Integrations
Connect Your Stack
OpenSOAR ships with a focused built-in integration set today and a Python-first extension path for the rest of your stack.
5 built-in integrations
Python extension path for everything else
External directories and webhooks supported
Built-in today
E
Elastic Security
Webhook ingestion and detection workflow
V
VirusTotal
File, domain, and URL enrichment
A
AbuseIPDB
IP reputation lookups
S
Slack
Notifications and escalation messaging
E
Email
SMTP-style notifications
Common external systems
S
Splunk
Enterprise security analytics
M
Microsoft Sentinel
Cloud-native SIEM
Q
QRadar
IBM threat detection
EDR/XDR
C
CrowdStrike Falcon
Endpoint detection & response
S
SentinelOne
Autonomous endpoint protection
M
Microsoft Defender
XDR across endpoints & cloud
C
Carbon Black
VMware endpoint security
Cloud Security
A
AWS GuardDuty
AWS threat detection
A
Azure Security Center
Azure workload protection
G
GCP Security Command Center
Google Cloud security
Threat Intelligence
V
VirusTotal
File & URL analysis
A
AbuseIPDB
IP reputation lookups
O
OTX (AlienVault)
Open threat exchange
M
MISP
Threat intelligence sharing
Email Security
P
Proofpoint
Email threat protection
M
Mimecast
Email security gateway
M
Microsoft Defender for Office 365
Office 365 protection
Network
S
Suricata
Network IDS/IPS
Z
Zeek
Network traffic analysis
P
Palo Alto
Next-gen firewall
F
Fortinet
Network security platform
Identity
O
Okta
Identity & access management
A
Azure AD
Microsoft identity platform
C
CrowdStrike Identity
Identity threat detection
Ticketing & Communication
J
Jira
Issue tracking & workflows
S
ServiceNow
IT service management
S
Slack
Team messaging & alerts
M
Microsoft Teams
Collaboration & notifications
P
PagerDuty
Incident management & on-call
Monitoring & Observability
D
Datadog
Infrastructure and application monitoring
G
Grafana
Dashboards and alerting
P
Prometheus
Metrics and alerting
N
New Relic
Full-stack observability
Cloud Platforms
A
AWS
EC2, Lambda, CloudWatch, S3
G
Google Cloud
GKE, Cloud Functions, Cloud Monitoring
A
Azure
VMs, Functions, Monitor, Key Vault
DevOps & CI/CD
G
GitHub
Actions, Issues, Webhooks
G
GitLab
Pipelines, Issues, Webhooks
T
Terraform
Infrastructure state and drift
K
Kubernetes
Pod health, scaling, rollbacks
Custom
W
Webhooks
HTTP callback integrations
R
REST API
Connect any HTTP API
S
Syslog
Standard log forwarding
P
Python SDK
Build custom integrations
Build your own integrations
Any tool with an API can be integrated into OpenSOAR in a few lines of Python. Built-ins are discovered automatically, and external connector directories can be loaded alongside them. Import any library, call any endpoint, parse any response format.
custom_integration.py
from opensoar.integrations.base import IntegrationBase
class MyTool(IntegrationBase):
async def lookup(self, indicator):
resp = await self.http.get(
f"https://api.mytool.com/v1/{indicator}"
)
return resp.json() All integrations are open source. Contribute new ones or customize existing ones for your environment.
One command. No credit card.
Apache 2.0 licensed. Self-host on your infrastructure. No feature gates, no per-action billing, no vendor lock-in. Your playbooks are yours.
$
GitHub
curl -fsSL https://opensoar.app/install.sh | sh