Integrations
Connects to yourexisting stack.
SIEM, single sign-on, alerts, cloud APIs and exports. CISGuard fits into the infrastructure you run today, and every integration is included in every tier.
- SIEM transports
- Syslog over UDP, TCP and TLS, CEF, JSON over HTTPS, Azure Log Analytics, Grafana Loki
- Identity
- SAML 2.0, Microsoft Entra ID, LDAP and Active Directory, TOTP multi-factor
- Alerts
- Email over SMTP or Microsoft Graph, and HMAC-signed webhooks
- Cloud and clusters
- Azure, AWS, Microsoft 365, Kubernetes, AKS, EKS, OpenShift
- Exports
- PDF, HTML, JSON, CSV and SARIF
- Licensing
- Every integration in every tier, no add-on modules
SIEM and security operations
Every compliance event, in the monitoring you already run.
Seven transports, fanned out in parallel to every destination you enable. Scan results, drift events, exception decisions and administrative actions all forward.
Syslog (RFC 5424)
UDP, TCP and TLS transports. Works with Splunk, Microsoft Sentinel, QRadar, ArcSight and Graylog.
CEF
ArcSight-standard Common Event Format over syslog, with the CIS control carried in the severity and name fields.
JSON over HTTPS
Structured events posted to any HTTPS endpoint you run, authenticated with a token you control.
Azure Log Analytics
Direct ingestion into your Log Analytics workspace for Microsoft Sentinel and KQL.
Grafana Loki
Events pushed straight into Loki for Grafana dashboards and alerting.
Identity and access
Your identity provider, your roles, your network.
Single sign-on and directory integration, with role-based access for administrators, compliance managers and auditors.
Microsoft Entra ID
Sign in with your Entra tenant. Tenant validation and token refresh are handled for you.
SAML 2.0
Works with Okta, AD FS, PingIdentity, OneLogin and any SAML 2.0 identity provider.
LDAP and Active Directory
Bind-and-search authentication with just-in-time provisioning and directory role mapping.
Multi-factor (TOTP)
Time-based one-time passwords with recovery codes and replay protection, enforced per policy.
Role-based access
Administrator, compliance manager and auditor roles. Auditors see reports and evidence without changing anything.
IP allowlists
Restrict dashboard access to the networks you approve.
Alerts and notifications
Know the moment posture changes.
Alert rules fire on compliance drops, new failures, critical failures and regressions, and route to the channels you choose.
Email
HTML alerts and scheduled reports over your own SMTP server or Microsoft Graph, from your own sender address.
Webhooks
JSON posted to any endpoint with an HMAC-SHA256 signature, so the receiver can verify every payload.
Alert rules
Compliance drop thresholds, new failure, critical failure and regression conditions, each routed per channel.
Delivery retries
Failed deliveries are retried, then kept with the failure reason so an operator can resend them.
Cloud and Kubernetes
Agentless scanning through native APIs.
Cloud resources and clusters are assessed through their own control planes, alongside the agent on every endpoint.
Microsoft Azure
Azure Resource Manager scanning for the Azure Foundations, Compute and AKS benchmarks, using client credentials.
Amazon Web Services
AWS Foundations and EKS scanning with an access key or an assumed role.
Microsoft 365
Microsoft Graph scanning of Exchange Online, SharePoint, Teams and Entra ID policies.
Kubernetes and OpenShift
API-server scanning with a bearer token and CA certificate. Self-managed clusters, AKS, EKS and OpenShift.
Reports and exports
Evidence leaves in the format the next system wants.
Reports on demand or on a schedule, and machine-readable exports for GRC tools, spreadsheets and pipelines.
PDF and HTML reports
Executive summary, detailed compliance and gap analysis reports, generated on demand or on a schedule.
CSV and JSON
Framework coverage and control results as RFC 4180 CSV or JSON for GRC tools and spreadsheets.
SARIF
SARIF 2.1.0 exports that drop into CI/CD pipelines and code-scanning dashboards.
Scheduled reports
Recurring executive and coverage reports emailed to the people who need them.
Need a custom integration?
Signed webhooks and JSON over HTTPS reach any endpoint you run. Talk to our engineers about the connector you need.