Integrations
Verified connections for the investigation record.
Connections use OAuth 2.0 or scoped API keys. Access is read-only unless a customer explicitly enables a response recommendation to be pushed to a source system.
Connection records
Source, direction, and cadence.
CrowdStrike Falcon
Live APIinbound event ingestion into the Evidence Index
near real-time webhook
Splunk Enterprise
Connectorinbound query-based record retrieval
on-demand or polling
Okta
Live APIinbound identity correlation into the Entity Map
hourly
ServiceNow
Connectorbidirectional Investigation Matter and ticket sync
real-time
Microsoft Sentinel
Live APIinbound incident signal into an Investigation Matter
real-time
Connections use OAuth 2.0 or scoped API keys. Access is read-only unless a customer explicitly enables a response recommendation to be pushed to a source system.
Missing a source?
Tell us which record you need collected.
Name the system and the records you need in the Evidence Index.
Request a connector
Tell us what you need to connect.
Contact sales
Tell us about your team and we'll route you to the right person.