A different stack at every customer. One operating system.
Connect endpoint, identity, cloud, network, email, OT and business context. CYREBRO handles parsing, normalization and enrichment across a diverse vendor ecosystem.
267 vendors.
29 categories.
Broader context.
Correlate the endpoint alert with identity activity, cloud events, email, physical access or operational technology. The attack story can cross every one of them.
Keep your customer’s security investments
Existing EDR, firewall, cloud and identity tools continue to protect the environment and provide telemetry.
Normalize before you reason
Parsing and enrichment turn diverse raw logs into contextualized data for detection and investigation.
Go beyond a standard connector list
Evaluate custom, unusual and non-English sources with the technical team during onboarding.
Explore the mapped telemetry sources.
267 mapped vendors across 29 categories
Identity & Access Management (IAM) / Directory Services
- Microsoft Entra ID (Azure AD)
- Okta
- Active Directory (on-prem)
- Ping Identity
- CyberArk Identity
- SailPoint
- Duo Security (Cisco)
- Auth0 (Okta)
- ForgeRock (Ping Identity)
- AWS IAM
- Google Cloud Identity / Workspace
- OneLogin
- JumpCloud
- IBM Security Verify
- Oracle Identity Cloud Service
- RSA SecurID
- Beyond Identity
- Saviynt
- Yubico (YubiKey MFA)
DNS Security
- Cisco Umbrella
- Infoblox
- Cloudflare Gateway
- Palo Alto Networks DNS Security
- Akamai Enterprise Threat Protector
- Zscaler
- BlueCat
- EfficientIP
- DNSFilter
Container / Kubernetes Security
- Wiz
- Aqua Security
- Sysdig
- Palo Alto Networks Prisma Cloud
- CrowdStrike Falcon Cloud Security
- Red Hat Advanced Cluster Security (StackRox)
- Snyk
- Trend Micro Cloud One Container Security
Physical Security / Badge Access (correlate physical + logical access)
- HID Global
- Lenel (Carrier)
- Genetec
- Verkada
- Honeywell
- Motorola Solutions (Openpath)
Cloud Billing & Cost Management (resource-abuse / cryptomining signals)
- AWS Cost Explorer
- Azure Cost Management
- Google Cloud Billing
- CloudHealth (Broadcom)
- Apptio Cloudability
Privileged Access Management (PAM)
- CyberArk
- BeyondTrust
- Delinea (Thycotic + Centrify)
- HashiCorp Vault
- One Identity
- Saviynt
- WALLIX
- ARCON
- senhasegura
- Broadcom Symantec PAM
Cloud Security Posture Management (CSPM) / CNAPP
- Wiz
- Palo Alto Networks Prisma Cloud
- Orca Security
- CrowdStrike Falcon Cloud Security
- Microsoft Defender for Cloud
- Aqua Security
- Sysdig
- Lacework (Fortinet)
- Check Point CloudGuard
- Tenable Cloud Security
- Rapid7 InsightCloudSec
- Trend Micro Cloud One
Data Loss Prevention (DLP)
- Microsoft Purview DLP
- Broadcom Symantec DLP
- Forcepoint DLP
- Proofpoint DLP
- Digital Guardian (Fortra)
- Trellix DLP
- Netskope DLP
- Zscaler DLP
- Code42 Incydr
- Varonis
Backup / Ransomware Detection Signals
- Veeam
- Rubrik
- Cohesity
- Commvault
- Druva
- Veritas NetBackup
DevOps / CI-CD & Source Code Repositories (supply-chain & insider investigations)
- GitHub
- GitLab
- Bitbucket (Atlassian)
- Jenkins
- Azure DevOps
- CircleCI
- JFrog Artifactory
Endpoint Detection & Response (EDR) / EPP
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
- SentinelOne
- Palo Alto Networks Cortex XDR
- Sophos Intercept X
- Trend Micro Vision One
- Trellix (McAfee + FireEye)
- VMware Carbon Black
- Cisco Secure Endpoint
- Symantec Endpoint Security (Broadcom)
- Check Point Harmony Endpoint
- Cybereason
- Bitdefender GravityZone
- ESET PROTECT
- Kaspersky Endpoint Security
- Elastic Security (Endpoint)
- Cynet
- Deep Instinct
- WithSecure
- Malwarebytes
Secure Web Gateway (SWG) / Proxy
- Zscaler Internet Access
- Netskope
- Cisco Umbrella / Secure Access
- Palo Alto Networks Prisma Access
- Forcepoint
- Skyhigh Security (McAfee)
- Broadcom Symantec ProxySG
- iboss
- Menlo Security
OT / ICS / SCADA Security
- Claroty
- Dragos
- Nozomi Networks
- Armis
- Forescout
- Tenable.ot
- Honeywell Forge Cybersecurity
- Fortinet FortiGate Rugged
Collaboration & Productivity Suites (what was accessed, shared, or sent)
- Microsoft 365
- Google Workspace
- Slack
- Zoom
- Cisco Webex
- SharePoint
- Box
- Dropbox
- Atlassian Confluence
Network Firewall / NGFW
- Palo Alto Networks (NGFW / Panorama)
- Fortinet FortiGate
- Cisco Secure Firewall
- Check Point Quantum
- Juniper Networks SRX
- SonicWall
- Sophos Firewall
- Barracuda CloudGen Firewall
- WatchGuard
- Zscaler (Firewall-as-a-Service)
- Cato Networks
- pfSense / Netgate
SaaS Security Posture Management (SSPM) / CASB
- Microsoft Defender for Cloud Apps
- Netskope
- Zscaler
- Palo Alto Networks Prisma SASE
- AppOmni
- Obsidian Security
- Adaptive Shield
- Valence Security
- Wing Security
- Forcepoint (Bitglass)
VPN / Zero Trust Network Access (ZTNA)
- Cisco AnyConnect / Secure Client
- Palo Alto Networks GlobalProtect
- Zscaler Private Access
- Fortinet FortiClient
- Cloudflare Access
- Ivanti Connect Secure (Pulse Secure)
- Check Point Perimeter 81
- Netskope Private Access
- Twingate
IT Service Management / CMDB (asset & ownership context)
- ServiceNow
- Jira Service Management (Atlassian)
- Freshservice
- Ivanti Neurons
- ManageEngine ServiceDesk Plus
- Lansweeper
- Device42
Mobile Device Management / UEM (device-level context)
- Microsoft Intune
- Jamf
- VMware Workspace ONE (Omnissa)
- Ivanti UEM
- Google Endpoint Management
Network Detection & Response (NDR) / Network Telemetry
- Darktrace
- Corelight (Zeek-based)
- Vectra AI
- ExtraHop
- Cisco Secure Network Analytics (Stealthwatch)
- Gigamon
- NETSCOUT
- Fidelis Network
- Plixer Scrutinizer
- Arista NDR (Awake Security)
- Progress Flowmon
Email Security / Anti-Phishing
- Proofpoint
- Mimecast
- Microsoft Defender for Office 365
- Abnormal Security
- Barracuda Email Protection
- Cisco Secure Email
- Check Point Harmony Email
- Trend Micro Email Security
- Google Workspace Security
- Fortinet FortiMail
- IRONSCALES
- Sublime Security
Data Security / Data Detection & Classification
- Varonis
- Rubrik
- Cohesity
- BigID
- Netwrix
- Fortra Titus
- Spirion
Threat Intelligence Platforms (as SOC data sources)
- Recorded Future
- Mandiant Threat Intelligence (Google)
- CrowdStrike Falcon Intelligence
- Microsoft Defender Threat Intelligence
- Anomali
- ThreatConnect
- IBM X-Force Exchange
- Flashpoint
- Intel 471
- GreyNoise
- DomainTools
- Team Cymru
Travel & Expense Systems (impossible-travel corroboration)
- SAP Concur
- Navan (formerly TripActions)
- Expensify
Cloud Infrastructure Logs (IaaS)
- AWS (CloudTrail / GuardDuty / VPC Flow Logs)
- Microsoft Azure (Activity Log / Defender for Cloud)
- Google Cloud Platform (Cloud Audit Logs / Security Command Center)
- Oracle Cloud Infrastructure
- IBM Cloud
- Alibaba Cloud
- DigitalOcean
Web Application Firewall (WAF) / CDN Security
- Cloudflare
- Akamai
- Imperva
- F5 (Distributed Cloud / BIG-IP ASM)
- AWS WAF
- Fortinet FortiWeb
- Azure WAF
- Google Cloud Armor
- Barracuda WAF
- Radware
- Fastly (Signal Sciences)
- Wallarm
Vulnerability Management
- Tenable (Nessus / Tenable.io)
- Qualys
- Rapid7 InsightVM
- Microsoft Defender Vulnerability Management
- CrowdStrike Falcon Spotlight
- Tanium
- Ivanti Neurons for Vulnerability Management
- Greenbone
- Nucleus Security
- Holm Security
HRIS / Identity Source of Truth (employee status verification)
- Workday
- SAP SuccessFactors
- Oracle HCM Cloud
- UKG (Ultimate Kronos Group)
- ADP
- BambooHR
Business Applications / ERP / CRM (data exposure & exfiltration scope)
- Salesforce
- SAP
- Oracle ERP Cloud
- Microsoft Dynamics 365
- NetSuite
- HubSpot
Vendor ecosystem mapped in CYREBRO’s October 2026 partner materials. Integration scope and source-specific requirements are confirmed during evaluation. Vendor names identify telemetry sources and do not imply an endorsement.
Build your security service on CYREBRO.
Let’s map the platform to your customers, your team and your next stage of growth.
