Skip to main content
Reference · The integration catalogue

The integrations list, with the ones we have not built yet left in.

A wall of logos is impossible to plan against, because it never tells you which of them is wired and which one somebody hopes to wire. Every row below carries a status, the roadmap rows say Planned rather than “coming soon”, and every figure on this page is counted from the catalogue when the page is built rather than typed into a sentence. Where nothing here fits your stack, the read-and-write API and webhooks further down this page are the answer, and they are not a consolation prize.

86

Integrations available today

19

Categories they group into

17

Named but not yet built, listed below

A vendor is named here because we have committed to delivering it, not because the logo balanced a grid — which is precisely why the roadmap rows are published rather than hidden. If a tool you already run appears below as Planned, say so during evaluation: it is built and wired as part of your onboarding, not parked on a roadmap you have no visibility of. This page is the detail behind the integrations band on the platform overview.

The vocabulary

Four statuses, and what each one actually commits us to

The status column is the only part of this page worth arguing with, so it is defined before the catalogue instead of after it. Planned means not built. It is not softened into a launch date, it is not folded into the headline figure, and it is not hidden behind a tooltip that only appears on a desktop.

The four values the catalogue carries, and what each one is worth to somebody planning a deployment.
StateWhat it meansWhat follows
Available Shipped and running in customer environments today. Configuration is part of deployment rather than a project of its own. Nothing to schedule. Name it on the deployment call and it is switched on.
Beta Built and running with at least one customer, but through too few estates for us to call the configuration settled. Usable now, and named as beta in writing rather than counted quietly as shipped. Expect the configuration surface to move under you.
Planned Not built yet. That is the entire meaning of the word, and it is deliberately not written as “coming soon”. It appears on this page because we have committed to building it — naming a vendor here is a delivery commitment, not a claim about today. Raise it during evaluation and it is delivered alongside your onboarding rather than joining a queue you cannot see.
Suggested Proposed internally and not committed to. No row in the catalogue currently carries it — every proposal was promoted to Planned in May 2026, and the status is kept so that a future proposal has somewhere honest to sit. Where a row does carry it, read it as: we have discussed this and have not decided. It is not a commitment, and it is counted in nothing.
Key
  • Wired and in use
  • Wired, still settling
  • Not built

Available today counts the Available and Beta rows together — 86 of 103. The remaining 17 are counted separately, listed below by name, and never folded into the headline. Anyone comparing us on this page should be asking every other vendor on the shortlist for the same split.

The catalogue

Every integration we hold, grouped by the job it does

Grouped by what the tool is for rather than alphabetically, because nobody arrives at a page like this wanting the letter S. Within a group, the category tells you which shelf a tool sits on and the last column says what data actually moves — which is almost always the real question behind “do you integrate with X”.

Where findings land

The detection stack a finding has to reach before anyone acts on it. Exposure discovered outside your perimeter arrives as an event in the shape each platform already expects, so your existing detection content can match on it rather than being rewritten around a new source.

Where findings land — 22 integrations, all of them available today. Statuses as of August 2026.
IntegrationCategoryStatusWhat it exchanges
Splunk SIEM Available Findings, IoCs, asset events
Microsoft Sentinel SIEM Available Findings, IoCs, asset events
IBM QRadar SIEM Available Findings, IoCs
Elastic Security SIEM Available Findings, IoCs, asset events
Google SecOps (Chronicle) SIEM Available Findings, IoCs, asset events
Sumo Logic SIEM Available Findings, asset events
Exabeam SIEM Available Findings, credential exposure events
Securonix SIEM Available Findings, IoCs, credential events
Devo SIEM Available Findings, asset events
Cortex XSOAR SOAR Available Findings (trigger), playbook outcomes back
Tines SOAR Available Findings, webhook events
Splunk SOAR SOAR Available Findings, playbook outcomes
Swimlane SOAR Available Findings, takedown status, case updates
Torq SOAR Available Findings, webhooks, case updates
D3 Security SOAR Available Findings, case updates
CrowdStrike Falcon EDR / XDR Available Findings, host telemetry queries
SentinelOne Singularity EDR / XDR Available Findings, host telemetry queries
Microsoft Defender for Endpoint EDR / XDR Available Findings, host telemetry queries
Trend Vision One EDR / XDR Available IoCs, asset correlation
Sophos Intercept X EDR / XDR Available IoCs, compromised device signals
Cybereason EDR / XDR Available IoCs, credential events
Trellix EDR / XDR Available IoCs, asset correlation

Where findings land — 22 integrations, all of them available today. Statuses as of August 2026.

Splunk

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs, asset events

Microsoft Sentinel

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs, asset events

IBM QRadar

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs

Elastic Security

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs, asset events

Google SecOps (Chronicle)

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs, asset events

Sumo Logic

Category
SIEM
Status
Available
What it exchanges
Findings, asset events

Exabeam

Category
SIEM
Status
Available
What it exchanges
Findings, credential exposure events

Securonix

Category
SIEM
Status
Available
What it exchanges
Findings, IoCs, credential events

Devo

Category
SIEM
Status
Available
What it exchanges
Findings, asset events

Cortex XSOAR

Category
SOAR
Status
Available
What it exchanges
Findings (trigger), playbook outcomes back

Tines

Category
SOAR
Status
Available
What it exchanges
Findings, webhook events

Splunk SOAR

Category
SOAR
Status
Available
What it exchanges
Findings, playbook outcomes

Swimlane

Category
SOAR
Status
Available
What it exchanges
Findings, takedown status, case updates

Torq

Category
SOAR
Status
Available
What it exchanges
Findings, webhooks, case updates

D3 Security

Category
SOAR
Status
Available
What it exchanges
Findings, case updates

CrowdStrike Falcon

Category
EDR / XDR
Status
Available
What it exchanges
Findings, host telemetry queries

SentinelOne Singularity

Category
EDR / XDR
Status
Available
What it exchanges
Findings, host telemetry queries

Microsoft Defender for Endpoint

Category
EDR / XDR
Status
Available
What it exchanges
Findings, host telemetry queries

Trend Vision One

Category
EDR / XDR
Status
Available
What it exchanges
IoCs, asset correlation

Sophos Intercept X

Category
EDR / XDR
Status
Available
What it exchanges
IoCs, compromised device signals

Cybereason

Category
EDR / XDR
Status
Available
What it exchanges
IoCs, credential events

Trellix

Category
EDR / XDR
Status
Available
What it exchanges
IoCs, asset correlation

Where the work gets tracked

A finding nobody owns is a slide, not a finding. These put it in the tracker your engineers already live in and the channel your responders already watch; on the ticketing integrations that support it, state moves in both directions, so closing the ticket closes the item.

Where the work gets tracked — 19 integrations, all of them available today. Statuses as of August 2026.
IntegrationCategoryStatusWhat it exchanges
Atlassian Jira Ticketing Available Findings (create), state (bidirectional)
ServiceNow ITSM Ticketing Available Findings (create), CMDB (lookup), state (bidirectional)
Linear Ticketing Available Findings (create), state (bidirectional)
Freshservice Ticketing Available Findings, ticket status, SLA state
Zendesk Ticketing Available Findings, ticket status
Asana Ticketing Available Findings, task status
monday.com Ticketing Available Findings, task status
ClickUp Ticketing Available Findings, task status
BMC Helix ITSM Ticketing Available Findings, CMDB asset records
Slack Communications Available Alerts, daily digests, two-way commands
Microsoft Teams Communications Available Alerts, daily digests
PagerDuty Communications Available Critical alerts only
Google Chat Communications Available Alerts, digests
Mattermost Communications Available Alerts, digests
Cisco Webex Communications Available Alerts, digests
Opsgenie Communications Available Alerts, escalation state
Zapier Workflow Automation Available Webhooks, findings
n8n Workflow Automation Available Webhooks, findings
Microsoft Power Automate Workflow Automation Available Webhooks, findings

Where the work gets tracked — 19 integrations, all of them available today. Statuses as of August 2026.

Atlassian Jira

Category
Ticketing
Status
Available
What it exchanges
Findings (create), state (bidirectional)

ServiceNow ITSM

Category
Ticketing
Status
Available
What it exchanges
Findings (create), CMDB (lookup), state (bidirectional)

Linear

Category
Ticketing
Status
Available
What it exchanges
Findings (create), state (bidirectional)

Freshservice

Category
Ticketing
Status
Available
What it exchanges
Findings, ticket status, SLA state

Zendesk

Category
Ticketing
Status
Available
What it exchanges
Findings, ticket status

Asana

Category
Ticketing
Status
Available
What it exchanges
Findings, task status

monday.com

Category
Ticketing
Status
Available
What it exchanges
Findings, task status

ClickUp

Category
Ticketing
Status
Available
What it exchanges
Findings, task status

BMC Helix ITSM

Category
Ticketing
Status
Available
What it exchanges
Findings, CMDB asset records

Slack

Category
Communications
Status
Available
What it exchanges
Alerts, daily digests, two-way commands

Microsoft Teams

Category
Communications
Status
Available
What it exchanges
Alerts, daily digests

PagerDuty

Category
Communications
Status
Available
What it exchanges
Critical alerts only

Google Chat

Category
Communications
Status
Available
What it exchanges
Alerts, digests

Mattermost

Category
Communications
Status
Available
What it exchanges
Alerts, digests

Cisco Webex

Category
Communications
Status
Available
What it exchanges
Alerts, digests

Opsgenie

Category
Communications
Status
Available
What it exchanges
Alerts, escalation state

Zapier

Category
Workflow Automation
Status
Available
What it exchanges
Webhooks, findings

n8n

Category
Workflow Automation
Status
Available
What it exchanges
Webhooks, findings

Microsoft Power Automate

Category
Workflow Automation
Status
Available
What it exchanges
Webhooks, findings

Where your estate is described

These mostly run inward. Cloud inventory, repository events and code-scanning results come to ShadowMap so that what we observe from outside can be reconciled against what you believe you are running — and the gap between the two is usually the interesting part. Secrets managers run the other way: a key found in a public repository triggers rotation where that workflow exists.

Where your estate is described — 27 integrations, 21 of them available today. Statuses as of August 2026.
IntegrationCategoryStatusWhat it exchanges
AWS Security Hub Cloud Sources Available Cloud asset inventory, findings
Microsoft Defender for Cloud Cloud Sources Available Cloud asset inventory, findings
Google Cloud Security Command Center Cloud Sources Available Cloud asset inventory, findings
AWS Config Cloud Sources Available Resource inventory + drift events
GCP Cloud Asset Inventory Cloud Sources Available Resource inventory
Azure Resource Graph Cloud Sources Available Resource inventory
DigitalOcean Cloud Sources Available Resource inventory
Wiz Cloud Security Posture (CSPM) Planned Cloud findings, attributed inventory (bidirectional)
Bidirectional by design: cloud findings and attributed inventory would move in both directions. It is listed as Planned, which means none of that is wired yet.
Lacework Cloud Security Posture (CSPM) Planned Cloud findings
Orca Security Cloud Security Posture (CSPM) Planned Cloud findings
Prisma Cloud Cloud Security Posture (CSPM) Available Asset inventory, misconfiguration findings
Sysdig Cloud Security Posture (CSPM) Available Asset inventory, findings
Aqua Security Cloud Security Posture (CSPM) Available Asset inventory, findings
GitHub Source Control Available Repo events, secret-scanning hits
GitLab Source Control Available Repo events, secret-scanning hits
Atlassian Bitbucket Source Control Available Repo events, secret-scanning hits
Azure DevOps Source Control Available Repo metadata, secret findings
Snyk DevSecOps Planned SCA + SAST findings
GitHub Advanced Security DevSecOps Planned Secret-scanning hits, code-scanning alerts
Semgrep DevSecOps Planned Code-scan findings
SonarQube DevSecOps Available Findings
Checkmarx DevSecOps Available Findings
Veracode DevSecOps Available Findings
JFrog Xray DevSecOps Available Findings, SBOM data
HashiCorp Vault Secrets Management Available Secret findings, rotation events
AWS Secrets Manager Secrets Management Available Secret findings, rotation events
Azure Key Vault Secrets Management Available Secret findings, rotation events

Where your estate is described — 27 integrations, 21 of them available today. Statuses as of August 2026.

AWS Security Hub

Category
Cloud Sources
Status
Available
What it exchanges
Cloud asset inventory, findings

Microsoft Defender for Cloud

Category
Cloud Sources
Status
Available
What it exchanges
Cloud asset inventory, findings

Google Cloud Security Command Center

Category
Cloud Sources
Status
Available
What it exchanges
Cloud asset inventory, findings

AWS Config

Category
Cloud Sources
Status
Available
What it exchanges
Resource inventory + drift events

GCP Cloud Asset Inventory

Category
Cloud Sources
Status
Available
What it exchanges
Resource inventory

Azure Resource Graph

Category
Cloud Sources
Status
Available
What it exchanges
Resource inventory

DigitalOcean

Category
Cloud Sources
Status
Available
What it exchanges
Resource inventory

Wiz

Category
Cloud Security Posture (CSPM)
Status
Planned
What it exchanges
Cloud findings, attributed inventory (bidirectional)

Bidirectional by design: cloud findings and attributed inventory would move in both directions. It is listed as Planned, which means none of that is wired yet.

Lacework

Category
Cloud Security Posture (CSPM)
Status
Planned
What it exchanges
Cloud findings

Orca Security

Category
Cloud Security Posture (CSPM)
Status
Planned
What it exchanges
Cloud findings

Prisma Cloud

Category
Cloud Security Posture (CSPM)
Status
Available
What it exchanges
Asset inventory, misconfiguration findings

Sysdig

Category
Cloud Security Posture (CSPM)
Status
Available
What it exchanges
Asset inventory, findings

Aqua Security

Category
Cloud Security Posture (CSPM)
Status
Available
What it exchanges
Asset inventory, findings

GitHub

Category
Source Control
Status
Available
What it exchanges
Repo events, secret-scanning hits

GitLab

Category
Source Control
Status
Available
What it exchanges
Repo events, secret-scanning hits

Atlassian Bitbucket

Category
Source Control
Status
Available
What it exchanges
Repo events, secret-scanning hits

Azure DevOps

Category
Source Control
Status
Available
What it exchanges
Repo metadata, secret findings

Snyk

Category
DevSecOps
Status
Planned
What it exchanges
SCA + SAST findings

GitHub Advanced Security

Category
DevSecOps
Status
Planned
What it exchanges
Secret-scanning hits, code-scanning alerts

Semgrep

Category
DevSecOps
Status
Planned
What it exchanges
Code-scan findings

SonarQube

Category
DevSecOps
Status
Available
What it exchanges
Findings

Checkmarx

Category
DevSecOps
Status
Available
What it exchanges
Findings

Veracode

Category
DevSecOps
Status
Available
What it exchanges
Findings

JFrog Xray

Category
DevSecOps
Status
Available
What it exchanges
Findings, SBOM data

HashiCorp Vault

Category
Secrets Management
Status
Available
What it exchanges
Secret findings, rotation events

AWS Secrets Manager

Category
Secrets Management
Status
Available
What it exchanges
Secret findings, rotation events

Azure Key Vault

Category
Secrets Management
Status
Available
What it exchanges
Secret findings, rotation events

Who your people are

Identity is what turns a leaked credential from a string into an account somebody owns. These attach the account, its privilege and its MFA posture to the exposure, and carry the single sign-on and provisioning path into the console.

Who your people are — 10 integrations, all of them available today. Statuses as of August 2026.
IntegrationCategoryStatusWhat it exchanges
Okta Identity Providers Available SSO, SCIM, login events
Microsoft Entra ID Identity Providers Available SSO, SCIM, identity events
Active Directory (legacy) Identity Providers Available Account state, credential checks
Ping Identity Identity Providers Available Identity events, credential exposure
Cisco Duo Identity Providers Available Identity events, credential exposure
JumpCloud Identity Providers Available Identity events
CyberArk IGA / PAM Available Credential exposure events
BeyondTrust IGA / PAM Available Credential exposure events
SailPoint IGA / PAM Available Identity events, credential exposure
Delinea IGA / PAM Available Credential exposure events

Who your people are — 10 integrations, all of them available today. Statuses as of August 2026.

Okta

Category
Identity Providers
Status
Available
What it exchanges
SSO, SCIM, login events

Microsoft Entra ID

Category
Identity Providers
Status
Available
What it exchanges
SSO, SCIM, identity events

Active Directory (legacy)

Category
Identity Providers
Status
Available
What it exchanges
Account state, credential checks

Ping Identity

Category
Identity Providers
Status
Available
What it exchanges
Identity events, credential exposure

Cisco Duo

Category
Identity Providers
Status
Available
What it exchanges
Identity events, credential exposure

JumpCloud

Category
Identity Providers
Status
Available
What it exchanges
Identity events

CyberArk

Category
IGA / PAM
Status
Available
What it exchanges
Credential exposure events

BeyondTrust

Category
IGA / PAM
Status
Available
What it exchanges
Credential exposure events

SailPoint

Category
IGA / PAM
Status
Available
What it exchanges
Identity events, credential exposure

Delinea

Category
IGA / PAM
Status
Available
What it exchanges
Credential exposure events

What already tests, blocks or shares

The tools that already act on the outside world. Scanners and prioritisation platforms, so external and internal findings sit in one backlog. Email security and edge providers, so a look-alike domain we detect becomes something your gateway blocks. Awareness platforms, so an exposed employee identifier seeds your own training list rather than ours. Data-loss controls, so a leaked file can be matched against what you already classify. Intelligence platforms, so indicators leave in a format your CTI function already reads.

What already tests, blocks or shares — 25 integrations, 14 of them available today. Statuses as of August 2026.
IntegrationCategoryStatusWhat it exchanges
Tenable Vulnerability Management Planned Vulnerability data (one-way: VM → SM)
What arrives from a scanner is output, not a verdict. Continuous Automated Red-Teaming tests exploitability only where testing is safe and authorised; anything outside that scope stays marked as untested rather than assumed clean. The same qualifier applies to every vulnerability-management row here.
Qualys VMDR Vulnerability Management Planned Vulnerability data
Rapid7 InsightVM Vulnerability Management Planned Vulnerability data
Nucleus Security Vulnerability Management Available Findings, validation evidence
Vulcan Cyber Vulnerability Management Available Findings, validation evidence
Proofpoint Email Security Planned Look-alike domain feed (one-way: SM → Proofpoint)
Mimecast Email Security Planned Look-alike domain feed
Abnormal Security Email Security Planned Look-alike domain feed, executive-impersonation watchlist
KnowBe4 Phishing Simulation Planned Target-list seeding (SM → KnowBe4), campaign outcomes back
Listed as Planned, so none of this is wired yet. Built, it is seeding only: exposed employee identifiers would become the target list for your own awareness programme, and the result would come back as context on the exposed account — ShadowMap does not run the campaign.
Cofense Phishing Simulation Planned Target-list seeding (SM → Cofense), campaign outcomes back
MISP Threat Intel Sharing Beta IoCs (bidirectional)
Counted as available because it runs with customers today, and labelled Beta rather than quietly promoted — the configuration surface is still settling.
Anomali ThreatStream Threat Intel Sharing Planned IoCs
OpenCTI Threat Intel Sharing Available STIX objects, IoCs
ThreatConnect Threat Intel Sharing Available STIX objects, IoCs
VirusTotal Threat Intel Sharing Available IoC enrichment
EclecticIQ Threat Intel Sharing Available STIX objects, IoCs
Cloudflare WAF / CDN Planned Asset metadata, abuse reports
Akamai WAF / CDN Planned Asset metadata, abuse reports
Imperva WAF / CDN Available Asset metadata, abuse reports
Fastly WAF / CDN Available Asset metadata
AWS WAF WAF / CDN Available Asset metadata
F5 WAF / CDN Available Asset metadata
Netskope CASB / DLP Available Data exposure findings
Zscaler CASB / DLP Available Data exposure findings, IoCs
Forcepoint CASB / DLP Available Data exposure findings

What already tests, blocks or shares — 25 integrations, 14 of them available today. Statuses as of August 2026.

Tenable

Category
Vulnerability Management
Status
Planned
What it exchanges
Vulnerability data (one-way: VM → SM)

What arrives from a scanner is output, not a verdict. Continuous Automated Red-Teaming tests exploitability only where testing is safe and authorised; anything outside that scope stays marked as untested rather than assumed clean. The same qualifier applies to every vulnerability-management row here.

Qualys VMDR

Category
Vulnerability Management
Status
Planned
What it exchanges
Vulnerability data

Rapid7 InsightVM

Category
Vulnerability Management
Status
Planned
What it exchanges
Vulnerability data

Nucleus Security

Category
Vulnerability Management
Status
Available
What it exchanges
Findings, validation evidence

Vulcan Cyber

Category
Vulnerability Management
Status
Available
What it exchanges
Findings, validation evidence

Proofpoint

Category
Email Security
Status
Planned
What it exchanges
Look-alike domain feed (one-way: SM → Proofpoint)

Mimecast

Category
Email Security
Status
Planned
What it exchanges
Look-alike domain feed

Abnormal Security

Category
Email Security
Status
Planned
What it exchanges
Look-alike domain feed, executive-impersonation watchlist

KnowBe4

Category
Phishing Simulation
Status
Planned
What it exchanges
Target-list seeding (SM → KnowBe4), campaign outcomes back

Listed as Planned, so none of this is wired yet. Built, it is seeding only: exposed employee identifiers would become the target list for your own awareness programme, and the result would come back as context on the exposed account — ShadowMap does not run the campaign.

Cofense

Category
Phishing Simulation
Status
Planned
What it exchanges
Target-list seeding (SM → Cofense), campaign outcomes back

MISP

Category
Threat Intel Sharing
Status
Beta
What it exchanges
IoCs (bidirectional)

Counted as available because it runs with customers today, and labelled Beta rather than quietly promoted — the configuration surface is still settling.

Anomali ThreatStream

Category
Threat Intel Sharing
Status
Planned
What it exchanges
IoCs

OpenCTI

Category
Threat Intel Sharing
Status
Available
What it exchanges
STIX objects, IoCs

ThreatConnect

Category
Threat Intel Sharing
Status
Available
What it exchanges
STIX objects, IoCs

VirusTotal

Category
Threat Intel Sharing
Status
Available
What it exchanges
IoC enrichment

EclecticIQ

Category
Threat Intel Sharing
Status
Available
What it exchanges
STIX objects, IoCs

Cloudflare

Category
WAF / CDN
Status
Planned
What it exchanges
Asset metadata, abuse reports

Akamai

Category
WAF / CDN
Status
Planned
What it exchanges
Asset metadata, abuse reports

Imperva

Category
WAF / CDN
Status
Available
What it exchanges
Asset metadata, abuse reports

Fastly

Category
WAF / CDN
Status
Available
What it exchanges
Asset metadata

AWS WAF

Category
WAF / CDN
Status
Available
What it exchanges
Asset metadata

F5

Category
WAF / CDN
Status
Available
What it exchanges
Asset metadata

Netskope

Category
CASB / DLP
Status
Available
What it exchanges
Data exposure findings

Zscaler

Category
CASB / DLP
Status
Available
What it exchanges
Data exposure findings, IoCs

Forcepoint

Category
CASB / DLP
Status
Available
What it exchanges
Data exposure findings

The escape hatch

If it is not in the table, it goes through the API

A catalogue is a finite list and your stack is not. Everything the rows above move — findings with their evidence, discovered assets and inventory records, indicators, and the state of a case — is reachable over the API, and the same events that drive a channel alert can be pushed to any endpoint you control. Nothing on this page is gated behind having picked a vendor we happen to have wired.

01 Pull and write back

The read-and-write API

What is reachable
The same objects the catalogue moves: findings and the evidence attached to them, discovered assets and inventory records, indicators, and the state of a case or a ticket. If a built-in integration can send it, the API can hand it to you.
Both directions, which is the part that matters
It is not an export. State written back — an acknowledgement, an owner, a closure — lands on the item itself, which is what stops the queue in your tooling and the queue in ShadowMap from quietly diverging over a quarter.
What is deliberately not on this page
Endpoints, authentication and payload schemas are not published here. Ask for the API documentation during evaluation — that is a better use of a technical call than a marketing page impersonating a reference manual.
02 Push

Webhooks, for anything that has to be immediate

What fires
A new finding, and a change of state on one you have already seen. It is the same trigger the alerting integrations above are built on; the destination is the only difference between a channel message and your own endpoint.
Where teams actually reach for it
Self-hosted automation where data residency rules out a SaaS workflow tool, and internal systems that were never going to appear in anybody’s catalogue. Two rows above — n8n and Mattermost — are in the list for exactly that reason.
Where a built-in still wins
A webhook hands you the event. A built-in integration hands it over already shaped the way the receiving tool expects it — CEF for QRadar, ECS for Elastic, a Jira issue with an owner on it. Where we ship one, take it; the API is for where we do not.

What is actually moving

Which capability each integration is carrying, and in which direction

An integration is only interesting because of what sits on the other end of it. This is the catalogue read the other way round — by the capability generating the signal rather than the vendor receiving it — and it is the honest way to answer whether a connector is worth configuring. Direction is stated on every row, because plenty of these run one way only and a page that implied otherwise would be found out in the first deployment call.

Each capability, the signal it puts on the wire, and the integration categories that carry it. Capability names link through to what each one does.
CapabilityWhat leaves ShadowMapWhat comes backCategories that carry it
Attack Surface Management Discovered internet-facing assets and services, origin infrastructure found sitting behind an edge, and asset-change events as they happen. Cloud and posture inventory, edge and load-balancer metadata, and CMDB records — so what we see from outside can be reconciled against what you believe you run. Cloud Sources · CSPM · WAF / CDN · Ticketing
Dark Web Monitoring Credential-exposure events and compromised-device signals, each credential carrying the state it was left in. Identity events, MFA posture and privileged-account context, so an exposed string resolves to an account somebody is accountable for. SIEM · EDR / XDR · Identity Providers · IGA / PAM
Data Exposure Monitoring Secrets and source found in public repositories, exposed storage objects, and indexed documents attributed to an owner. Repository and pipeline events, secret-scanning hits, and application-testing findings against the same codebase. Source Control · DevSecOps · Secrets Management · CASB / DLP
Domain Monitoring Look-alike, typosquatted and permutation registrations, as a domain feed your gateway and edge can act on directly. Edge and hosting metadata, which is often what establishes who is actually serving a look-alike. Email Security · WAF / CDN
Brand Protection Impersonating profiles, cloned listings and an executive-impersonation watchlist, in the form the receiving control can block on. Little, and by design — detection happens on our side, and the value is entirely in what your controls do with it. Email Security
Phishing and Domain Takedown Case state as a notice moves between counterparties, with the evidence pack attached to it. Abuse-report acknowledgements from edge and hosting providers. SOAR · Ticketing · Communications · WAF / CDN
Every state a case can close in is published, including the three that close without one: takedown denied, counter notice received, dismissed. None of them is ever counted as a removal.
Continuous Automated Red-Teaming Validation evidence — what was tested, what it opened, and the scope it was tested under. Vulnerability-scanner findings and cloud misconfiguration findings, which is the material there is to validate. Vulnerability Management · CSPM
Validation runs where it is safe and authorised. Anything outside that scope leaves the platform marked as not tested — never as clean.
Threat Intelligence Indicators, and structured actor, campaign and malware objects in the exchange formats a CTI platform already ingests. Community and commercial intelligence, and enrichment of infrastructure we have already observed on your estate. Threat Intel Sharing · SIEM

Each capability, the signal it puts on the wire, and the integration categories that carry it. Capability names link through to what each one does.

Attack Surface Management

What leaves ShadowMap
Discovered internet-facing assets and services, origin infrastructure found sitting behind an edge, and asset-change events as they happen.
What comes back
Cloud and posture inventory, edge and load-balancer metadata, and CMDB records — so what we see from outside can be reconciled against what you believe you run.
Categories that carry it
Cloud Sources · CSPM · WAF / CDN · Ticketing

Dark Web Monitoring

What leaves ShadowMap
Credential-exposure events and compromised-device signals, each credential carrying the state it was left in.
What comes back
Identity events, MFA posture and privileged-account context, so an exposed string resolves to an account somebody is accountable for.
Categories that carry it
SIEM · EDR / XDR · Identity Providers · IGA / PAM

Data Exposure Monitoring

What leaves ShadowMap
Secrets and source found in public repositories, exposed storage objects, and indexed documents attributed to an owner.
What comes back
Repository and pipeline events, secret-scanning hits, and application-testing findings against the same codebase.
Categories that carry it
Source Control · DevSecOps · Secrets Management · CASB / DLP

Domain Monitoring

What leaves ShadowMap
Look-alike, typosquatted and permutation registrations, as a domain feed your gateway and edge can act on directly.
What comes back
Edge and hosting metadata, which is often what establishes who is actually serving a look-alike.
Categories that carry it
Email Security · WAF / CDN

Brand Protection

What leaves ShadowMap
Impersonating profiles, cloned listings and an executive-impersonation watchlist, in the form the receiving control can block on.
What comes back
Little, and by design — detection happens on our side, and the value is entirely in what your controls do with it.
Categories that carry it
Email Security

Phishing and Domain Takedown

What leaves ShadowMap
Case state as a notice moves between counterparties, with the evidence pack attached to it.
What comes back
Abuse-report acknowledgements from edge and hosting providers.
Categories that carry it
SOAR · Ticketing · Communications · WAF / CDN

Every state a case can close in is published, including the three that close without one: takedown denied, counter notice received, dismissed. None of them is ever counted as a removal.

Continuous Automated Red-Teaming

What leaves ShadowMap
Validation evidence — what was tested, what it opened, and the scope it was tested under.
What comes back
Vulnerability-scanner findings and cloud misconfiguration findings, which is the material there is to validate.
Categories that carry it
Vulnerability Management · CSPM

Validation runs where it is safe and authorised. Anything outside that scope leaves the platform marked as not tested — never as clean.

Threat Intelligence

What leaves ShadowMap
Indicators, and structured actor, campaign and malware objects in the exchange formats a CTI platform already ingests.
What comes back
Community and commercial intelligence, and enrichment of infrastructure we have already observed on your estate.
Categories that carry it
Threat Intel Sharing · SIEM

A row above tends to be receiving from more than one of these at once, and that is the point rather than a coincidence: the capabilities run on one correlated exposure model, so a ticket raised from an exposed key already carries the asset it belongs to and whether anything tested it. How that fits together is on the platform overview; the counterparties a takedown case is actually filed with are listed in the provider directory.

Derivation

Where the numbers came from, and what is deliberately not here

One count carries this whole page, so it gets its working shown. It is worth showing because we have already got it wrong: three ShadowMap pages once published three different figures for the same thing, each of them typed by a different person on a different day.

Integration counts — how they are derived, and what is left out As of August 2026
  • Every figure on this page is computed from the catalogue at build time. None of them is typed into a sentence, which is the only reliable defence against the three-pages-three-numbers failure that prompted the rule.
  • Available today is the Available and Beta rows counted together. Planned is counted separately, published by name, and never added to the headline to make it look larger.
  • The grouping above is asserted against the catalogue when the page builds: a category added to the data and not placed in a group here fails the build rather than disappearing. That failure has already happened elsewhere — four categories were missing from the platform grid, and every integration inside them rendered on no page at all.
  • A vendor appears here because we have committed to delivering it. That commitment is what makes it legitimate to publish the roadmap rows by name, and the reason they carry Planned rather than a softer word.

Deliberately excluded

  • No vendor logos. A logo wall implies a partnership that a status column does not, and it is exactly why integration pages are so hard to plan a deployment against.
  • No endpoint reference, authentication scheme or payload schema. Those belong in the API documentation issued during evaluation, where they can be read in full and kept current.
  • No delivery timeframe on the Planned rows. The commitment behind them is real and it is made in the room — a figure on a marketing page is the one number a customer could later hold a contract up against, which is a lesson this site has already learned once.
  • No claim that this is everything you run. It is the set we have wired or committed to wire; anything outside it goes through the API and webhooks above, which is a genuine route rather than a polite way of saying no.

See what these integrations would actually be carrying

One apex domain, two business days, a written snapshot of what is exposed — the same findings that would land in your SIEM, your tracker and your channel on day one.