Darktrace/ IDENTITY integrations

Technology Integrations

We know how important it is for your security solutions to talk to each other. Darktrace was built with an open architecture, making integrations quick and simple. Find some common cases listed below. Custom integrations are available upon request.

Integrations with Darktrace/Apps

AWS
Detect and respond to cloud based threats across AWS services from EC2 to EKS and monitor administrative and resource management activity.
AWS Lambda
Take custom actions through invoked AWS Lambda functions to respond to any threat across your AWS footprint.
Azure
Detect and respond to cloud based threats across IaaS, PaaS, and control planes. Monitor M365 administration and access via AzureAD and cloud infrastructure resource management.
Azure Sentinel
Analyze Darktrace AI Analyst incidents and model breach alerts in Azure Sentinel.
Box
Detect unusual user behavior and resource actions in Box.
Cortex XSOAR
Leverage custom playbooks to orchestrate actions triggered by Darktrace alerts.
Dropbox
Detect unusual user behavior and resource actions in Dropbox.
Duo
Detect and respond to threats from across the organization via Duo IAM.
Egnyte
Detect unusual user behavior and resource activities in Egnyte.
Elastic Security
Analyze, correlate, and visualize Darktrace AI Analyst incidents and model breach alerts.
FortiSOAR
Leverage custom playbooks to orchestrate actions triggered by Darktrace AI Analyst incidents and model breaches. Automate commands to pull deeper information back from Darktrace.
Google Cloud Platform
Detect and respond to cloud based threats across VMs and containers and monitor administrative activity and resource management in GCP.
Google Workspace
Detect and respond to threats in Gmail, and monitor user activity, user management, file creation and sharing, and administrative events across Google Workspace apps.
Hunters SOC Platform
Integrate Darktrace with Hunters to allow triaging of Darktrace alerts and incidents via the Hunters console, as well as further investigating and correlating them to related threats
InsightConnect
Leverage custom playbooks to orchestrate actions triggered by Darktrace AI Analyst incidents and model breaches. Automate commands to pull deeper information back from Darktrace.
InsightIDR
Analyze Darktrace AI Analyst incidents and model breach alerts in InsightIDR.
Jira
Create Jira issues for AI Analyst incidents, model breaches, and system health alerts.
Jumpcloud
Detect unusual administration and user activity within Jumpcloud.
LogRhythm
Analyze Darktrace AI Analyst incidents and model breach alerts in LogRhythm.
Microsoft 365
Detect and respond to threats across M365 services, including Exchange, Sharepoint/OneDrive for Business, Dynamics, and Teams.
Microsoft Graph Security API
Enrich Darktrace detection with alerts from Microsoft Cloud App Security, the Microsoft Defender suite, Azure Information Protection, and Azure Identity Protection.
Microsoft Teams
Insert Darktrace alerting into Microsoft Teams channels.
Okta
Detect and respond to threats from across the organization via Okta IAM.
QRadar
Analyze Darktrace AI Analyst incidents and model breach alerts in Qradar.
ReliaQuest
Investigate AI Analyst Incidents and Model Alerts within GreyMatter. Commands can be executed to pull back further information from Darktrace.
Salesforce
Detect unusual user behavior and resource actions in Salesforce.
ServiceNow ITSM
Automate IT tasks in ITSM triggered by Darktrace alerts.
ServiceNow SecOps
Leverage custom playbooks to orchestrate actions triggered by Darktrace alerts.
Siemplify
Leverage custom playbooks to orchestrate actions triggered by Darktrace alerts.
Slack
Insert Darktrace alerting into a Slack channel or chat.
Slack Enterprise
Detect unusual administrative and user activity in Slack.
Splunk
Analyze Darktrace AI Analyst incidents and model breach alerts in CIM compatible Splunk dashboards, and poll Splunk data to enrich Darktrace modeling with additional contextual information.
Splunk SOAR
Leverage custom playbooks to orchestrate actions triggered by Darktrace AI Analyst incidents and model breaches. Automate commands to pull deeper information back from Darktrace.
Swimlane
Leverage custom playbooks to orchestrate actions triggered by Darktrace alerts.
Tines
Leverage custom playbooks to orchestrate actions triggered by Darktrace alerts.
Zoom
Detect and respond to unusual administrative and user activity in Zoom.
Customer stories