Available integrations
Content sources
Import playbooks and documentation from — and publish documentation back to — GitHub, GitLab, GitBook, SharePoint, and Confluence.
Detection sources
Derive preset scope from what you actually detect, using Wazuh, Microsoft Sentinel, or Splunk Enterprise Security.
Cloud & assets
Discover and import cloud resources as Cymph assets from AWS and Azure.
SOAR & automation
Deploy playbooks as executable workflows to Cortex XSOAR, n8n, and StackStorm.
Ticketing & case management
Deploy playbook steps into JIRA, ServiceNow, and DFIR-IRIS.
Notifications
Send execution and task notifications to a Slack channel.
What each integration can do
* Markdown only — GitBook and Confluence do not accept PDF.
** Splunk SOAR imports playbooks but cannot yet be deployed to — see its limitations. Slack is not in the table because it does none of the above: it is a one-way notification target that posts execution and task updates to a channel.
Deploying playbooks
There are two distinct kinds of deployment, and an integration supports one or the other — never both:- Workflow — the playbook is translated into an executable artefact on the target: an XSOAR or n8n workflow, a StackStorm action, a JIRA or ServiceNow ticket, a DFIR-IRIS case task.
- Documentation — the playbook is published as a document: either a Markdown file, or a summary report PDF including metadata, contributors, and the workflow image.
Publishing documentation is a write operation, so it needs broader credentials than importing does. Every content-source page states its read-only requirement and the additional permission publishing needs, side by side — check the Permissions section before granting anything.

