Skip to main content

Changelog

Follow new updates and improvements to Praetorian.

Hack via Slack with MarcusBot

Guard's existing Slack integration delivered one-way webhook notifications. Marcus replaces that with a real Slack app: a multi-tenant OAuth install that delivers rich notifications via bot token, brings interactive Marcus conversations into your Slack channels, and ties every Slack interaction to a verified Guard identity so personalized queries and actions execute with the right permissions.

Highlights

  • Multi-tenant OAuth install — a Guard admin clicks Add to Slack, completes OAuth v2, picks target channels, and the app is live. No webhook URL to paste or rotate.
  • Channel binding and management — map specific Slack channels to your Guard tenant with a confirmation step before the connection is established, view all connected channels with per-row tenant mapping, and disconnect any channel through a confirmation-gated flow.
  • Block Kit notifications — risk transitions, exposure alerts, and emergent-threat notifications arrive as structured Block Kit messages through the bot token rather than plain-text webhook payloads.
  • Interactive conversations in Slack — mention Marcus in a connected channel to run the same queries and actions available in the Guard UI, with threaded replies keeping each conversation in context.
  • Explicit account linking — a Slack user runs a one-time Connect your Guard account flow to bind their Slack identity to their Guard user. Subsequent queries and actions execute as that Guard identity, with full Guard RBAC applied.
  • Revocable bindings — account links can be revoked from either Guard or Slack, immediately severing the identity binding without affecting other users.
  • Product-facing status labels — Marcus surfaces finding statuses as Detected, Demonstrated, Resolved, Accepted, and Rejected — matching what the Guard UI shows.

Why This Matters

Email-match-only authorization (the approach used by many chat integrations) is spoofable via Slack Connect guests and mutable email attributes. Marcus's explicit binding model means every action in Slack is traceable to an authenticated Guard user, making it safe to expose Guard's full query and action surface through the chat interface. Findings, alerts, and workflows now reach the channels your team already uses for incident response and collaboration — without the context-switch back to the Guard UI.

Get Started

Go to Integrations > Notifications > Slack (Chat Bot), then click Add to Slack and complete the OAuth flow. After authorizing, bind one or more channels to your tenant. Each team member links their Guard account once by following the in-app prompt.

Documentation

https://docs.praetorian.com/en/articles/25815125222171-slack

NewIntegration

Jamf Pro integration: import Apple device inventory as Guard assets

Organizations managing Mac and iOS fleets through Jamf Pro can now bring that device inventory into Guard. Connecting Jamf Pro imports computers and mobile devices as Guard assets — including hostname, last known IP, serial number, OS version, and FileVault status — giving security teams full visibility alongside the rest of their attack surface.

Highlights

  • Mac and iOS inventory — computers (Jamf Pro v4 API) and mobile devices (v2 API) are ingested as Guard assets.
  • OAuth authentication — connects via Jamf Pro API Client credentials (clientId + clientSecret); no personal access token required.
  • Cloud and on-premises — compatible with both Jamf Cloud and self-hosted Jamf Pro deployments.
  • Asset detail — hostname, last IP address, serial number, UDID, OS version, and FileVault encryption status are captured per device.

Get Started

Go to Integrations > Asset Management > Jamf Pro, then connect with a Jamf Pro API Client ID and Client Secret.

NewIntegration

JupiterOne meets Guard: Turn Your Asset Inventory into an Attacker's Playbook (Defended)

We're fired up to announce that Praetorian Guard now integrates with JupiterOne — bringing your entire cyber asset inventory into Guard's adversary-driven attack surface engine.

What's new

Guard pulls cyber assets and security findings directly from your JupiterOne tenant — across US and EU regions — and overlays them with Guard's attacker-perspective intelligence. Every asset, identity, and finding JupiterOne knows about gets the Praetorian treatment: scope-validated, attacker-prioritized, and materiality-tested.

Why this matters

JupiterOne is incredible at telling you what you have. Guard tells you what an attacker would do with what you have. Together, they answer the question security leaders actually lose sleep over: "Of all these assets and findings, which ones would a real adversary chain into a breach?"

With this integration, you get:

  • Attacker's-eye context on your asset graph — Guard correlates JupiterOne's cyber asset inventory against live attack paths, exposed services, and exploitable conditions. Your CAASM data becomes adversarial intelligence, not just a system of record.
  • Scope validation across cloud, identity, and beyond — Confirm whether assets surfaced by JupiterOne are actually in your attack surface, owned by you, and worth defending. Cut the noise, focus on what's real.
  • Materiality scoring on findings — Guard's offensive intelligence weighs every JupiterOne finding against what a skilled attacker could actually achieve — not theoretical CVSS, but real exploitability against your real environment.
  • Unified visibility — Your JupiterOne asset graph and Guard's adversarial validation live side-by-side. No more pivoting between tools to figure out if a finding matters.

The bottom line

JupiterOne gives you the map. Guard shows you which routes the attacker actually takes. With JupiterOne + Guard, your asset inventory stops being a list — it becomes a battleground you've already scouted. Spend your team's time on the assets and findings that move the needle, and let Guard rule out the rest.

NewIntegration

Earlier updates