Integrations

Overview of the Integrations page, including integration categories, configuration, integration health states, integration-suggestion prompts, and the legacy AWS integration badge.

Overview

The Integrations page is your central hub for connecting external security tools, cloud providers, and services with the Praetorian Guard Platform (PGP). By integrating your existing technology stack, you can consolidate security data, automate workflows, and gain comprehensive visibility across your entire attack surface — all from a single platform.

When you navigate to the Integrations page, you'll find the Add Integrations view, which presents a collection of integration cards organized by category. Each card displays the service's logo and name, making it easy to locate and configure the integration you need.

Why Integrate?

Connecting your tools and services to PGP allows you to:

  • Achieve comprehensive visibility — Combine data from multiple security tools to build a complete picture of your security posture.
  • Automate asset discovery — Automatically import assets from cloud providers, identity platforms, and security tools instead of manually tracking them.
  • Enrich vulnerability context — Correlate findings from scanners, EDR solutions, and threat intelligence feeds to prioritize what matters most.
  • Streamline workflows — Push alerts, tickets, and findings to the platforms your team already uses.
  • Reduce manual effort — Eliminate the need to collect and correlate data across disconnected tools.

Integration Health

Guard continuously monitors each integration and records its health state so that configuration problems are visible without requiring you to manually verify whether data is flowing correctly.

Health states

State

Meaning

Healthy

The integration is authenticating and importing data successfully.

Expired

Credentials or configuration for the integration have expired or become invalid — action is required to restore the integration.

Configuration issue

A persistent problem has been detected that requires manual remediation — see below for the specific failure types.

Transient failure

A temporary connectivity or service error occurred; Guard will retry automatically.

Configuration-issue and Expired states are distinguished from transient failures so the remediation path is clear and no manual diagnosis is required.

Expired status

When an integration's credentials have expired or become misconfigured, Guard displays a red Expired chip on that integration's row on the Integrations page. This indicator is visible to all users on your team.

Hovering over the Expired chip surfaces a tooltip that describes the specific configuration issue detected, so you know exactly what needs to be corrected before attempting to reconnect the integration.

The Expired chip replaces the previously staff-only health failure display, meaning your team can now self-diagnose broken integrations directly from the Integrations page without needing to contact support.

Persistent configuration failures

When an integration encounters a configuration problem, Guard records and retains the failure state across import cycles. The record persists until the underlying configuration is corrected, ensuring the issue remains visible even if no imports are actively running.

The following conditions are classified as persistent configuration failures:

  • Expired or invalid credentials — The stored API key, token, or other credential is no longer accepted by the connected service. Re-enter valid credentials in the integration configuration to resolve this.
  • Missing or revoked OAuth scopes — An OAuth authorization is missing a required permission scope, or a previously granted scope has been revoked. Re-authorize the integration and confirm all required scopes are granted.
  • Missing required configuration fields — A required configuration field is absent or blank. Open the integration configuration, supply the missing value, and save.

Resolving a configuration issue

  1. Navigate to the Integrations page and locate integrations marked with an Expired chip or other configuration-issue indicator.
  2. Hover over the Expired chip to read the tooltip describing the specific issue.
  3. Open the integration's configuration panel.
  4. Correct the relevant credential, scope authorization, or field value based on the reported failure.
  5. Save the configuration. Guard will attempt an import on the next scheduled cycle and clear the health state if the issue is resolved.

If you are unsure which credential or scope is required, refer to the service-specific integration guide or contact support@praetorian.com.

Integration Suggestions

When Guard detects assets that are likely hosted on a cloud provider or managed through a service you have not yet connected, it surfaces a suggestion prompt encouraging you to set up the relevant integration.

These prompts appear in a collapsible summary bar at the bottom of the page. The bar uses a red color treatment to signal that action is needed, distinguishing it clearly from success states. If Guard has detected multiple potential integrations, all suggestions are grouped within the same bar. You can expand the bar to review each suggestion individually, or collapse and dismiss it without affecting primary page content.

To act on a suggestion, expand the bar, select the relevant prompt, and follow the standard integration configuration steps.

Integration Categories

PGP supports integrations across a wide range of security and IT categories. Below is an overview of each category available on the Integrations page.

Application Security Posture Management

Platforms that provide visibility into application-level security risks by correlating data from code, cloud, and runtime environments to help prioritize remediation efforts.

Application Security Testing

Dynamic application security testing (DAST) tools that scan running web applications to identify vulnerabilities such as injection flaws, authentication issues, and misconfigurations.

Breach Attack Simulation

Tools that simulate real-world cyber attacks against your environment to validate the effectiveness of your security controls and identify gaps in your defenses.

Bug Bounty

Platforms that manage bug bounty programs, allowing you to import externally reported vulnerabilities and track them alongside your other security findings.

Cloud Service Providers

Direct integrations with major cloud computing platforms — including AWS, Azure, GCP, and Digital Ocean — that allow Guard to discover and monitor cloud-hosted resources across your accounts and subscriptions.

Cloud Security Posture Management

Solutions that continuously monitor your cloud infrastructure to identify security risks, compliance violations, and misconfigurations across cloud environments.

Content Delivery Solutions

Integrations with CDN providers that allow Guard to discover and monitor assets distributed through content delivery networks.

Cyber Asset Attack Surface Management

Platforms that help organizations discover, inventory, and manage their digital assets and external attack surface. These integrations enrich Guard's asset data with additional context from specialized discovery tools.

Firewalls

Integrations with web application firewalls (WAFs) and network firewalls that allow Guard to discover assets protected behind these services and incorporate firewall context into your security posture.

Identity and Access Management

Identity provider integrations that allow Guard to discover users, connected applications, and directory resources managed through your IAM platform.

IT Service Management

Ticketing and service management platforms that enable you to create and track remediation tickets directly from Guard, integrating vulnerability management into your existing ITSM workflows.

Managed Detection and Response

Endpoint detection and response tools and device-management platforms — CrowdStrike Falcon, Microsoft Defender, SentinelOne, ExtraHop, and Microsoft Intune. These integrations let Guard incorporate detection and device-management data into your attack surface view.

Managed DNS Providers

Integrations with DNS hosting providers that allow Guard to enumerate all zones and records within your DNS infrastructure for thorough domain discovery.

Passive DNS Providers

Services that collect and analyze historical DNS resolution data. These integrations enhance Guard's ability to discover subdomains and track changes in your DNS footprint over time.

SaaS Security

Software-as-a-service collaboration and productivity platforms — knowledge bases, work management, messaging, and document stores. PGP scans these platforms for exposed secrets and sensitive information across their content and history.

Security Ratings

Third-party cyber-risk rating platforms. These integrations import company assets, scores, and vulnerability findings from providers such as Black Kite and SecurityScorecard.

Secure Code Scanning

Static application security testing (SAST) tools that analyze source code for vulnerabilities, coding errors, and security weaknesses before applications are deployed.

Security Information and Event Management

SIEM platforms that aggregate and analyze security event data. These integrations allow you to forward Guard findings into your centralized security monitoring workflows.

Source Code Managers

Integrations with code repository platforms that allow Guard to discover and monitor your organization's repositories as part of your attack surface.

Threat Intelligence

Threat intelligence platforms that provide enriched context about threats, indicators of compromise, and adversary tactics to support security investigations and proactive defense.

Vulnerability Management

Integrations with vulnerability scanning and management platforms that allow you to import scan results into Guard, consolidating findings from multiple scanners into a unified view.

Web Application Hosting

A reserved Integrations category for web-application hosting providers. Guard shows the category on the Integrations page; no hosting integrations are listed yet.

Workplace Messaging

Chat and collaboration channels used to deliver Guard alerts — Slack, Microsoft Teams, Google Chat, and Zulip. The Marcus Slack chatbot (Slack (Chat Bot)) is also installed from this category. Email alerts are configured under Settings → Notifications.

Configuring an Integration

The setup process follows a consistent pattern across all integrations. Click on an integration card to open its configuration interface, which will present you with the specific fields required for that service — typically API keys, authentication credentials, or account identifiers. Most integrations can be configured in just a few steps.

For detailed setup instructions and information about what each integration does, refer to the dedicated Integrations section of the documentation, which provides service-specific guides for every supported integration.

Legacy AWS Integrations

AWS integrations set up before Guard's CloudFormation-based integration flow do not have access to all capabilities available to current integrations. To make these integrations easy to identify, the Integrations page displays an orange Legacy badge on any AWS integration that lacks a current CloudFormation-based credential node.

If you see a Legacy badge on one of your AWS integrations, that integration should be migrated to the current CloudFormation-based flow to take full advantage of Guard's AWS capabilities. AWS integrations configured through the CloudFormation flow display no badge and require no action.

To migrate a legacy AWS integration, follow the standard AWS integration setup instructions or contact support@praetorian.com for assistance.

Support

If you have questions about setting up or managing integrations, reach out to our support team at support@praetorian.com.