1Password (Actions)
Run remediation actions on compromised 1Password users
Platform · Connectors
Hot-path data that detection depends on is ingested directly. High-volume data is queried where it already lives. Connect your first sources in under an hour.
Run remediation actions on compromised 1Password users
Detect suspicious activity in your 1Password account
Cloud email security telemetry from Abnormal AI
Reference Akeyless secrets in connectors and actions
Query AMP metrics with PromQL during investigations
Audit Claude activity across your Anthropic org
Asset alerts and activities from Armis Centrix
Detect identity attacks in Auth0 tenants
Sync Auth0 users, roles, and orgs into inventory
Detect prompt injection and abuse in AWS Bedrock
Detect attacks across your AWS environment
Pull tagged CloudWatch log groups from your AWS account
AWS identities, resources, cost savings, and efficiency
Ingest logs from your S3 bucket
Push logs from any pipeline into Artemis
Reference Secrets Manager secrets across Artemis
Inspector CVEs, CSPM controls, and product alerts
Detect and investigate using AWS Security Lake data
Publish case notifications to your AWS SNS topic
Send case notifications to your AWS SQS queue
Reference SSM parameters in connectors and actions
Federated asset enrichment during investigations
Detect attacks across your Azure subscriptions
Enrich detections with BambooHR employee data
Run AI Mode SQL queries against Google BigQuery
Trigger BlinkOps workflows from Artemis cases
Detect endpoint threats with Carbon Black Cloud
Federated read-only SQL queries against ClickHouse
Dispatch Cloudflare response actions from Artemis
Detect threats and config changes in Cloudflare
Detect web app attacks blocked by Cloudflare WAF
Detect threats across Cloudflare Zero Trust / WARP
Ingest Coralogix alert events for detection
Forward events from your Cribl pipeline to Artemis
Cloud posture and asset inventory from Falcon CSPM
Detect endpoint threats and hunt on Falcon Intelligence
Run remediation actions on CrowdStrike Falcon
Send cases to CrowdStrike and query NG-SIEM data
Connect a Model Context Protocol server to AI Mode
Ingest Cyberhaven DLP incidents and context
Federated IOC reputation lookups via Cyble Vision
Sync Dashlane members, devices, and password health
AI-powered threat hunting over Datadog logs
Dispatch DNSFilter response actions from Artemis cases
Sync DNSFilter sites, policies, and roaming clients
Ingest DNSFilter DNS query and threat-block logs via S3
Connect Artemis to data in Elasticsearch
Inbound mailing-list inbox routed to SOAR workflows
Receive case notifications by email
Send logs from any endpoint directly to Artemis
Ingest Flashpoint Ignite alerts for detection
NAC events and device visibility from Forescout
Email response through Perception Point and FortiMail
Detect threats in your Freshservice audit log
Detect attacks across your Google Cloud environment
Detect threats across your GitHub organization
Let Artemis read your repos during investigations
Detect threats across your GitLab instance
Read GitLab repos during AI Mode investigations
Ingest logs from your Cloud Storage buckets
Investigate using data in Google SecOps (Chronicle)
Detect threats across Google Workspace
Enrich detections with Google Workspace user context
Investigate using data in Grafana
Reference Vault secrets in connectors and SOAR actions
Send logs to Artemis from any HEC-compatible client
Ingest autonomous pentest results from NodeZero
Create incident.io incidents for security cases
Detect DNS threats blocked by Infoblox Threat Defense
Detect threats across your Apple device fleet
Audit user activity in the Island browser
Track device security and admin activity in Jamf Pro
Ingest Jamf Protect telemetry, unified logs, and Alerts
Create and manage Jira issues from cases and workflows
Sync Jira identities; query tickets in AI Mode
Detonate files and URLs in Joe Sandbox from workflows
Detect identity attacks in JumpCloud tenants
Federated query + ingest from on-prem LogRhythm SIEM
Detect threats in your Looker environment
Audit M365 Copilot, Copilot Studio, and Agent365
Run remediation actions on compromised M365 mailboxes
Detect threats across the Microsoft Defender suite
Enrich detections with Entra ID user and group context
Detect identity attacks in Microsoft Entra ID
Enrich detections with Intune device posture
Enrich detections with O365 user and group context
Detect attacks across Microsoft 365 email and apps
Federated content search via Purview eDiscovery
Investigate using data in Microsoft Sentinel
Receive Teams case alerts and EI digests
Admin audit and threat events from Mimecast
Stream Netskope SSE web, CASB, ZTNA & alert events
Ingest Nightfall AI DLP findings via Splunk HEC webhook
Send case alerts to any webhook endpoint
Detect threats in your Notion Enterprise workspace
SaaS threat alerts and activity from Obsidian
Run remediation actions on compromised Okta users
Enrich detections with Okta user and group context
Detect Okta identity attacks in real time
Audit logs, usage counters, and cost totals from OpenAI
OpenCTI lookups and threat Reports for applicable hunts
Send logs and metrics from any OTLP source to Artemis
Surface cloud security alerts from Orca Security
Investigate endpoint threats with Cortex XDR
Pull data and alerts from Palo Alto Cortex XSIAM
Create Cortex XSOAR incidents for security cases
Block malicious IPs on your Palo Alto firewall
Detect macOS endpoint threats with Phorion
Detect identity attacks across your PingOne tenant
Email threat telemetry from Proofpoint TAP
Enrich investigations with vulnerability context
Enrich investigations with Rapid7 vulnerability context
Ingest alerts and hunt with Recorded Future intel
Security alert records from Rootly
Salesforce login, EventLogFile, and audit ingest
Enrich investigations with employee travel and expenses
AI-driven federated log queries via Scanner.dev
Detect endpoint threats with SentinelOne
Ingest firewall and SIEM logs from SentinelOne
Create ServiceNow incidents for security cases
Ingest ServiceNow platform activity logs
Surface Artemis signals in your Slack workspace
Audit Slack auth, file, and admin activity
Connect Artemis to data in Snowflake and audit activity
Connect Artemis to data in Splunk
Federated IP-context lookups via Spur
Detect supply-chain attacks on CI/CD runners
Connect Artemis to data in Sumo Logic
Trigger Swimlane playbooks from Artemis cases
Forward syslog data directly to Artemis
Detect threats across your Tailscale network
Endpoint platform audit and Threat Response logs
Enrich investigations with vulnerability context
Ingest Thinkst Canary deception alerts
Federated threat-intel lookups via ThreatER
Trigger Tines workflows from Artemis cases
Trigger Torq workflows from Artemis cases
Securely store Torq Query Cases API credentials
Detect threats across your Twingate network
Query Uptycs endpoint telemetry on demand
Detect runtime threats and risks with Upwind
IP, domain, and URL reputation lookups via URLscan
Ingest Varonis SaaS data-security alerts
Forward logs from your Vector pipeline to Artemis
AppSec audit logs and vulnerability findings
IP and domain reputation lookups via VirusTotal
Send events to Artemis from any webhook source
Surface cloud issues and hunt on Wiz Threat Center
Detect risky Workato admin and config changes
Enrich detections with Workday employee data
Detect threats across your Zoom organization
Stream ZIA logs via Cloud NSS or a VM-based NSS feed
No connectors match your search.