Federated XDR
Overview
OneFirewall Alliance is a federated Global XDR platform. Member organizations securely share real-time threat signals through an alliance model, building a threat intelligence ecosystem that spans multiple networks, clouds, and geographies, rather than operating within a single enterprise or data center.Key Components
World Crime Feeds Agent Listener
A modular agent that integrates with security telemetry sources, including:- Intrusion detection systems (IDS) such as Snort
- SIEM platforms such as ELK Security, QRadar, and Splunk
- Raw system events, audit logs, endpoint telemetry, and cloud logs
Global Threat Intelligence Engine
- Curated and enriched using machine learning and human analysis
- Sources signals from enterprise environments, public data sources, and proprietary honeypots
- Identifies new attack vectors, zero-days, and active campaigns early
Instruction Layer – Distributed IPS Control
Once threats are detected, OneFirewall can instruct defense mechanisms through integrations with:- Firewalls: Checkpoint, Fortinet, Cisco
- Endpoint and network security: Trellix, Sophos, SonicWall
- Cloud providers: AWS Shield, Google Chronicle SOC
- Application security: Cloudflare, web layers, proxies
- Routers, email gateways, and more
Comparison with Traditional XDR
How It Works
Proactive Defense
Members receive threat data shared by other alliance members before a specific threat targets their organization, rather than relying solely on signature updates.Federated Intelligence
Threats discovered in one environment inform defenses across all others, reducing mean time to detect (MTTD) and mean time to respond (MTTR).Plug-in Ecosystem
Integrations support deployment across legacy systems, modern cloud platforms, and hybrid environments.Privacy-Preserving Design
Information sharing uses metadata exchange, anonymization, and zero-trust principles, within GDPR, HIPAA, and similar compliance boundaries.Use Cases
- Pre-emptively block IPs or domains reported as malicious by other alliance members
- Respond to ransomware campaigns observed in other alliance nodes before local infection
- Integrate with SIEM/SOAR pipelines to enrich investigations with global context
- Orchestrate firewall and endpoint reconfigurations across hybrid environments

