Connected, deliberately

Platform reach without capability theater.

Threat Foundry states whether each target supports bounded read-only search, rule verification, inventory, validation, or portable export. Provider contact is explicit; provider mutation remains outside the workflow.

Threat intelligence

Bring intelligence in without surrendering control.

MI

MISP

Bounded, read-only event synchronization through a configured integration. Review normalized entities before downstream use.

Read-only sync
OC

OpenCTI

Bounded, read-only GraphQL intake from a configured server and token. Entity and relationship content stays tenant-owned.

Read-only sync
SX

STIX 2.x

Upload a bounded STIX bundle for review when a live platform connection is not appropriate for the environment.

File intake

Connected platform families

Read-only search, validation, or rule verification—capability by capability.

Configuration, licensed products, tenant policy, permissions, telemetry, mappings, and the selected workflow determine which controls are available.

SP

Splunk

Use configured search and detection workflows with bounded queries, reviewed limits, normalized fields, and current connector readiness.

Read-only operations
CS

CrowdStrike LogScale

Investigate normalized alerts and run explicitly reviewed, time-bounded searches where the tenant connection is ready.

Read-only operations
MS

Microsoft Sentinel

Use the bounded, read-only telemetry query path when the tenant connector is configured. Detection-rule deployment is not implied.

Read-only query
EL

Elastic Security

Use the bounded, read-only telemetry query path when the tenant connector is configured. Detection-rule deployment is not implied.

Read-only query
GS

Google SecOps

Keep UDM Search as the read-only telemetry path and YARA-L as the separate rule-verification target.

Search + verification
PX

Palo Alto Cortex XSIAM

Use allowlisted read operations with the provider's broad-RBAC warning visible during setup and review.

Read-only boundary
Connected does not mean deployed

A connected target may support only some combination of translation, linting, query validation, bounded search, rule verification, or inventory. Threat Foundry does not create, update, enable, disable, delete, or deploy provider content.

Portable detection targets

Prepare a review package when direct validation is not available.

QR

IBM QRadar

Customer-controlled portable export; no provider contact.

SD

Sumo Logic + Devo

Review-package output for the customer's deployment process.

LR

LogRhythm

Portable artifacts with the supported context and limitations attached.

RI

Rapid7 InsightIDR

Export-only handoff rather than simulated validation.

EX

Exabeam

Review package for customer-controlled implementation.

PK

Detection-as-Code packages

Source, generated artifacts, tests, evidence index, approvals, checksums, guidance, and rollback planning.

Exposure + Asset Context

Connect findings to the systems and owners that make them matter.

QV

Qualys VMDR

Bring configured vulnerability and scanner context into KEV and exposure prioritization.

Configured enrichment
MD

Microsoft Defender Vulnerability Management

Use tenant-approved exposure evidence to enrich affected-asset and remediation decisions.

Configured enrichment
FI

Scanner + CMDB files

Upload bounded CSV or JSON findings and business metadata when an API connection is not appropriate.

File intake

Threat Modeling inventory

Seed Threat Blueprints from offline cloud exports.

Export inventory from the customer cloud, inspect the file, and import it without granting Threat Foundry standing cloud credentials.

AW

Amazon Web Services

Import a supported bounded inventory export to propose components, relationships, and security zones for analyst review.

Offline export
AZ

Microsoft Azure

Translate supported Azure inventory exports into Blueprint proposals without a live control-plane connection.

Offline export
GC

Google Cloud

Use supported Cloud Asset inventory exports to seed a reviewable architecture model.

Offline export

Bring your own AI

One active route, selected by the customer.

Configure supported providers for the tenant, retain alternatives for later use, and activate exactly one. AI-assisted workflows bind the selected provider and model through Generate → Review → Run so a route change cannot silently redirect an approved handoff.

  • Exactly one active provider; inactive configurations are never fallback routes
  • Default, deep-analysis, and background model roles
  • Every row and field in the reviewed evidence scope is retained without hidden compaction
  • Reusable credential values are visibly protected; provider, connector, and configuration secrets are never prompt content
  • No silent provider failover or partial AI verdict when the route or complete handoff is unavailable
Customer provider and data decision

The customer selects the provider, models, account, and reviewed workflow evidence. Saving and using that route confirms acceptance of the provider’s applicable terms, privacy, retention, pricing, and data-handling conditions. Provider-account and model-choice governance remain the customer’s responsibility; Threat Foundry enforces the configured route without silently substituting or approving a provider.

Operations ecosystem

Connect context and handoff at your pace.

ED

Endpoint and alert context

Use supported normalized alerts and bounded host context for review-first investigation without endpoint response.

TK

Ticketing and cases

Hand reviewed work to configured ticket providers while retaining the internal evidence and decision record.

AI

AI providers

Use the customer-selected route for supported summarization, scoping, drafting, and analysis with visible evidence handoff and review.

AP

API Connect

Manage supported non-secret settings and purpose-bound credential references through tenant-aware configuration.

FL

Field normalization

Map customer aliases into a consistent investigation and detection entity model; draft mappings with Field Builder.

DP

Data + Query Policy

Constrain indexes, sources, fields, time ranges, result limits, overrides, and telemetry expectations before execution.

Availability note

Availability depends on licensed third-party products, current configuration, supported formats, permissions, customer policy, and the exact workflow. Vendor names describe possible interoperability and do not imply partnership, endorsement, certification, or uniform feature parity.

Start with the workflow

Map Threat Foundry to your current stack.

We will identify what can work on day one, what requires a connection, and where offline import or portable export is the safer first step.