Integrations & API

Our preemptive intelligence. Your tools and workflows. Searchlight integrates with the tools you already use – so you can resolve threats before attacks begin.

Background Gradient

Supported Integrations

Connect with the tools you already use

Cloud

Akamai Edge DNS

Cloud

Alibaba

Identity & SSO

Any SAML IdP

Cloud

AWS

Cloud

Azure

Cloud

CloudFlare

Cloud

Fastly

Cloud

Google Cloud Platform

Bug Bounty

HackerOne

Ticketing & Collaboration

Jira

Identity & SSO

Microsoft Entra ID

SIEM & SOAR

Microsoft Sentinel

Ticketing & Collaboration

Microsoft Teams

Identity & SSO

Okta

Ticketing & Collaboration

ServiceNow

Ticketing & Collaboration

Slack

SIEM & SOAR

Splunk

Blockchain

TRM Labs

Threat Intelligence

VirusTotal

Event Delivery

Webhooks

Ticketing & Collaboration

Zoom

API

More on Request

No result to show

Try looking for something else.

See all

Integration categories

How Searchlight fits into your security stack

How preemptive intelligence powers the tools you already run.

1

SIEM & SOAR

Enrich event and log data with validated exposure findings and observed attacker activity. Native integrations push alerts already prioritized, with the evidence attached, the proof, the actor, the context, into your existing detection and response workflow, so what arrives is ready to act on, not triage.

Splunk

Microsoft Sentinel

Generic SIEM via API

2

Ticketing & Collaboration

Get alerted in the tools your team already works in. Custom notifications and automated ticket creation route confirmed exposures from Searchlight into the systems analysts use to manage remediation, with mitigation guidance and the proof of concept in the ticket.

ServiceNow

Jira

Slack

Microsoft Teams

Zoom

3

Threat Intelligence & Investigation

Enrich your investigations in Searchlight with third-party intelligence, such as blockchain or malware analysis, or pull Searchlight's context-rich exposure and threat alerts into the platforms you already run. Intelligence flows both ways, so an investigation that starts with one indicator runs to a conclusion.

HackerOne

VirusTotal

TRM Labs

4

Identity & SSO

Single sign-on via SAML 2.0 with any identity provider. Whichever IdP you use, your team accesses Searchlight through your existing authentication flow.

Okta

Microsoft Entra ID

Any SAML 2.0 IdP

API

A flexible REST API for everything else

Programmatic access to Searchlight Exposure and Threat’s dataset and capabilities.

Used by enterprise customers to push validated findings into custom workflows, and by technology partners to build Searchlight intelligence into their own products.

What integrating unlocks

Operationalize Preemptive Threat Exposure Management

What changes once Searchlight flows into the rest of the stack.

One place to work from

Validated exposure findings and attacker behavior intelligence land in the tools your team already uses, with the context and metadata attached, so nothing new to check and nothing to re-verify.

Detections with context

Internal signals gain the context only Searchlight has: validated exploitability from Searchlight Labs research and attacker activity observed at the source. Detections correlate against what's actually happening, with data quality your team can act on without re-verifying.

Preemptive action, automated

Every integration can trigger response the moment Searchlight confirms an exposure is exploitable and actively targeted. Findings auto-route to the right team with the mitigation attached, so SLAs hold even as exposure windows shrink from weeks to hours. Action starts before anyone opens a dashboard.

Background Gradient

Trusted by leading companies

1/5

The platform has well and truly paid for itself in what it’s found and how it’s helped us respond to incidents.

Information Security Manager

Insurance company

With Searchlight, they are the good guys that think like the bad guys, they look at our attack surface through the eyes of a malicious actor and will try to imitate similar techniques to find where we might have a problem.

Chief Information Security Officer

Multi-national Technology Company

We got more done for our security in three days using Searchlight than we have in the last four years using [competing platform].

VP, Information Security

Network Appliances company

FAQ

Frequently asked questions

Searchlight has native integrations with Splunk and Microsoft Sentinel, and programmatic integration with any SIEM via the API. Alerts arrive enriched with the evidence behind them, including MITRE ATT&CK mapping, so they fit your existing detection workflow without translation.

Single sign-on runs on SAML 2.0, so any compliant identity provider your organization already uses is supported, including Okta and Microsoft Entra ID. Your team can continue to sign in through the authentication flow you already enforce.

A flexible REST API provides programmatic access to the platform's dataset and capabilities, with HTTP webhook delivery for event-driven workflows. Enterprise customers use it to push findings into custom pipelines; technology partners use it to build Searchlight intelligence into their own products.

Webhooks push events to your endpoints the moment they happen, a confirmed exposure, a new detection, a status change, so downstream notification, ticketing, and workflow systems act on Searchlight findings in real time instead of polling for updates.

Ready to integrate?

See how Searchlight can enhance your preemptive security

Background Gradient