SSO + lifecycle + risk events via System Log API
Microsoft Entra ID
Microsoft
DEEP APISign-in logs, conditional access, PIM via Graph
PingOne Risk + PingFederate audit ingest
Tenant log streams to Hayaiti SIEM
Authentication + admin logs via Admin API
Reports API + Alert Center webhook
1Password Business
1Password
SIEM INGESTEvents Reporting API for vault access
CrowdStrike Falcon
CrowdStrike
DEEP APIStreaming API + RTR for live containment
SentinelOne Singularity
SentinelOne
DEEP APIMgmt API + Storyline graph ingest
Microsoft Defender for Endpoint
Microsoft
DEEP APIDefender XDR Graph + advanced hunting
Palo Alto Cortex XDR
Palo Alto Networks
DEEP APICortex API + XQL queries
Central Admin API + tamper events
VMware Carbon Black
Broadcom
DEEP APILive Response + alert notification API
HEC ingest + bidirectional alert sync
Microsoft Sentinel
Microsoft
DEEP APINative KQL hunting + Logic App SOAR
Google Chronicle SecOps
Google
DEEP APIUnified Data Model + UDM search
Sumo Logic Cloud SIEM
Sumo Logic
SIEM INGESTSearch Job API + insight ingest
ECS-normalized indices + alert API
Detections-as-code + lookup tables
Lead correlation + auto-investigation
Findings ingest + EventBridge auto-remediation
Azure Defender for Cloud
Microsoft
DEEP APIARG queries + recommendation API
Google Security Command Ctr.
Google
DEEP APISCC findings + asset inventory
Issues API + GraphQL + push to Jira
Lacework FortiCNAPP
Fortinet
DEEP APICompliance + composite alerts
Side-scan inventory + risk scoring
Zero Trust audit + WAF events
Snowflake Horizon
Snowflake
SIEM INGESTAccount usage + access history
Microsoft Defender for O365
Microsoft
DEEP APIThreat Explorer + UAL ingest
Proofpoint TAP / TRAP
Proofpoint
DEEP APISIEM API + auto URL rewrite
Threat Intel feed + audit logs
Abnormal Security
Abnormal AI
DEEP APIBEC detection + auto-remediation
Material Security
Material
DEEP APIMailbox-level posture management
Tenable.io / Nessus
Tenable
DEEP APIAsset + vulnerability + ACR ingest
Scan results + risk scoring
Asset + KnowledgeBase + patch jobs
SAST + SCA + container findings
External attack surface + target tags
Unauthenticated asset discovery
SOC 2 + ISO + HIPAA evidence sync
Continuous control monitoring
Multi-framework evidence automation
Risk + vendor + privacy modules
SOX + IT audit issue sync
ITSM ticket + risk register
Palo Alto NGFW
Palo Alto Networks
DEEP APIPanorama + Cortex Data Lake
Fortinet FortiGate
Fortinet
SIEM INGESTFortiAnalyzer log forwarding
Cisco Secure Firewall
Cisco
SIEM INGESTFMC + Talos intel ingest
Check Point Quantum
Check Point
SIEM INGESTSmartEvent + IPS forwarding
Zscaler Internet Access
Zscaler
DEEP APIZIA + ZPA logs via NSS
Single-pass cloud + audit ingest