Have something to say?

Tell us how we could make the product more useful to you.

Google Workspace Integration

Summary Build a Google Workspace integration for Guard to discover and inventory assets across Google Cloud Identity, Gmail, Drive, and other Workspace services. Background Customers using Google Workspace lack visibility into their Google-managed assets within Guard. Similar to existing Azure AD and Okta integrations, a Workspace integration would provide identity-based asset discovery and configuration posture assessment. Scope Integrate with Google Workspace Admin SDK for user and device inventory Discover Google Cloud Identity assets (users, groups, devices) Surface Workspace configuration risks (e.g., MFA status, admin privileges, sharing policies) Acceptance Criteria Google Workspace assets are discovered and visible in the Guard asset inventory Integration supports OAuth 2.0 with appropriate Workspace scopes Configuration risks are surfaced as findings Tests passing / Documentation updated References Comparable: Azure AD, Okta identity integrations API: Google Workspace Admin SDK

πŸ’‘

Feature

8 months ago

Splunk Cloud Integration

Value Proposition What customers get by integrating Guard and Splunk Cloud: Guard becomes the external attack surface intelligence layer that feeds Splunk's detection engine β€” customers get continuous asset discovery and vulnerability data flowing directly into their SIEM, enabling risk-based alerting on real external exposure rather than relying solely on internal log telemetry. This closes the blind spot between what Splunk can see (internal events) and what attackers can see (external attack surface). Specifically, customers gain: Automated risk enrichment: Guard-discovered assets, vulnerabilities, and risk scores injected into Splunk's Risk-Based Alerting (RBA) framework, correlating external exposure with internal threat signals for higher-fidelity alerts (Splunk claims 50-90% alert volume reduction with RBA) Continuous attack surface visibility in SOC workflows: Guard findings surface directly in the ES Analyst Queue β€” no context-switching between platforms Detection coverage expansion: Guard's external asset inventory mapped against Splunk's 1,615+ MITRE ATT&CK-aligned detections, identifying gaps where external exposure exists but detection coverage doesn't Compliance evidence automation: Combined internal (Splunk) + external (Guard) security posture for FedRAMP, SOC 2, PCI DSS, and HIPAA reporting β€” Splunk Cloud holds FedRAMP High, DoD IL5, and PCI DSS Level 1 certifications SOAR-driven response: Guard findings trigger Splunk SOAR playbooks (300+ integrations, 2,800+ automated actions) for automated remediation workflows Integration Research Summary Splunk Cloud Platform Overview Splunk Cloud is a fully managed, single-tenant SaaS SIEM/analytics platform deployed across 3 availability zones on AWS, Azure, or GCP. Key facts: Market position: Gartner SIEM Leader for 11 consecutive years, IDC #1 SIEM provider for 5 years Acquisition: Cisco acquired Splunk for B (March 2024), integrating Talos threat intelligence and Data Fabric architecture Pricing: Two models β€” Ingest (GB/day) and Workload (SVC compute-based). Most expensive SIEM; 40-60% first-year cost overruns are common. New analytics-based pricing coming to reduce ingestion cost sensitivity Architecture: Victoria Experience (new default, self-service) replacing Classic. SmartStore decouples compute from storage via object storage Data Ingestion Architecture HEC (HTTP Event Collector) is the universal ingestion gateway β€” all cloud-native connectors route through it. This is the primary integration point for Guard. Seven connector families: Universal Forwarder, HEC, SC4S (syslog), SCK (Kubernetes), OpenTelemetry Collector, Kafka Connect, Docker. Enterprise Security (ES) 8.x Unified TDIR platform: SIEM + SOAR + UEBA + Agentic AI Two editions: Essentials (core) and Premier (agentic AI capabilities) Key SOC surfaces: Analyst Queue, Security Posture dashboard, Executive Summary, SOC Operations Detection Library 1,615+ detections in YAML across 5 domains: Endpoint (1,000+), Cloud (321), Application (108), Network (100), Web (86) 337 analytic stories covering major threat campaigns All detections MITRE ATT&CK mapped with kill chain and CIS Controls alignment Detection-as-Code pipeline: security_content repo β†’ contentctl CI/CD β†’ ESCU App Risk-Based Alerting (RBA) Aggregates low-fidelity events as risk scores (0-100)

πŸ’‘

Feature

8 months ago