Ecosystem

AuditToolkit integrates into your existing stack rather than replacing it.

Findings flow to your SIEM. Tickets open in your ITSM. Alerts land in Slack or Teams. Audit results surface in your GitHub Security tab. The platform ships with pre-built integrations across 7 SIEM platforms, 2 ITSM systems, major cloud providers, and 40+ vendor connectors — no integration projects required.

Execution Flexibility

Five integration paths from any tool

AuditToolkit audit tools support five execution methods to fit any infrastructure environment. Choose the best fit for your network topology — from direct SSH/WinRM to agent-based or local execution.

flowchart LR TOOL["Audit Tool"] TOOL -->|"Local"| LOCAL["Local Execution"] TOOL -->|"Agent"| AGENT["Fleet Agent"] TOOL -->|"SSH"| SSH["SSH"] TOOL -->|"WinRM"| WINRM["WinRM"] TOOL -->|"SNMP"| SNMP["SNMP"] AGENT --> TARGET["Target Host"] SSH --> TARGET WINRM --> TARGET SNMP --> TARGET LOCAL --> TARGET

Why it matters: Each execution path is optimised for different scenarios — agents work best for air-gapped networks, SSH/WinRM for open infrastructure, SNMP for network devices, and local execution for single-host verification.

SIEM & Security Operations

7 SIEM Platforms

Every integration supports real-time event streaming. Your SOC sees configuration risk and compliance state changes alongside threat telemetry, in the tools they already monitor.

Platform Transport What flows through
Wazuh Syslog REST API Finding events, compliance state changes, remediation actions — correlates with Wazuh intrusion detection alerts
Splunk HTTP Event Collector (HEC) JSON-formatted finding events with full control mapping metadata — build SPL queries across compliance and threat data
Elastic Stack (ELK) Webhook (JSON) Filebeat log output Structured finding events with severity, control ID, host, and timestamp — visualise in Kibana alongside Elasticsearch threat data
Microsoft Sentinel Webhook → Azure Log Analytics Finding events in JSON format with full control context — feed Sentinel analytics rules and workbooks
IBM QRadar Syslog (CEF) REST API CEF-formatted finding events with severity mapping — correlate with QRadar offenses and reference sets
Graylog GELF Syslog Structured finding events across Graylog streams and dashboards alongside other log sources
Prometheus + Grafana Prometheus metrics endpoint 60+ metrics — compliance scores, finding counts by severity, remediation velocity, host coverage — alert via Alertmanager

ITSM & Workflow

ServiceNow & Jira

Remediation tickets open automatically when findings exceed a configured severity threshold. Status is kept in sync as findings are addressed — no manual handoff between security and operations.

📋

ServiceNow

Bi-directional REST API integration

  • Automatic incident or problem record creation with finding detail, severity, affected host, and remediation guidance pre-populated
  • SLA timer alignment to finding severity levels
  • Ticket closure in ServiceNow acknowledged in AuditToolkit; re-opened findings re-open or create new tickets
  • Instance URL, API credentials, and field mapping configured via admin panel
📄

Jira

Bi-directional Jira REST API with deduplication

  • Automatic issue creation in a configurable project with labels, priority, and description derived from the finding
  • Deduplication — existing open issues are tracked by ID; no duplicate issues for the same finding
  • Issue transitions in Jira reflected back to AuditToolkit finding status
  • Instance URL, project key, API token, and field mapping configured via admin panel

Collaboration

Slack & Microsoft Teams

Daily digest summaries and real-time critical-finding alerts delivered to the channels where your team already operates.

💬

Slack

Incoming Webhook — configurable channel and threshold

  • Daily digest: compliance posture changes, new critical findings, and remediation progress on schedule
  • Real-time alert when a FAIL finding at or above the configured severity threshold is detected
  • Structured message blocks with severity colour coding, affected host, control reference, and direct link to the finding
📱

Microsoft Teams

Incoming Webhook — Adaptive Card format

  • Daily digest delivered to a Teams channel on the same schedule as the Slack integration
  • Real-time Teams message for critical findings with severity, host, control reference, and direct link
  • Adaptive Card format for rich rendering in Teams channels

Developer & CI/CD

GitHub Actions, SARIF & External Ingest

Embed audit results in the development workflow. Configuration regressions surface in pull requests before reaching production.

GitHub Actions & Security Tab

SARIF output + upload-sarif action

  • SARIF output uploaded to the GitHub Security tab — findings appear alongside code scanning results
  • Pull request merges blocked when audits introduce new critical findings
  • CI workflow templates provided for immediate integration into existing pipelines
🐞

GitHub Issues

Linux Security Lite — direct issue creation from findings

  • Deduplicated GitHub Issues created from audit findings — existing open issues are not duplicated
  • Automatically assigned and labelled for triage by the owning team
🔁

External Ingest API

POST /api/external-ingest — API key authenticated

  • Push findings from any third-party or in-house tool into the AuditToolkit unified posture view
  • Uses the standard producer-output schema — no custom adapters required
  • Idempotency key support prevents duplicate records from repeated pushes

Identity & Access

AD, Entra ID, Okta & TOTP MFA

Integrate with the identity infrastructure your organisation already runs. Role-based access control applied throughout — every UI screen and API endpoint.

Provider Protocol Notes
LDAP / Active Directory RFC 4510 (ldap3) AD group membership mapped to AuditToolkit RBAC roles
Microsoft Entra ID OAuth 2.0 / OIDC Single sign-on; Entra group membership used for RBAC role assignment
Okta OIDC SSO with Okta as identity provider; supports Okta MFA policies
TOTP MFA RFC 6238 QR code enrolment, backup recovery codes generated at enrolment for account recovery

Cloud Platforms

AWS, Azure, GCP & Oracle Cloud

Native connectors for all four major cloud providers. Asset discovery and configuration collection without deploying agents in cloud workloads.

Amazon Web Services

AWS SDK — IAM role or access key auth

  • EC2, RDS, S3, IAM, VPC, EKS, Lambda
  • CloudTrail, Config, Security Hub
🔸

Microsoft Azure

Azure SDK — service principal or managed identity

  • Virtual Machines, AKS, Azure SQL, Storage Accounts
  • Key Vault, Entra ID, Defender for Cloud
🔹

Google Cloud Platform

GCP SDK — service account auth

  • Compute Engine, GKE, Cloud SQL, Cloud Storage
  • IAM, Security Command Center
🔺

Oracle Cloud Infrastructure

OCI SDK

  • Compute, VCN, Object Storage
  • IAM, Database

Network & Infrastructure

Cisco, Juniper, Arista, Aruba, Dell & more

Live API-backed collection from network switching infrastructure. Firmware versions correlated against vendor advisories, CVE databases, and CISA KEV status. No CLI scraping — structured API data only.

Vendor Platform Transport
Cisco IOS-XE, NX-OS REST API NETCONF
Cisco MDS SAN fabric Scaffolded — roadmap
Juniper JunOS REST API NETCONF/YANG
Arista EOS eAPI (REST)
Aruba (HPE) AOS-CX REST API
Dell OS10 REST API
Brocade SAN fabric Scaffolded — roadmap
Checkpoint Firewall management Management API
Fortinet FortiGate Management API
Infoblox IPAM / DDI Management API
Switch Exposure Centre: firmware currency and CVE advisory correlation for all live API-backed network vendors above. Vendor advisory feeds via public RSS, vendor-gated account feeds, or customer-managed CSV/XML imports.

Integration not listed?

The External Ingest API accepts findings from any tool using the standard producer schema. Contact us to discuss your environment.