Google Cloud VPC Flow Logs
Google Cloud Logging centralizes logs from Google Cloud products.
Fortinet FortiSOAR
To install the FortiSOAR integration, you first have to create an API Key in Sekoia.io XDR with specific permissions.
Windows
Microsoft Windows is a widely used operating system that has been developed by Microsoft since 1985.
Vectra Cognito Detect
Vectra provides AI-powered incident detection and resolution support for native and hybrid clouds.
Microsoft Always On VPN
This guide will explain how to forward Network Policy Server (NPS) logs to Sekoia.io.
STIX
STIX is a cybersecurity serialization format used to represent cyber threat intelligence, directed by the OASIS Cyber Threat Intelligence Technical Committee.
Sophos EDR
Sophos EDR monitors, detects and mitigates threats on endpoints.
Proofpoint PoD
ProofPoint On Demand (PoD) offers a real-time email processing feed to detect, classify and mitigate threats.
Proofpoint TAP
Proofpoint Targeted Attack Protection (TAP) helps detect, mitigate, and block advanced threats that target people through email.
Palo Alto NGFW
Palo Alto Networks offers an enterprise cybersecurity platform which provides network security, cloud security, endpoint protection, and various cloud-delivered security services.
Microsoft Intune
Microsoft Intune helps you protect your workforce's corporate data by managing devices and apps.
Skyhigh Secure Web Gateway / McAfee Web Gateway
Skyhigh Secure Web Gateway (SWG) (previously McAfee Web Gateway (MWG)) is a web gateway offering malware detection, threat prevention and reputation filtering.
Imperva WAF
Imperva Web Application Firewall helps you to protect your web applications and your APIs.
Hatching Triage
Triage is a malware analysis sandbox as a service, brought by Hatching.
Google Kubernetes Engine
Google Cloud Logging centralizes logs from Google Cloud products.
Cybereason EDR
Cybereason offers a set of Endpoint Detection and Response (EDR) solutions. Through the Cybereason platform, all suspicious operations will be gathered in MalOps, a multi-stage visualizations of device activities.
Cloudflare DNS logs
Cloudflare is a global network designed to make everything you connect to the Internet secure, private, fast, and reliable.
Cisco Umbrella IP
Cisco Umbrella offers flexible, cloud-delivered security.
Azure Database for MySQL
Azure Database for MySQL provides fully managed, enterprise-ready community MySQL database as a service.
AWS CloudTrail
AWS CloudTrail is a service that enables governance, compliance, and operational and risk auditing of your AWS account.
VMware vCenter
VMWare VCenter is a centralized management software.
Rubycat PROVE IT
PROVE IT by Rubycat is a privileged access management solution.
RSS playbooks
RSS Playbooks is a strategic framework used primarily by cybersecurity teams to automate and standardize their response to security threats.
Ivanti / Pulse Connect Secure
Pulse Connect Secure is an SSL VPN solution for remote and mobile users.
OpenSSH
As of now, the main solution to collect OpenSSH logs leverages the Rsyslog recipe.
Microsoft 365 / Office 365
Microsoft Office 365 is an online service, providing the Microsoft Office Products.
Infoblox DDI
Infoblox DNS, DHCP, and IP address management (DDI) enables customers to control and automate their network.
ISC DHCP
ISC DHCP offers a complete open-source solution for implementing DHCP servers.
IBM AIX
AIX (Advanced Interactive eXecutive) is a series of proprietary Unix operating systems developed and sold by IBM for several of its computer platforms.
HarfangLab EDR
HarfangLab is an Endpoint detection and response (EDR) solution certified by ANSSI since 2020.