Integrations
Integrate with confidence
across 130+ trusted integrations, and secure your business at every stage with the Exaforce SOC platform.
Featured integrations
Amazon Web Services
Ingest AWS logs & configs for detections, investigations, and response
CrowdStrike
Triage CrowdStrike alerts and enrich with context
Google Cloud Platform
Ingest GCP logs & configs for detections, investigations, and response
Microsoft Entra ID
Ingest Entra ID identity events for detections, investigations, and response
1Password
Ingest 1Password identity and access logs for detections and investigations
Abnormal
Triage, investigate, and respond to Abnromal identified threats.
AbuseIPDB
Enrich detections with threat intelligence data from AbuseIPDB
Amazon GuardDuty
Triage GuardDuty alerts and enrich with context
Amazon Web Services
Ingest AWS logs & configs for detections, investigations, and response
Amplifier
Use Amplifier to route notifications.
Anthropic
Monitor Claude compliance activities to ensure responsible AI deployment and security
AppOmni
Ingest AppOmni SaaS security posture and activity events for detections and investigations
Apple Business Manager
Ingest Apple Business Manager device and account activity for detections and investigations
Asana
Ingest Asana audit logs and workspace activity for investigations
Atlassian Bitbucket
Ingest Bitbucket logs, code & configs for detections, investigations, and response
Atlassian Jira
Ingest Jira logs & configs for detections, investigations, and response
Auth0
Ingest Auth0 events for detections and investigations
Authentik
Ingest Authentik audit logs for detections and investigations
Automox
Endpoint patch management and vulnerability remediation from Automox.
Axonius
Ingest Axonius asset and activity logs for detections and investigations
Azure Cloud
Ingest Azure logs & configs for detections, investigations, and response
Azure Data Explorer
Query Azure Data Explorer event data on demand to add evidence to investigations
BambooHR
Enrich alerts with HR data from BambooHR
BeyondTrust EPM
Ingest BeyondTrust EPM privilege elevation events to add endpoint context to investigations
Beyondrust
Ingest BeyondTrust PAM alerts and session activity to detect privileged access abuse, credential misuse, and lateral movement.
Cato Networks
Monitor unified SASE events from Cato Networks for comprehensive cloud network and security visibility.
Censys
Enrich Exaforce investigations with Censys internet intelligence to identify attacker infrastructure, validate external IPs, and accelerate incident triage.
Cequence
Ingest Cequence API Security findings to triage and investigate bot events and API-layer threats.
CircleCI
Ingest CircleCI audit logs for detections and investigations
ClickHouse
Ingest ClickHouse audit logs and query activity for triage and investigations
Cloudflare
Ingest Cloudflare network events for detections and investigations
Code42 Incydr
Monitor Code42 Incydr file exfiltration events for detection, investigation, and response
Cohesity
Ingest Cohesity logs & configs for detections and investigations
Cortex XDR
Monitor Palo Alto Networks Cortex XDR security alerts, threat detections, and incident response activities.
CrowdStrike
Triage CrowdStrike alerts and enrich with context
Cursor
Ingest Cursor audit logs for detections and investigations
Custom Log Source
Ingest logs for detections and investigations from any source
Cyberhaven
Ingest Cyberhaven DLP and insider risk findings to triage and investigate data exfiltration and policy violation events.
Darktrace
Ingest, triage and contextualize Darktrace alerts
Databricks
Ingest Databricks logs & configs for detections and investigations
Digital Envoy
Enrich detections with threat intelligence data from Digital Envoy
Docusign
Ingest Docusign Connect logs for detections and investigations
Doppler
Ingest Doppler secrets access logs for detections and investigations
Elastic
Triage Elastic Security alerts and enrich with context
Envoy
Ingest Envoy HTTP logs for detections and investigations
Extrahop
Ingest ExtraHop NDR network detections to investigate and respond to threats
Fastly
Ingest Fastly access logs for detections and investigations
Fireblocks
Ingest Fireblocks crypto events for detections and investigations
Fleet
Monitor Fleet activities for administrative actions, enrollment changes, software installation events, and control plane activity.
FortiMail
Ingest FortiMail email security events to add message context to investigations
Fortinet
Triage and investigate Fortinet firewall alerts and logs with enrichment and contextual analysis.
Freshworks Freshservice
Ingest Freshworks Freshservice audit logs and user activity for detections, investigations and response
GitHub
Ingest GitHub logs, code & configs for detections, investigations, and response
GitHub Copilot
Monitor GitHub Copilot activities to ensure responsible AI deployment and security.
Gitlab
Ingest GitLab audit events and repository activity for detections and investigations
Google Cloud Platform
Ingest GCP logs & configs for detections, investigations, and response
Google Gmail Phishing
Triage Gmail phishing alerts and enrich with message context
Google SecOps
Triage Google SecOps alerts and enrich with context
Google Security Command Center
Triage Google SCC alerts and enrich with context
Google Workspace
Ingest Google Workspace activity for detections and investigations
HashiCorp Vault
Ingest HashiCorp Vault audit logs of secret access for detections and investigations
Have I Been Pwned
Threat feed of compromised emails from Have I Been Pwned.
Heroku
Ingest Heroku audit and runtime logs for detections and investigations
Hex
Ingest Hex audit logs from your data workspace for detections and investigations
Hornetsecurity
Ingest Hornetsecurity email threat alerts for triage and investigation
Hugging Face
Monitor Hugging Face organization activities, access, and API usage.
Ironscales
Ingest Ironscales email security and phishing events for detections and investigations
Island
Ingest Island enterprise browser activity logs for detections and investigations
Jamf
Monitor Jamf events, device activities, and security posture.
Jazz Security
Ingest Jazz Security findings and posture data for investigations
Jumpcloud
Ingest JumpCloud directory and device events for investigations
Kandji
Ingest, triage and expand context for Kandji detections and device information.
Keycloak
Ingest Keycloak user and admin audit events for detections and investigations
KnowBe4
Track KnowBe4 training compliance and phishing test results.
Linear
Get and create tickets in Linear.
Linux Syslog
Ingest Linux syslog events for detections, investigations, and triage
Material Security
Ingest Material Security email threat findings for triage and investigation
Microsoft Copilot
Ingest Microsoft Copilot logs & activity for detections and investigations
Microsoft Defender
Triage Defender alerts and enrich with endpoint context
Microsoft Defender for Cloud
Ingest Microsoft Defender for Cloud to contextualize and triage alerts.
Microsoft Defender for Identity
Ingest alerts from Microsoft Defender for Identity to contextualize and triage
Microsoft Entra ID
Ingest Entra ID identity events for detections, investigations, and response
Microsoft Entra ID Protection
Triage Entra ID Protection alerts and enrich with identity risk context
Microsoft Intune
Ingest Intune device compliance and policy data to investigate endpoints.
Microsoft Office365
Ingest Office365 activity for detections and investigations
Microsoft Sentinel
Ingest Sentinel detections and correlate with other telemetry
Microsoft SharePoint
Ingest SharePoint collaboration activity for detections and investigations
Microsoft Teams
Orchestrate response notifications and collaboration in Microsoft Teams
Mimecast
Triage Mimecast email security alerts and enrich with message context
Nightfall
Ingest Nightfall sensitive data alerts for triage and investigation
Notion
Ingest Notion audit logs for detections and investigations
Nozomi Networks
Ingest Nozomi Networks alerts from OT and IoT assets for triage and investigation
Odoo
Ingest Odoo audit logs and user activity for detections and investigations
Okta
Ingest Okta identity events for detections, investigations, and response
Okta ThreatInsights
Triage ThreatInsights alerts and enrich with authentication risk context
OneLogin
Ingest OneLogin SSO and identity events for detections and investigations
OpenAI
Monitor OpenAI usage events for detections and investigations
Ox Security
Read Ox Security application and pipeline findings during investigation
Palo Alto Networks NGFW
Triage and investigate Palo Alto Networks NGFW alerts and logs with enrichment and contextual analysis.
Perplexity
Enrich detections with Perplexity threat intelligence context
Ping Identity
Ingest Ping Identity events for detections, investigations, and response
Proofpoint
Triage, investigate, and respond to Proofpoint identified threats.
Qualys
Triage vulnerabilities and enrich alerts with context from Qualys.
Recorded Future
Enrich detections with adversary, IOC, and vulnerability intelligence from Recorded Future
Replit
Ingest Replit events and configs for detections and investigations
Rippling
Ingest Rippling events for investigations
Salesforce
Ingest Salesforce activity for detections and investigations
Secureworks Taegis
Ingest Secureworks Taegis detections and correlate with other telemetry
SentinelOne
Triage SentinelOne alerts and enrich with endpoint context
Seraphic
Ingest Seraphic browser security telemetry for detections and investigations
ServiceNow
Orchestrate response actions and ticketing automation in ServiceNow
Slack
Identify Slack threats, send notifications for response collaboration
Snowflake
Ingest Snowflake data access logs for detections and investigations
Sophos Central
Triage and respond to Sophos Central endpoint detections, enriched with context
Spamhaus
Enrich email detections with spam data from Spamhaus
Splunk
Ingest Splunk alerts and correlate detections for triage and investigation
SpyCloud
Ingest SpyCloud identity threat intelligence to investigate compromised credentials, stolen session cookies, and darknet exposures tied to active incidents.
Sublime Security
Triage Sublime email security alerts and enrich with message context
Sumo Logic
Ingest Sumo Logic alerts and correlate detections for triage and investigation
Sysdig
Ingest Sysdig Secure runtime threat alerts, security policy events, and cloud security findings for detection and response.
Tableau
Ingest Tableau logs & configs for detections and investigations
Tenable
Ingest Tenable vulnerability findings and scan data for detections and investigations
Tines
Orchestrate Tines automated response workflows
URLScan
Enrich detections with phishing and URL intelligence from URLScan
Upwind
Ingest Upwind findings for triage and investigation.
Vercel
Ingest Vercel events and configs for detections and investigations
VirusTotal
Enrich detections with malware and file reputation data from VirusTotal
Windows Event Log
Ingest Windows event logs for detections, investigations, and threat hunting
WithSecure
Ingest WithSecure Elements endpoint detections for triage and investigation
Wiz
Ingest Wiz findings for triage and investigation
Workday
Enrich alerts with HR data from Workday to enrich context
ZPA (Zscaler Private Access)
Ingest Zscaler Private Access connection and access logs for detections and investigations
Zoom
Orchestrate response notifications and collaboration in Zoom
Zscaler
Triage Zscaler alerts and enrich with context
incident.io
Orchestrate response workflows and post-incident tracking in incident.io
n8n
Ingest n8n workflow automation logs for detections and investigations
runZero
Read runZero asset inventory and exposure data during investigation
There are no matching integrations.
Can't find the integration you're looking for?
Tell us what you need. Coverage is driven by what customers actually run, and requests go straight to the team that builds them.





