Connect the tools you already run

Deep native connectors for the tools security teams live in, a searchable catalog covering the rest, and generic webhooks for anything else.

Ask About Your Stack
Native
Pull connectors, no code to write
8
Categories Covered
∞
Via Webhook / HTTP

Native connectors

Built and maintained by THEWATCH. Each one pulls security signals on a schedule with your own credentials and feeds them through the same normalize-to-alert pipeline, so every source becomes a case-ready alert.

The Connector Catalog

A searchable library generated from vendors' published API specs, across EDR, SIEM, identity, ticketing, email, network, cloud, and threat intel. Configure one and its actions become playbook steps.

Webhooks & generic HTTP

Anything that can send JSON can raise a THEWATCH alert through the inbound webhook connector, and playbooks can call any API through catalog actions. If a tool has an API, THEWATCH can work with it.

Live today
Microsoft Defender Microsoft Entra ID Microsoft Sentinel SplunkSplunk Okta ServiceNow Jira CrowdStrike PagerDuty Proofpoint Google Workspace AWS GuardDuty SentinelOne HuntressHuntress Trend Micro Vision One Rapid7InsightIDR Cloudflare Snyk Auth0
Also live today
SentinelOne Huntress Trend Vision One Rapid7 InsightIDR Snyk Box 1Password Auth0 Datadog Zendesk NinjaOne Sophos Central Cisco Umbrella Malwarebytes Bitwarden Cisco Meraki Tailscale Carbon Black Cloud Kolide JumpCloud Slack Atlassian OneLogin GitLab GitGuardian Semgrep Netskope Freshservice Freshdesk Opsgenie Syncro Stripe Radar HackerOne Elastic Security Cortex XDR COLLECTiT! TAMPERLOGS RESEEKiT! and the whole PROVEiT! family
Product names identify each vendor's own service; THEWATCH connectors are built by THEWATCH and are not endorsed by or affiliated with these vendors.

Don't see your tool?

Tell us what you run and we'll confirm coverage, or build the connector natively when it earns a deep integration.

Ask about a connector →