360 Response: Enforced control across identity, devices, and network traffic

Decisive containment during active attacks. Lockdown compromised identities, isolate devices, and block attacker traffic using high-fidelity detections.

Demo video

See 360 Response in action

WHY VECTRA AI

360 Response:
unified containment for hybrid attacks

Most tools try to stop attackers by disrupting a single connection, with actions like TCP resets. It sounds effective. It isn't enough.

360 Response converts Vectra AI’s attack signal intelligence into precise, enforced actions wherever attackers operate in your hybrid environment:

  • Identity Lockdown

    Account containment across AD and Entra ID

    • Disable or restrict compromised accounts
    • Invalidate active sessions and force reauthentication
    • Support password reset workflows to remove stolen credential advantage

    Result

    Attackers lose their identity foothold in across on-prem and cloud environments.

  • Device Lockdown

    Host and endpoint containment using your existing EDR

    • Isolate compromised hosts from the network
    • Stop lateral movement and data staging on the device
    • Triggered manually or automatically from high-confidence detections

    Result

    The endpoint the attacker depends on is removed from play.

  • Traffic Lockdown

    Network containment enforced by your firewalls

    • Add risky host IPs to a Vectra managed IP blocklist
    • Let firewalls subscribe to that list as an external threat feed
    • Block all traffic from those sources according to your policies

    Result

    Command-and-control, exfiltration, and internal pivoting are cut off at the network layer.

All three layers work together, driven by the same AI signal, from the same analyst experience.

approach

What is the 360 Response workflow?

Detect
  • Vectra AI analyzes behavior across identity, cloud, SaaS, and network, and scores entities with urgency and importance
Decide
  • High confidence threats reach 360 Response. Policies define when actions are manual, and when they are automatic
Lockdown
  • Identity Lockdown removes attacker access to identities
  • Device Lockdown isolates compromised endpoints
  • Traffic Lockdown blocks communication at the firewall
Contain
  • Attack paths are cut at multiple layers in minutes, not hours
Release and improve
  • Lockdowns expire on a set schedule or are lifted by analysts, and the data feeds directly into reporting and resilience metrics
OUTCOMES

How does 360 Response put defenders back in control?

With 360 Response, defenders move from hoping disruption is enough to knowing containment is enforced.

  • You get

    • Real control across identity, host, and network
    • Containment you can explain and prove to your leadership
    • Automation that targets only high confidence threats
    • Response that scales without adding additional manual work
  • Your leadership sees

    • Fewer incidents that progress
    • Faster containment times
    • Stronger evidence of resilience and control across hybrid environments

360 Response turns every high-fidelity detection into a decisive action that stops attackers and shows that your team is in command of the environment.

FAQ

Top FAQs: 360 Response

What is 360 Response in the Vectra AI Platform?

How does 360 Response support continuous control during an active attack?

How does Identity Lockdown help stop identity-based attacks?

How does Device Lockdown isolate compromised devices without adding operational overhead?

How does Traffic Lockdown enforce network-level containment?

How does 360 Response fit into Vectra AI’s continuous control framework?

NEXT STEPS

Gain the control, clarity, and coverage you need to stop hybrid attacks

360 Response delivers true control across identity, host, and network so attackers lose every path they rely on. Paired with the Vectra AI Platform’s extensive attack surface coverage, high-fidelity signal and unified investigation experience, your team gets control to enforce containment across your entire hybrid environment.