Threat Intelligence Integrations

Connect intelligence
to everything.

Bring Team Cymru internet visibility and threat intelligence directly into your SIEM, SOAR, graph analysis tools, AI copilots, and custom applications. Enrich events where analysts already work, automate lookups instead of swivel-chairing between consoles, and connect AI-powered threat intelligence to the workflows that move investigations from raw signal to action.

Integration Ecosystem

16

Integrations & Tools

6

Workflow Categories

3

SDK Languages

2.1

Stix & Taxii Support

Why Integrate

Intelligence that meets your team where it already works.

Team Cymru integrations activate internet visibility and threat intelligence directly inside SIEM, SOAR, graph analysis, AI copilots, TAXII workflows, and custom applications. No new console to learn, no context switching mid-investigation. The same source-layer intelligence, delivered into the detection, automation, and investigation workflows your team runs every day.

01

Enrichment where analysts work

Alerts, events, and dashboards enriched in place, inside Splunk, Google SecOps, and the platforms your SOC already runs. Context arrives with the event, not three tabs later.

02

Automation-ready by design

Certified SOAR content, webhook delivery, and standards-based STIX 2.1 output make intelligence lookups repeatable. Playbooks handle the routine so analysts handle the judgment calls.

03

Built for AI-powered workflows

Natural language querying through Microsoft Security Copilot, SDK access for agent frameworks, and structured output that AI-enabled and agentic threat intelligence workflows can act on.

04

Standards-based and portable

STIX 2.1 and TAXII 2.1 support means intelligence moves cleanly between platforms, threat intelligence operations stay interoperable, and nothing locks your stack to a single vendor path.

Integration Catalog

Organized by what you need to do

Every integration below is grouped by workflow, not by product line. Start with the outcome your team needs, then pick the platform you already run.

Category 01

Enrich SIEM & SecOps Workflows

Every integration below is grouped by workflow, not by product line. Start with the outcome your team needs, then pick the platform you already run.

Splunk · Scout

Scout App for Splunk

Splunk app with custom search commands that enrich events, dashboards, and saved searches with Scout IP intelligence.

Splunk · Feeds

Feed App for Splunk

Pulls indicators from the Team Cymru Feed API into Splunk and ships an IP Overview dashboard for visualization.

Google SecOps · Scout

Google SecOps for Scout

Chronicle / Google SecOps integration that brings Scout enrichment and response actions into SIEM and SOAR playbooks.

Multi-SIEM · TAXII

TAXII Webhook Server

Polls TAXII 2.1 feeds and forwards STIX objects to Chronicle, Splunk HEC, Microsoft Sentinel, and raw webhooks.

Python · Redis
TC DocsSTIX / TAXII

Category 02

Automate Threat Intelligence Lookups

Automate intelligence lookups inside SOAR playbooks, enrichment flows, and repeatable investigation workflows to reduce manual investigation time and improve response consistency.

Palo Alto · Scout

Cortex XSOAR for Scout

Certified Palo Alto Networks content pack that automates Scout lookups and enrichment inside incident response workflows.

Standards · Scout

Scout to STIX 2.1 Proxy

Lightweight FastAPI proxy that relays Scout API calls and returns Foundation, search, and IP detail data as STIX 2.1.

Python · FastAPI
TC DocsSTIX 2 SDK
Automation · TAXII

TAXII Webhook Server

Forwards STIX objects to downstream webhooks with queuing and retry, so automated delivery survives bursts and outages.

Python · Redis
TC docsSTIX / TAXII

Category 03

Power AI & Agentic Security Workflows

Query Team Cymru intelligence through natural language and connect structured threat intelligence to AI-enabled and agentic security workflows. These AI integrations make Team Cymru intelligence usable by copilots, agent frameworks, and the AI-powered threat intelligence workflows security teams are building now.

Microsoft · Scout

Security Copilot Plugin

Custom Security Copilot plugin (manifest + OpenAPI) for real-time Scout threat intel on IPs and domains in natural language.

Filigran · Scout

OpenCTI Search Connector

On-demand search connector that lets analysts enrich observables against Scout from inside OpenCTI.

SDKs · Python, JS/TS, Go

SDKs for Agentic Workflows

Async Python, typed JavaScript/TypeScript, and Go clients give agent frameworks direct access to the Recon API.

Python · TS · Go
TC Docs Coming Soon

Category 04

Visualize Adversary Infrastructure

Map IP intelligence, infrastructure relationships, and connected assets in graph-based investigation tools built for visual threat analysis. Investigate relationships, infrastructure overlap, and connected threat activity on the graph.

Maltego · Scout + Radar

Maltego Transforms

Custom transforms that query Scout IP intelligence and Radar asset discovery, visualizing results on the Maltego graph.

Maltego + SDKs · Radar

Radar Asset Discovery

Radar asset discovery surfaces through the Maltego transforms and all three Recon SDKs, no separate connector required.

Via Maltego + SDKs
Maltego Hub
Filigran · Scout

OpenCTI Connector

Connector that ingests Scout intelligence as STIX entities into the OpenCTI knowledge base.

Category 05

Deliver Threat Feeds Through TAXII

Serve, manage, and forward the IP Insights feed as STIX bundles through TAXII 2.1 and webhook-based delivery workflows. Standards-based delivery for threat intelligence operations, from deployment automation through user, token, and audit management.

TAXII 2.1 · Feeds

OpenTAXII Server

Serves the IP Insights feed as STIX bundles over the TAXII 2.1 API, with idempotent Postgres-backed ingestion.

Deployment · Ansible

OpenTAXII Ansible

Ansible playbooks that build and operate the OpenTAXII stack, covering nginx, firewall, and server lifecycle automation.

Administration · TAXII

TAXII User Portal

React + Node management portal for OpenTAXII: user management, JWT token generation, audit logs, and health monitoring.

React · Node
TC Docs
Splunk · Feeds

Feed App for Splunk

Pulls indicators from the Feed API and ships an IP Overview dashboard, closing the loop from delivery to analyst view.

Category 06

Build Custom Intelligence Workflows

Official SDKs for the Recon API: jobs, schedules, malware search, Scout access, and Radar asset discovery. Built for developers, advanced security teams, and internal platforms that extend investigations through SDKs and APIs.

Recon SDK · Python

Python SDK

Async Python client for the Recon API covering jobs, schedules, malware search, Scout, and Radar asset discovery.

Python 3.12+ · Async
TC Docs
Recon SDK · JavaScript / TypeScript

JavaScript / TypeScript SDK

Typed JavaScript/TypeScript client for the Recon API, distributed via npm for browser and Node projects.

Node 18+ · TypeScript
TC Docs
Recon SDK · Go

Go SDK

Go client for the Recon API with access to jobs, schedules, malware search, Scout, and Radar asset discovery.

Go 1.26+
TC Docs

Powered By

The same intelligence, every integration.

Every connector, app, plugin, and SDK on this page delivers the same source-layer internet visibility. Pick the integration that fits your workflow; the intelligence underneath does not change.

STEP 1 · SOURCE TELEMETRY
  • Netflow
  • Certificates
  • BGP
  • Routing
  • Passive DNS
  • Infrastructure
STEP 2 · TEAM CYMRU

Correlation & Enrichment

Source signals validated, correlated, and scored before delivery.

STEP 3 · YOUR SECURITY STACK
  • SIEM
  • AI Copilot
  • SOAR
  • TAXII
  • Graph Analysis
  • SDKs

ONE DATA FABRIC

EVERY INTEGRATION

Built With Practitioners

Don't see your platform
Tell us what to connect next.

This catalog grows with the teams that use it. If your stack includes a platform, TIP, or workflow you want Team Cymru intelligence inside, submit a request. The most-requested integrations shape the roadmap.

Every request is reviewed by the team building these integrations.

Get Connected

Bring Team Cymru intelligence into your stack.

Whether you start with a Splunk app, a SOAR pack, a TAXII feed, or an SDK, the path from raw signal to action gets shorter. Talk with our team about which integrations fit your workflows.