Integrations List

Everything that connects to CyberFortress

43 integrations across email, storage, network, endpoint and your SOC tooling. 16 ship as built-in connectors; the rest connect through the RESTful API or syslog.

43

Integrations available today

16

Built-in connectors, no code required

27

Connected over the API or syslog

8

Categories, from mail flow to threat intel

API & automation

The two open interfaces underneath every other integration on this page – and the route for anything not listed.

2
API

RESTful API

Submit files and URLs, poll or receive verdicts, pull full reports and IOCs, and drive platform actions from your own tooling. Every integration below is built on this interface.

API · Syslog

Syslog

Stream analysis results, verdicts and platform events to any collector that speaks syslog, for SIEMs and log platforms that prefer ingestion over polling.

Email

Attachments are pulled out of the mail flow and detonated before they reach a mailbox.

2
Built-in

Imap Email

Imap Email integration scans incoming emails and automatically sends the attachments to CyberFortress SBOX for security analysis.

Built-in

Postfix Email

Postfix Email integration scans incoming emails to the smtp port and automatically sends the attachments to CyberFortress SBOX for security analysis.

Files & storage

Anything landing in shared storage is checked before another user or workload picks it up.

12
Built-in

Sharepoint

SharePoint integration enhances file sharing security in Microsoft's cloud-based storage platforms through CyberFortress SBOX.

Built-in

File Share

The File Share integration allows CyberFortress SBOX to scan the traffic that takes place in various other party file sharing locations.

Built-in

Bulk Scan

The Bulk Scan integration allows CyberFortress SBOX to scan the traffic that takes place in various other party file sharing locations.

Push

USB Transfer

The USB Transfer integration secures data transfers conducted through USB using CyberFortress SBOX.

API

OneDrive

Files synced to OneDrive are submitted for analysis before they are shared onward or pulled down by another device.

API

Google Drive

Uploads and shared-drive activity are forwarded for sandbox analysis through the Drive API.

API

Box

Content uploaded to Box is checked for malicious payloads before it becomes available to collaborators.

API

Dropbox

Dropbox uploads are submitted for detonation, keeping shared team folders clear of weaponised documents.

API

Amazon S3

Objects written to S3 buckets are scanned on arrival, so malicious uploads never reach downstream workloads.

API

Azure Blob Storage

Blob container activity is inspected for malicious content as part of the cloud storage protection workflow.

API

FTP / SFTP

Files arriving over FTP or SFTP transfer points are analysed before release into the internal network.

API

Nextcloud

Self-hosted Nextcloud instances submit uploaded files for sandbox analysis through the API.

Network

Traffic is inspected in path or out of band, so malicious content is caught in transit.

4
Built-in

ICAP Proxy

ICAP Proxy integration aims to protect users from malicious content within web proxy communications by analyzing it through CyberFortress SBOX.

Built-in

Tap Interface

TAP Interface integration allows for the analysis of network traffic through CyberFortress SBOX.

Push

Broadcom CAS

Broadcom Content Analysis System integration enables automatic forwarding of suspicious files from Broadcom CAS to CyberFortress SBOX as an external analysis engine.

Push

OPSWAT MetaDefender

OPSWAT MetaDefender NDR integration forwards suspicious network artifacts detected by MetaDefender directly to CyberFortress SBOX for in-depth sandbox analysis.

Endpoint & EDR

Files an EDR flags as suspicious are escalated for full sandbox analysis automatically.

2
Built-in

CS Falcon

The EDR API integration enhances the security of files flagged by EDR systems by automatically analyzing those that are identified as malicious or suspicious.

Built-in

MS Defender

The Microsoft Defender integration enhances the security of endpoint devices by analyzing files that Windows Defender flags as potentially malicious.

SIEM & log platforms

Verdicts, IOCs and platform events land in the system your analysts already watch – over the API, or streamed as syslog.

11
Push

Google Security Operations

Google Security Operations integration enables Chronicle SIEM/SOAR playbooks to automatically submit suspicious samples to CyberFortress SBOX during threat investigations.

Push

Sumo Logic

Sumo Logic integration connects CyberFortress SBOX with Sumo Logic's security analytics platform to enrich threat investigations with automated sandbox analysis.

API · Syslog

Splunk

Analysis results and extracted IOCs are indexed in Splunk, and saved searches can submit suspicious artefacts back for detonation.

API · Syslog

Elastic Security

Verdicts and sandbox reports are shipped into Elastic, enriching detection rules and investigation timelines.

API · Syslog

IBM QRadar

Offenses in QRadar are enriched with CyberFortress verdicts, and suspicious files can be escalated for full analysis.

API · Syslog

Microsoft Sentinel

Sentinel incidents receive sandbox context and IOCs, so analysts triage with the full picture in the Azure console.

API · Syslog

Rapid7 InsightIDR

Detections raised in InsightIDR are enriched with behavioural analysis results from the sandbox.

API · Syslog

LogRhythm

Sandbox verdicts and IOCs are forwarded into LogRhythm for correlation against the rest of your telemetry.

API · Syslog

ArcSight

Events and analysis outcomes stream into ArcSight over syslog for long-running correlation use cases.

API · Syslog

Graylog

Platform events and verdicts are ingested by Graylog through standard syslog forwarding.

API · Syslog

Wazuh

Wazuh agents and rulesets are enriched with CyberFortress analysis results for open-source SIEM deployments.

SOAR & automation platforms

CyberFortress becomes a step in your existing playbooks: submit, wait for the verdict, then act on it.

6
Push

Cortex XSOAR

Cortex XSOAR integration embeds CyberFortress SBOX as a sandbox analysis engine within XSOAR playbooks for automated file inspection during incident response.

API

Splunk SOAR

Splunk SOAR playbooks call CyberFortress as a detonation action and branch on the returned verdict.

API

FortiSOAR

FortiSOAR playbooks submit suspicious files and IOCs for analysis, feeding results back into the incident record.

API

Tines

Tines stories orchestrate submission and verdict retrieval with no code, chaining CyberFortress into wider response workflows.

API

Swimlane

Swimlane automations use the API to escalate artefacts for sandbox analysis during case handling.

API

Torq

Torq workflows submit files and URLs for analysis and route the outcome to the right responder automatically.

Threat intelligence

Indicators flow both ways – enrich an investigation, then publish what the sandbox found back to the platform.

4
Push

ThreatQ

ThreatQ Platform integration submits suspicious files and IOCs from ThreatQ's threat intelligence workflows to CyberFortress SBOX, enriching analysis results back into the platform.

API

MISP

IOCs extracted during analysis are published to MISP events, and MISP attributes can be submitted for detonation.

API

Anomali ThreatStream

Observables from ThreatStream are enriched with sandbox verdicts and MITRE ATT&CK mappings.

API

OpenCTI

Analysis outputs are pushed into OpenCTI as observables and relationships for knowledge-graph driven investigation.

Not seeing yours?

The RESTful API covers anything not on this list – submit files and URLs, pull back verdicts and reports, and drive actions from your own tooling. Tell us what you run and we will show you how it connects.