Connect intelligence
to everything.
Bring Team Cymru internet visibility and threat intelligence directly into your SIEM, SOAR, graph analysis tools, AI copilots, and custom applications. Enrich events where analysts already work, automate lookups instead of swivel-chairing between consoles, and connect AI-powered threat intelligence to the workflows that move investigations from raw signal to action.
Intelligence that meets your team where it already works.
Team Cymru integrations activate internet visibility and threat intelligence directly inside SIEM, SOAR, graph analysis, AI copilots, TAXII workflows, and custom applications. No new console to learn, no context switching mid-investigation. The same source-layer intelligence, delivered into the detection, automation, and investigation workflows your team runs every day.
Enrichment where analysts work
Alerts, events, and dashboards enriched in place, inside Splunk, Google SecOps, and the platforms your SOC already runs. Context arrives with the event, not three tabs later.
Automation-ready by design
Certified SOAR content, webhook delivery, and standards-based STIX 2.1 output make intelligence lookups repeatable. Playbooks handle the routine so analysts handle the judgment calls.
Built for AI-powered workflows
Natural language querying through Microsoft Security Copilot, SDK access for agent frameworks, and structured output that AI-enabled and agentic threat intelligence workflows can act on.
Standards-based and portable
STIX 2.1 and TAXII 2.1 support means intelligence moves cleanly between platforms, threat intelligence operations stay interoperable, and nothing locks your stack to a single vendor path.
Integration Catalog
Every integration below is grouped by workflow, not by product line. Start with the outcome your team needs, then pick the platform you already run.
Category 01
Every integration below is grouped by workflow, not by product line. Start with the outcome your team needs, then pick the platform you already run.
Splunk app with custom search commands that enrich events, dashboards, and saved searches with Scout IP intelligence.
Pulls indicators from the Team Cymru Feed API into Splunk and ships an IP Overview dashboard for visualization.
Chronicle / Google SecOps integration that brings Scout enrichment and response actions into SIEM and SOAR playbooks.
Polls TAXII 2.1 feeds and forwards STIX objects to Chronicle, Splunk HEC, Microsoft Sentinel, and raw webhooks.
Category 02
Automate intelligence lookups inside SOAR playbooks, enrichment flows, and repeatable investigation workflows to reduce manual investigation time and improve response consistency.
Certified Palo Alto Networks content pack that automates Scout lookups and enrichment inside incident response workflows.
Lightweight FastAPI proxy that relays Scout API calls and returns Foundation, search, and IP detail data as STIX 2.1.
Forwards STIX objects to downstream webhooks with queuing and retry, so automated delivery survives bursts and outages.
Category 03
Query Team Cymru intelligence through natural language and connect structured threat intelligence to AI-enabled and agentic security workflows. These AI integrations make Team Cymru intelligence usable by copilots, agent frameworks, and the AI-powered threat intelligence workflows security teams are building now.
Custom Security Copilot plugin (manifest + OpenAPI) for real-time Scout threat intel on IPs and domains in natural language.
On-demand search connector that lets analysts enrich observables against Scout from inside OpenCTI.
Async Python, typed JavaScript/TypeScript, and Go clients give agent frameworks direct access to the Recon API.
Category 04
Map IP intelligence, infrastructure relationships, and connected assets in graph-based investigation tools built for visual threat analysis. Investigate relationships, infrastructure overlap, and connected threat activity on the graph.
Custom transforms that query Scout IP intelligence and Radar asset discovery, visualizing results on the Maltego graph.
Radar asset discovery surfaces through the Maltego transforms and all three Recon SDKs, no separate connector required.
Connector that ingests Scout intelligence as STIX entities into the OpenCTI knowledge base.
Category 05
Serve, manage, and forward the IP Insights feed as STIX bundles through TAXII 2.1 and webhook-based delivery workflows. Standards-based delivery for threat intelligence operations, from deployment automation through user, token, and audit management.
Serves the IP Insights feed as STIX bundles over the TAXII 2.1 API, with idempotent Postgres-backed ingestion.
Ansible playbooks that build and operate the OpenTAXII stack, covering nginx, firewall, and server lifecycle automation.
React + Node management portal for OpenTAXII: user management, JWT token generation, audit logs, and health monitoring.
Pulls indicators from the Feed API and ships an IP Overview dashboard, closing the loop from delivery to analyst view.
Category 06
Official SDKs for the Recon API: jobs, schedules, malware search, Scout access, and Radar asset discovery. Built for developers, advanced security teams, and internal platforms that extend investigations through SDKs and APIs.
Async Python client for the Recon API covering jobs, schedules, malware search, Scout, and Radar asset discovery.
Typed JavaScript/TypeScript client for the Recon API, distributed via npm for browser and Node projects.
Go client for the Recon API with access to jobs, schedules, malware search, Scout, and Radar asset discovery.
Powered By
Every connector, app, plugin, and SDK on this page delivers the same source-layer internet visibility. Pick the integration that fits your workflow; the intelligence underneath does not change.
Correlation & Enrichment
Source signals validated, correlated, and scored before delivery.
ONE DATA FABRIC
EVERY INTEGRATION
Don't see your platform
Tell us what to connect next.
This catalog grows with the teams that use it. If your stack includes a platform, TIP, or workflow you want Team Cymru intelligence inside, submit a request. The most-requested integrations shape the roadmap.
Every request is reviewed by the team building these integrations.
Get Connected
Bring Team Cymru intelligence into your stack.
Whether you start with a Splunk app, a SOAR pack, a TAXII feed, or an SDK, the path from raw signal to action gets shorter. Talk with our team about which integrations fit your workflows.