Connectors - Artemis Security
150+ connectors across the stack you already run.
Hot-path data that detection depends on is ingested directly. High-volume data is queried where it already lives. Connect your first sources in under an hour.
1Password (Actions)
Run remediation actions on compromised 1Password users
1Password Audit Logs
Detect suspicious activity in your 1Password account
Abnormal AI
Cloud email security telemetry from Abnormal AI
Akeyless
Reference Akeyless secrets in connectors and actions
Amazon Managed Service for Prometheus
Query AMP metrics with PromQL during investigations
Anthropic Claude Compliance
Audit Claude activity across your Anthropic org
Armis Centrix
Asset alerts and activities from Armis Centrix
Auth0
Detect identity attacks in Auth0 tenants
Auth0 Directory Sync
Sync Auth0 users, roles, and orgs into inventory
AWS Bedrock Model Invocations
Detect prompt injection and abuse in AWS Bedrock
AWS CloudTrail
Detect attacks across your AWS environment
AWS CloudWatch Logs (Pull)
Pull tagged CloudWatch log groups from your AWS account
AWS Environment & Cost Intelligence
AWS identities, resources, cost savings, and efficiency
AWS S3 Pull (From My Bucket)
Ingest logs from your S3 bucket
AWS S3 Push (To Artemis Bucket)
Push logs from any pipeline into Artemis
AWS Secrets Manager
Reference Secrets Manager secrets across Artemis
AWS Security Hub
Inspector CVEs, CSPM controls, and product alerts
AWS Security Lake
Detect and investigate using AWS Security Lake data
AWS SNS Sender
Publish case notifications to your AWS SNS topic
AWS SQS Sender
Send case notifications to your AWS SQS queue
AWS SSM Parameter Store
Reference SSM parameters in connectors and actions
Axonius
Federated asset enrichment during investigations
Azure Activity Logs
Detect attacks across your Azure subscriptions
BambooHR Directory Sync
Enrich detections with BambooHR employee data
BigQuery
Run AI Mode SQL queries against Google BigQuery
BlinkOps
Trigger BlinkOps workflows from Artemis cases
Carbon Black Cloud
Detect endpoint threats with Carbon Black Cloud
ClickHouse
Federated read-only SQL queries against ClickHouse
Cloudflare Actions
Dispatch Cloudflare response actions from Artemis
Cloudflare Audit Logs
Detect threats and config changes in Cloudflare
Cloudflare WAF
Detect web app attacks blocked by Cloudflare WAF
Cloudflare WARP / Zero Trust
Detect threats across Cloudflare Zero Trust / WARP
Coralogix Events
Ingest Coralogix alert events for detection
Cribl Stream
Forward events from your Cribl pipeline to Artemis
CrowdStrike CSPM
Cloud posture and asset inventory from Falcon CSPM
CrowdStrike Falcon
Detect endpoint threats and hunt on Falcon Intelligence
CrowdStrike Falcon Actions
Run remediation actions on CrowdStrike Falcon
CrowdStrike NG-SIEM
Send cases to CrowdStrike and query NG-SIEM data
Custom MCP
Connect a Model Context Protocol server to AI Mode
Cyberhaven
Ingest Cyberhaven DLP incidents and context
Cyble
Federated IOC reputation lookups via Cyble Vision
Dashlane Directory Sync
Sync Dashlane members, devices, and password health
Datadog
AI-powered threat hunting over Datadog logs
DNSFilter Actions
Dispatch DNSFilter response actions from Artemis cases
DNSFilter Inventory Sync
Sync DNSFilter sites, policies, and roaming clients
DNSFilter Logs
Ingest DNSFilter DNS query and threat-block logs via S3
Elasticsearch
Connect Artemis to data in Elasticsearch
Email Listener
Inbound mailing-list inbox routed to SOAR workflows
Email Sender
Receive case notifications by email
Endpoint Log Receiver
Send logs from any endpoint directly to Artemis
Flashpoint
Ingest Flashpoint Ignite alerts for detection
Forescout
NAC events and device visibility from Forescout
FortiMail / Perception Point Response
Email response through Perception Point and FortiMail
Freshservice Audit Logs
Detect threats in your Freshservice audit log
GCP Cloud Audit Logs
Detect attacks across your Google Cloud environment
GitHub Audit Logs
Detect threats across your GitHub organization
GitHub Repo Access
Let Artemis read your repos during investigations
GitLab Audit Events
Detect threats across your GitLab instance
GitLab Repo Access
Read GitLab repos during AI Mode investigations
Google Cloud Storage
Ingest logs from your Cloud Storage buckets
Google SecOps
Investigate using data in Google SecOps (Chronicle)
Google Workspace Activity
Detect threats across Google Workspace
Google Workspace Directory Sync
Enrich detections with Google Workspace user context
Grafana
Investigate using data in Grafana
HashiCorp Vault
Reference Vault secrets in connectors and SOAR actions
HEC Receiver
Send logs to Artemis from any HEC-compatible client
Horizon3 NodeZero
Ingest autonomous pentest results from NodeZero
incident.io
Create incident.io incidents for security cases
Infoblox Threat Defense
Detect DNS threats blocked by Infoblox Threat Defense
Iru
Detect threats across your Apple device fleet
Island Enterprise Browser
Audit user activity in the Island browser
Jamf Pro
Track device security and admin activity in Jamf Pro
Jamf Protect
Ingest Jamf Protect telemetry, unified logs, and Alerts
Jira (Ticketing & Actions)
Create and manage Jira issues from cases and workflows
Jira Directory Sync
Sync Jira identities; query tickets in AI Mode
Joe Sandbox (Actions)
Detonate files and URLs in Joe Sandbox from workflows
JumpCloud Events
Detect identity attacks in JumpCloud tenants
LogRhythm
Federated query + ingest from on-prem LogRhythm SIEM
Looker
Detect threats in your Looker environment
Microsoft 365 Copilot Audit
Audit M365 Copilot, Copilot Studio, and Agent365
Microsoft 365 Remediation Actions
Run remediation actions on compromised M365 mailboxes
Microsoft Defender XDR
Detect threats across the Microsoft Defender suite
Microsoft Entra Directory Sync
Enrich detections with Entra ID user and group context
Microsoft Entra ID
Detect identity attacks in Microsoft Entra ID
Microsoft Intune Inventory
Enrich detections with Intune device posture
Microsoft O365 Directory Sync
Enrich detections with O365 user and group context
Microsoft O365 Email and Audit Logs
Detect attacks across Microsoft 365 email and apps
Microsoft Purview
Federated content search via Purview eDiscovery
Microsoft Sentinel
Investigate using data in Microsoft Sentinel
Microsoft Teams
Receive Teams case alerts and EI digests
Mimecast
Admin audit and threat events from Mimecast
Netskope SSE
Stream Netskope SSE web, CASB, ZTNA & alert events
Nightfall AI — Sensitive Data Protection
Ingest Nightfall AI DLP findings via Splunk HEC webhook
Notifications Webhook
Send case alerts to any webhook endpoint
Notion Audit Logs
Detect threats in your Notion Enterprise workspace
Obsidian Security
SaaS threat alerts and activity from Obsidian
Okta (Actions)
Run remediation actions on compromised Okta users
Okta Directory Sync
Enrich detections with Okta user and group context
Okta EventBridge
Detect Okta identity attacks in real time
OpenAI Platform
Audit logs, usage counters, and cost totals from OpenAI
OpenCTI
OpenCTI lookups and threat Reports for applicable hunts
OpenTelemetry (OTLP)
Send logs and metrics from any OTLP source to Artemis
Orca Security
Surface cloud security alerts from Orca Security
Palo Alto Cortex XDR
Investigate endpoint threats with Cortex XDR
Palo Alto Cortex XSIAM
Pull data and alerts from Palo Alto Cortex XSIAM
Palo Alto Cortex XSOAR
Create Cortex XSOAR incidents for security cases
Palo Alto Networks NGFW
Block malicious IPs on your Palo Alto firewall
Phorion
Detect macOS endpoint threats with Phorion
PingOne Identity
Detect identity attacks across your PingOne tenant
Proofpoint TAP
Email threat telemetry from Proofpoint TAP
Qualys VMDR
Enrich investigations with vulnerability context
Rapid7 InsightVM
Enrich investigations with Rapid7 vulnerability context
Recorded Future
Ingest alerts and hunt with Recorded Future intel
Rootly Alerts
Security alert records from Rootly
Salesforce
Salesforce login, EventLogFile, and audit ingest
SAP Concur
Enrich investigations with employee travel and expenses
Scanner.dev
AI-driven federated log queries via Scanner.dev
SentinelOne
Detect endpoint threats with SentinelOne
SentinelOne AI SIEM
Ingest firewall and SIEM logs from SentinelOne
ServiceNow ITSM Notifications
Create ServiceNow incidents for security cases
ServiceNow Logs
Ingest ServiceNow platform activity logs
Slack
Surface Artemis signals in your Slack workspace
Slack Audit Logs
Audit Slack auth, file, and admin activity
Snowflake
Connect Artemis to data in Snowflake and audit activity
Splunk
Connect Artemis to data in Splunk
Spur
Federated IP-context lookups via Spur
StepSecurity
Detect supply-chain attacks on CI/CD runners
Sumo Logic
Connect Artemis to data in Sumo Logic
Swimlane
Trigger Swimlane playbooks from Artemis cases
Syslog
Forward syslog data directly to Artemis
Tailscale
Detect threats across your Tailscale network
Tanium
Endpoint platform audit and Threat Response logs
Tenable
Enrich investigations with vulnerability context
Thinkst Canary
Ingest Thinkst Canary deception alerts
ThreatER
Federated threat-intel lookups via ThreatER
Tines
Trigger Tines workflows from Artemis cases
Torq
Trigger Torq workflows from Artemis cases
Torq Cases
Securely store Torq Query Cases API credentials
Twingate
Detect threats across your Twingate network
Uptycs
Query Uptycs endpoint telemetry on demand
Upwind
Detect runtime threats and risks with Upwind
URLscan
IP, domain, and URL reputation lookups via URLscan
Varonis
Ingest Varonis SaaS data-security alerts
Vector AWS S3 Sink
Forward logs from your Vector pipeline to Artemis
Veracode
AppSec audit logs and vulnerability findings
VirusTotal
IP and domain reputation lookups via VirusTotal
Webhook Receiver
Send events to Artemis from any webhook source
Wiz
Surface cloud issues and hunt on Wiz Threat Center
Workato Audit Logs
Detect risky Workato admin and config changes
Workday Directory Sync
Enrich detections with Workday employee data
Zoom
Detect threats across your Zoom organization
Zscaler Internet Access
Stream ZIA logs via Cloud NSS or a VM-based NSS feed
No connectors match your search.