Platform · Connectors

150+ connectors across the stack you already run.

Hot-path data that detection depends on is ingested directly. High-volume data is queried where it already lives. Connect your first sources in under an hour.

1Password (Actions)

Run remediation actions on compromised 1Password users

1Password Audit Logs

Detect suspicious activity in your 1Password account

Abnormal AI

Cloud email security telemetry from Abnormal AI

Akeyless

Reference Akeyless secrets in connectors and actions

Amazon Managed Service for Prometheus

Query AMP metrics with PromQL during investigations

Anthropic Claude Compliance

Audit Claude activity across your Anthropic org

Armis Centrix

Asset alerts and activities from Armis Centrix

Auth0

Detect identity attacks in Auth0 tenants

Auth0 Directory Sync

Sync Auth0 users, roles, and orgs into inventory

AWS Bedrock Model Invocations

Detect prompt injection and abuse in AWS Bedrock

AWS CloudTrail

Detect attacks across your AWS environment

AWS CloudWatch Logs (Pull)

Pull tagged CloudWatch log groups from your AWS account

AWS Environment & Cost Intelligence

AWS identities, resources, cost savings, and efficiency

AWS S3 Pull (From My Bucket)

Ingest logs from your S3 bucket

AWS S3 Push (To Artemis Bucket)

Push logs from any pipeline into Artemis

AWS Secrets Manager

Reference Secrets Manager secrets across Artemis

AWS Security Hub

Inspector CVEs, CSPM controls, and product alerts

AWS Security Lake

Detect and investigate using AWS Security Lake data

AWS SNS Sender

Publish case notifications to your AWS SNS topic

AWS SQS Sender

Send case notifications to your AWS SQS queue

AWS SSM Parameter Store

Reference SSM parameters in connectors and actions

Axonius

Federated asset enrichment during investigations

Azure Activity Logs

Detect attacks across your Azure subscriptions

BambooHR Directory Sync

Enrich detections with BambooHR employee data

BigQuery

Run AI Mode SQL queries against Google BigQuery

BlinkOps

Trigger BlinkOps workflows from Artemis cases

Carbon Black Cloud

Detect endpoint threats with Carbon Black Cloud

ClickHouse

Federated read-only SQL queries against ClickHouse

Cloudflare Actions

Dispatch Cloudflare response actions from Artemis

Cloudflare Audit Logs

Detect threats and config changes in Cloudflare

Cloudflare WAF

Detect web app attacks blocked by Cloudflare WAF

Cloudflare WARP / Zero Trust

Detect threats across Cloudflare Zero Trust / WARP

Coralogix Events

Ingest Coralogix alert events for detection

Cribl Stream

Forward events from your Cribl pipeline to Artemis

CrowdStrike CSPM

Cloud posture and asset inventory from Falcon CSPM

CrowdStrike Falcon

Detect endpoint threats and hunt on Falcon Intelligence

CrowdStrike Falcon Actions

Run remediation actions on CrowdStrike Falcon

CrowdStrike NG-SIEM

Send cases to CrowdStrike and query NG-SIEM data

Custom MCP

Connect a Model Context Protocol server to AI Mode

Cyberhaven

Ingest Cyberhaven DLP incidents and context

Cyble

Federated IOC reputation lookups via Cyble Vision

Dashlane Directory Sync

Sync Dashlane members, devices, and password health

Datadog

AI-powered threat hunting over Datadog logs

DNSFilter Actions

Dispatch DNSFilter response actions from Artemis cases

DNSFilter Inventory Sync

Sync DNSFilter sites, policies, and roaming clients

DNSFilter Logs

Ingest DNSFilter DNS query and threat-block logs via S3

Elasticsearch

Connect Artemis to data in Elasticsearch

Email Listener

Inbound mailing-list inbox routed to SOAR workflows

Email Sender

Receive case notifications by email

Endpoint Log Receiver

Send logs from any endpoint directly to Artemis

Flashpoint

Ingest Flashpoint Ignite alerts for detection

Forescout

NAC events and device visibility from Forescout

FortiMail / Perception Point Response

Email response through Perception Point and FortiMail

Freshservice Audit Logs

Detect threats in your Freshservice audit log

GCP Cloud Audit Logs

Detect attacks across your Google Cloud environment

GitHub Audit Logs

Detect threats across your GitHub organization

GitHub Repo Access

Let Artemis read your repos during investigations

GitLab Audit Events

Detect threats across your GitLab instance

GitLab Repo Access

Read GitLab repos during AI Mode investigations

Google Cloud Storage

Ingest logs from your Cloud Storage buckets

Google SecOps

Investigate using data in Google SecOps (Chronicle)

Google Workspace Activity

Detect threats across Google Workspace

Google Workspace Directory Sync

Enrich detections with Google Workspace user context

Grafana

Investigate using data in Grafana

HashiCorp Vault

Reference Vault secrets in connectors and SOAR actions

HEC Receiver

Send logs to Artemis from any HEC-compatible client

Horizon3 NodeZero

Ingest autonomous pentest results from NodeZero

incident.io

Create incident.io incidents for security cases

Infoblox Threat Defense

Detect DNS threats blocked by Infoblox Threat Defense

Iru

Detect threats across your Apple device fleet

Island Enterprise Browser

Audit user activity in the Island browser

Jamf Pro

Track device security and admin activity in Jamf Pro

Jamf Protect

Ingest Jamf Protect telemetry, unified logs, and Alerts

Jira (Ticketing & Actions)

Create and manage Jira issues from cases and workflows

Jira Directory Sync

Sync Jira identities; query tickets in AI Mode

Joe Sandbox (Actions)

Detonate files and URLs in Joe Sandbox from workflows

JumpCloud Events

Detect identity attacks in JumpCloud tenants

LogRhythm

Federated query + ingest from on-prem LogRhythm SIEM

Looker

Detect threats in your Looker environment

Microsoft 365 Copilot Audit

Audit M365 Copilot, Copilot Studio, and Agent365

Microsoft 365 Remediation Actions

Run remediation actions on compromised M365 mailboxes

Microsoft Defender XDR

Detect threats across the Microsoft Defender suite

Microsoft Entra Directory Sync

Enrich detections with Entra ID user and group context

Microsoft Entra ID

Detect identity attacks in Microsoft Entra ID

Microsoft Intune Inventory

Enrich detections with Intune device posture

Microsoft O365 Directory Sync

Enrich detections with O365 user and group context

Microsoft O365 Email and Audit Logs

Detect attacks across Microsoft 365 email and apps

Microsoft Purview

Federated content search via Purview eDiscovery

Microsoft Sentinel

Investigate using data in Microsoft Sentinel

Microsoft Teams

Receive Teams case alerts and EI digests

Mimecast

Admin audit and threat events from Mimecast

Netskope SSE

Stream Netskope SSE web, CASB, ZTNA & alert events

Nightfall AI — Sensitive Data Protection

Ingest Nightfall AI DLP findings via Splunk HEC webhook

Notifications Webhook

Send case alerts to any webhook endpoint

Notion Audit Logs

Detect threats in your Notion Enterprise workspace

Obsidian Security

SaaS threat alerts and activity from Obsidian

Okta (Actions)

Run remediation actions on compromised Okta users

Okta Directory Sync

Enrich detections with Okta user and group context

Okta EventBridge

Detect Okta identity attacks in real time

OpenAI Platform

Audit logs, usage counters, and cost totals from OpenAI

OpenCTI

OpenCTI lookups and threat Reports for applicable hunts

OpenTelemetry (OTLP)

Send logs and metrics from any OTLP source to Artemis

Orca Security

Surface cloud security alerts from Orca Security

Palo Alto Cortex XDR

Investigate endpoint threats with Cortex XDR

Palo Alto Cortex XSIAM

Pull data and alerts from Palo Alto Cortex XSIAM

Palo Alto Cortex XSOAR

Create Cortex XSOAR incidents for security cases

Palo Alto Networks NGFW

Block malicious IPs on your Palo Alto firewall

Phorion

Detect macOS endpoint threats with Phorion

PingOne Identity

Detect identity attacks across your PingOne tenant

Proofpoint TAP

Email threat telemetry from Proofpoint TAP

Qualys VMDR

Enrich investigations with vulnerability context

Rapid7 InsightVM

Enrich investigations with Rapid7 vulnerability context

Recorded Future

Ingest alerts and hunt with Recorded Future intel

Rootly Alerts

Security alert records from Rootly

Salesforce

Salesforce login, EventLogFile, and audit ingest

SAP Concur

Enrich investigations with employee travel and expenses

Scanner.dev

AI-driven federated log queries via Scanner.dev

SentinelOne

Detect endpoint threats with SentinelOne

SentinelOne AI SIEM

Ingest firewall and SIEM logs from SentinelOne

ServiceNow ITSM Notifications

Create ServiceNow incidents for security cases

ServiceNow Logs

Ingest ServiceNow platform activity logs

Slack

Surface Artemis signals in your Slack workspace

Slack Audit Logs

Audit Slack auth, file, and admin activity

Snowflake

Connect Artemis to data in Snowflake and audit activity

Splunk

Connect Artemis to data in Splunk

Spur

Federated IP-context lookups via Spur

StepSecurity

Detect supply-chain attacks on CI/CD runners

Sumo Logic

Connect Artemis to data in Sumo Logic

Swimlane

Trigger Swimlane playbooks from Artemis cases

Syslog

Forward syslog data directly to Artemis

Tailscale

Detect threats across your Tailscale network

Tanium

Endpoint platform audit and Threat Response logs

Tenable

Enrich investigations with vulnerability context

Thinkst Canary

Ingest Thinkst Canary deception alerts

ThreatER

Federated threat-intel lookups via ThreatER

Tines

Trigger Tines workflows from Artemis cases

Torq

Trigger Torq workflows from Artemis cases

Torq Cases

Securely store Torq Query Cases API credentials

Twingate

Detect threats across your Twingate network

Uptycs

Query Uptycs endpoint telemetry on demand

Upwind

Detect runtime threats and risks with Upwind

URLscan

IP, domain, and URL reputation lookups via URLscan

Varonis

Ingest Varonis SaaS data-security alerts

Vector AWS S3 Sink

Forward logs from your Vector pipeline to Artemis

Veracode

AppSec audit logs and vulnerability findings

VirusTotal

IP and domain reputation lookups via VirusTotal

Webhook Receiver

Send events to Artemis from any webhook source

Wiz

Surface cloud issues and hunt on Wiz Threat Center

Workato Audit Logs

Detect risky Workato admin and config changes

Workday Directory Sync

Enrich detections with Workday employee data

Zoom

Detect threats across your Zoom organization

Zscaler Internet Access

Stream ZIA logs via Cloud NSS or a VM-based NSS feed