Connect the evidence behind an investigation
An endpoint alert may need account activity, device-management context and network evidence to become understandable. When those sources sit in separate consoles, the team can spend time finding context before deciding who should act.
ThreatShield supports connections that bring relevant evidence into security operations, assessment reporting and IT workflows. This is useful for organisations with an established toolset and for service partners agreeing a consistent approach across client workspaces. The scope should follow the required evidence, rather than the number of products connected.
Supported products and connection types
The directory includes endpoint products such as CrowdStrike Falcon, SentinelOne and Microsoft Defender for Endpoint; SIEM sources including Microsoft Sentinel, Splunk and Elastic; and identity sources including Microsoft Entra ID, Okta and Google Workspace. Supported categories also cover vulnerability tools, cloud platforms, network products, email security and service-management systems.
Setup varies. Some products have workspace connection and test workflows. Microsoft Intune capabilities use the Microsoft connection. On-premises Active Directory, ThreatShield agents and sources such as pfSense use collectors. Other sources need assisted configuration. The integration directory identifies these distinctions so a product listing does not imply identical setup or coverage.
From a source to useful collection
First agree the product, environment and intended use: for example, identity evidence for an investigation or device inventory for a business review. Identify who owns the source and who can authorise the required credentials or consent.
Next configure the supported connection, check access and review the data made available by collection. A successful authentication test is only one part of that review. The team also needs to understand which records are present, how current they are and whether missing permissions, licensing or provider limits leave important questions unanswered.
Coverage and action permissions stay explicit
A connection provides the fields and capabilities supported by that source and the access granted to it. It does not establish that every endpoint, historical event or product feature is visible. Collection gaps need to remain visible in the investigation or report that depends on them.
Monitoring access is separate from authority to make changes or send notifications. Agree those workflows independently, including the relevant owners and approval boundaries. For a source outside the directory, ITS Consulting can discuss a bespoke connection around the available API or collection method; feasibility and scope must be established before delivery is promised.
Questions about Security integrations
Do we have to replace our existing security products?
The supported integration approach is designed to work with existing products. The directory and scoping discussion establish which sources can contribute to your required workflow.
Does a listed integration mean every product feature is supported?
No. API access, licensing, permissions and the implemented collection path determine the available evidence. Product registration is not a claim of complete feature coverage or vendor endorsement.
Can you connect an internal or specialised system?
A bespoke connection can be scoped when the system exposes a suitable API or collection method. Share the evidence you need and the interface available so the work and limitations can be assessed.
