systems, modern cloud platforms, and hybrid environments.

Privacy-Preserving Design

Information sharing uses metadata exchange, anonymization, and zero-trust principles, within GDPR, HIPAA, and similar compliance boundaries.

Use Cases

  • Pre-emptively block IPs or domains reported as malicious by other alliance members
  • Respond to ransomware campaigns observed in other alliance nodes before local infection
  • Integrate with SIEM/SOAR pipelines to enrich investigations with global context
  • Orchestrate firewall and endpoint reconfigurations across hybrid environments

Compatible Security Products by Category

The tables below list SIEM, WAF, EDR, XDR, firewall, and IPS products that are natively compatible with, or have existing integrations with, the OneFirewall Global XDR platform.

SIEM (Security Information and Event Management)


WAF (Web Application Firewall)


EDR (Endpoint Detection and Response)


XDR (Extended Detection and Response)


Firewalls


IPS (Intrusion Prevention Systems)


Integration Compatibility

OneFirewall supports ingestion of telemetry, threat intelligence enrichment, and coordinated response actions across the products listed above, through the plugin ecosystem and the World Crime Feeds Agent Listener. For systems not yet integrated, OneFirewall’s team can develop dedicated connectors or adapt existing APIs for compatibility.