43 integrations across email, storage, network, endpoint and your SOC tooling. 16 ship as built-in connectors; the rest connect through the RESTful API or syslog.
Integrations available today
Built-in connectors, no code required
Connected over the API or syslog
Categories, from mail flow to threat intel
The two open interfaces underneath every other integration on this page – and the route for anything not listed.
Submit files and URLs, poll or receive verdicts, pull full reports and IOCs, and drive platform actions from your own tooling. Every integration below is built on this interface.
Stream analysis results, verdicts and platform events to any collector that speaks syslog, for SIEMs and log platforms that prefer ingestion over polling.
Attachments are pulled out of the mail flow and detonated before they reach a mailbox.
Imap Email integration scans incoming emails and automatically sends the attachments to CyberFortress SBOX for security analysis.
Postfix Email integration scans incoming emails to the smtp port and automatically sends the attachments to CyberFortress SBOX for security analysis.
Anything landing in shared storage is checked before another user or workload picks it up.
SharePoint integration enhances file sharing security in Microsoft's cloud-based storage platforms through CyberFortress SBOX.
The File Share integration allows CyberFortress SBOX to scan the traffic that takes place in various other party file sharing locations.
The Bulk Scan integration allows CyberFortress SBOX to scan the traffic that takes place in various other party file sharing locations.
The USB Transfer integration secures data transfers conducted through USB using CyberFortress SBOX.
Files synced to OneDrive are submitted for analysis before they are shared onward or pulled down by another device.
Uploads and shared-drive activity are forwarded for sandbox analysis through the Drive API.
Content uploaded to Box is checked for malicious payloads before it becomes available to collaborators.
Dropbox uploads are submitted for detonation, keeping shared team folders clear of weaponised documents.
Objects written to S3 buckets are scanned on arrival, so malicious uploads never reach downstream workloads.
Blob container activity is inspected for malicious content as part of the cloud storage protection workflow.
Files arriving over FTP or SFTP transfer points are analysed before release into the internal network.
Self-hosted Nextcloud instances submit uploaded files for sandbox analysis through the API.
Traffic is inspected in path or out of band, so malicious content is caught in transit.
ICAP Proxy integration aims to protect users from malicious content within web proxy communications by analyzing it through CyberFortress SBOX.
TAP Interface integration allows for the analysis of network traffic through CyberFortress SBOX.
Broadcom Content Analysis System integration enables automatic forwarding of suspicious files from Broadcom CAS to CyberFortress SBOX as an external analysis engine.
OPSWAT MetaDefender NDR integration forwards suspicious network artifacts detected by MetaDefender directly to CyberFortress SBOX for in-depth sandbox analysis.
Files an EDR flags as suspicious are escalated for full sandbox analysis automatically.
The EDR API integration enhances the security of files flagged by EDR systems by automatically analyzing those that are identified as malicious or suspicious.
The Microsoft Defender integration enhances the security of endpoint devices by analyzing files that Windows Defender flags as potentially malicious.
Verdicts, IOCs and platform events land in the system your analysts already watch – over the API, or streamed as syslog.
Google Security Operations integration enables Chronicle SIEM/SOAR playbooks to automatically submit suspicious samples to CyberFortress SBOX during threat investigations.
Sumo Logic integration connects CyberFortress SBOX with Sumo Logic's security analytics platform to enrich threat investigations with automated sandbox analysis.
Analysis results and extracted IOCs are indexed in Splunk, and saved searches can submit suspicious artefacts back for detonation.
Verdicts and sandbox reports are shipped into Elastic, enriching detection rules and investigation timelines.
Offenses in QRadar are enriched with CyberFortress verdicts, and suspicious files can be escalated for full analysis.
Sentinel incidents receive sandbox context and IOCs, so analysts triage with the full picture in the Azure console.
Detections raised in InsightIDR are enriched with behavioural analysis results from the sandbox.
Sandbox verdicts and IOCs are forwarded into LogRhythm for correlation against the rest of your telemetry.
Events and analysis outcomes stream into ArcSight over syslog for long-running correlation use cases.
Platform events and verdicts are ingested by Graylog through standard syslog forwarding.
Wazuh agents and rulesets are enriched with CyberFortress analysis results for open-source SIEM deployments.
CyberFortress becomes a step in your existing playbooks: submit, wait for the verdict, then act on it.
Cortex XSOAR integration embeds CyberFortress SBOX as a sandbox analysis engine within XSOAR playbooks for automated file inspection during incident response.
Splunk SOAR playbooks call CyberFortress as a detonation action and branch on the returned verdict.
FortiSOAR playbooks submit suspicious files and IOCs for analysis, feeding results back into the incident record.
Tines stories orchestrate submission and verdict retrieval with no code, chaining CyberFortress into wider response workflows.
Swimlane automations use the API to escalate artefacts for sandbox analysis during case handling.
Torq workflows submit files and URLs for analysis and route the outcome to the right responder automatically.
Indicators flow both ways – enrich an investigation, then publish what the sandbox found back to the platform.
ThreatQ Platform integration submits suspicious files and IOCs from ThreatQ's threat intelligence workflows to CyberFortress SBOX, enriching analysis results back into the platform.
IOCs extracted during analysis are published to MISP events, and MISP attributes can be submitted for detonation.
Observables from ThreatStream are enriched with sandbox verdicts and MITRE ATT&CK mappings.
Analysis outputs are pushed into OpenCTI as observables and relationships for knowledge-graph driven investigation.
The RESTful API covers anything not on this list – submit files and URLs, pull back verdicts and reports, and drive actions from your own tooling. Tell us what you run and we will show you how it connects.