Skip to main content
Wirespeed connects to your existing security tools to provide automated threat detection, investigation, and response. Our integrations are designed to work together—combining detection sources with user directories, endpoint managers, and communication platforms to enable a fully automated MDR experience.
New to Wirespeed? Start by connecting a user directory and a detection source to see our automation in action.

How Integrations Work

When you connect an integration, Wirespeed automatically:
  1. Syncs your data — We pull user directories, endpoint inventories, and detection history to build context about your environment
  2. Ingests detections — Security alerts flow into Wirespeed in real-time from your detection platforms
  3. Enriches and triages — Each detection is automatically enriched with context and triaged using our verdict system
  4. Takes action — Based on your configured verdicts, Wirespeed can contain threats, notify users via chat ops, or escalate to your team
All integrations use secure OAuth or API tokens. We request only the permissions necessary to deliver our service and never store credentials in plain text.

Integration Categories


Detection Sources

Detection sources are the foundation of Wirespeed. These integrations provide the security alerts that Wirespeed automatically triages and responds to. Connect your EDR, XDR, identity protection, or SIEM platform to get started.

User Directories

User directories help Wirespeed understand your organization. We sync users, groups, roles, and managers to enrich detections with context and enable features like VIP protection, chat ops escalation, and user containment.
Connecting a user directory unlocks automatic VIP detection, manager escalation paths, and user-aware threat context.

Endpoint Management

Endpoint management integrations provide device inventory and health data. Wirespeed uses this information to identify high-value assets, correlate detections with device context, and enable endpoint containment actions.

Communication

Communication integrations enable Chat Ops—Wirespeed’s ability to verify suspicious activity directly with your users. When a detection requires user verification, we reach out through your existing communication channels.
SMS verification is available as an add-on to any communication integration for enhanced identity verification. Learn more about SMS Chat Ops.

Ticketing

Ticketing integrations sync Wirespeed cases with your existing ticket management system. Cases and detections can automatically create tickets, and updates flow bidirectionally.

Enrichment

Enrichment integrations provide additional context and threat intelligence to enhance detection triage. These services help identify known-bad indicators and provide reputation data.

Log Forwarding

For platforms without native integrations, Wirespeed supports standard log forwarding protocols and network-based telemetry sources. These allow you to send security events from any source, including firewalls, network devices, and log aggregation platforms.

Getting Started

Ready to connect your first integration? Here’s the recommended order:
1

Connect a User Directory

Start with Microsoft 365, Google Workspace, or Okta to import your users and organizational structure.
2

Add a Detection Source

Connect your primary security platform—Microsoft Defender, CrowdStrike, or SentinelOne are great starting points.
3

Enable Communication

Set up Slack or Microsoft Teams to enable Chat Ops for user verification.
4

Configure Containment

Review your containment settings to enable automated threat response.
Need help setting up an integration? Use the Chat button in the Wirespeed platform to talk directly with our engineers, or email [email protected].