Integrations
Ingest from your tools. Act on them too.
XenXDR connects the tools you already run. This is the current catalogue, with a clear status for each.
30
integrations available today
5
in the pipeline, UI ready
Integrations
Inputs
Push telemetry over a protocol the device already speaks.
- Elastic Beats (winlogbeat, filebeat)live
- Syslog (RFC 3164/5424)live
- CEFlive
- LEEFlive
- HTTP JSONlive
- Splunk HEClive
- Sysmonlive
- Microsoft Defender Antivirus eventslive
- Windows Event Loglive
- Linux journaldlive
- Linux auditdlive
- FortiGate (syslog)live
Integrations
Pull connectors
XenXDR pulls from the API and reports lag.
- Okta System Loglive
- Microsoft Entra ID / Microsoft 365live
- Fluence Account audit loglive
- AWS CloudTrailcoming soon
- CrowdStrike Falconcoming soon
- Microsoft Defender for Endpointcoming soon
- Google Workspacecoming soon
Integrations
Enrichment
Context for indicators during triage and at ingest.
- Indicator feeds (STIX/CSV)live
- VirusTotallive
- AbuseIPDBlive
Integrations
Response actions
What a playbook or an analyst can do in another system.
- Okta: disable user, revoke sessionslive
- Entra ID: disable userlive
- FortiGate: block IPlive
- Microsoft 365: quarantine maillive
- Defender for Endpoint: isolate devicecoming soon
Integrations
Notifications and egress
Where outcomes go.
- Webhook (HMAC-signed)live
- Slacklive
- Microsoft Teamslive
- Discordlive
- Email (SMTP)live
- Jiralive
- TheHivelive
- Upstream SIEM forwardlive
Missing something?
We add new sources quickly. Tell us what you run.
See XenXDR on your own telemetry.
A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.