Third Party Integrations

  • SIEM: Syslog (UDP 514 / TLS) forwarding of all events, alerts, and analytics.

  • SOAR: REST API + webhook triggers for automated playbooks.

  • EDR/XDR: Correlation via API or syslog (endpoint context enrichment).

  • Sandboxes: Automatic file submission (extracted files → external sandbox).

  • Identity Solutions: AD/LDAP/Okta integration for user context.

  • Access Control: Dynamic blocking via firewall/NAC APIs based on threat verdicts.