My detection tooling lives in a SIEM and EDR, and I want 3B to work alongside them rather than in isolation. How do I integrate 3B with a SIEM or EDR platform? I’m curious how alerts flow in and how 3B can push actions back out. A picture of the typical integration pattern would help me plan the build.
3B has over 1,000 connectors out of the box, so there is a fairly high chance that it can integrate with your SIEM or EDR platform of choice. If your platform isn’t yet supported, as long as it has an API, you can integrate with it. That’s one of the strengths of 3B.
It can connect beyond HTTP. So if you want to connect directly to a database like Postgres or Microsoft SQL, you can do that TCP networking from 3B.
In terms of a typical pattern, you’d have your SIEM or EDR send alerts to 3B, 3B enriches and triages them, then pushes actions back out like isolating a host, updating a case, or opening a ticket. It all depends on your workflows and how you want to build it. It’s a use case that’s a perfect fit for 3B.