Google Security Operations
Export rule-driven findings as Unified Data Model events through the Chronicle API. See the Google SecOps integration guide.
Connectors link third-party services so alerts, workflows, and monitoring results can reach Elastic Security, Google SecOps, Microsoft Sentinel, Splunk, Slack channels, custom HTTP endpoints, or Tines stories. In the app, open Connectors to configure available connections.
Google Security Operations
Export rule-driven findings as Unified Data Model events through the Chronicle API. See the Google SecOps integration guide.
Elastic Security
Write rule-driven findings to an Elasticsearch data stream as Elastic Common Schema documents. See the Elastic Security integration guide.
Microsoft Sentinel
Export rule-driven findings to a Log Analytics table and add cited lookalike domains to Sentinel threat intelligence as expiring indicators. See the Microsoft Sentinel integration guide.
Splunk
Send rule alerts and cited domain names through HTTP Event Collector. See the Splunk integration guide.
Slack
Send alerts, analysis updates, and domain discovery notifications to Slack channels. See the Slack integration guide.
Webhooks
Deliver real-time events to any HTTP endpoint with signed payloads. See the Webhook integration guide.
Tines
Use Have I Been Squatted templates in Tines stories for lookup, enrichment, and usage workflows. See the Tines integration guide.
Cloudflare Zero Trust
Push flagged domains to a dedicated Cloudflare Gateway list so they are blocked on your network. See the Cloudflare Zero Trust integration guide.
Microsoft Defender for Endpoint
Block lookalike domains that rules cite on managed devices with expiring Defender indicators. See the Microsoft Defender for Endpoint integration guide.
Microsoft 365 Quarantine
Quarantine mail from lookalike domains that rules cite with expiring sender blocks in the Exchange Online Tenant Allow/Block List. See the Microsoft 365 Quarantine integration guide.
CrowdStrike Falcon
Raise Falcon detections when hosts resolve lookalike domains that rules cite, with expiring custom IOCs. See the CrowdStrike Falcon integration guide.
Each Slack channel or webhook endpoint has its own filters.