1Password (Actions)
Run remediation actions on compromised 1Password users
Platform · Connectors
Hot-path data that detection depends on is ingested directly. High-volume data is queried where it already lives. Connect your first sources in under an hour.
Run remediation actions on compromised 1Password users
Reference 1Password items in connectors and actions
Detect suspicious activity in your 1Password account
File Detection 360 reports with Abnormal from workflows
Cloud email security telemetry from Abnormal AI
Check IP reputation against AbuseIPDB from workflows
Configurable ADP event ingest, HR data removed
Reference Akeyless secrets in connectors and actions
Query AMP metrics with PromQL during investigations
Audit Claude activity across your Anthropic org
Device inventory, alerts, and activities from Armis
Vulnerability report hunts and asset risk lookups
Detect identity attacks in Auth0 tenants
Sync Auth0 users, roles, and orgs into inventory
Query your S3 security data lake in place with Athena
Detect prompt injection and abuse in AWS Bedrock
Investigate GuardDuty, EC2, IAM; optional containment
Detect attacks across your AWS environment
Pull tagged CloudWatch log groups from your AWS account
AWS identities, resources, cost savings, and efficiency
Ingest logs from your S3 bucket
Push logs from any pipeline into Artemis
Write SOAR workflow outputs to your AWS S3 bucket
Reference Secrets Manager secrets across Artemis
Inspector CVEs, CSPM controls, and product alerts
Detect and investigate using AWS Security Lake data
Publish case notifications to your AWS SNS topic
Send case notifications to your AWS SQS queue
Reference SSM parameters in connectors and actions
Federated APL queries against your Axiom datasets
Federated asset enrichment during investigations
Detect attacks across your Azure subscriptions
Ingest logs from your Azure Blob Storage containers
Enrich detections with BambooHR employee data
Run AI Mode SQL queries against Google BigQuery
Trigger BlinkOps workflows from Artemis cases
Box audit trail and Shield threat detection alerts
Deliver raw logs into a retention-locked bucket you own
Run remediation actions on Carbon Black Cloud endpoints
Detect endpoint threats with Carbon Black Cloud
Block IPv4 addresses and domains
Stream Cato SASE firewall, threat, CASB & SDP events
Email security events from Check Point Harmony
Federated read-only SQL queries against ClickHouse
Dispatch Cloudflare response actions from Artemis
Detect Cloudflare config changes and web attacks
Detect threats across Cloudflare Zero Trust / WARP
Ingest Confluence pages for investigation context
Ingest Coralogix alert events for detection
Forward events from your Cribl pipeline to Artemis
Cloud posture and asset inventory from Falcon CSPM
Detect endpoint threats and hunt on Falcon Intelligence
Run remediation actions on CrowdStrike Falcon
Send cases to CrowdStrike and query NG-SIEM data
Cursor team and Origin audit logs
Read-only Origin repository access for AI Mode
Connect an MCP server to AI Mode and investigations
Ingest Cyberhaven DLP incidents and context
Dark-web exposure alerts and IOC reputation
Surface DSPM findings and DLP incidents from Cyera
Breach-and-attack-simulation assessment results
Raw Darktrace breaches and AI Analyst incidents
Team audit activity from Dashlane
Sync Dashlane members, devices, and password health
AI-powered threat hunting over Datadog logs
Dispatch DNSFilter response actions from Artemis cases
Sync DNSFilter sites, policies, and roaming clients
Ingest DNSFilter DNS query and threat-block logs via S3
Lookalike domains, phishing and impersonation alerts
Audit changes to the workplace that holds your secrets
Verify a person with a Duo MFA push from a workflow
MFA authentication events from the Duo Admin API
Enrich investigations with Egencia travel bookings
Connect Artemis to data in Elasticsearch
Inbound mailing-list inbox routed to SOAR workflows
Receive case notifications by email
Send logs from any endpoint directly to Artemis
Federated query + ingest from the Exabeam SIEM
Ingest client-side security findings from Feroot
Ingest Flashpoint Ignite alerts for detection
NAC events and device visibility from Forescout
Every query and command Formal proxied, and by whom
Email response through Perception Point and FortiMail
Detect threats in your Freshservice audit log
Detect attacks across your Google Cloud environment
GCP resources, IAM, billing, and savings
Store arbitrary encrypted (key, value) credentials
Detect threats across your GitHub organization
Let Artemis read your repos during investigations
Detect threats across your GitLab instance
Read GitLab repos during AI Mode investigations
Permission-aware Glean knowledge in AI Mode
Trigger SOAR workflows on inbound Gmail
Ingest logs from your Cloud Storage buckets
Gemini for Google Workspace usage audit logs
Investigate using data in Google SecOps (Chronicle)
Read a range from a Google Sheet in a workflow
Detect threats across Google Workspace
Enrich detections with Google Workspace user context
Investigate using data in Grafana
Monitor SaaS risk with Grip alerts and inventory
Detect ransomware activity with Halcyon alerts
Reference Vault secrets in connectors and SOAR actions
Send logs to Artemis from any HEC-compatible client
Ingest autonomous pentest results from NodeZero
Create incident.io incidents for security cases
Detect DNS threats blocked by Infoblox Threat Defense
Exposure findings, audit logs, and asset inventory
Detect threats across your Apple device fleet
Dispatch Island Enterprise Browser response actions
Audit user activity in the Island browser
Track device security and admin activity in Jamf Pro
Ingest Jamf Protect telemetry, unified logs, and Alerts
Create and manage Jira issues from cases and workflows
Sync Jira identities; query tickets in AI Mode
Detonate files and URLs in Joe Sandbox from workflows
Detect identity attacks in JumpCloud tenants
Security awareness and phishing simulation visibility
Look up directory records during investigations
Create Linear issues from cases and workflows
Federated query + ingest from on-prem LogRhythm SIEM
Detect threats in your Looker environment
Email threats, DLP, app protection and audit events
Audit M365 Copilot, Copilot Studio, and Agent365
Remediate mailboxes and triage reported phishing
Detect threats across the Microsoft Defender suite
Isolate hosts, collect evidence, update Defender alerts
Browser security events from Edge Reporting Connector
Enrich detections with Entra ID user and group context
Detect identity attacks in Microsoft Entra ID
Enrich detections with Intune device posture
Enrich detections with O365 user and group context
Detect attacks across Microsoft 365 email and apps
Federated content search via Purview eDiscovery
Investigate using data in Microsoft Sentinel
Receive Teams case alerts and EI digests
Case cards, answers, and workflows in Teams
Admin audit and threat events from Mimecast
Threat-intel attributes (IOCs) from a MISP instance
Call the monday.com API from a workflow
Run bounded read-only SQL against a MySQL database
Stream Netskope SSE web, CASB, ZTNA & alert events
Collect NetSuite audit and role-permitted ERP data
Nightfall DLP findings via API or HEC webhook
Send case alerts to any webhook endpoint
Detect threats in your Notion Enterprise workspace
OT/ICS alerts, vulnerabilities & session flows
Assets and vulnerability findings
SaaS threat alerts and activity from Obsidian
Run remediation actions on compromised Okta users
Enrich detections with Okta user and group context
Detect Okta identity attacks in real time
Audit logs, usage counters, and cost totals from OpenAI
OpenCTI lookups and threat Reports for applicable hunts
Send logs and metrics from any OTLP source to Artemis
Page an on-call rotation from workflows
Surface cloud security alerts from Orca Security
Trigger PagerDuty alerts for security cases
Investigate endpoint threats with Cortex XDR
Pull data and alerts from Palo Alto Cortex XSIAM
Create Cortex XSOAR incidents for security cases
GlobalProtect VPN logins and tunnels from PAN-OS
Block malicious IPs on your Palo Alto firewall
Detect macOS endpoint threats with Phorion
Detect identity attacks across your PingOne tenant
Email threat telemetry from Proofpoint TAP
PTR/TRAP and Cloud Threat Response incidents
Enrich investigations with vulnerability context
Enrich investigations with Rapid7 vulnerability context
Ingest alerts and hunt with Recorded Future intel
Employee directory sync from Rippling
Device inventory and MDM posture from Rippling
Security alert records from Rootly
Salesforce login, EventLogFile, and audit ingest
SAP BTP platform audit trail
Enrich investigations with employee travel and expenses
Device inventory and availability from Scalefusion
AI-driven federated log queries via Scanner.dev
Detect endpoint threats with SentinelOne
Run remediation actions on SentinelOne endpoints
Ingest firewall and SIEM logs from SentinelOne
Create ServiceNow incidents for security cases
Ingest ServiceNow platform activity logs
Admin and staff audit activity from Shopify
Surface Artemis signals in your Slack workspace
Audit Slack auth, file, and admin activity
Connect Artemis to data in Snowflake and audit activity
Connect Artemis to data in Splunk
Read SOAR containers, notes, and evidence in workflows
Federated IP-context lookups via Spur
Detect supply-chain attacks on CI/CD runners
Detect threats across your Stripe account
Connect Artemis to data in Sumo Logic
Trigger Swimlane playbooks from Artemis cases
Forward syslog data directly to Artemis
Detect threats across your Tailscale network
Endpoint platform audit and Threat Response logs
Enrich investigations with vulnerability context
Ingest Thinkst Canary deception alerts
Federated threat-intel lookups via ThreatER
Trigger Tines workflows from Artemis cases
Trigger Torq workflows from Artemis cases
Federated read-only SQL against Trino and Presto
Detect threats across your Twingate network
Query Uptycs endpoint telemetry on demand
Detect runtime threats and risks with Upwind
IP, domain, and URL reputation lookups via URLscan
Audit log and compliance test results from Vanta
Ingest Varonis SaaS data-security alerts
Forward logs from your Vector pipeline to Artemis
Raw Vectra detections, scoring, and audits
AppSec audit logs and vulnerability findings
Collect Veza administrative audit events
Sync identity-provider users and groups from Veza
IP and domain reputation lookups via VirusTotal
Scan URLs and files with VirusTotal from workflows
Send events to Artemis from any webhook source
Centralized Windows events via the on-prem agent
Surface cloud issues and hunt on Wiz Threat Center
Detect risky Workato admin and config changes
Enrich detections with Workday employee data
Detect identity threats in your WorkOS environment
Ingest ZeroFox external threat alerts for detection
Detect threats across your Zoom organization
Stream ZIA logs via Cloud NSS or a VM-based NSS feed
No connectors match your search.