All Available Integrations
Data Collectors ⫘
- AWS Data Collector
- Azure Data Collector
- GCP Data Collector
- On-Premises Data Collector
- On-Premises HA Data Collector
- Applications
Endpoint Agents ⫘
- Sophos Endpoint Agent
- Taegis Endpoint Agent
- Introduction
- Beta Release Channel
- Groups
- Group Policies
- Host Isolation Exceptions
- Downloads
- Supported OS and System Recommendations
- Agent Technical Details
- Installation Info and Prerequisites
- Windows Installation
- macOS Installation
- Linux Installation
- Windows Troubleshooting
- macOS Troubleshooting
- Linux Troubleshooting
- Agent Uninstall
- FAQ
- Known Issues
- Changelog
- Taegis NGAV
- Red Cloak Endpoint Agent
- CrowdStrike
- Microsoft Defender for Endpoint
- SentinelOne
- VMWare Carbon Black
- VMware Carbon Black Cloud Endpoint Standard and Enterprise EDR
- VMWare Carbon Black Response Cloud
Custom Data Source Integrations ⫘
- Custom Transport Methods
- EDR OCSF Ingest
- Transport via Azure Event Hub
- Transport via File Upload API
- Transport via HTTP Ingest
- Transport via Secureworks-Managed S3
- Transport via Syslog
- Transport via Azure Storage Account
Optimized Data Source Integrations ⫘
AWS Integrations ⫘
- AWS Overview
- Amazon CloudWatch Logs
- Amazon GuardDuty
- AWS ALB Logs
- AWS CloudTrail
- AWS VPC Flow Logs
- AWS WAF Logs
- AWS S3 Event Archiving
AWS Supporting Documents ⫘
- Find Your AWS Account ID
- Test AWS Lambda Logs
- View AWS Lambda Logs
- Lambda Migration
- AWS Lambda Update
- AWS Lambda Trigger
- Multitenant CloudTrail Permissions
Azure Integrations ⫘
- Azure and O365 Overview
- Microsoft Entra Activity Reports
- Microsoft Azure Activity Log
- Microsoft Azure Application Gateway
- Microsoft Azure Event Hubs
- Microsoft Azure Firewall
- Flow Logs from Microsoft Azure Network Watcher
- Microsoft Azure Front Door
- Microsoft Azure Storage Account
Azure & Office 365 Supporting Documents ⫘
- Office 365 and Azure Data Availability
- Permissions Used by XDR for Microsoft 365 and Azure Integrations
GCP Integrations ⫘
OCI Integrations ⫘
Cloud Integrations ⫘
- Abnormal Inbound Email Security
- Akamai App and API Protector
- Akamai Enterprise Application Access (EAA)
- AlienVault OTX
- Anomali
- Cato Networks
- Cisco Duo
- Cisco Umbrella
- Cloudflare
- Google Workspace
- Configure HTTP Ingest
- Imperva Cloud
- Microsoft Entra Risk Detection
- Microsoft Graph Security Alerts
- Office 365 Management API
- Mimecast
- Netskope SSE
- Okta
- Palo Alto Prisma Access
- Proofpoint Targeted Attack Protection (TAP)
- S3 Ingest (Secureworks-Managed)
- Salesforce Real-Time Event Monitoring
- Snowflake (Preview)
- TAXII 2.1
Network Integrations ⫘
- Aruba ClearPass
- Barracuda NGFW
- Barracuda WAF
- Check Point
- Cisco ASA
- Cisco FTD Firewall
- Cisco IOS and NX-OS
- Cisco Ironport
- Cisco ISE
- Cisco Meraki
- Citrix ADC
- Claroty Continuous Threat Detection (CTD)
- Corelight
- CyberArk
- Darktrace
- Dragos Platform
- F5 ASM WAF
- F5 BIG-IP Local Traffic Manager
- Forcepoint Firewall
- Forcepoint Web Security
- Fortinet Fortigate
- Fortinet FortiWeb
- Imperva WAF
- Infoblox
- Juniper Pulse Secure
- Juniper SRX Firewall
- Lastline
- Nozomi Guardian
- OPNsense
- Palo Alto Firewall
- pfSense
- SCADAfence
- Skyhigh (McAfee/Trellix) Secure Web Gateway
- SonicWall Firewall
- Sophos XGS Firewall
- Suricata
- Symantec (Blue Coat) ProxySG
- Taegis NDR (Physical)
- Taegis NDR (Virtual)
- VMware vCenter
- WatchGuard Firewall
- Zscaler
Endpoint Integrations ⫘
- Linux Servers
- McAfee ePO
- Microsoft DHCP
- Microsoft DNS
- Microsoft IIS
- Microsoft Windows Event Log
- Symantec Endpoint Protection
- Trend Micro Deep Security