Ecosystem
Findings flow to your SIEM. Tickets open in your ITSM. Alerts land in Slack or Teams. Audit results surface in your GitHub Security tab. The platform ships with pre-built integrations across 7 SIEM platforms, 2 ITSM systems, major cloud providers, and 40+ vendor connectors — no integration projects required.
Execution Flexibility
AuditToolkit audit tools support five execution methods to fit any infrastructure environment. Choose the best fit for your network topology — from direct SSH/WinRM to agent-based or local execution.
Why it matters: Each execution path is optimised for different scenarios — agents work best for air-gapped networks, SSH/WinRM for open infrastructure, SNMP for network devices, and local execution for single-host verification.
SIEM & Security Operations
Every integration supports real-time event streaming. Your SOC sees configuration risk and compliance state changes alongside threat telemetry, in the tools they already monitor.
| Platform | Transport | What flows through |
|---|---|---|
| Wazuh | Syslog REST API | Finding events, compliance state changes, remediation actions — correlates with Wazuh intrusion detection alerts |
| Splunk | HTTP Event Collector (HEC) | JSON-formatted finding events with full control mapping metadata — build SPL queries across compliance and threat data |
| Elastic Stack (ELK) | Webhook (JSON) Filebeat log output | Structured finding events with severity, control ID, host, and timestamp — visualise in Kibana alongside Elasticsearch threat data |
| Microsoft Sentinel | Webhook → Azure Log Analytics | Finding events in JSON format with full control context — feed Sentinel analytics rules and workbooks |
| IBM QRadar | Syslog (CEF) REST API | CEF-formatted finding events with severity mapping — correlate with QRadar offenses and reference sets |
| Graylog | GELF Syslog | Structured finding events across Graylog streams and dashboards alongside other log sources |
| Prometheus + Grafana | Prometheus metrics endpoint | 60+ metrics — compliance scores, finding counts by severity, remediation velocity, host coverage — alert via Alertmanager |
ITSM & Workflow
Remediation tickets open automatically when findings exceed a configured severity threshold. Status is kept in sync as findings are addressed — no manual handoff between security and operations.
Bi-directional REST API integration
Bi-directional Jira REST API with deduplication
Collaboration
Daily digest summaries and real-time critical-finding alerts delivered to the channels where your team already operates.
Incoming Webhook — configurable channel and threshold
Incoming Webhook — Adaptive Card format
Developer & CI/CD
Embed audit results in the development workflow. Configuration regressions surface in pull requests before reaching production.
SARIF output + upload-sarif action
Linux Security Lite — direct issue creation from findings
POST /api/external-ingest — API key authenticated
Identity & Access
Integrate with the identity infrastructure your organisation already runs. Role-based access control applied throughout — every UI screen and API endpoint.
| Provider | Protocol | Notes |
|---|---|---|
| LDAP / Active Directory | RFC 4510 (ldap3) | AD group membership mapped to AuditToolkit RBAC roles |
| Microsoft Entra ID | OAuth 2.0 / OIDC | Single sign-on; Entra group membership used for RBAC role assignment |
| Okta | OIDC | SSO with Okta as identity provider; supports Okta MFA policies |
| TOTP MFA | RFC 6238 | QR code enrolment, backup recovery codes generated at enrolment for account recovery |
Cloud Platforms
Native connectors for all four major cloud providers. Asset discovery and configuration collection without deploying agents in cloud workloads.
AWS SDK — IAM role or access key auth
Azure SDK — service principal or managed identity
GCP SDK — service account auth
OCI SDK
Network & Infrastructure
Live API-backed collection from network switching infrastructure. Firmware versions correlated against vendor advisories, CVE databases, and CISA KEV status. No CLI scraping — structured API data only.
| Vendor | Platform | Transport |
|---|---|---|
| Cisco | IOS-XE, NX-OS | REST API NETCONF |
| Cisco | MDS SAN fabric | Scaffolded — roadmap |
| Juniper | JunOS | REST API NETCONF/YANG |
| Arista | EOS | eAPI (REST) |
| Aruba (HPE) | AOS-CX | REST API |
| Dell | OS10 | REST API |
| Brocade | SAN fabric | Scaffolded — roadmap |
| Checkpoint | Firewall management | Management API |
| Fortinet | FortiGate | Management API |
| Infoblox | IPAM / DDI | Management API |
The External Ingest API accepts findings from any tool using the standard producer schema. Contact us to discuss your environment.