Platform · Connectors

200+ connectors across the stack you already run.

Hot-path data that detection depends on is ingested directly. High-volume data is queried where it already lives. Connect your first sources in under an hour.

1Password (Actions)

Run remediation actions on compromised 1Password users

1Password (Secrets)

Reference 1Password items in connectors and actions

1Password Audit Logs

Detect suspicious activity in your 1Password account

Abnormal Actions

File Detection 360 reports with Abnormal from workflows

Abnormal AI

Cloud email security telemetry from Abnormal AI

AbuseIPDB

Check IP reputation against AbuseIPDB from workflows

ADP

Configurable ADP event ingest, HR data removed

Akeyless

Reference Akeyless secrets in connectors and actions

Amazon Managed Service for Prometheus

Query AMP metrics with PromQL during investigations

Anthropic Claude Compliance

Audit Claude activity across your Anthropic org

Armis Centrix

Device inventory, alerts, and activities from Armis

Armis VIPR

Vulnerability report hunts and asset risk lookups

Auth0

Detect identity attacks in Auth0 tenants

Auth0 Directory Sync

Sync Auth0 users, roles, and orgs into inventory

AWS Athena

Query your S3 security data lake in place with Athena

AWS Bedrock Model Invocations

Detect prompt injection and abuse in AWS Bedrock

AWS Cloud Actions

Investigate GuardDuty, EC2, IAM; optional containment

AWS CloudTrail

Detect attacks across your AWS environment

AWS CloudWatch Logs (Pull)

Pull tagged CloudWatch log groups from your AWS account

AWS Environment & Cost Intelligence

AWS identities, resources, cost savings, and efficiency

AWS S3 Pull (From My Bucket)

Ingest logs from your S3 bucket

AWS S3 Push (To Artemis Bucket)

Push logs from any pipeline into Artemis

AWS S3 Writer

Write SOAR workflow outputs to your AWS S3 bucket

AWS Secrets Manager

Reference Secrets Manager secrets across Artemis

AWS Security Hub

Inspector CVEs, CSPM controls, and product alerts

AWS Security Lake

Detect and investigate using AWS Security Lake data

AWS SNS Sender

Publish case notifications to your AWS SNS topic

AWS SQS Sender

Send case notifications to your AWS SQS queue

AWS SSM Parameter Store

Reference SSM parameters in connectors and actions

Axiom

Federated APL queries against your Axiom datasets

Axonius

Federated asset enrichment during investigations

Azure Activity Logs

Detect attacks across your Azure subscriptions

Azure Blob Storage

Ingest logs from your Azure Blob Storage containers

BambooHR Directory Sync

Enrich detections with BambooHR employee data

BigQuery

Run AI Mode SQL queries against Google BigQuery

BlinkOps

Trigger BlinkOps workflows from Artemis cases

Box

Box audit trail and Shield threat detection alerts

Bucket Log Exporter

Deliver raw logs into a retention-locked bucket you own

Carbon Black Actions

Run remediation actions on Carbon Black Cloud endpoints

Carbon Black Cloud

Detect endpoint threats with Carbon Black Cloud

Cato Networks Response Actions

Block IPv4 addresses and domains

Cato Networks SASE

Stream Cato SASE firewall, threat, CASB & SDP events

Check Point Harmony Email & Collaboration

Email security events from Check Point Harmony

ClickHouse

Federated read-only SQL queries against ClickHouse

Cloudflare Actions

Dispatch Cloudflare response actions from Artemis

Cloudflare Logs

Detect Cloudflare config changes and web attacks

Cloudflare WARP / Zero Trust

Detect threats across Cloudflare Zero Trust / WARP

Confluence

Ingest Confluence pages for investigation context

Coralogix Events

Ingest Coralogix alert events for detection

Cribl Stream

Forward events from your Cribl pipeline to Artemis

CrowdStrike CSPM

Cloud posture and asset inventory from Falcon CSPM

CrowdStrike Falcon

Detect endpoint threats and hunt on Falcon Intelligence

CrowdStrike Falcon Actions

Run remediation actions on CrowdStrike Falcon

CrowdStrike NG-SIEM

Send cases to CrowdStrike and query NG-SIEM data

Cursor Audit Logs

Cursor team and Origin audit logs

Cursor Origin Repositories

Read-only Origin repository access for AI Mode

Custom MCP

Connect an MCP server to AI Mode and investigations

Cyberhaven

Ingest Cyberhaven DLP incidents and context

Cyble

Dark-web exposure alerts and IOC reputation

Cyera

Surface DSPM findings and DLP incidents from Cyera

Cymulate

Breach-and-attack-simulation assessment results

Darktrace

Raw Darktrace breaches and AI Analyst incidents

Dashlane Audit Logs

Team audit activity from Dashlane

Dashlane Directory Sync

Sync Dashlane members, devices, and password health

Datadog

AI-powered threat hunting over Datadog logs

DNSFilter Actions

Dispatch DNSFilter response actions from Artemis cases

DNSFilter Inventory Sync

Sync DNSFilter sites, policies, and roaming clients

DNSFilter Logs

Ingest DNSFilter DNS query and threat-block logs via S3

Doppel Alerts

Lookalike domains, phishing and impersonation alerts

Doppler Activity Logs

Audit changes to the workplace that holds your secrets

Duo Actions

Verify a person with a Duo MFA push from a workflow

Duo Authentication Logs

MFA authentication events from the Duo Admin API

Egencia Travel Sync

Enrich investigations with Egencia travel bookings

Elasticsearch

Connect Artemis to data in Elasticsearch

Email Listener

Inbound mailing-list inbox routed to SOAR workflows

Email Sender

Receive case notifications by email

Endpoint Log Receiver

Send logs from any endpoint directly to Artemis

Exabeam

Federated query + ingest from the Exabeam SIEM

Feroot Security

Ingest client-side security findings from Feroot

Flashpoint

Ingest Flashpoint Ignite alerts for detection

Forescout

NAC events and device visibility from Forescout

Formal Audit Logs

Every query and command Formal proxied, and by whom

FortiMail / Perception Point Response

Email response through Perception Point and FortiMail

Freshservice Audit Logs

Detect threats in your Freshservice audit log

GCP Cloud Audit Logs

Detect attacks across your Google Cloud environment

GCP Environment & Cost Intelligence

GCP resources, IAM, billing, and savings

Generic Secrets

Store arbitrary encrypted (key, value) credentials

GitHub Audit Logs

Detect threats across your GitHub organization

GitHub Repo Access

Let Artemis read your repos during investigations

GitLab Audit Events

Detect threats across your GitLab instance

GitLab Repo Access

Read GitLab repos during AI Mode investigations

Glean

Permission-aware Glean knowledge in AI Mode

Gmail Workspace

Trigger SOAR workflows on inbound Gmail

Google Cloud Storage

Ingest logs from your Cloud Storage buckets

Google Gemini Audit

Gemini for Google Workspace usage audit logs

Google SecOps

Investigate using data in Google SecOps (Chronicle)

Google Sheets

Read a range from a Google Sheet in a workflow

Google Workspace Activity

Detect threats across Google Workspace

Google Workspace Directory Sync

Enrich detections with Google Workspace user context

Grafana

Investigate using data in Grafana

Grip Security

Monitor SaaS risk with Grip alerts and inventory

Halcyon Anti-Ransomware

Detect ransomware activity with Halcyon alerts

HashiCorp Vault

Reference Vault secrets in connectors and SOAR actions

HEC Receiver

Send logs to Artemis from any HEC-compatible client

Horizon3 NodeZero

Ingest autonomous pentest results from NodeZero

incident.io

Create incident.io incidents for security cases

Infoblox Threat Defense

Detect DNS threats blocked by Infoblox Threat Defense

IONIX

Exposure findings, audit logs, and asset inventory

Iru

Detect threats across your Apple device fleet

Island Browser Actions

Dispatch Island Enterprise Browser response actions

Island Enterprise Browser

Audit user activity in the Island browser

Jamf Pro

Track device security and admin activity in Jamf Pro

Jamf Protect

Ingest Jamf Protect telemetry, unified logs, and Alerts

Jira (Ticketing & Actions)

Create and manage Jira issues from cases and workflows

Jira Directory Sync

Sync Jira identities; query tickets in AI Mode

Joe Sandbox (Actions)

Detonate files and URLs in Joe Sandbox from workflows

JumpCloud Events

Detect identity attacks in JumpCloud tenants

KnowBe4 KMSAT

Security awareness and phishing simulation visibility

LDAP / Active Directory

Look up directory records during investigations

Linear

Create Linear issues from cases and workflows

LogRhythm

Federated query + ingest from on-prem LogRhythm SIEM

Looker

Detect threats in your Looker environment

Material Security

Email threats, DLP, app protection and audit events

Microsoft 365 Copilot Audit

Audit M365 Copilot, Copilot Studio, and Agent365

Microsoft 365 Response Actions

Remediate mailboxes and triage reported phishing

Microsoft Defender XDR

Detect threats across the Microsoft Defender suite

Microsoft Defender XDR Response Actions

Isolate hosts, collect evidence, update Defender alerts

Microsoft Edge for Business

Browser security events from Edge Reporting Connector

Microsoft Entra Directory Sync

Enrich detections with Entra ID user and group context

Microsoft Entra ID

Detect identity attacks in Microsoft Entra ID

Microsoft Intune Inventory

Enrich detections with Intune device posture

Microsoft O365 Directory Sync

Enrich detections with O365 user and group context

Microsoft O365 Email and Audit Logs

Detect attacks across Microsoft 365 email and apps

Microsoft Purview

Federated content search via Purview eDiscovery

Microsoft Sentinel

Investigate using data in Microsoft Sentinel

Microsoft Teams

Receive Teams case alerts and EI digests

Microsoft Teams Bot

Case cards, answers, and workflows in Teams

Mimecast

Admin audit and threat events from Mimecast

MISP Threat Intelligence

Threat-intel attributes (IOCs) from a MISP instance

monday.com

Call the monday.com API from a workflow

MySQL

Run bounded read-only SQL against a MySQL database

Netskope SSE

Stream Netskope SSE web, CASB, ZTNA & alert events

NetSuite

Collect NetSuite audit and role-permitted ERP data

Nightfall AI Sensitive Data Protection

Nightfall DLP findings via API or HEC webhook

Notifications Webhook

Send case alerts to any webhook endpoint

Notion Audit Logs

Detect threats in your Notion Enterprise workspace

Nozomi Vantage

OT/ICS alerts, vulnerabilities & session flows

Nucleus

Assets and vulnerability findings

Obsidian Security

SaaS threat alerts and activity from Obsidian

Okta (Actions)

Run remediation actions on compromised Okta users

Okta Directory Sync

Enrich detections with Okta user and group context

Okta EventBridge

Detect Okta identity attacks in real time

OpenAI Platform

Audit logs, usage counters, and cost totals from OpenAI

OpenCTI

OpenCTI lookups and threat Reports for applicable hunts

OpenTelemetry (OTLP)

Send logs and metrics from any OTLP source to Artemis

Opsgenie

Page an on-call rotation from workflows

Orca Security

Surface cloud security alerts from Orca Security

PagerDuty

Trigger PagerDuty alerts for security cases

Palo Alto Cortex XDR

Investigate endpoint threats with Cortex XDR

Palo Alto Cortex XSIAM

Pull data and alerts from Palo Alto Cortex XSIAM

Palo Alto Cortex XSOAR

Create Cortex XSOAR incidents for security cases

Palo Alto Networks GlobalProtect VPN

GlobalProtect VPN logins and tunnels from PAN-OS

Palo Alto Networks NGFW

Block malicious IPs on your Palo Alto firewall

Phorion

Detect macOS endpoint threats with Phorion

PingOne Identity

Detect identity attacks across your PingOne tenant

Proofpoint TAP

Email threat telemetry from Proofpoint TAP

Proofpoint Threat Response (TRAP / Cloud)

PTR/TRAP and Cloud Threat Response incidents

Qualys VMDR

Enrich investigations with vulnerability context

Rapid7 InsightVM

Enrich investigations with Rapid7 vulnerability context

Recorded Future

Ingest alerts and hunt with Recorded Future intel

Rippling Directory Sync

Employee directory sync from Rippling

Rippling MDM Inventory

Device inventory and MDM posture from Rippling

Rootly Alerts

Security alert records from Rootly

Salesforce

Salesforce login, EventLogFile, and audit ingest

SAP BTP Audit Logs

SAP BTP platform audit trail

SAP Concur

Enrich investigations with employee travel and expenses

Scalefusion MDM

Device inventory and availability from Scalefusion

Scanner.dev

AI-driven federated log queries via Scanner.dev

SentinelOne

Detect endpoint threats with SentinelOne

SentinelOne Actions

Run remediation actions on SentinelOne endpoints

SentinelOne AI SIEM

Ingest firewall and SIEM logs from SentinelOne

ServiceNow ITSM Notifications

Create ServiceNow incidents for security cases

ServiceNow Logs

Ingest ServiceNow platform activity logs

Shopify Audit Logs

Admin and staff audit activity from Shopify

Slack

Surface Artemis signals in your Slack workspace

Slack Audit Logs

Audit Slack auth, file, and admin activity

Snowflake

Connect Artemis to data in Snowflake and audit activity

Splunk

Connect Artemis to data in Splunk

Splunk SOAR Actions

Read SOAR containers, notes, and evidence in workflows

Spur

Federated IP-context lookups via Spur

StepSecurity

Detect supply-chain attacks on CI/CD runners

Stripe

Detect threats across your Stripe account

Sumo Logic

Connect Artemis to data in Sumo Logic

Swimlane

Trigger Swimlane playbooks from Artemis cases

Syslog

Forward syslog data directly to Artemis

Tailscale

Detect threats across your Tailscale network

Tanium

Endpoint platform audit and Threat Response logs

Tenable

Enrich investigations with vulnerability context

Thinkst Canary

Ingest Thinkst Canary deception alerts

ThreatER

Federated threat-intel lookups via ThreatER

Tines

Trigger Tines workflows from Artemis cases

Torq

Trigger Torq workflows from Artemis cases

Trino

Federated read-only SQL against Trino and Presto

Twingate

Detect threats across your Twingate network

Uptycs

Query Uptycs endpoint telemetry on demand

Upwind

Detect runtime threats and risks with Upwind

URLscan

IP, domain, and URL reputation lookups via URLscan

Vanta

Audit log and compliance test results from Vanta

Varonis

Ingest Varonis SaaS data-security alerts

Vector AWS S3 Sink

Forward logs from your Vector pipeline to Artemis

Vectra AI

Raw Vectra detections, scoring, and audits

Veracode

AppSec audit logs and vulnerability findings

Veza Audit Logs

Collect Veza administrative audit events

Veza Directory Sync

Sync identity-provider users and groups from Veza

VirusTotal

IP and domain reputation lookups via VirusTotal

VirusTotal (Actions)

Scan URLs and files with VirusTotal from workflows

Webhook Receiver

Send events to Artemis from any webhook source

Windows Event Collector

Centralized Windows events via the on-prem agent

Wiz

Surface cloud issues and hunt on Wiz Threat Center

Workato Audit Logs

Detect risky Workato admin and config changes

Workday Directory Sync

Enrich detections with Workday employee data

WorkOS Audit Logs

Detect identity threats in your WorkOS environment

ZeroFox

Ingest ZeroFox external threat alerts for detection

Zoom

Detect threats across your Zoom organization

Zscaler Internet Access

Stream ZIA logs via Cloud NSS or a VM-based NSS feed