Skip to main content

Integrations

Connects to yourexisting stack.

SIEM, single sign-on, alerts, cloud APIs and exports. CISGuard fits into the infrastructure you run today, and every integration is included in every tier.

SIEM transports
Syslog over UDP, TCP and TLS, CEF, JSON over HTTPS, Azure Log Analytics, Grafana Loki
Identity
SAML 2.0, Microsoft Entra ID, LDAP and Active Directory, TOTP multi-factor
Alerts
Email over SMTP or Microsoft Graph, and HMAC-signed webhooks
Cloud and clusters
Azure, AWS, Microsoft 365, Kubernetes, AKS, EKS, OpenShift
Exports
PDF, HTML, JSON, CSV and SARIF
Licensing
Every integration in every tier, no add-on modules

SIEM and security operations

Every compliance event, in the monitoring you already run.

Seven transports, fanned out in parallel to every destination you enable. Scan results, drift events, exception decisions and administrative actions all forward.

  • Syslog (RFC 5424)

    UDP, TCP and TLS transports. Works with Splunk, Microsoft Sentinel, QRadar, ArcSight and Graylog.

  • CEF

    ArcSight-standard Common Event Format over syslog, with the CIS control carried in the severity and name fields.

  • JSON over HTTPS

    Structured events posted to any HTTPS endpoint you run, authenticated with a token you control.

  • Azure Log Analytics

    Direct ingestion into your Log Analytics workspace for Microsoft Sentinel and KQL.

  • Grafana Loki

    Events pushed straight into Loki for Grafana dashboards and alerting.

Identity and access

Your identity provider, your roles, your network.

Single sign-on and directory integration, with role-based access for administrators, compliance managers and auditors.

  • Microsoft Entra ID

    Sign in with your Entra tenant. Tenant validation and token refresh are handled for you.

  • SAML 2.0

    Works with Okta, AD FS, PingIdentity, OneLogin and any SAML 2.0 identity provider.

  • LDAP and Active Directory

    Bind-and-search authentication with just-in-time provisioning and directory role mapping.

  • Multi-factor (TOTP)

    Time-based one-time passwords with recovery codes and replay protection, enforced per policy.

  • Role-based access

    Administrator, compliance manager and auditor roles. Auditors see reports and evidence without changing anything.

  • IP allowlists

    Restrict dashboard access to the networks you approve.

Alerts and notifications

Know the moment posture changes.

Alert rules fire on compliance drops, new failures, critical failures and regressions, and route to the channels you choose.

  • Email

    HTML alerts and scheduled reports over your own SMTP server or Microsoft Graph, from your own sender address.

  • Webhooks

    JSON posted to any endpoint with an HMAC-SHA256 signature, so the receiver can verify every payload.

  • Alert rules

    Compliance drop thresholds, new failure, critical failure and regression conditions, each routed per channel.

  • Delivery retries

    Failed deliveries are retried, then kept with the failure reason so an operator can resend them.

Cloud and Kubernetes

Agentless scanning through native APIs.

Cloud resources and clusters are assessed through their own control planes, alongside the agent on every endpoint.

  • Microsoft Azure

    Azure Resource Manager scanning for the Azure Foundations, Compute and AKS benchmarks, using client credentials.

  • Amazon Web Services

    AWS Foundations and EKS scanning with an access key or an assumed role.

  • Microsoft 365

    Microsoft Graph scanning of Exchange Online, SharePoint, Teams and Entra ID policies.

  • Kubernetes and OpenShift

    API-server scanning with a bearer token and CA certificate. Self-managed clusters, AKS, EKS and OpenShift.

Reports and exports

Evidence leaves in the format the next system wants.

Reports on demand or on a schedule, and machine-readable exports for GRC tools, spreadsheets and pipelines.

  • PDF and HTML reports

    Executive summary, detailed compliance and gap analysis reports, generated on demand or on a schedule.

  • CSV and JSON

    Framework coverage and control results as RFC 4180 CSV or JSON for GRC tools and spreadsheets.

  • SARIF

    SARIF 2.1.0 exports that drop into CI/CD pipelines and code-scanning dashboards.

  • Scheduled reports

    Recurring executive and coverage reports emailed to the people who need them.

Need a custom integration?

Signed webhooks and JSON over HTTPS reach any endpoint you run. Talk to our engineers about the connector you need.