Alerts & investigations
Pull active findings, dig into an investigation, or summarize what happened on a shift.
Ask about alerts, investigations, audit logs, and configuration in plain language, and get answers grounded in your Exaforce data, without leaving the conversation.
Pull active findings, dig into an investigation, or summarize what happened on a shift.
Trace who accessed what, when, and from where across your cloud and SaaS estate.
Check policies, roles, and settings, like which Okta policies apply to a group.
In the Exaforce Console, open Edit User Profile, click Generate API Token, set an expiry and roles, then copy it.
Point Claude at your tenant's /mcp/ endpoint with your token in the X-EXF-API-TOKEN header, one entry in claude_desktop_config.json, or a single command in Claude Code.
Restart Claude Desktop (or reload your Claude Code session). The exabot_search tool appears automatically, ready to call.
Type your question in natural language. Claude routes it to Exabot Search and shows the synthesized answer inline, no special syntax required.
If your team already runs Exaforce, the connector turns any Claude session into a front door to your security data, no new dashboards to learn. Best for SOC analysts, detection & response engineers, and on-call responders who live in Claude and want answers grounded in their own environment.
Investigate straight from the terminal while you work. Ask in plain language, Claude calls exabot_search and returns grounded results.
SIEM query languages take months to learn and produce brittle queries that break when schemas change. Build powerful queries using natural language and/or simple dropdowns. Query Builder lets you combine behavioral events and configuration context (identity, permissions, SaaS settings, cloud resources, etc.) into a single query so you can correlate “what changed” with “what happened”.
The connector is a query path, not a copy. Claude sends your question to your Exaforce tenant; Exabot Search runs against your connected sources and returns a synthesized answer. Access is always scoped to your token's roles.
The connector is available to existing Exaforce customers. Reach our team for setup help or to enable it for your tenant.
Email support@exaforce.com