INTEGRATIONS

Your tools.
A more connected picture.

Connect endpoint, identity, cloud and network sources to give investigations and reporting the context they need.

37 sources in this directory

Setup and coverage vary by source.

EDR & XDR

CrowdStrike Falcon

Endpoint detections, incidents and host inventory.

Workspace connection
EDR & XDR

SentinelOne

Endpoint threats, agents and activity for investigation context.

Workspace connection
EDR & XDR

Microsoft Defender for Endpoint

Endpoint alerts, machines and vulnerability findings.

Workspace connection
EDR & XDR

Wazuh

Endpoint alerts, agent inventory and vulnerability findings.

Workspace connection
SIEM & logs

Microsoft Sentinel

Security incidents and analytics-rule context from your Sentinel workspace.

Workspace connection
SIEM & logs

Splunk

Notable events, saved searches and platform health context.

Workspace connection
SIEM & logs

Elastic SIEM

Security alerts, detection rules and Elasticsearch cluster health.

Workspace connection
Identity & access

Microsoft Entra ID / M365

Microsoft 365 identity, configuration, governance and security evidence.

Workspace connection
Identity & access

Okta

Identity and access evidence from your Okta environment.

Workspace connection
Identity & access

Google Workspace

Workspace identity and governance collection.

Workspace connection
Identity & access

Cisco Duo

Authentication and multifactor-access context.

Workspace connection
Endpoint management

Microsoft Intune

Managed-device posture and application workflows through your Microsoft connection.

Through Microsoft 365
Email security

Proofpoint

Email-security evidence for the wider security picture.

Workspace connection
Email security

Mimecast

Email-protection context from your Mimecast environment.

Workspace connection
Vulnerability management

Tenable

Vulnerability and asset evidence for prioritisation.

Workspace connection
Vulnerability management

Qualys

Asset and vulnerability-management evidence.

Workspace connection
Vulnerability management

Rapid7

Insight vulnerability context and assessment data.

Workspace connection
Network & firewall

Palo Alto

Firewall and network-security context.

Workspace connection
Network & firewall

Fortinet

FortiGate network and firewall evidence.

Workspace connection
Network & firewall

Cisco Meraki

Network devices and security-event context.

Workspace connection
Network & firewall

Ubiquiti UniFi

Network-controller integration through the provider framework.

Assisted setup
Network & firewall

pfSense

On-premises firewall telemetry and hardening audits through collector workflows.

Collector connection
Cloud platforms

AWS

Cloud-security and configuration evidence from Amazon Web Services.

Workspace connection
Cloud platforms

Microsoft Azure

Azure subscription and cloud-security context.

Workspace connection
Cloud platforms

Google Cloud

Cloud-platform evidence through your Google Cloud connection.

Workspace connection
Security awareness

KnowBe4

Awareness and phishing-training context for people risk.

Workspace connection
Security awareness

Symbol Security

Security-awareness collection and reporting context.

Workspace connection
Ticketing & ITSM

Jira

Issue and service-delivery context from your Jira instance.

Workspace connection
Ticketing & ITSM

ServiceNow

IT service-management context from your ServiceNow instance.

Workspace connection
Threat intelligence

VirusTotal

Threat-intelligence provider connection through the integration framework.

Assisted setup
Threat intelligence

AlienVault OTX

Subscribed threat-intelligence pulses and recent activity.

Assisted setup
Notifications

Slack

Channel-based alert delivery through a configured Slack bot.

Assisted setup
Notifications

Microsoft Teams

Notification cards through a configured Teams webhook.

Assisted setup
Notifications

PagerDuty

Incident escalation and on-call context through a configured provider.

Assisted setup
Agents & collectors

ThreatShield agents

Host inventory, health and on-premises evidence through the signed-agent workflows.

Collector connection
Agents & collectors

On-premises Active Directory

Domain, identity, group-policy and certificate-services auditing through on-premises collection.

Collector connection
Agents & collectors

Syslog / CEF

Push-based network and security-event collection for supported log formats.

Collector connection
NEED SOMETHING DIFFERENT?

We can create bespoke connections.

Tell us about your API, data source or on-premises system. We’ll scope a connection around the available interface, permissions and evidence you need.

Discuss your connection

Setup depends on source capabilities, licensing and the permissions you approve. The directory distinguishes workspace integrations, assisted setup, Microsoft-connected capabilities and collectors.

LET’S CONNECT THE PICTURE

Start with a clearer view of your security.

Tell us about your environment, your priorities and where you need support.