Partners
ThreatMap is the intelligence layer. These capabilities are served by best-in-class partners — we integrate, we don't compete. We feed aggregated intelligence into their workflows; they make everything smarter.
Want to become a partner? Email partners@threatmap.co.
Integration categories
Cloud security (CSPM, CDR)
Cy5, Wiz, Orca, Prisma Cloud, Defender for Cloud
We push intel into their findings; they push posture data back for enrichment.
SIEM
Splunk, Microsoft Sentinel, Elastic, Google Chronicle, Sumo Logic, Devo, QRadar, Exabeam
OCSF-format push connectors. ThreatMap intel flows into your SIEM as enrichment.
SOAR
Tines, Splunk SOAR, Palo Alto XSOAR, Torq
Bidirectional — your playbooks call ThreatMap to enrich; ThreatMap pushes alerts to trigger playbooks.
EDR / XDR
CrowdStrike, SentinelOne, Microsoft Defender for Endpoint
Your EDR pushes detection events via webhook; we enrich with full threat intel context.
Email security
Proofpoint, Mimecast, Microsoft Defender for Office, Abnormal
We accept webhook events for IOC enrichment on inbound email threats.
Deception / honeypot
Thinkst Canary, Attivo, TrapX, OpenCanary
When a canary fires, ThreatMap enriches the attacker IP across all feeds instantly.
WAF / CDN
Cloudflare, Akamai, Imperva, AWS WAF, F5
We accept webhook events from your WAF for real-time IOC enrichment.
Vulnerability scanner
Tenable, Qualys, Rapid7, Nucleus
Read-only pull of findings; we enrich with EPSS, KEV, and exploitation evidence.
CMDB / asset criticality
ServiceNow, Device42, Axonius
Customer pushes descriptors (asset IDs + criticality) so we can weight vuln priorities.
Pen test / breach simulation
Mandiant, Bishop Fox, Pentera, NodeZero
We feed intel to scope the test; partner executes; we ingest findings.
Security awareness training
KnowBe4, Proofpoint (Wombat), Mimecast
Partner owns content; we provide the intel layer.
Compliance / GRC
Vanta, Drata, Secureframe, OneTrust, Archer, ServiceNow GRC
We feed external evidence (CT logs, posture checks); they own the audit workflow.
Brand protection
MarkMonitor, CSC, LookalikeDomains
Partner monitors for typosquats and impersonation; we aggregate and alert.
Dark web monitoring
Searchlight Cyber, Flashpoint, Intel 471, SpyCloud
Partner owns collection; we aggregate and normalise into one feed.
Code leak detection
GitGuardian, TruffleHog, GitHub Secret Scanning
Partner scans repos; we aggregate alerts across your codebase.
AI security (MAIEM)
HiddenLayer, Protect AI, Lakera
Emerging — we aggregate AI supply chain risk signals.
ICS / OT security
Claroty, Nozomi, Dragos
Partner owns OT collection; we alert on external ICS exposure.
MSSP / MDR distribution
Deloitte, EY, IBM Security, ReliaQuest, Arctic Wolf, eSentire
MSSPs OEM ThreatMap as the intel layer inside their MDR products.
How integrations work
ThreatMap never enters your network or reads your data. Integrations work through three patterns:
- Push (outbound): ThreatMap pushes enriched alerts to your SIEM, SOAR, Slack, or webhook via OCSF JSON.
- Pull (inbound): Your tools call ThreatMap's API to enrich entities on demand.
- Webhook ingress: Your EDR, WAF, or honeypot pushes events to ThreatMap; we enrich and return context.
All integrations use standard protocols — OCSF, STIX 2.1, TAXII 2.1, and HTTPS webhooks with HMAC signatures.