Home Integrations

Integrations

Bhairava ships with 76 built-in integrations across SIEM, EDR, threat intelligence, cloud, network, notification, ticketing and identity — all exposed to the AI agents as tools through 15 MCP servers.

How integrations work

A central IntegrationRegistry manages every connector, runs bounded health checks, caches enrichment results in Redis, and exports each integration's actions as Anthropic/MCP-compatible tools so agents can call them during investigation. Adding an API key (in /opt/bhairava/.env or the Integrations page) activates a connector.

CategoryExamplesCount (approx)
SIEM / XDRWazuh, Sentinel, QRadar, Splunk, Elastic5
EDR / EndpointCrowdStrike, Defender, Sophos, Velociraptor6
Threat IntelVirusTotal, MISP, ThreatFox, OTX20+
CloudAWS, Azure, GCP, Kubernetes6
NOC / NetworkPrometheus, Zabbix, Suricata, Zeek12
Notification / ITSMSlack, PagerDuty, Jira, ServiceNow8
Identity / FirewallKeycloak, AD, WAF6

SIEM, XDR & EDR

Bhairava reads detections and telemetry from your SIEM and endpoint tools, and can push response actions back to them. Wazuh is the primary, natively bundled data source; the rest connect over their vendor APIs.

Threat Intelligence

Enrichment connectors resolve indicators — hashes, IPs, domains, URLs, emails and CVEs — against reputation, malware and vulnerability feeds, with results cached in Redis.

Cloud & Containers

Cloud connectors pull findings, audit logs and asset inventory from your providers so agents can investigate cloud-native activity alongside endpoint telemetry.

NOC & Network

Network and operations connectors feed metrics, flows and packet-level telemetry into the platform for correlation, availability monitoring and forensic analysis.

Notification, ITSM & Identity

Outbound connectors route alerts and human-in-the-loop approvals to your team, open and update tickets, and let agents query and act on identity and network-edge systems.

Detection & forensics tooling — YARA, Sigma, osquery, Volatility, OpenVAS and Trivy — are also integrated, powering the detection engine and forensic pipelines.