Skip to main content

Ordr

Overview

Ordr is a leading healthcare IoT security platform that provides comprehensive visibility, security, and asset management for connected medical and IoT devices. Ordr automatically discovers and profiles every connected device, providing deep asset intelligence including device types, manufacturers, models, risk levels, and vulnerabilities – all without requiring agents or credentials.

Ordr's AI-powered platform continuously monitors device behavior, identifies anomalies, and detects threats across clinical, enterprise, and IoT environments. It provides real-time risk scoring, vulnerability management, and network segmentation guidance to protect critical infrastructure and sensitive patient data.

Xshield leverages Ordr's comprehensive API to import enriched device inventory and vulnerability data, automatically applying them as core tags, asset attributes, and properties in Xshield. This seamless integration eliminates manual tagging effort and enables you to immediately leverage Ordr's deep device intelligence for zero-trust segmentation, risk-based policies, and compliance reporting.

Prerequisites

Ordr

  • An active Ordr deployment with API access enabled.
  • Username and Password created in Platform API Integration in Ordr to read device inventory and vulnerability data.
  • Ordr Endpoint – Base URL of your Ordr deployment (e.g., https://ordr.example.com). Must include the scheme (https://).

Xshield

  • Admin role to enable the integration.

Integration

Follow the steps below to connect Ordr to Xshield:

  1. Log in to Xshield and navigate to Integrations.

  2. Select the EAM/ITAM category and click Activate on Ordr.

  3. In the Ordr Endpoint section, enter:

    • Ordr Endpoint – Base URL of your Ordr deployment, including the scheme (e.g., https://ordr.example.com).
  4. In the Ordr Credentials section, enter:

    • Username – API username from Ordr.
    • Password – API password from Ordr.
  5. In the Target Asset Types section, select the types of assets for which you want to import data:

    • Devices – Import for Gatekeeper's managed & unmanaged assets.
    • Servers – Import for Server assets.
    • Endpoints – Import for Endpoints assets.
  6. Click Test to validate the credentials and connectivity.

  7. If the test succeeds, click Save to enable the integration.

    Ordr Integration

  8. A success message is logged under Monitor > Logs confirming activation.

  9. Once enabled, Xshield immediately initiates a sync job to fetch asset information from Ordr. After the initial sync completes, Xshield schedules a job every 24 hours to update asset information from Ordr.

Attribute Mapping

Note: Only devices whose MAC address matches an existing Xshield asset are updated.

The tables below show how Ordr attributes are mapped inside Xshield for both managed assets and unmanaged devices.

Managed Assets

Core Tags (for segments)

These core tags can be used for searching and creating segments.

Ordr AttributeXshield Core Tag
GroupCategory
MfgName/LongMfgNameManufacturer
ModelNameNoModel
DeviceLocationLocation
ProfileSubcategory
EndpointTypeRole

Asset Attributes (searchable)

Ordr AttributeXshield Asset Attribute
SerialNoSerial Number
OsTypeOS Name
OsVersionKernel Version

Properties (for tag rules)

These properties can be used to create tag rules.

Ordr AttributeXshield PropertyValue Format
CriticalityOrdr CriticalityString value
DeviceTypeOrdr Device TypeString value
RiskStateOrdr Risk StateString value
RiskScoreOrdr Risk ScoreCategorized: Normal(0), Low(0.1-3.9), Medium(4.0-6.9), High(7.0-8.9), Critical(9.0+)
KnownVulnRiskStateOrdr Known Vulnerability Risk StateString value
ConnStatusOrdr Connection StatusString value
ClassificationStateOrdr Classification StateString value
HasExternalFlowsOrdr Has External FlowsString value
AccessTypeOrdr Access TypeString value
VlanNameOrdr VLAN NameString value
SubnetOrdr SubnetString value
SensorNameOrdr Sensor NameString value
SensorIpOrdr Sensor IP AddressString value
SwVersionOrdr Software VersionString value
FqdnOrdr FQDNString value
DhcpHostnameOrdr DHCP HostnameString value
AlarmCountOrdr Alarm CountCategorized: 0, 1-9, 10-50, 50+
FdaClassOrdr FDA ClassNumeric value
HasPhiOrdr Has PHIBoolean value
IsBlacklistedOrdr Is BlacklistedBoolean value
ProxiedOrdr Is ProxiedBoolean value
DeviceNameOrdr Device NameString value
DeviceSubCategoryOrdr Device Sub CategoryString value
DhcpEnabledOrdr DHCP EnabledBoolean value
GuestDeviceOrdr Is Guest DeviceBoolean value
NwLocationOrdr Network LocationString value

Unmanaged Devices

Core Tags

These core tags are applied to unmanaged devices when the Devices option is selected in Target Asset Types.

Ordr AttributeXshield Core Tag
MfgName/LongMfgNameDevice Manufacturer
GroupDevice Category
ProfileDevice Subcategory
ModelNameNoDevice Model
SwVersionDevice Version
SerialNoDevice Serial Number

Vulnerabilities

Ordr continuously discovers and correlates CVEs (Common Vulnerabilities and Exposures) for each asset in your environment. Xshield imports these vulnerability lists during every sync, enabling you to:

  • Search for devices that contain specific CVEs.
  • Create Tag Rules that automatically tag vulnerable assets based on their CVE lists (for example, tag assets whose CVE list contains CVE-2021-44228 or other critical vulnerabilities).
  • Prioritize remediation efforts by identifying high-risk devices with known vulnerabilities.
  • Generate compliance reports showing vulnerability posture across your OT/IoT environment.

The vulnerability data imported from Ordr includes CVE IDs, severity scores, and risk categorizations, providing comprehensive visibility into the security posture of your connected device infrastructure.