Docs

Integrations

Connect your existing security tools and cloud services to Zaun.

Zaun integrates with your existing infrastructure via APIs, webhooks, and the Zaun agent. Your Forward Deployed Engineer (FDE) helps you set up and configure each integration during onboarding, feeding both Reagent (AI Adoption Security) and Ember (Agentic Security Operations).

The full catalog below is the source of truth for what's connectable today. Detailed setup guides for each category live under Integration Setup Guides in the left nav.

Identity / Access Management

IntegrationWhat it does
OktaWorkforce identity provider. Zaun watches sign-ins, MFA changes, OAuth grants, role assignments, and admin actions.
Microsoft GraphTenant-wide events from the Microsoft 365 graph: Entra (Azure AD), conditional access, and risky users.
Microsoft Entra IDIdentity-side coverage for Entra: directory changes, group membership, privileged role activation.
Active DirectoryOn-prem AD events streamed via the Zaun agent: domain authentications, group writes, GPO changes.
Cisco DuoMulti-factor auth telemetry: bypass codes, factor enrollment, admin events.
Ping IdentityPingOne workforce identity events: sign-ins, risk signals, admin actions.
Auth0Customer identity events from Auth0 tenants: logins, anomalous geo / device, tenant config changes.
Jamf ProApple device management and identity binding: enrollment, profile drift, user binding.
1PasswordVault and item events from 1Password Business.
BitwardenPassword manager events and admin trail.

See Identity / Access Management for setup steps.

Cloud Security

IntegrationWhat it does
AWSCloudTrail, Config, GuardDuty, IAM, and resource activity across every region. Streamed via Kinesis.
AzureAzure Monitor activity logs and Defender for Cloud signals across subscriptions.
Google CloudGCP audit logs, Security Command Center, and IAM events.
CloudflareZero Trust access logs, WAF events, R2 audit, and account-level activity.
WizCloud Security findings, toxic combinations, and exposure paths.
DatadogAudit trail and security signals stream into Zaun Lake.
FastlyCDN access logs and Next-Gen WAF events.
AkamaiAkamai SIEM events: WAF, bot manager, and DDoS alerts.
UpwindCloud-native runtime security and CDR events.

See Cloud Security for setup steps.

EDR / Endpoint Protection

IntegrationWhat it does
CrowdStrike FalconEndpoint detections, host inventory, and real-time response sessions.
SentinelOneSingularity threats, host posture, and Storyline activity.
Microsoft DefenderDefender for Endpoint alerts, vuln status, ASR rules.
Trend Micro Vision OneXDR alerts and workbench events from Vision One.
Bitdefender EDRBitdefender endpoint detections and incidents.
Sophos EDREndpoint detections and managed threat response signals.
ESET ProtectESET endpoint detections and policy events.
Fortinet EDRFortiEDR detections and response actions.
QRadar EDRIBM Reaqta endpoint events.
Webroot EDRWebroot endpoint detections.
Cisco Secure EndpointCisco AMP for Endpoints events and outbreak controls.
Jamf ProtectmacOS-native EDR signals from Jamf Protect.
WatchGuard EDRPanda / WatchGuard EDR detections and isolation.
ThreatLockerApplication allowlisting and ringfencing events.
osqueryOpen-source host telemetry. The Zaun agent streams osquery results into Zaun Lake.
AddigymacOS device management telemetry.
AutomoxPatch and configuration management events.
HalcyonAnti-ransomware platform events.

See EDR / Endpoint Protection for setup steps.

Firewalls / Network Security

IntegrationWhat it does
Palo Alto FirewallPAN-OS traffic, threat, URL, and config logs.
FortiGate FirewallFortiGate event, traffic, and security logs.
Cisco FirepowerFirepower threat intel, intrusion, and access logs.
Cisco MerakiMeraki MX security and event log streams.
Cisco UmbrellaDNS-layer security events.
Sophos FirewallSophos XGS firewall events.
Juniper SRXSRX security and traffic events.
WatchGuard FirewallWatchGuard Firebox events.
SonicWallSonicOS security and traffic logs.
Zscaler ZIAZIA web access, sandbox, and DLP events.
NetskopeSASE / CASB events and DLP findings.
Cato NetworksSASE platform events and threat detection.

See Firewalls / Network Security for setup steps.

Email Security

IntegrationWhat it does
Abnormal SecurityBEC, account takeover, and attack detection signals from Abnormal.
Proofpoint TAPTargeted Attack Protection threat events and clicks.
Sublime SecurityDetection-as-code email security events.
ExchangeMailbox and transport telemetry from Exchange / EXO.

See Email Security for setup steps.

SaaS & Productivity

IntegrationWhat it does
Google WorkspaceDrive sharing, admin console, login challenges, OAuth tokens, and audit log.
Microsoft 365Unified audit log: SharePoint, Teams, OneDrive, mailbox.
Microsoft TeamsTeams admin and message-level events.
SlackSlack Enterprise audit log: token leaks, app installs, public channel changes.
ZoomZoom account events and meeting telemetry.
BoxBox content and admin events.
GitHubGitHub org audit log: visibility flips, deploy keys, secret scanning.
AtlassianJira & Confluence audit and Atlassian Guard signals.
SalesforceSalesforce admin and API audit telemetry.
WorkdayHRIS events for joiner / mover / leaver context.

SaaS Security

IntegrationWhat it does
Obsidian SecuritySaaS posture and identity threat detection across third-party apps.
Grip SecuritySaaS Security Posture Management events.
KnowBe4Phishing simulation and training results.

AI Security

IntegrationWhat it does
OpenAIOrg-level audit log: API key creation, model access, project changes.
AnthropicOrg admin events, key usage, and model invocation telemetry.
Claude CodeCoding-agent activity from Claude Code installations.
CursorCursor IDE telemetry: prompts, agent runs, and shared sessions.
GleanEnterprise search and assistant telemetry.

SIEM / XDR

IntegrationWhat it does
SplunkForward Zaun investigations to Splunk and pull saved searches on demand.
Microsoft SentinelSentinel incidents and analytics rules.
Azure SentinelSentinel incident routing across workspaces.
CrowdStrike NG-SIEMFalcon NG-SIEM detections and saved searches.
Cortex XSIAMCortex XSIAM alerts and analytics.
IBM QRadarQRadar offenses and search forwarding.
Sumo LogicSumo Cloud SIEM signals.
DevoDevo data lake forwarding.
PantherPanther alerts and detections.
Stellar CyberStellar Cyber alerts and case data.
ExpelExpel alerts forwarded into Zaun investigations.
OpenSearchPull from OpenSearch indices on demand.
ElasticsearchPull from Elasticsearch on demand.
AlienVault OTXOTX pulse and indicator data.

See SIEM / XDR for setup steps.

Data Platforms

IntegrationWhat it does
SnowflakeSnowflake account usage, login history, and warehouse access.
BigQueryBigQuery audit telemetry: job audit, dataset access.
ClickHouseClickHouse query logs and cluster events.
PostgreSQLPostgres audit and pgAudit events.

Vulnerability Management

IntegrationWhat it does
TenableTenable Vulnerability Management findings.
Rapid7 IDRRapid7 incident detection and response findings.
QualysQualys VMDR vulnerabilities and asset posture.

Threat Intelligence

IntegrationWhat it does
VulnCheckExploit prioritization and threat intelligence feeds.
VirusTotalFile and URL reputation lookups during enrichment.
ShodanExternal attack surface and exposed-asset enrichment.
DeHashedCredential exposure lookups during identity investigations.
CywareThreat intel sharing and IOC feeds.

See Threat Intelligence for setup steps.

Ticketing / Workflow

IntegrationWhat it does
PagerDutyPage on-call when an investigation needs human attention.
ServiceNowOpen and update ServiceNow tickets from a runbook.
JiraOpen Jira issues with full investigation context.
ZendeskCustomer support ticketing integration.
FreshserviceIT service management ticketing.
FreshdeskCustomer support ticketing.
SwimlaneForward investigations into Swimlane SOAR cases.
WorkatoTrigger Workato recipes from a runbook.

See PSA / Ticketing and SOAR / Incident Response for setup steps.

RMM / MSP Tools

IntegrationWhat it does
ConnectWise PSAMulti-tenant ConnectWise PSA telemetry.
ConnectWise ASIOConnectWise ASIO automation events.
ConnectWise RMMConnectWise RMM endpoint events.
Datto RMMDatto RMM agent events and policies.
Kaseya VSA XKaseya VSA X endpoint and patch events.
N-able N-centralN-central monitoring and remediation.
N-able N-sightN-sight monitoring events.
NinjaOneNinjaOne endpoint management telemetry.
PulsewayPulseway monitoring and automation.
SyncroMSPSyncroMSP endpoint and ticket events.
SuperOpsSuperOps RMM / PSA telemetry.
AutotaskDatto Autotask PSA telemetry.
AteraAtera monitoring events.
HaloPSAHaloPSA service desk telemetry.

See RMM / Endpoint Management for setup steps.

Backup / Storage

IntegrationWhat it does
Afi BackupSaaS data backup and recovery events.

Developer Tools / DFIR

IntegrationWhat it does
DFIR-IRISOpen-source incident response case management.
CoworkCowork agent telemetry: tool calls, tasks, and shared sessions.

Setting Up an Integration

Using the CLI

# Add an AWS integration
zaun integrations add aws \
  --account-id 123456789012 \
  --role-arn arn:aws:iam::123456789012:role/ZaunSecurityAudit \
  --regions us-east-1,us-west-2

# Add an Okta integration
zaun integrations add okta \
  --domain your-company.okta.com \
  --api-token $OKTA_API_TOKEN

# List all integrations
zaun integrations list

# Test an integration
zaun integrations test aws --account-id 123456789012

Using the Dashboard

  1. Navigate to Settings → Integrations
  2. Click Add Integration
  3. Select your platform and follow the setup wizard
  4. Zaun verifies the connection and begins surfacing findings and detections

Data Flow

Your Infrastructure → Zaun Integration Layer → Zaun Lake → Detection Engine
     (APIs)              (Normalization)        (Storage)    (Analysis)

All data is:

  • Encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Stored in your dedicated Zaun Lake instance
  • Subject to your configured retention policies
  • Accessible via the investigation console

Don't see your tool?

The catalog grows continuously. If something you rely on isn't listed, we can usually add it via Zaun's generic webhook ingest, syslog forwarder, or a custom collector. Email [email protected] with the platform name and use case.