Integrations
Bhairava ships with 76 built-in integrations across SIEM, EDR, threat intelligence, cloud, network, notification, ticketing and identity — all exposed to the AI agents as tools through 15 MCP servers.
How integrations work
A central IntegrationRegistry manages every connector, runs bounded health checks, caches enrichment results in Redis, and exports each integration's actions as Anthropic/MCP-compatible tools so agents can call them during investigation. Adding an API key (in /opt/bhairava/.env or the Integrations page) activates a connector.
| Category | Examples | Count (approx) |
|---|---|---|
| SIEM / XDR | Wazuh, Sentinel, QRadar, Splunk, Elastic | 5 |
| EDR / Endpoint | CrowdStrike, Defender, Sophos, Velociraptor | 6 |
| Threat Intel | VirusTotal, MISP, ThreatFox, OTX | 20+ |
| Cloud | AWS, Azure, GCP, Kubernetes | 6 |
| NOC / Network | Prometheus, Zabbix, Suricata, Zeek | 12 |
| Notification / ITSM | Slack, PagerDuty, Jira, ServiceNow | 8 |
| Identity / Firewall | Keycloak, AD, WAF | 6 |
SIEM, XDR & EDR
Bhairava reads detections and telemetry from your SIEM and endpoint tools, and can push response actions back to them. Wazuh is the primary, natively bundled data source; the rest connect over their vendor APIs.
Wazuh— native SIEM/HIDS/FIMMicrosoft SentinelIBM QRadarSplunkElasticsearchCrowdStrike FalconMicrosoft Defender for EndpointSophos CentralVelociraptor- The built-in Bhairava managed agent
Threat Intelligence
Enrichment connectors resolve indicators — hashes, IPs, domains, URLs, emails and CVEs — against reputation, malware and vulnerability feeds, with results cached in Redis.
VirusTotalShodanMISPAlienVault OTXabuse.ch ThreatFoxabuse.ch MalwareBazaarAbuseIPDBURLhausGreyNoisePhishTankNVDCISA KEVGitHub Security Advisories (GHSA)OSVIPinfoWHOISHave I Been Pwned (HIBP)SpyCloudFlare
Cloud & Containers
Cloud connectors pull findings, audit logs and asset inventory from your providers so agents can investigate cloud-native activity alongside endpoint telemetry.
AWS— GuardDuty, CloudTrail, EC2Azure— Activity Log, NSG, Defender for CloudGCP— Audit Logs, Security Command CenterKubernetes
NOC & Network
Network and operations connectors feed metrics, flows and packet-level telemetry into the platform for correlation, availability monitoring and forensic analysis.
PrometheusGrafanaLokiZabbixOpenSearchSyslogNetFlow/sFlow/IPFIXSuricataZeekNetBoxPCAP
Notification, ITSM & Identity
Outbound connectors route alerts and human-in-the-loop approvals to your team, open and update tickets, and let agents query and act on identity and network-edge systems.
SlackPagerDutyWebhookEmailJiraServiceNowosTicketActive Directory / IAMKeycloakSAML- Plus firewall, WAF and proxy connectors
Detection & forensics tooling — YARA, Sigma, osquery, Volatility, OpenVAS and Trivy — are also integrated, powering the detection engine and forensic pipelines.