Partners

ThreatMap is the intelligence layer. These capabilities are served by best-in-class partners — we integrate, we don't compete. We feed aggregated intelligence into their workflows; they make everything smarter.

Want to become a partner? Email partners@threatmap.co.

Integration categories

Cloud security (CSPM, CDR)

Cy5, Wiz, Orca, Prisma Cloud, Defender for Cloud

We push intel into their findings; they push posture data back for enrichment.

SIEM

Splunk, Microsoft Sentinel, Elastic, Google Chronicle, Sumo Logic, Devo, QRadar, Exabeam

OCSF-format push connectors. ThreatMap intel flows into your SIEM as enrichment.

SOAR

Tines, Splunk SOAR, Palo Alto XSOAR, Torq

Bidirectional — your playbooks call ThreatMap to enrich; ThreatMap pushes alerts to trigger playbooks.

EDR / XDR

CrowdStrike, SentinelOne, Microsoft Defender for Endpoint

Your EDR pushes detection events via webhook; we enrich with full threat intel context.

Email security

Proofpoint, Mimecast, Microsoft Defender for Office, Abnormal

We accept webhook events for IOC enrichment on inbound email threats.

Deception / honeypot

Thinkst Canary, Attivo, TrapX, OpenCanary

When a canary fires, ThreatMap enriches the attacker IP across all feeds instantly.

WAF / CDN

Cloudflare, Akamai, Imperva, AWS WAF, F5

We accept webhook events from your WAF for real-time IOC enrichment.

Vulnerability scanner

Tenable, Qualys, Rapid7, Nucleus

Read-only pull of findings; we enrich with EPSS, KEV, and exploitation evidence.

CMDB / asset criticality

ServiceNow, Device42, Axonius

Customer pushes descriptors (asset IDs + criticality) so we can weight vuln priorities.

Pen test / breach simulation

Mandiant, Bishop Fox, Pentera, NodeZero

We feed intel to scope the test; partner executes; we ingest findings.

Security awareness training

KnowBe4, Proofpoint (Wombat), Mimecast

Partner owns content; we provide the intel layer.

Compliance / GRC

Vanta, Drata, Secureframe, OneTrust, Archer, ServiceNow GRC

We feed external evidence (CT logs, posture checks); they own the audit workflow.

Brand protection

MarkMonitor, CSC, LookalikeDomains

Partner monitors for typosquats and impersonation; we aggregate and alert.

Dark web monitoring

Searchlight Cyber, Flashpoint, Intel 471, SpyCloud

Partner owns collection; we aggregate and normalise into one feed.

Code leak detection

GitGuardian, TruffleHog, GitHub Secret Scanning

Partner scans repos; we aggregate alerts across your codebase.

AI security (MAIEM)

HiddenLayer, Protect AI, Lakera

Emerging — we aggregate AI supply chain risk signals.

ICS / OT security

Claroty, Nozomi, Dragos

Partner owns OT collection; we alert on external ICS exposure.

MSSP / MDR distribution

Deloitte, EY, IBM Security, ReliaQuest, Arctic Wolf, eSentire

MSSPs OEM ThreatMap as the intel layer inside their MDR products.

How integrations work

ThreatMap never enters your network or reads your data. Integrations work through three patterns:

  • Push (outbound): ThreatMap pushes enriched alerts to your SIEM, SOAR, Slack, or webhook via OCSF JSON.
  • Pull (inbound): Your tools call ThreatMap's API to enrich entities on demand.
  • Webhook ingress: Your EDR, WAF, or honeypot pushes events to ThreatMap; we enrich and return context.

All integrations use standard protocols — OCSF, STIX 2.1, TAXII 2.1, and HTTPS webhooks with HMAC signatures.