Integration options

ThreatMap can supply intelligence to external security workflows through authenticated REST and MCP. A named vendor in an early product proposal is not evidence of a contractual partnership or a packaged connector.

Implemented integration surfaces

  • REST enrichment and infrastructure pivots for application/playbook clients.
  • Stdio and Streamable HTTP MCP for compatible AI clients.
  • Configured monitor alert destinations: email, HTTPS webhook, and Slack.
  • Licensed provider credentials through BYOK and source preferences.

Scope to confirm before integration

Confirm request/response schemas, provider licenses, plan gates, target authorization, and delivery configuration. Generic API access does not imply built-in SIEM/SOAR/EDR connectors, bidirectional event ingestion, OCSF push, or TAXII/STIX delivery. These require a specific implemented integration.

Contact your ThreatMap account team for partnership and connector scope. See implemented APIs.