Skip to content
Explore platformIntegrations
Integrations

Put the tools you own
to work together.

Imperum’s connectors bring external data and actions into your SOC workflows. Find your tools in the Marketplace, configure their access, and use their capabilities in investigations, playbooks and agents.

1,551 catalogue entries40 categories29,060 listed actions
From the catalogue to a connector’s actionsCatalogue snapshot · 1 Sep 2026
crowdstrikeOne dot = one catalogue entry
Explore all 40 categories
Threat intelligence188Cloud122Endpoint / EDR99Network99Identity89Email security76SIEM74Webhook sources69Vulnerability63Other47Compliance46Firewall45IT service management42Communication41Sandbox40SOAR39DevSecOps38Data security35IoT and OT35Antivirus32Database31Backup27DNS security25Deception21Ticketing19Mobile / MDM18MSP18Automation16AI and LLM14SaaS security10Productivity8Browser security7Cloud platform5Forensics5ERP2Log management2CI / CD1Monitoring1NDR1Network security1
10 matches for “crowdstrike”Across 8 categories
CrowdStrike Falcon Endpoint SecurityEndpoint / EDR
302listed actions
92 search85 read16 execute109 other

Inspect the connector’s listed actions before configuring it. Action categories describe operations; they are not approval or risk levels.

Inventory figures describe the bundled catalogue, not active connections. Available actions depend on the connector, configuration, vendor access and the workflow using them.

DiscoverFind the relevant connector
ConfigureSet access for your environment
UseBring data and actions into work
01 - Find your tools

See what connects. And what it can do.

Search the catalogue by product name or connector ID. An entry represents a connector; its actions are the individual operations it lists, such as searching detections or reading endpoint details.

Showing 12 of 1,551 catalogue entries

  • CrowdStrike Falcon Endpoint SecurityEndpoint / EDR302 actions
  • Palo Alto PAN-OSFirewall204 actions
  • WazuhSIEM149 actions
  • MMicrosoft Defender for Endpoint (Graph)Endpoint / EDR100 actions
  • MMicrosoft Defender for Endpoint (Security Center)Endpoint / EDR100 actions
  • FFortiweb VmFirewall99 actions
  • LogRhythm SIEMSIEM94 actions
  • SentinelOne SingularityEndpoint / EDR90 actions
  • IBM QRadar SIEMSIEM87 actions
  • Google Cloud ComputeCloud83 actions
  • SSplunk EnterpriseSIEM75 actions
  • TTeamT5 ThreatVisionThreat intelligence71 actions

Catalogue snapshot: 1 September 2026. Product names and marks belong to their owners; their inclusion does not imply endorsement or partnership.

02 - Connect and use

Make the connection useful.

A catalogue entry is the starting point. Configure the connector for your environment, then use the data and operations it supports.

  1. 01

    Choose the connector and tenant

    Select the connector in Marketplace and choose its deployment context. In multi-tenant environments, profiles keep each tenant’s endpoint and credentials separate.

  2. 02

    Configure access and check the result

    Supply the required endpoint and credentials, stored encrypted in the Vault. Test the connection and review the reported result: reaching an endpoint does not by itself confirm authentication.

  3. 03

    Bring data into investigations

    For connectors with ingestion support, configure polling or the relevant webhook path and field mapping. Normalized events give your team a consistent basis for search and investigation.

  4. 04

    Use actions in the workflow

    Automatio playbooks can call connector actions, and agents can use the connector tools enabled for them. Credentials, tenant access and the calling workflow’s permissions and approval rules determine what can run.

03 - Extend the catalogue

Connect the systems built around your business.

When you need an internal API or a different set of operations, Developer Studio lets you author a connector and bring it into the same Marketplace workflow.

Define the connector

Specify authentication, actions and entities. Add ingestion and normalization where needed, then review and deploy the package.

Give your own systems a reusable connection to SOC workflows.

Start from an API specification

Import an OpenAPI or Swagger specification, review the proposed operations and select the ones to turn into connector actions.

Reuse the API’s structure as the starting point for authoring.

InputAPI specificationOpenAPI 3 · Swagger 2
ReviewSelected operationsUp to 150 per generation
OutputConnector actionsReview, configure, deploy

Developer Studio authoring in the Marketplace UI requires SecOps Platform and the relevant permissions. Authoring and deployment remain subject to product access and permissions. Specification imports have a size limit, 16 MB by default. Generated connectors still need configuration and testing.

Questions about integrations.

1Is a connector the same as an action?

A connector describes an integration with a system. Its actions are individual operations, such as searching for detections or reading a host record. The catalogue counts entries and their listed actions separately.

2Does every connector ingest alerts?

No. Ingestion depends on the connector’s capabilities and configuration. Some support polling or webhook input; others supply actions used for enrichment or response. Review the connector before deployment.

3Can different tenants use different credentials?

Yes. In multi-tenant environments, connector profiles hold tenant-specific endpoints and credentials. Named instance profiles also support separate deployments of the same connector within a tenant.

4Will every action wait for approval?

No. Approval depends on the action, the agent or playbook calling it, and the configured policy. Catalogue categories such as “read” or “execute” are not a universal approval rule. Review the execution controls when enabling actions.

5What if our tool is not listed?

Developer Studio supports custom connectors and API specification import, subject to product access and permissions. Share the tool and API requirements with our team to discuss the appropriate integration approach.

Have another question?
Talk to our team

Bring your tools.Build the connection.

Share the systems your SOC runs. We’ll explore the relevant connectors, the actions they expose and how to connect what is unique to your environment.