Integrations

Ingest from your tools. Act on them too.

XenXDR connects the tools you already run. This is the current catalogue, with a clear status for each.

30
integrations available today
5
in the pipeline, UI ready

Integrations

Inputs

Push telemetry over a protocol the device already speaks.

  • Elastic Beats (winlogbeat, filebeat)live
  • Syslog (RFC 3164/5424)live
  • CEFlive
  • LEEFlive
  • HTTP JSONlive
  • Splunk HEClive
  • Sysmonlive
  • Microsoft Defender Antivirus eventslive
  • Windows Event Loglive
  • Linux journaldlive
  • Linux auditdlive
  • FortiGate (syslog)live

Integrations

Pull connectors

XenXDR pulls from the API and reports lag.

  • Okta System Loglive
  • Microsoft Entra ID / Microsoft 365live
  • Fluence Account audit loglive
  • AWS CloudTrailcoming soon
  • CrowdStrike Falconcoming soon
  • Microsoft Defender for Endpointcoming soon
  • Google Workspacecoming soon

Integrations

Enrichment

Context for indicators during triage and at ingest.

  • Indicator feeds (STIX/CSV)live
  • VirusTotallive
  • AbuseIPDBlive

Integrations

Response actions

What a playbook or an analyst can do in another system.

  • Okta: disable user, revoke sessionslive
  • Entra ID: disable userlive
  • FortiGate: block IPlive
  • Microsoft 365: quarantine maillive
  • Defender for Endpoint: isolate devicecoming soon

Integrations

Notifications and egress

Where outcomes go.

  • Webhook (HMAC-signed)live
  • Slacklive
  • Microsoft Teamslive
  • Discordlive
  • Email (SMTP)live
  • Jiralive
  • TheHivelive
  • Upstream SIEM forwardlive

Missing something?

We add new sources quickly. Tell us what you run.

Request a connector

See XenXDR on your own telemetry.

A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.