Integrations

Works with your
entire stack.

n0limit plugs directly into every major SIEM, EDR, SOAR, cloud platform, and ticketing system. No rip-and-replace — your investment is protected.

40+Vendor integrations
<1 hrAverage time to connect
MCPAI agent protocol
Step 01

Connect your sources

Point n0limit at your existing SIEM or EDR via API key or OAuth. No agents to install, no firewall changes required.

Step 02

Normalize at ingestion

Every alert is mapped to OCSF and enriched with threat intelligence — vendor-agnostic, searchable, and correlated across sources.

Step 03

Push findings back

Case briefs, verdicts, and response actions write back to your ticketing and SOAR system automatically — closing the loop.

NEW
Model Context Protocol

n0limit speaks MCP.

Model Context Protocol (MCP) is the open standard for connecting AI agents to live data sources and tools. n0limit ships a fully compliant MCP server — meaning any MCP-capable AI assistant can query your security posture, pull investigation context, and take response actions, all via a standard, secure interface.

No bespoke integrations. No custom plugins. If your AI tool speaks MCP, it works with n0limit out of the box.

● Live in production
MCP Server
n0limit as a data source

AI agents connect to n0limit to fetch open investigations, alert summaries, threat intelligence context, and verdict history — in real time, with tenant-scoped access control.

MCP Client
n0limit calling external tools

During investigations, n0limit's AI engine uses MCP to pull context from external tool servers — enriching detections with asset inventory, vulnerability data, or business context from your stack.

Compatible with
Claude
Cursor
Windsurf
Any MCP host

Security Information & Event Management

n0limit ingests alerts from every major SIEM, normalizes them, and returns enriched verdicts with full investigation context.

Microsoft Sentinel

Cloud-native SIEM. Pull all incidents and analytics rules via the Microsoft Sentinel REST API.

● Native
Splunk Enterprise

On-prem and Cloud SIEM. Bidirectional integration via Splunk REST API and HEC input.

● Native
IBM QRadar

IBM's SIEM platform. Pull offenses and flows via QRadar RESTful API.

● Supported
Elastic SIEM

Elastic Security. Ingest detection alerts via Elasticsearch API, sync cases back.

● Supported
Google Chronicle

Google's planet-scale SIEM. Integration via Chronicle API with UDM event support.

● Supported
LogRhythm SIEM

Ingest alarms and log sources from LogRhythm via REST API.

● Supported

Endpoint Detection & Response

n0limit enriches EDR detections with investigation context and returns response actions — isolate, contain, remediate — all from a single workflow.

CrowdStrike Falcon

Industry-leading EDR. Pull detections and stream telemetry via Falcon Data Replicator and SIEM Connector.

● Native
SentinelOne

AI-powered EDR. Pull threats, query Deep Visibility, and trigger response via Management API.

● Native
Microsoft Defender

Microsoft Defender for Endpoint. Pull alerts and advanced hunting results via Graph Security API.

● Native
Palo Alto Cortex XDR

Cortex XDR alerts, incidents, and endpoint telemetry via Cortex REST API.

● Supported
VMware Carbon Black

CB Cloud alerts and process activity via Carbon Black Cloud REST API with watchlist integration.

● Supported
Cybereason

Malop detections and investigation timelines via Cybereason API.

● Supported

Orchestration & Case Management

Close the loop — n0limit returns investigation verdicts directly into your playbooks and service desk, fully automated.

ServiceNow

Create, update, and close SecOps incidents and change requests automatically via ServiceNow REST API.

● Native
Jira / Atlassian

Auto-create and update Jira issues for every confirmed threat via Atlassian REST API and webhooks.

● Native
PagerDuty

Trigger and auto-resolve PagerDuty incidents with full n0limit investigation context attached.

● Supported
Splunk SOAR

Feed n0limit verdicts into Splunk SOAR playbooks for fully automated response execution.

● Supported
Palo Alto XSOAR

Push n0limit case data into XSOAR incidents and trigger automated playbooks via REST.

● Supported
Microsoft Teams

Post threat verdicts and analyst notifications to Teams channels via Incoming Webhooks.

● Supported

Cloud Security & Identity Platforms

Correlate cloud posture alerts, identity events, and IAM anomalies alongside endpoint and network detections — all in one investigation.

AWS Security Hub

Ingest GuardDuty, Security Hub findings, and CloudTrail events via EventBridge.

● Native
Azure Defender

Microsoft Defender for Cloud alerts via Event Hub streaming and Azure Monitor APIs.

● Native
Okta

Pull Okta System Log events, detect impossible travel and credential stuffing, feed into investigations.

● Native
Google Cloud SCC

Google Security Command Center findings via Pub/Sub streaming and the Security Command Center API.

● Supported
Microsoft Entra ID

Azure AD sign-in logs and Identity Protection risk events via Microsoft Graph API.

● Supported
Wiz

Cloud posture issues and critical attack path alerts from Wiz via REST API integration.

● Supported

Network Security & Firewall Platforms

Network telemetry and firewall logs enrich every investigation with traffic context, lateral movement signals, and perimeter breach data.

Palo Alto Networks

Firewall threat logs, WildFire malware events, and Panorama policy data via PAN-OS XML API.

● Native
Fortinet FortiGate

FortiGate and FortiSIEM logs via syslog and REST API, including IPS and application control events.

● Supported
Check Point

SmartEvent and Harmony Endpoint alerts via Check Point Smart-1 API and log export.

● Supported
Cisco Secure

Cisco Secure Firewall and Umbrella events via SecureX API and syslog ingestion.

● Supported
Darktrace

AI-detected anomalies and model breaches via Darktrace REST API for network correlation.

● Supported
Custom Connector

Not listed? Use the n0limit Connector SDK to build a custom integration in under a day.

→ SDK docs

Ready to connect your stack?

A solutions engineer will map your existing tools to n0limit in 30 minutes.

Book a demo