Connect the stack you already own.
Connectors bring posture and evidence in. Slack and Microsoft Teams integrations post platform events out to where your team works.
Your security tools
Connectors
Scheduled collection
cursors, retry, run history
Rules
authorable, versioned
Control result and evidence
with provenance
Posture and report
board, manager, regulator
Your security tools feed a scheduled collection. Rules turn what was collected into a control result and an evidence item carrying its provenance. That result drives the posture dashboard and the reports read from it.
Continuous control monitoring connectors
These bring posture and evidence in. They run inside the platform, and each connection can reach only the hosts allowed for it.
Identity
Active Directory / Entra ID (LDAP)
In cataloguead-entra
Directory accounts, group membership and stale-account state.
Microsoft Entra ID (Graph)
In catalogueentra.graph.v1
Conditional access policies, MFA registration and privileged role assignment.
Okta
In catalogueokta.v1
Sign-on policies, factor enrolment and application assignment.
Ping Identity
In catalogueping.v1
Authentication policies and user population state.
Cloud security posture
Microsoft Defender for Cloud
In catalogueazure.defender-cloud.v1
Secure score, regulatory compliance state and resource recommendations.
Wiz
In cataloguewiz.v1
Cloud configuration issues, toxic combinations and exposure findings.
Prisma Cloud
In catalogueprisma-cloud.v1
Policy violations and compliance posture across cloud accounts.
Check Point CloudGuard
In cataloguecheckpoint.cloudguard.v1
Cloud posture rulesets and configuration drift.
Vulnerability management
Tenable.io
In cataloguetenable.io.v1
Scan results, asset vulnerability state and remediation age.
Qualys VMDR
In cataloguequalys.vmdr.v1
Detections by severity, asset coverage and patch currency.
Rapid7 InsightVM
In cataloguerapid7.insightvm.v1
Vulnerability findings and remediation SLA state.
Microsoft Defender Vulnerability Management
In cataloguedefender.vm.v1
Device weaknesses, exposure score and recommended actions.
Greenbone
In cataloguegreenbone.v1
Open-source scan results and host findings.
Acunetix (DAST)
In catalogueacunetix.v1
Web application scan findings by severity.
SIEM and detection
Microsoft Sentinel
In catalogueazure.sentinel.v1
Analytics rule coverage, incident volume and data connector health.
Splunk
In cataloguesplunk.v1
Saved search results, index coverage and detection state.
IBM QRadar
In catalogueqradar.v1
Offence counts, rule state and log source health.
Elastic Security
In catalogueelastic.security.v1
Detection rule status and alert volume.
LogRhythm
In cataloguelogrhythm.v1
Alarm state and log source coverage.
Exabeam
In catalogueexabeam.v1
Analytics coverage and case state.
Cortex XSIAM
In cataloguecortex.xsiam.v1
Incident state and detection coverage.
Endpoint and EDR
CrowdStrike
In cataloguecrowdstrike.falcon.v1
Sensor coverage, host health and detection state.
SentinelOne
In cataloguesentinelone.v1
Agent deployment, policy state and threat detections.
Code and AppSec
Snyk
In cataloguesnyk.v1
Dependency, container and IaC findings by project.
SonarQube
In cataloguesonarqube.v1
Quality gate state and security hotspot counts.
GitHub Advanced Security
In cataloguegithub.advanced-security.v1
Code scanning alerts, secret scanning and Dependabot state.
ITSM
ServiceNow ITSM
In catalogueservicenow.itsm.v1
Change and incident records used as control evidence.
Jira Service Management
In cataloguejira.sm.v1
Request and change workflow state.
ManageEngine ServiceDesk Plus
In cataloguemanageengine.sdp.v1
Ticket and change approval records.
Freshservice
In cataloguefreshservice.v1
Change records and approval trails.
Key management
Azure Key Vault
In catalogueazure.keyvault.v1
Key rotation age, expiry and access policy state.
AWS KMS
In catalogueaws.kms.v1
Key rotation state, grants and key policy configuration.
HashiCorp Vault
In cataloguehashicorp.vault.v1
Secret engine configuration and lease state.
Thales CipherTrust
In cataloguethales.ciphertrust.v1
Key lifecycle state and policy configuration.
Workflow integrations
These post events to the tools your team works in. Slack and Microsoft Teams are available today; Jira, ServiceNow, Microsoft 365 and Google Workspace are planned.
Slack
Platform events, such as incident alerts, posted to a channel you choose.
AvailableMicrosoft Teams
Platform events, such as incident alerts, posted to a channel you choose.
AvailableJira
Treatment milestones and findings as tracked issues.
PlannedServiceNow
Findings and remediation tasks into your existing queues.
PlannedMicrosoft 365
Calendar items for reviews and mail through your own tenant.
PlannedGoogle Workspace
Calendar items for reviews and mail through your own domain.
Planned
Build your own
Generic REST connector
Any JSON endpoint you can reach, mapped by a rule you write and version yourself.
Inbound webhook
For tools that push rather than wait to be polled. The result enters the same control result model.
Outbound webhook subscriptions
Push results and events to subscribed systems, with a delivery log you can inspect.
API tokens
A REST API with tenant-scoped tokens, for anything a connector does not cover.
OData v4 feed
A live, token-authenticated feed that Power BI or any BI tool reads directly.
A note for air-gapped sites
In an air-gapped installation, connectors run inside the platform on your network and each connection can reach only the internal hosts on its allowlist, so continuous control monitoring works without internet access. Secrets are encrypted and stored per tenant.
About this catalogue
Every connector listed here has a driver in the platform. Confirm the connectors your programme relies on during scoping. Product names are trademarks of their owners, used for identification only, and imply no partnership, certification or endorsement.
See monitoring running on your own tools.
Bring the list of what you run and we will go through it connector by connector.