Integrations

Verified connections for the investigation record.

Connections use OAuth 2.0 or scoped API keys. Access is read-only unless a customer explicitly enables a response recommendation to be pushed to a source system.

Connection records

Source, direction, and cadence.

CrowdStrike Falcon
Live API

inbound event ingestion into the Evidence Index

near real-time webhook
Splunk Enterprise
Connector

inbound query-based record retrieval

on-demand or polling
Okta
Live API

inbound identity correlation into the Entity Map

hourly
ServiceNow
Connector

bidirectional Investigation Matter and ticket sync

real-time
Microsoft Sentinel
Live API

inbound incident signal into an Investigation Matter

real-time

Connections use OAuth 2.0 or scoped API keys. Access is read-only unless a customer explicitly enables a response recommendation to be pushed to a source system.

Missing a source?

Tell us which record you need collected.

Name the system and the records you need in the Evidence Index.

Request a connector

Tell us what you need to connect.

Contact sales
Tell us about your team and we'll route you to the right person.
Your request is stored for team review.