Integrations

15 live
EDR Endpoint detection & response
CrowdStrike Falcon
EDR · Endpoint telemetry
Live
last run 5m ago24h runs 24
OAuth · device + detectionsConfigured
Microsoft Defender for Endpoint
EDR · Endpoint telemetry
Live
last run 9m ago24h runs 24
Graph API · alertsConfigured
SentinelOne
EDR · Endpoint telemetry
Live
last run 11m ago24h runs 24
API token · threatsConfigured
SIEM Log & event correlation
Splunk
SIEM · Search & correlation
Live
last run 1h ago24h runs 6
HEC · saved searchesConfigured
Microsoft Sentinel
SIEM · Cloud-native
Live
last run 1h ago24h runs 6
Log Analytics · KQLConfigured
Scanner Vulnerability assessment
Tenable.io
Scanner · Vuln management
Live
last run 2h ago24h runs 3
API keys · asset vulnsConfigured
Qualys VMDR
Scanner · Vuln management
Live
last run 6h ago24h runs 4
Basic auth · scan resultsConfigured
CSPM Cloud posture management
AWS Security Hub
CSPM · Cloud findings
Live
last run 6h ago24h runs 4
IAM role · ASFF findingsConfigured
Microsoft Secure Score
CSPM · M365 posture
Live
last run 1d ago24h runs 1
Graph API · control scoresConfigured
Identity IdP & access
Microsoft Entra ID
Identity · Directory & SSO
Live
last run 14m ago24h runs 24
Graph API · sign-ins, MFAConfigured
Okta
Identity · Directory & SSO
Live
last run 18m ago24h runs 24
SSWS token · system logConfigured
Patch Patch & configuration
Microsoft SCCM
Patch · Config Manager
Live
last run 1d ago24h runs 1
WMI · update complianceConfigured
Microsoft Intune
Patch · MDM compliance
Live
last run 1d ago24h runs 1
Graph API · device stateConfigured
Tanium
Patch · Endpoint management
Live
last run 1d ago24h runs 1
API token · patch statusConfigured
Feed Threat intelligence
CISA KEV
Feed · Known Exploited Vulns
Live
last run 31m ago24h runs 24
Public feed · no authConfigured

Data both ways

300+ REST API Inbound webhooks (HMAC) Outbound webhooks (signed) CSV export
New connectors take ~days to land — they ride the same shared integration framework, so adding a source is config, not a rebuild.