One Identity Safeguard for Privileged Sessions (SPS)
One Identity Safeguard for Privileged Sessions (SPS) is a core module of the One Identity Safeguard suite that focuses on securing, monitoring, and auditing privileged access to critical systems.
Delinea Platform Audit Logs
Delinea Platform is a secure session-broker solution that lets organizations grant, monitor and audit elevated RDP, SSH and SFTP connections to critical systems.
Juniper Networks NGFW
Juniper Next-Generation Firewall (NGFW) services provide a set of cyber defenses that, together, reduce your attack surface.
Keycloak
Keycloak is an open-source identity and access management solution that enables Single Sign-On (SSO), social login and standard protocols like OAuth2, OpenID Connect and SAML.
New Relic playbooks
New Relic is a cloud-based observability platform delivering full-stack monitoring for applications, infrastructure, logs and metrics.
New Relic
New Relic is a cloud-native observability platform for real-time monitoring of applications, infrastructure, logs, and metrics.
Azure Activity Logs
Azure Activity Logs deliver a subscription-level audit trail of control-plane events including resource creations, modifications, deletions and service health incidents.
CyberArk Vault
CyberArk Vault is a secure digital repository designed to protect and manage sensitive information, particularly privileged account credentials and secrets.
Trellix Advanced Threat Defense
The Advanced Threat Defense Appliances are purpose-built, scalable, and flexible high-performance servers designed to analyze suspicious files for malware.
Forcepoint Management Server
The Management Server is the central component for system administration.
OpenCTI - Import external IoCs to Sekoia Defend
The OpenCTI Sekoia.io Intel Stream Connector allows organizations to automatically feed their Sekoia.io IOC collections with threat intelligence from OpenCTI.
Okta - Asset connector (Users)
Okta is a cloud-based identity and access management platform that provides secure authentication, authorization, and user management services.
AWS IAM - Asset connector (Users)
AWS Identity and Access Management (IAM) is a web service that helps you securely control access to AWS resources.
Nucleon EDR
Nucleon EDR is an Endpoint Detection & Response platform built on Zero-Trust principles and enhanced by AI-driven detection.
Forcepoint Next-Generation Firewall
Forcepoint Next-Generation Firewall provide advanced threat protection and network security, utilizing a blend of cloud and on-premises security solutions.
Netskope Log Streaming - Transaction Events
Netskope Log Streaming allows you to access all Netskope-generated logs directly within your preferred cloud storage and further SIEM tools without additional infrastructure.
Microsoft Entra ID - GraphAPI
Microsoft Entra ID (Graph API) is a cloud-based Identity and Rights management service developed and managed by Microsoft Corp.
Crowdstrike Falcon Discover - Asset connector (Devices)
CrowdStrike Falcon is an Endpoint Detection and Response solution.
Tenable Vulnerability Management - Asset connector (Vulnerabilities)
Tenable.io is a cloud-based exposure and vulnerability management platform that provides continuous visibility across on-prem, cloud, container, and web application assets.
Microsoft Entra ID - Asset connector (Users)
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service that provides secure authentication, authorization, and user management services.
AWS EC2 - Asset connector (Devices)
Amazon Elastic Compute Cloud (EC2) is a web service that provides secure, resizable compute capacity in the cloud.
Okta - Asset connector (Devices)
Okta is a cloud-based identity and access management platform that provides secure authentication, authorization, and device management services.
HarfangLab - Asset connector (Devices)
HarfangLab EDR is a European EDR for Windows, macOS, and Linux that delivers real-time telemetry, ATT&CK-mapped detections, and rapid response.
Qevlar AI
Qevlar AI is an Autonomous SOC Analyst platform designed to automate the heavy lifting of security investigations.
Broadcom SiteMinder
Siteminder generates access logs directly on the system.
TrendMicro Vision One playbooks
Trend Micro Vision One is a comprehensive XDR platform that integrates data from various sources, such as email, company intranet, workstations, servers, containerized and cloud environments.
Barracuda CloudGen Firewall
Barracuda NextGen Firewall is a unified network security appliance that combines stateful, application-aware firewalling with intrusion prevention, malware protection, web-filtering and full-mesh VPN/SD-WAN.
Bitdefender GravityZone - Playbook actions
Bitdefender is a global cybersecurity company renowned for its advanced antivirus software, providing comprehensive security solutions and threat intelligence.
Nozomi Central Management Console (CMC)
Nozomi Central Management Console is a centralized platform that streamlines the management of cybersecurity across industrial networks.
Nozomi Vantage
Nozomi Vantage is a comprehensive SaaS-based platform that delivers real-time visibility, threat detection, and incident response for industrial environments.