INTEGRATIONS
Sentinel Integration
The Sentinel integration sends alert data into Microsoft Sentinel through a codeless connector in the content hub. It includes prebuilt analytic rules and workbooks for visualizing risk scores and leaked credentials.
Azure Sentinel Integration (Legacy)
The Azure Sentinel integration (legacy) sends alerts directly to an Azure Sentinel workspace using a workspace ID and shared key. New setups should use the Sentinel integration instead.
Discord
The Discord integration sends alerts to a Discord channel through Discord's native webhook feature. Setup takes just a channel name and a webhook URL.
Jira
The Jira integration creates Jira issues automatically from alerts, with optional Jira Service Management support. It supports custom labels, dynamic formatting, and additional custom fields.
Microsoft Entra ID
The Microsoft Entra ID integration checks whether flagged credentials are still active in Entra ID and links to the affected user. It requires an app registration with directory read permissions.
ServiceNow
The ServiceNow integration posts alert data as records into a ServiceNow table using API key authentication. Setup requires an authentication profile, REST API key, and access policy in ServiceNow.
Slack
The Slack integration sends alerts to a Slack channel through an incoming webhook. Setup takes just a channel name and a webhook URL.
Splunk Cloud (Legacy)
The Splunk Cloud integration (legacy) sends alert data into a Splunk index using an HTTP Event Collector token. The Splunk app is the newer on-premises option.
Splunk App
The Splunk app brings full event data into Splunk for correlation, enrichment, and automated response. It installs from the Splunk marketplace or Splunkbase and configures with an API key.
Microsoft Teams
The Microsoft Teams integration sends alerts to a Microsoft Teams channel through an incoming webhook workflow. Setup steps changed as of April 30, 2026, when Microsoft updated how Teams webhooks are created.
Webhooks
The webhooks integration sends alerts to any service that accepts incoming webhooks, such as Tines, Zapier, or IFTTT. It supports optional signature validation and basic auth for verifying payloads.