Supported Integrations

Prev Next

Red Canary MDR consolidates a diverse array of security providers, allowing you to centrally manage all your alerts and get more value from your security tools.

We analyze both alerts and raw telemetry from endpoint, network, cloud, identity and other data sources, helping you detect cyber threats earlier and stop them faster without disrupting your existing workflows.

The following providers are supported for Investigations in Red Canary MDR:

Provider

Supported Platform

Class of Security Data

Ingest Type

Amazon Web Services

AWS

Cloud

API

Broadcom

Carbon Black Cloud

EDR

API

Broadcom

Carbon Black EDR

EDR

API

Cisco

Duo

Identity

API

Cisco

Firepower

Network

Email, Syslog

Cisco

Meraki

Network

HTTP

Cisco

Umbrella

Network

Email

CrowdStrike

Falcon Identity Protection

Identity

API

CrowdStrike

Falcon Insight XDR

EDR

API

Darktrace

ActiveAI Security Platform

Network/Internet of Things

Email

Dragos

Platform

Operational Technology (OT)

Syslog

ExtraHop

Reveal(x)

Network

API

ExtraHop

Enterprise

Network

HTTP

Fortinet

FortiAnalyzer

Network

Syslog

Fortinet

FortiGate

Network

Syslog

Google

Cloud Platform (GCP)

Cloud

API

Google

Workspace

SaaS

API

Jamf

Pro/Protect

EDR

API

Lacework

FortiCNAPP

Cloud

API

Microsoft

Azure

Cloud

API

Microsoft

Copilot

AI Tools

N/A

Microsoft

Defender for Cloud

Cloud

API

Microsoft

Defender for Cloud Apps

Identity

API (via Microsoft Graph)

Microsoft

Defender for Endpoint

EDR

API Poll (via Microsoft Graph)

Microsoft

Defender for Identity

Identity

API (via Microsoft Graph)

Microsoft

Defender for Office 365

Email

API Poll (via Microsoft Graph)

Microsoft

Entra ID

Identity

API

Microsoft

Entra ID Protection

Identity

API (via Microsoft Graph)

Microsoft

Office 365 Management API

Aggregate

API

Microsoft

Sentinel

SIEM

API

Okta

Workforce Identity

Identity

API

Palo Alto

Cortex XDR

EDR

API

Palo Alto

PAN-OS

Network

Syslog

Palo Alto

Threat Prevention

Network

Syslog

Palo Alto

Wildfire

Network

Email, Syslog

SentinelOne

Singularity

EDR

API

Trend Micro

Vision One

EDR

API

Wiz

Wiz

Cloud

API

Zscaler

Zscaler Data Fabric for Security

Network

API