Starlink Terminal
SATELLITE
Dish status, link telemetry, outages, obstruction, and terminal diagnostics.
Connector package Capabilities & requirements
- Read terminal configuration, transceiver status, and bounded logs.
- Includes a Starlink decoder for use with the Network Packet Capture package.
Access / format: gRPC · HTTP/2
Before you connect: Active collection needs access to the terminal gRPC service. Passive decoding requires the separate capture package and visible plaintext HTTP/2 gRPC traffic; it does not decrypt TLS.
Cisco IOS
NETWORK
IOS and Catalyst device health, configuration evidence, and interface activity.
Connector package Capabilities & requirements
- SSH observations, diagnostic show commands, and security baseline audits.
- Supported security controls and site configuration changes with approval and verification.
Access / format: SSH · SNMP
Before you connect: Requires appropriate SSH access and SNMP community configuration for interface counters. Commands and remediation controls depend on device family, software, privileges, and policy.
Juniper Junos
NETWORK
Junos and SRX operational state, configuration audits, and interface telemetry.
Connector package Capabilities & requirements
- Read validated show commands for routing, chassis, VPN, and security evidence.
- Apply supported, approval-controlled management security settings.
Access / format: SSH · SNMP
Before you connect: Requires SSH permissions and SNMP configuration for interface counters. Supported security changes commit device configuration; command availability varies by Junos release and model.
Aruba AOS-Switch
NETWORK
AOS-Switch / ProVision inventory, health, configuration, and security posture.
Connector package Capabilities & requirements
- Read SSH show commands, configuration baselines, and structured audits.
- Collect IF-MIB interface traffic, errors, and operational state over SNMPv2c.
Access / format: SSH · SNMPv2c
Before you connect: Targets supported AOS-S / ProVision switches. This is not an AOS-CX or Aruba Central connector. SSH commands depend on the switch and release; the current interface collector uses SNMPv2c.
Aruba EdgeConnect
NETWORK
Physical and virtual EdgeConnect ECOS appliance health and SD-WAN observations.
Connector package Capabilities & requirements
- Inspect tunnels, IPsec, traffic, licensing, certificates, and management security over SSH.
- Collect SNMPv2c interface counters and supported baseline evidence.
Access / format: SSH · SNMPv2c
Before you connect: Connects to ECOS appliances, not a general Orchestrator or Aruba Central API. Available commands depend on appliance role, licensing, and release; interface collection currently uses SNMPv2c.
Forcepoint NGFW
SECURITY
NGFW engine health, policy state, routing, cluster status, and interface activity.
Connector package Capabilities & requirements
- Run fixed, read-only SSH diagnostics and security baseline checks.
- Collect SNMP v1/v2c/v3 interface counters, errors, discards, and link state.
Access / format: SSH · SNMPv1 · SNMPv2c · SNMPv3
Before you connect: Engine SSH/SNMP access must be enabled in the management policy. This package does not mutate configuration or expose arbitrary shell commands. Unsupported engine commands are reported as unavailable.
Netgate pfSense Plus
SECURITY
pfSense Plus health, firewall and VPN state, sanitized configuration, and interface telemetry.
Connector package Capabilities & requirements
- Read fixed SSH diagnostics and collect SNMP v1/v2c/v3 interface counters.
- Support guarded service restarts and firmware upgrades with explicit preflight checks and confirmations.
Access / format: SSH · SNMPv1 · SNMPv2c · SNMPv3
Before you connect: Targets pfSense Plus; do not assume pfSense CE compatibility. Some commands need elevated permissions. Firmware upgrades are destructive operations requiring a verified target, recovery access, backup, and maintenance window.
Gigamon
NETWORK
Packet broker identity, health, interface observations, and security baseline evidence.
Connector package Capabilities & requirements
- Read supported CLI diagnostics, routes, neighbors, logs, and configuration audits.
- Collect IF-MIB interface activity through SNMP.
Access / format: SSH · SNMP · Telnet
Before you connect: Requires compatible device CLI access and SNMP configuration. SSH is the preferred transport; legacy Telnet support is not an encrypted connection. Supported commands vary by device and release.
Windows Admin Center
COMPUTE
Windows server, cluster, and Hyper-V observations through a Windows Admin Center gateway.
Connector package Capabilities & requirements
- Discover registered connections and inspect gateway, server, security, update, and VM health.
- Read performance, event, certificate, and bounded CIM evidence with fixed PowerShell scripts.
Access / format: HTTPS · WAC gateway
Before you connect: Uses a WAC gateway username/password login and authorized target access. Gateway UI/extension API compatibility must be checked on upgrade. It does not accept arbitrary PowerShell or use Microsoft Graph authentication.
Microsoft Graph · Entra Security
CLOUD & IDENTITY
Entra identity inventory, sign-ins, directory audits, access policy, and identity risk evidence.
Connector package Capabilities & requirements
- Read users, groups, devices, applications, service principals, grants, and role assignments.
- Inspect Conditional Access, authentication registration, risky identities, and risk detections.
Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0
Before you connect: Uses Graph v1.0 application permissions with tenant admin consent. Individual resources may require additional roles or licenses. The source UI uses a saved Microsoft App Registration credential.
Microsoft Graph · Defender XDR
SECURITY
Defender incidents, alerts, Secure Score, identity health, and Advanced Hunting evidence.
Connector package Capabilities & requirements
- Read incidents, alerts, score controls, Defender for Identity sensors, and health issues.
- Run a supplied, bounded KQL query through Graph Advanced Hunting.
Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0 · KQL
Before you connect: Requires Graph application consent and relevant Defender licenses and permissions. Hunting requires ThreatHunting.Read.All and an explicit query; it is not part of default scheduled collection.
Microsoft Graph · Intune
ENDPOINT
Intune managed device inventory, compliance policy, configuration, and detected application evidence.
Connector package Capabilities & requirements
- Read managed devices, compliance policies, and device configuration policies.
- Inspect detected applications and Windows Autopilot device identities.
Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0
Before you connect: Requires an Intune-enabled tenant and the appropriate Graph application permissions and admin consent. Collection covers implemented read endpoints, not device administration or every Intune service.
Microsoft Graph · Microsoft 365 Health
CLOUD & IDENTITY
Microsoft 365 service health, active service issues, and Message Center announcements.
Connector package Capabilities & requirements
- Read service health overviews and service incident details.
- Collect service messages relevant to tenant operations.
Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0
Before you connect: Requires consented Graph application permissions for service health and messages. Endpoint availability varies by tenant cloud and entitlement; this is not a mailbox, Teams, or SharePoint content connector.
Splunk Search
SECURITY
SPL search results and operational observations from the Splunk Enterprise management API.
Connector package Capabilities & requirements
- Collect configured searches, platform and license health, and ingest activity.
- Inspect supported index, input, alert, and knowledge-object summaries.
Access / format: HTTPS · SPL
Before you connect: Needs management API connectivity and a suitably scoped Splunk account or token. Review query permissions and supported endpoints. Splunk HEC output is a separate data-sink integration.
ACAS Security Center
SECURITY
Tenable.sc / ACAS assets, vulnerability findings, scan health, and platform observations.
Connector package Capabilities & requirements
- Model host assets and vulnerability findings from Security Center.
- Inspect scanners, repositories, feeds, licensing, and security configuration.
Access / format: HTTPS
Before you connect: Needs a supported Security Center API and account permissions. It reads existing scanner and vulnerability evidence; it does not replace a scanner or imply support for every Tenable product.
Security Onion
SECURITY
Zeek and Suricata telemetry, Elasticsearch health, and supported Security Onion operational status.
Connector package Capabilities & requirements
- Read network/security observations and Elasticsearch index, node, and shard health.
- Use supported SOC API and fixed manager SSH status commands for grid and service evidence.
Access / format: HTTPS · SSH
Before you connect: Elasticsearch, SOC API, and SSH paths have separate access requirements. Some SOC APIs require Pro/Enterprise availability; supported version and authentication paths must be confirmed.
Trellix ePO
ENDPOINT
ePO platform health, managed endpoint inventory, agent status, and security events.
Connector package Capabilities & requirements
- Collect system, agent, and operational health evidence through the ePO API.
- Create inventory observations for groups, managed systems, agent handlers, and rogue systems.
Access / format: HTTPS
Before you connect: Requires an accessible ePO API and account rights for the selected commands. Installed ePO extensions and product versions determine available observations.
Elasticsearch
DATA
Search results, cluster health, inventory, pipelines, and document ingest activity.
Connector package Capabilities & requirements
- Run configured JSON searches and inspect recent documents.
- Read index, node, ingest pipeline, and cluster summaries.
Access / format: HTTPS · JSON
Before you connect: Requires reachable Elasticsearch endpoints and appropriate search/monitoring permissions. Index mappings and access policies determine what can be collected; this is not a connector for every Elastic product.
VMware vSphere
COMPUTE
vCenter and ESXi inventory, host and virtual machine health, datastores, and events.
Connector package Capabilities & requirements
- Create dynamic inventory observations for hosts and virtual machines.
- Inspect vCenter identity, compute health, datastore state, and collection status.
Access / format: HTTPS
Before you connect: Requires a compatible vSphere endpoint and permissions for the selected inventory and health reads. This catalog does not imply VM lifecycle or power-control operations.
ServiceNow Table API
DATA
Read selected ServiceNow records into the model using table queries and field mappings.
Connector package Capabilities & requirements
- Collect permitted incident, change, CMDB, alert, or other table records.
- Choose fields, query filters, and result limits for each collection.
Access / format: HTTPS · JSON
Before you connect: Uses Table API GET requests. The account, table ACLs, installed applications, and licensed plugins determine available data; each source needs an appropriate query and mapping.
Azure Data Explorer
DATA
KQL query results from Azure Data Explorer, with parameters, timeouts, and result bounds.
Connector package Capabilities & requirements
- Map query rows into CyberStitch observations.
- Execute parameterized KQL; management commands are rejected.
Access / format: HTTPS · KQL
Before you connect: Requires cluster/database access and configured Azure credentials. This is a query adapter, not an ADX administration or ingestion connector. Define the query and row mapping for the desired signals.
PostgreSQL Query
DATA
Collect PostgreSQL query results and map rows into operational observations.
Connector package Capabilities & requirements
- Run configured SQL with a connection DSN and timeout.
- Apply result bounds and map selected columns into the model.
Access / format: PostgreSQL · SQL
Before you connect: Use a database account restricted to the required reads. The connector passes SQL to PostgreSQL; a read-only transaction or SQL safety policy is not enforced by the connector itself.
Oracle Query
DATA
Collect Oracle Database SQL query results as rows for your operational model.
Connector package Capabilities & requirements
- Connect using the configured database endpoint, service, and credentials.
- Read query rows with a configured execution timeout.
Access / format: Oracle Database · SQL
Before you connect: Use a least-privilege database account and bounded queries. The connector executes supplied SQL; it does not independently enforce read-only transactions or cap every query result.
HTTP / JSON
GENERIC
Connect JSON APIs and JSON-lines sources with requests and row mappings you define.
Connector package Capabilities & requirements
- Configure URL, method, headers, query parameters, body, and authentication.
- Select a result path and bounds before mapping rows into observations.
Access / format: HTTP · HTTPS · JSON · NDJSON
Before you connect: This is a configurable connector package, not automatic compatibility with every API. Review request methods and account permissions; it is not restricted to read-only HTTP methods.
SSH Command
GENERIC
Collect output from configured SSH commands, text searches, and login banners.
Connector package Capabilities & requirements
- Run selected commands and map their output into observations.
- Search permitted paths and inspect the remote login banner.
Access / format: SSH
Before you connect: The exec command runs supplied shell commands with the remote account’s permissions; it is not a read-only sandbox. Restrict credentials, commands, host trust, and operator access accordingly.
HTTP Ingress
STREAMING INGRESS
Accept pushed JSON objects, arrays, or NDJSON into a configured CyberStitch feed.
Connector package Capabilities & requirements
- Receive HTTP batches with optional gzip and bearer authentication.
- Acknowledge requests after the raw data reaches the durable acceptance boundary.
Access / format: HTTP · HTTPS · JSON · NDJSON
Before you connect: Requires a configured listener, feed route, authentication, and suitable TLS/network protection. HTTP 202 confirms durable acceptance, not completed downstream application or exactly-once delivery.
gRPC Ingress
STREAMING INGRESS
Accept unary and streamed batches through the CyberStitch IngressService protocol.
Connector package Capabilities & requirements
- Receive Publish and client-streaming PublishStream requests with durable receipts.
- Configure bearer authentication, TLS, or mutual TLS for the listener.
Access / format: gRPC · TLS · mTLS
Before you connect: Senders must implement CyberStitch IngressService. This is not an OTLP receiver or a listener for arbitrary gRPC APIs. A receipt confirms raw acceptance, not downstream exactly-once processing.
Syslog Ingress
STREAMING INGRESS
Receive RFC 3164 and RFC 5424 syslog over UDP, TCP, or TLS.
Connector package Capabilities & requirements
- Parse syslog messages and supported RFC 6587 stream framing.
- Forward records to the configured durable raw-store boundary.
Access / format: Syslog · UDP · TCP · TLS
Before you connect: Configure listener exposure, TLS, and sender/network controls. UDP is best effort and can lose messages; TCP/TLS acceptance does not establish a universal exactly-once delivery guarantee.
Kafka Ingress
STREAMING INGRESS
Consume Kafka topic records through configured consumer groups into CyberStitch feeds.
Connector package Capabilities & requirements
- Read JSON payloads with configurable topic, group, TLS, and SASL settings.
- Commit offsets after the CyberStitch core acknowledges durable raw acceptance.
Access / format: Kafka · TLS · SASL · JSON
Before you connect: Requires broker/topic permissions and compatible payload mappings. Recovery can repeat downstream application. This package consumes Kafka records; Kafka output uses a separate data sink.
Network Packet Capture
NETWORK
Capture packets or payload-free flow summaries from a TAP, SPAN, or host interface.
Connector package Capabilities & requirements
- Filter capture lanes and query indexed packet/flow records by time and network metadata.
- Use approved decoder packages for supported reassembled application traffic.
Access / format: AF_PACKET · BPF · Packet capture · Flow records
Before you connect: Linux amd64/arm64 and CAP_NET_RAW are required. Plan capture access, storage, and retention. Current gRPC decoding uses plaintext HTTP/2; encrypted payloads are not decrypted. Flow mode is not a NetFlow exporter receiver.
CyberStitch Mirror
FIRST PARTY
Passively ingest authenticated CyberStitch Mirror UDP records observed on a capture path.
Connector package Capabilities & requirements
- Observe compatible direct, VLAN, GRE/ERSPAN, or VXLAN mirror traffic.
- Spool and reassemble fragments; only complete authenticated executions enter collection.
Access / format: CyberStitch Mirror UDP · AF_PACKET
Before you connect: A separate Linux amd64/arm64 package requiring CAP_NET_RAW, compatible senders, and mirror keys. It is not generic packet capture and does not import legacy internal mirror state.
CyberStitch Transfer
FIRST PARTY
Pull authorized record exports between CyberStitch instances over an authenticated connection.
Built into CyberStitch Capabilities & requirements
- Exchange capabilities, read bounded exports, and acknowledge transfer progress.
- Resume collection using checkpoints within the configured peer/export scope.
Access / format: CyberStitch transfer · TCP
Before you connect: Built into the core. Requires a CyberStitch credential, a permitted export, the expected remote instance, and a compatible TCP transfer profile. It does not grant arbitrary remote administration.
Core Analysis
FIRST PARTY
Native model, signal-history, dependency, and observation tools for scoped analysis.
Built into CyberStitch Capabilities & requirements
- Inspect bounded node snapshots, dependency paths, feed schemas, and raw evidence.
- Use native impact-analysis tools within the selected model and node scope.
Access / format: Native core tools
Before you connect: Internal CyberStitch tools, not a device connector or separately downloaded package. Evidence access depends on permissions, scope, available history, and tool limits.
Package installation, approval, supported platforms, vendor permissions, and version compatibility apply. This catalog describes implemented integrations; the customer portal shows the releases available to your organization. Generic adapters need configured queries or mappings. Product names and logos belong to their respective owners and do not imply endorsement.