THE CONNECTOR ECOSYSTEM

Your environment.
Already in the conversation.

Connect to the infrastructure and tools that know your world. Normalize their observations into a shared operational model.

31 connector packages2 built-in integrations

Showing 33 of 33 integrations

Cisco IOS

NETWORK

IOS and Catalyst device health, configuration evidence, and interface activity.

Connector package
Capabilities & requirements
  • SSH observations, diagnostic show commands, and security baseline audits.
  • Supported security controls and site configuration changes with approval and verification.

Access / format: SSH · SNMP

Before you connect: Requires appropriate SSH access and SNMP community configuration for interface counters. Commands and remediation controls depend on device family, software, privileges, and policy.

Juniper Junos

NETWORK

Junos and SRX operational state, configuration audits, and interface telemetry.

Connector package
Capabilities & requirements
  • Read validated show commands for routing, chassis, VPN, and security evidence.
  • Apply supported, approval-controlled management security settings.

Access / format: SSH · SNMP

Before you connect: Requires SSH permissions and SNMP configuration for interface counters. Supported security changes commit device configuration; command availability varies by Junos release and model.

Aruba AOS-Switch

NETWORK

AOS-Switch / ProVision inventory, health, configuration, and security posture.

Connector package
Capabilities & requirements
  • Read SSH show commands, configuration baselines, and structured audits.
  • Collect IF-MIB interface traffic, errors, and operational state over SNMPv2c.

Access / format: SSH · SNMPv2c

Before you connect: Targets supported AOS-S / ProVision switches. This is not an AOS-CX or Aruba Central connector. SSH commands depend on the switch and release; the current interface collector uses SNMPv2c.

Aruba EdgeConnect

NETWORK

Physical and virtual EdgeConnect ECOS appliance health and SD-WAN observations.

Connector package
Capabilities & requirements
  • Inspect tunnels, IPsec, traffic, licensing, certificates, and management security over SSH.
  • Collect SNMPv2c interface counters and supported baseline evidence.

Access / format: SSH · SNMPv2c

Before you connect: Connects to ECOS appliances, not a general Orchestrator or Aruba Central API. Available commands depend on appliance role, licensing, and release; interface collection currently uses SNMPv2c.

Forcepoint NGFW

SECURITY

NGFW engine health, policy state, routing, cluster status, and interface activity.

Connector package
Capabilities & requirements
  • Run fixed, read-only SSH diagnostics and security baseline checks.
  • Collect SNMP v1/v2c/v3 interface counters, errors, discards, and link state.

Access / format: SSH · SNMPv1 · SNMPv2c · SNMPv3

Before you connect: Engine SSH/SNMP access must be enabled in the management policy. This package does not mutate configuration or expose arbitrary shell commands. Unsupported engine commands are reported as unavailable.

Netgate pfSense Plus

SECURITY

pfSense Plus health, firewall and VPN state, sanitized configuration, and interface telemetry.

Connector package
Capabilities & requirements
  • Read fixed SSH diagnostics and collect SNMP v1/v2c/v3 interface counters.
  • Support guarded service restarts and firmware upgrades with explicit preflight checks and confirmations.

Access / format: SSH · SNMPv1 · SNMPv2c · SNMPv3

Before you connect: Targets pfSense Plus; do not assume pfSense CE compatibility. Some commands need elevated permissions. Firmware upgrades are destructive operations requiring a verified target, recovery access, backup, and maintenance window.

Gigamon

NETWORK

Packet broker identity, health, interface observations, and security baseline evidence.

Connector package
Capabilities & requirements
  • Read supported CLI diagnostics, routes, neighbors, logs, and configuration audits.
  • Collect IF-MIB interface activity through SNMP.

Access / format: SSH · SNMP · Telnet

Before you connect: Requires compatible device CLI access and SNMP configuration. SSH is the preferred transport; legacy Telnet support is not an encrypted connection. Supported commands vary by device and release.

Windows Admin Center

COMPUTE

Windows server, cluster, and Hyper-V observations through a Windows Admin Center gateway.

Connector package
Capabilities & requirements
  • Discover registered connections and inspect gateway, server, security, update, and VM health.
  • Read performance, event, certificate, and bounded CIM evidence with fixed PowerShell scripts.

Access / format: HTTPS · WAC gateway

Before you connect: Uses a WAC gateway username/password login and authorized target access. Gateway UI/extension API compatibility must be checked on upgrade. It does not accept arbitrary PowerShell or use Microsoft Graph authentication.

Microsoft Graph · Entra Security

CLOUD & IDENTITY

Entra identity inventory, sign-ins, directory audits, access policy, and identity risk evidence.

Connector package
Capabilities & requirements
  • Read users, groups, devices, applications, service principals, grants, and role assignments.
  • Inspect Conditional Access, authentication registration, risky identities, and risk detections.

Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0

Before you connect: Uses Graph v1.0 application permissions with tenant admin consent. Individual resources may require additional roles or licenses. The source UI uses a saved Microsoft App Registration credential.

Microsoft Graph · Defender XDR

SECURITY

Defender incidents, alerts, Secure Score, identity health, and Advanced Hunting evidence.

Connector package
Capabilities & requirements
  • Read incidents, alerts, score controls, Defender for Identity sensors, and health issues.
  • Run a supplied, bounded KQL query through Graph Advanced Hunting.

Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0 · KQL

Before you connect: Requires Graph application consent and relevant Defender licenses and permissions. Hunting requires ThreatHunting.Read.All and an explicit query; it is not part of default scheduled collection.

Microsoft Graph · Intune

ENDPOINT

Intune managed device inventory, compliance policy, configuration, and detected application evidence.

Connector package
Capabilities & requirements
  • Read managed devices, compliance policies, and device configuration policies.
  • Inspect detected applications and Windows Autopilot device identities.

Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0

Before you connect: Requires an Intune-enabled tenant and the appropriate Graph application permissions and admin consent. Collection covers implemented read endpoints, not device administration or every Intune service.

Microsoft Graph · Microsoft 365 Health

CLOUD & IDENTITY

Microsoft 365 service health, active service issues, and Message Center announcements.

Connector package
Capabilities & requirements
  • Read service health overviews and service incident details.
  • Collect service messages relevant to tenant operations.

Access / format: Microsoft Graph v1.0 · HTTPS · OAuth 2.0

Before you connect: Requires consented Graph application permissions for service health and messages. Endpoint availability varies by tenant cloud and entitlement; this is not a mailbox, Teams, or SharePoint content connector.

ACAS Security Center

SECURITY

Tenable.sc / ACAS assets, vulnerability findings, scan health, and platform observations.

Connector package
Capabilities & requirements
  • Model host assets and vulnerability findings from Security Center.
  • Inspect scanners, repositories, feeds, licensing, and security configuration.

Access / format: HTTPS

Before you connect: Needs a supported Security Center API and account permissions. It reads existing scanner and vulnerability evidence; it does not replace a scanner or imply support for every Tenable product.

Security Onion

SECURITY

Zeek and Suricata telemetry, Elasticsearch health, and supported Security Onion operational status.

Connector package
Capabilities & requirements
  • Read network/security observations and Elasticsearch index, node, and shard health.
  • Use supported SOC API and fixed manager SSH status commands for grid and service evidence.

Access / format: HTTPS · SSH

Before you connect: Elasticsearch, SOC API, and SSH paths have separate access requirements. Some SOC APIs require Pro/Enterprise availability; supported version and authentication paths must be confirmed.

Trellix ePO

ENDPOINT

ePO platform health, managed endpoint inventory, agent status, and security events.

Connector package
Capabilities & requirements
  • Collect system, agent, and operational health evidence through the ePO API.
  • Create inventory observations for groups, managed systems, agent handlers, and rogue systems.

Access / format: HTTPS

Before you connect: Requires an accessible ePO API and account rights for the selected commands. Installed ePO extensions and product versions determine available observations.

VMware vSphere

COMPUTE

vCenter and ESXi inventory, host and virtual machine health, datastores, and events.

Connector package
Capabilities & requirements
  • Create dynamic inventory observations for hosts and virtual machines.
  • Inspect vCenter identity, compute health, datastore state, and collection status.

Access / format: HTTPS

Before you connect: Requires a compatible vSphere endpoint and permissions for the selected inventory and health reads. This catalog does not imply VM lifecycle or power-control operations.

ServiceNow Table API

DATA

Read selected ServiceNow records into the model using table queries and field mappings.

Connector package
Capabilities & requirements
  • Collect permitted incident, change, CMDB, alert, or other table records.
  • Choose fields, query filters, and result limits for each collection.

Access / format: HTTPS · JSON

Before you connect: Uses Table API GET requests. The account, table ACLs, installed applications, and licensed plugins determine available data; each source needs an appropriate query and mapping.

Azure Data Explorer

DATA

KQL query results from Azure Data Explorer, with parameters, timeouts, and result bounds.

Connector package
Capabilities & requirements
  • Map query rows into CyberStitch observations.
  • Execute parameterized KQL; management commands are rejected.

Access / format: HTTPS · KQL

Before you connect: Requires cluster/database access and configured Azure credentials. This is a query adapter, not an ADX administration or ingestion connector. Define the query and row mapping for the desired signals.

PostgreSQL Query

DATA

Collect PostgreSQL query results and map rows into operational observations.

Connector package
Capabilities & requirements
  • Run configured SQL with a connection DSN and timeout.
  • Apply result bounds and map selected columns into the model.

Access / format: PostgreSQL · SQL

Before you connect: Use a database account restricted to the required reads. The connector passes SQL to PostgreSQL; a read-only transaction or SQL safety policy is not enforced by the connector itself.

Oracle Query

DATA

Collect Oracle Database SQL query results as rows for your operational model.

Connector package
Capabilities & requirements
  • Connect using the configured database endpoint, service, and credentials.
  • Read query rows with a configured execution timeout.

Access / format: Oracle Database · SQL

Before you connect: Use a least-privilege database account and bounded queries. The connector executes supplied SQL; it does not independently enforce read-only transactions or cap every query result.

HTTP / JSON

GENERIC

Connect JSON APIs and JSON-lines sources with requests and row mappings you define.

Connector package
Capabilities & requirements
  • Configure URL, method, headers, query parameters, body, and authentication.
  • Select a result path and bounds before mapping rows into observations.

Access / format: HTTP · HTTPS · JSON · NDJSON

Before you connect: This is a configurable connector package, not automatic compatibility with every API. Review request methods and account permissions; it is not restricted to read-only HTTP methods.

SSH Command

GENERIC

Collect output from configured SSH commands, text searches, and login banners.

Connector package
Capabilities & requirements
  • Run selected commands and map their output into observations.
  • Search permitted paths and inspect the remote login banner.

Access / format: SSH

Before you connect: The exec command runs supplied shell commands with the remote account’s permissions; it is not a read-only sandbox. Restrict credentials, commands, host trust, and operator access accordingly.

HTTP Ingress

STREAMING INGRESS

Accept pushed JSON objects, arrays, or NDJSON into a configured CyberStitch feed.

Connector package
Capabilities & requirements
  • Receive HTTP batches with optional gzip and bearer authentication.
  • Acknowledge requests after the raw data reaches the durable acceptance boundary.

Access / format: HTTP · HTTPS · JSON · NDJSON

Before you connect: Requires a configured listener, feed route, authentication, and suitable TLS/network protection. HTTP 202 confirms durable acceptance, not completed downstream application or exactly-once delivery.

gRPC Ingress

STREAMING INGRESS

Accept unary and streamed batches through the CyberStitch IngressService protocol.

Connector package
Capabilities & requirements
  • Receive Publish and client-streaming PublishStream requests with durable receipts.
  • Configure bearer authentication, TLS, or mutual TLS for the listener.

Access / format: gRPC · TLS · mTLS

Before you connect: Senders must implement CyberStitch IngressService. This is not an OTLP receiver or a listener for arbitrary gRPC APIs. A receipt confirms raw acceptance, not downstream exactly-once processing.

Syslog Ingress

STREAMING INGRESS

Receive RFC 3164 and RFC 5424 syslog over UDP, TCP, or TLS.

Connector package
Capabilities & requirements
  • Parse syslog messages and supported RFC 6587 stream framing.
  • Forward records to the configured durable raw-store boundary.

Access / format: Syslog · UDP · TCP · TLS

Before you connect: Configure listener exposure, TLS, and sender/network controls. UDP is best effort and can lose messages; TCP/TLS acceptance does not establish a universal exactly-once delivery guarantee.

Kafka Ingress

STREAMING INGRESS

Consume Kafka topic records through configured consumer groups into CyberStitch feeds.

Connector package
Capabilities & requirements
  • Read JSON payloads with configurable topic, group, TLS, and SASL settings.
  • Commit offsets after the CyberStitch core acknowledges durable raw acceptance.

Access / format: Kafka · TLS · SASL · JSON

Before you connect: Requires broker/topic permissions and compatible payload mappings. Recovery can repeat downstream application. This package consumes Kafka records; Kafka output uses a separate data sink.

Network Packet Capture

NETWORK

Capture packets or payload-free flow summaries from a TAP, SPAN, or host interface.

Connector package
Capabilities & requirements
  • Filter capture lanes and query indexed packet/flow records by time and network metadata.
  • Use approved decoder packages for supported reassembled application traffic.

Access / format: AF_PACKET · BPF · Packet capture · Flow records

Before you connect: Linux amd64/arm64 and CAP_NET_RAW are required. Plan capture access, storage, and retention. Current gRPC decoding uses plaintext HTTP/2; encrypted payloads are not decrypted. Flow mode is not a NetFlow exporter receiver.

CyberStitch Mirror

FIRST PARTY

Passively ingest authenticated CyberStitch Mirror UDP records observed on a capture path.

Connector package
Capabilities & requirements
  • Observe compatible direct, VLAN, GRE/ERSPAN, or VXLAN mirror traffic.
  • Spool and reassemble fragments; only complete authenticated executions enter collection.

Access / format: CyberStitch Mirror UDP · AF_PACKET

Before you connect: A separate Linux amd64/arm64 package requiring CAP_NET_RAW, compatible senders, and mirror keys. It is not generic packet capture and does not import legacy internal mirror state.

CyberStitch Transfer

FIRST PARTY

Pull authorized record exports between CyberStitch instances over an authenticated connection.

Built into CyberStitch
Capabilities & requirements
  • Exchange capabilities, read bounded exports, and acknowledge transfer progress.
  • Resume collection using checkpoints within the configured peer/export scope.

Access / format: CyberStitch transfer · TCP

Before you connect: Built into the core. Requires a CyberStitch credential, a permitted export, the expected remote instance, and a compatible TCP transfer profile. It does not grant arbitrary remote administration.

Core Analysis

FIRST PARTY

Native model, signal-history, dependency, and observation tools for scoped analysis.

Built into CyberStitch
Capabilities & requirements
  • Inspect bounded node snapshots, dependency paths, feed schemas, and raw evidence.
  • Use native impact-analysis tools within the selected model and node scope.

Access / format: Native core tools

Before you connect: Internal CyberStitch tools, not a device connector or separately downloaded package. Evidence access depends on permissions, scope, available history, and tool limits.

Package installation, approval, supported platforms, vendor permissions, and version compatibility apply. This catalog describes implemented integrations; the customer portal shows the releases available to your organization. Generic adapters need configured queries or mappings. Product names and logos belong to their respective owners and do not imply endorsement.

KEEP THE DATA MOVING

Inputs are only
half the picture.

Route selected records to HTTP, Kafka, syslog, cloud storage, and other CyberStitch instances. Data sinks are separate output integrations; the ingress packages above receive data.

Explore data integration ↗
LOOKING FOR SOMETHING ELSE?

Let's look at your systems.

Tell us what you need to connect, the versions you run, and the network boundaries that matter. We'll discuss the appropriate integration path.

Talk to our team ↗

THE WHOLE PICTURE STARTS HERE

Connect your signals.
Know what matters.

Bring your environment. We'll help you see the dependencies,
understand the impact, and find your next move.