REST API + webhooks
Endpoints for IoCs, alerts, breach hits, lookalikes. Webhooks for push (better latency than polling).
Threat Intel · Sub-capability
Integrate our threat intel with your SIEM/SOAR: Splunk, Microsoft Sentinel, Cortex XSOAR, Elastic, Chronicle. STIX/TAXII standard + REST + webhooks. No proprietary lock-in.
Endpoints for IoCs, alerts, breach hits, lookalikes. Webhooks for push (better latency than polling).
Standard TAXII server for SIEMs preferring the industry-standard protocol. Splunk + IBM QRadar + ArcSight out-of-the-box.
Cortex XSOAR (Palo Alto), Splunk SOAR, Microsoft Sentinel logic apps, Elastic SIEM, Chronicle (Google). 15-minute setup.
Streamed feeds (websocket) for production + batch endpoints for enriching historical logs. Same data, different delivery.
Per-team API keys with independent rate limits. Audit log of which team consumes which feed.
OpenAPI spec + Postman collection + sample integrations on GitHub. No "contact us for the schema".