Integrations
It has to fit the stack you already run.
Intelligence that cannot reach your tooling is intelligence nobody uses. These are the connections that exist today, with what each one is actually for.
Detection platforms
Ten consoles, each in its own language.
Detection content is generated in the target platform's query language, using the index and field names you configure, with a link that opens the query in your console.
SIEM
Elasticsearch / Kibana
KQLSplunk
SPLMicrosoft Sentinel
Sentinel KQLIBM QRadar
AQLGoogle Chronicle / SecOps
YARA-LEDR and XDR
CrowdStrike Falcon
FQLMicrosoft Defender for Endpoint
MDE KQLSentinelOne
S1QLVMware Carbon Black
CB QueryPalo Alto Cortex XDR
XQLCoverage is continuous on eight of the ten. Two are refreshed on a slower cycle for reasons outside our control, and we would rather state that here than have you find it during an evaluation.
Everything else
Identity, workflow and export.
Identity
- SAML / OIDC single sign-on
- Your identity provider governs who gets in
- Multi-factor authentication
- Time-based codes or email, enforced per organisation
- Role-based access
- Feature-level permissions, assigned by group
Workflow
- Ticketing
- Raise an incident in your service management tool from a finding
- Email and webhooks
- Route notifications into the channels your team already watches
Export
- STIX 2.1 over TAXII 2.1
- Indicators, malware, actors and vulnerabilities as standard objects
- CSV and Excel
- For the analysis that always ends up in a spreadsheet
- Scheduled reports
- Operations, executive and compliance reporting as documents
Not seeing yours?
Tell us what you run. Export formats are open, so most gaps are a question of where the data needs to land rather than whether it can get there.