Skip to main content
Firewalls

ThreatX WAF Integration

Connect ThreatX to Guard to automatically ingest WAF-protected hostnames and metadata into your attack surface inventory.

Guard can ingest asset inventory from ThreatX, bringing WAF-protected hostnames and associated metadata into your Guard attack surface automatically.

What Guard collects

When the integration is enabled, Guard imports each ThreatX-protected hostname as an asset, along with the origin servers behind it. Guard records whether ThreatX protection is enabled for each site.

Prerequisites

  • A ThreatX account with API access.
  • A ThreatX API key with sufficient permissions to read asset/hostname data.

Connect ThreatX to Guard

  1. In Guard, go to Integrations > WAF > ThreatX.
  2. Enter your ThreatX API key.
  3. Save the configuration.

Guard will begin ingesting assets on the next scheduled sync. Newly discovered hostnames and their metadata will appear in your asset inventory automatically.

Verify the integration

After the first sync completes, search your asset inventory for hostnames that are protected by ThreatX. Assets sourced from this integration will be attributed to ThreatX.

Troubleshooting

Symptom

Action

No assets appear after the first sync

Confirm the API key is valid and has read access to asset data in your ThreatX account.

Assets stop updating

Check that the API key has not been rotated or revoked. Re-enter the current key under Integrations > WAF > ThreatX.

Remove the integration

  1. Go to Integrations > WAF > ThreatX.
  2. Select Remove integration.

Removing the integration stops future syncs. Assets already imported are retained in your inventory until removed manually.

Still need help? Ask the team