Skip to main content
An integration is a connection between a Cymph workspace and a system you already operate: a SIEM, a SOAR platform, a ticketing system, a documentation space, or a cloud account. Integrations let Cymph pull context in (detection rules, assets, existing content) and push work out (deployed playbooks, published documentation, tasks, backups). Integrations are configured per workspace, under Manage → Integrations. When you create one you can choose to share it with the rest of your organisation, so other workspaces can reuse the same instance without re-entering credentials. See Manage integrations for creating, testing, editing, and deleting them.

Available integrations

Content sources

Import playbooks and documentation from — and publish documentation back to — GitHub, GitLab, GitBook, SharePoint, and Confluence.

Detection sources

Derive preset scope from what you actually detect, using Wazuh, Microsoft Sentinel, or Splunk Enterprise Security.

Cloud & assets

Discover and import cloud resources as Cymph assets from AWS and Azure.

SOAR & automation

Deploy playbooks as executable workflows to Cortex XSOAR, n8n, and StackStorm.

Ticketing & case management

Deploy playbook steps into JIRA, ServiceNow, and DFIR-IRIS.

Notifications

Send execution and task notifications to a Slack channel.

What each integration can do

* Markdown only — GitBook and Confluence do not accept PDF.
** Splunk SOAR imports playbooks but cannot yet be deployed to — see its limitations.
Slack is not in the table because it does none of the above: it is a one-way notification target that posts execution and task updates to a channel.

Deploying playbooks

There are two distinct kinds of deployment, and an integration supports one or the other — never both:
  • Workflow — the playbook is translated into an executable artefact on the target: an XSOAR or n8n workflow, a StackStorm action, a JIRA or ServiceNow ticket, a DFIR-IRIS case task.
  • Documentation — the playbook is published as a document: either a Markdown file, or a summary report PDF including metadata, contributors, and the workflow image.
Publishing documentation is a write operation, so it needs broader credentials than importing does. Every content-source page states its read-only requirement and the additional permission publishing needs, side by side — check the Permissions section before granting anything.

Network access

Most integrations require Cymph to make outbound connections to an endpoint you operate. If that endpoint sits behind a firewall or a source-IP allowlist, you will need to permit Cymph’s egress addresses — see Egress control.