Black Hat USA 2026Startup City, Booth 5815 · Aug 4–6 · Mandalay Bay, Las VegasBook a booth demo

Works with what you already run.

No rip-and-replace. AIDR pulls from your SIEM, EDR, identity, and cloud — and pushes response actions back.

Ungated · browse freely

Pull everything. Push actions back.

pull · alerts, telemetry, contextpush · attacks, actions, notificationsSplunkMicrosoft SentinelCrowdStrikeMicrosoft DefenderSentinelOneOktaAWSWizALERTAIDRevery alert investigatedAttacksResponse tasksNotificationsthe attack chain, mapped end to endproposed by AI — approved by yousent where your team already works

Sources feed alerts and telemetry into AIDR — attack cases, response tasks, and notifications flow back to your tools

Sources feed alerts and telemetry into AIDR — attack cases, response tasks, and notifications flow back to your tools

Connects to what you already run.

60 connectors · SIEM · Endpoint · Identity · Cloud · Network · XDR · Threat Intelligence

AbuseIPDB

Threat Intelligence

IP

AlienVault OTX

Threat Intelligence

IP, Malware, URL, Vulnerability

AWS

Cloud

Alert, Endpoint, User, Dynamic Query

Azure Cloud

Cloud

Alert, Endpoint, Dynamic Query

Azure Data Explorer

SIEM

Dynamic Query

Blocklist.de

Threat Intelligence

IP

Cato Networks

Network

Alert, Endpoint, User, Dynamic Query

CINS Army

Threat Intelligence

IP

CIRCL Hashlookup

Threat Intelligence

Malware

CISA KEV

Threat Intelligence

Vulnerability

Cisco Secure Firewall

Network

Alert, Endpoint, Dynamic Query

Code42

Endpoint

Alert, Endpoint

Cribl

SIEM

Dynamic Query

CrowdStrike

Endpoint

Alert, Endpoint, User, Dynamic Query

Datadog Cloud SIEM

SIEM

Alert, Endpoint, Dynamic Query

DShield / SANS

Threat Intelligence

IP

Elasticsearch

SIEM

Alert, Endpoint, Dynamic Query, Threat Intelligence

Exabeam

SIEM

Alert, Dynamic Query

eyeCloudXOAR

SIEM

Alert, Dynamic Query

Feodo Tracker

Threat Intelligence

IP

FireHOL Level 1

Threat Intelligence

IP

FortiSIEM

SIEM

Alert

Google Cloud SCC

Cloud

Alert, Endpoint

Google Security Operations

SIEM

Alert, Dynamic Query, Threat Intelligence

Google Workspace

Identity

Alert, User, Endpoint

GreyNoise

Threat Intelligence

IP

Hunters

SIEM

Alert, Dynamic Query

IBM QRadar

SIEM

Alert, Endpoint, Dynamic Query

MalShare

Threat Intelligence

Malware

MalwareBazaar

Threat Intelligence

Malware

Microsoft Defender

Endpoint

Alert, Endpoint, User, Dynamic Query

Microsoft Entra ID

Identity

Alert, User, Dynamic Query

Microsoft Sentinel

SIEM

Alert, User, Dynamic Query, Threat Intelligence

NetWitness

XDR

Alert, Endpoint, Dynamic Query

NIST NVD

Threat Intelligence

Vulnerability

Okta

Identity

Alert, User

OpenPhish

Threat Intelligence

URL

Osquery

Endpoint

Endpoint, Dynamic Query

Palo Alto Cortex

XDR

Alert, Endpoint, Dynamic Query

Palo Alto Networks Firewall

Network

Alert, Endpoint, Dynamic Query

Panther

SIEM

Alert, Dynamic Query

PhishTank

Threat Intelligence

URL

Pulsedive

Threat Intelligence

URL

Rapid7

SIEM

Alert, Endpoint, User, Dynamic Query

Sekoia

XDR

Alert, Endpoint, Dynamic Query, Threat Intelligence

SentinelOne

Endpoint

Alert, Endpoint, User, Dynamic Query

Shodan

Threat Intelligence

IP

Sophos

Endpoint

Alert, Endpoint, User, Dynamic Query

Spamhaus DROP

Threat Intelligence

IP

Splunk

SIEM

Alert, Dynamic Query

Stellar Cyber

XDR

Alert, Endpoint, Dynamic Query

Sumo Logic

SIEM

Alert, Endpoint, User, Dynamic Query

ThreatFox

Threat Intelligence

IP, Malware, URL

Tor Exit Nodes

Threat Intelligence

IP

URLhaus

Threat Intelligence

Malware

Vectra AI

Network

Alert, Endpoint, User

VirusTotal

Threat Intelligence

IP, Malware, URL

WAPPLES

Network

Alert

Wiz

Cloud

Alert, Endpoint

Zscaler

Network

User, Threat Intelligence

Don’t see your stack?

New connectors ship regularly — tell us what you run and we’ll confirm coverage.