Integrations & API
Our preemptive intelligence. Your tools and workflows. Searchlight integrates with the tools you already use – so you can resolve threats before attacks begin.

Supported Integrations
Connect with the tools you already use
Cloud
Akamai Edge DNS
Cloud
Alibaba
Identity & SSO
Any SAML IdP
Cloud
AWS
Cloud
Azure
Cloud
CloudFlare
Cloud
Fastly
Cloud
Google Cloud Platform
Bug Bounty
HackerOne
Ticketing & Collaboration
Jira
Identity & SSO
Microsoft Entra ID
SIEM & SOAR
Microsoft Sentinel
Ticketing & Collaboration
Microsoft Teams
Identity & SSO
Okta
Ticketing & Collaboration
ServiceNow
Ticketing & Collaboration
Slack
SIEM & SOAR
Splunk
Blockchain
TRM Labs
Threat Intelligence
VirusTotal
Event Delivery
Webhooks
Ticketing & Collaboration
Zoom
API
More on Request
Integration categories
How Searchlight fits into your security stack
How preemptive intelligence powers the tools you already run.
SIEM & SOAR
Enrich event and log data with validated exposure findings and observed attacker activity. Native integrations push alerts already prioritized, with the evidence attached, the proof, the actor, the context, into your existing detection and response workflow, so what arrives is ready to act on, not triage.
Splunk
Microsoft Sentinel
Generic SIEM via API
Ticketing & Collaboration
Get alerted in the tools your team already works in. Custom notifications and automated ticket creation route confirmed exposures from Searchlight into the systems analysts use to manage remediation, with mitigation guidance and the proof of concept in the ticket.
ServiceNow
Jira
Slack
Microsoft Teams
Zoom
Threat Intelligence & Investigation
Enrich your investigations in Searchlight with third-party intelligence, such as blockchain or malware analysis, or pull Searchlight's context-rich exposure and threat alerts into the platforms you already run. Intelligence flows both ways, so an investigation that starts with one indicator runs to a conclusion.
HackerOne
VirusTotal
TRM Labs
Identity & SSO
Single sign-on via SAML 2.0 with any identity provider. Whichever IdP you use, your team accesses Searchlight through your existing authentication flow.
Okta
Microsoft Entra ID
Any SAML 2.0 IdP
API
A flexible REST API for everything else
Programmatic access to Searchlight Exposure and Threat’s dataset and capabilities.
Used by enterprise customers to push validated findings into custom workflows, and by technology partners to build Searchlight intelligence into their own products.
What integrating unlocks
Operationalize Preemptive Threat Exposure Management
What changes once Searchlight flows into the rest of the stack.
One place to work from
Validated exposure findings and attacker behavior intelligence land in the tools your team already uses, with the context and metadata attached, so nothing new to check and nothing to re-verify.
Detections with context
Internal signals gain the context only Searchlight has: validated exploitability from Searchlight Labs research and attacker activity observed at the source. Detections correlate against what's actually happening, with data quality your team can act on without re-verifying.
Preemptive action, automated
Every integration can trigger response the moment Searchlight confirms an exposure is exploitable and actively targeted. Findings auto-route to the right team with the mitigation attached, so SLAs hold even as exposure windows shrink from weeks to hours. Action starts before anyone opens a dashboard.

Trusted by leading companies
FAQ
Frequently asked questions
Searchlight has native integrations with Splunk and Microsoft Sentinel, and programmatic integration with any SIEM via the API. Alerts arrive enriched with the evidence behind them, including MITRE ATT&CK mapping, so they fit your existing detection workflow without translation.
Single sign-on runs on SAML 2.0, so any compliant identity provider your organization already uses is supported, including Okta and Microsoft Entra ID. Your team can continue to sign in through the authentication flow you already enforce.
A flexible REST API provides programmatic access to the platform's dataset and capabilities, with HTTP webhook delivery for event-driven workflows. Enterprise customers use it to push findings into custom pipelines; technology partners use it to build Searchlight intelligence into their own products.
Webhooks push events to your endpoints the moment they happen, a confirmed exposure, a new detection, a status change, so downstream notification, ticketing, and workflow systems act on Searchlight findings in real time instead of polling for updates.












