Integrations

Jutsu connects to your SIEM and log sources, cloud and identity providers, response tools, and notification channels — so detection, investigation, and response all run against the systems you already operate.

How integrations work

Integrations fall into two halves of the SOC loop. Inbound integrations bring telemetry in: data sources stream alerts and events into the Jutsu Ingest API, where they are normalized and surfaced as alerts and events. Outbound integrations act on the world: cloud and identity connectors, SOAR platforms, ticketing systems, and notification channels let Jutsu and its AI agents respond, escalate, and inform.

Most inbound sources authenticate to the Ingest API with an organization-scoped API key, so each connection writes only to your organization's data. Outbound actions run through AgentSOAR connectors with a full, revertible audit trail.

Availability

The matrix below shows what is available today versus what is on the roadmap, grouped by category.

Roadmap items are planned and not yet available. Only entries marked Available can be connected in your deployment today.

Data sources

Telemetry that flows into Jutsu and becomes alerts and events. See Data sources.

IntegrationStatus
WazuhAvailable
Google Workspace email logsAvailable
SyslogAvailable
Custom eventsAvailable
SplunkRoadmap
Elastic SIEMRoadmap
Microsoft SentinelRoadmap
CrowdStrikeRoadmap
DatadogRoadmap
Sumo LogicRoadmap
GraylogRoadmap
IBM QRadarRoadmap

Cloud & identity

AgentSOAR connectors to cloud and identity providers that response actions run against. See Cloud & identity.

IntegrationStatus
AWSAvailable
GCPAvailable
AzureAvailable
HostingerAvailable
Google WorkspaceAvailable
Microsoft 365Available
AgentSOC Mail BlockAvailable

Response & SOAR

Where Jutsu runs and orchestrates response. See AgentSOAR overview.

IntegrationStatus
AgentSOAR (native)Available
ShuffleAvailable
Splunk SOARRoadmap
TinesRoadmap
Cortex XSOARRoadmap
n8nRoadmap
TorqRoadmap

Threat intelligence

Enrichment sources for indicators and reputation.

IntegrationStatus
VirusTotalRoadmap
AbuseIPDBRoadmap
AlienVault OTXRoadmap
GreyNoiseRoadmap
MalwareBazaarRoadmap
MISPRoadmap
CISA KEVRoadmap
ShodanRoadmap
Recorded FutureRoadmap

ITSM & ticketing

Hand off incidents to your service-management tools.

IntegrationStatus
ServiceNowRoadmap
JiraRoadmap
TheHiveRoadmap
PagerDutyRoadmap
OpsgenieRoadmap
ZendeskRoadmap

Notifications

Where Jutsu sends alerts and updates.

IntegrationStatus
SlackAvailable
TelegramAvailable
Microsoft TeamsRoadmap
DiscordRoadmap
MattermostRoadmap
TwilioRoadmap

Categories

Browse each category to set up a connection.

  • Wazuh — connect your first data source.
  • AWS — connect a cloud provider for response.
  • AgentSOAR overview — how response actions run.