Integrations
Connect your stack in minutes.
AiSOC ships with 78 first-party integrations across SIEM, endpoint, cloud, identity, network, and SaaS. Connect a source with a key or OAuth, and autonomous triage starts reasoning over your data. No agents to deploy.
SIEM & log analytics
17 integrationsPull notable events and run federated search across your logging stack.
Cortex XSIAM
Datadog (Logs + APM)
Datadog Cloud SIEM
Devo
Elastic SIEM
Elastic Security via the ES|QL search API. Federated-search ready.
Exabeam
Falco
Google Chronicle
IBM QRadar
Microsoft Sentinel
Microsoft Sentinel incidents via the Azure Security Insights REST API.
Rapid7 InsightIDR
Securonix
Splunk SIEM
Splunk Enterprise / Cloud notable events via the REST API.
Sumo Logic Cloud SIEM
Sysdig Secure
Trellix Helix
Wazuh
Endpoint & XDR
10 integrationsDetections plus response actions like host isolation on the endpoint.
Cortex XDR
Palo Alto Cortex XDR incidents via the public REST API.
CrowdStrike Falcon
CrowdStrike Falcon detections via the Falcon REST API.
FleetDM
Linux Auditd
Microsoft Defender
osctrl
SentinelOne
SentinelOne threat detections via the Management Console API.
Trend Vision One
VMware Carbon Black Cloud
Windows Event / Sysmon
Cloud security
14 integrationsFindings and audit trails across AWS, Azure, GCP, and OCI.
AWS CloudTrail
AWS GuardDuty
AWS Security Hub
AWS Security Hub findings (GuardDuty, Inspector, Macie, third-party).
AWS VPC Flow Logs
Azure Activity Logs
GCP Cloud Audit Logs
GCP Security Command Center
Kubernetes Audit Logs
Lacework
Oracle Cloud Infrastructure
Orca Security
Prisma Cloud
Tenable.io
Wiz
Wiz cloud security issues via the GraphQL API.
Identity & access
6 integrationsSign-in, MFA, and directory signal to catch identity-driven attacks.
1Password Events
1Password sign-in attempts via the Events Reporting API.
Auth0
Duo Security
Duo Security authentication logs via the Admin API (HMAC-SHA1 signed).
HashiCorp Vault Audit
Microsoft Entra ID
Okta Identity
Okta system log events (auth, MFA, account locks, blocked requests).
Network security
6 integrationsProxy, firewall, DNS, and zero-trust telemetry.
Cisco Umbrella
Cloudflare WAF + Zero Trust
Netskope
Syslog / CEF
Tailscale
Zscaler Internet Access
Zscaler Internet Access web security logs via the ZIA API.
Network detection
1 integrationsFlow and packet-based detection for east-west traffic.
Zeek / Suricata NDR
SaaS & productivity
21 integrationsAudit logs from the applications your business runs on.
Abnormal Security
AI / LLM Usage Audit
Box
Cloudflare
Confluence Audit
Dropbox Business
Email Inbox (IMAP)
Google Workspace
Jira
Jira Cloud issues via the REST API v3.
Microsoft 365 Audit
Mimecast
Opsgenie
PagerDuty
Proofpoint TAP
Proofpoint Targeted Attack Protection — blocked messages via the SIEM API.
Salesforce
ServiceNow
ServiceNow incidents via the Table API.
Slack Audit Logs
Snowflake Audit
Sublime Security
Tines
Torq
Code & DevOps
3 integrationsSecurity signal from your source code and software supply chain.
GitHub
GitLab
Snyk
Snyk vulnerability issues via the REST API.
Universal capture
Do not see your tool? Push anything.
Every workspace gets a private, rotatable inbox URL. Point any vendor webhook or log forwarder at it and AiSOC normalizes the payload into the same pipeline as a native connector. No custom code.
Generic JSON
Forward any JSON payload; best-effort field mapping.
Syslog / CEF
ArcSight Common Event Format over HTTPS.
Splunk HEC-compatible
Re-target anything already pointed at Splunk HEC.
AWS SNS / EventBridge
Subscribe an HTTPS endpoint or API destination.
PagerDuty / Opsgenie
Point the existing alert webhook at AiSOC.
Forwarded email
Inbound alert digests via SES or Mailgun routing.
Connect a source, see a verdict
Start free and wire up your first integration in minutes, or book a walkthrough with our team.