Every integration, one place to browse.
Mallory correlates threat intelligence and exposure data through the Intelligence Graph, then connects that correlation to the tools your team already trusts: cloud accounts, EDR, ticketing, chat, and observability. Browse what Mallory connects to today, filter by how you want to connect, and tell us if your stack isn't listed yet.
App: Installed integrations like the Mallory chat bot in Slack or Microsoft Teams. Analysts can @-mention or DM Mallory directly inside the tool they're already in.
API: Direct API and webhook connections. Mallory pulls assets, findings, and telemetry straight from the platform, no manual export required.
MCP: MCP servers Mallory can call directly, so the Mallory Agent can query and act on the tool as part of an investigation or workflow.
Attack Surface Management
Attack Surface Management
Queries Censys for internet-exposed hosts, certificates, and web properties.
Attack Surface Management
Queries Shodan for internet-exposed hosts and services.
Cloud Security
Cloud Security
Connects an AWS account for vulnerability findings, asset inventory, and sandbox-mode access.
Cloud Security
Imports device and user assets from an Axonius cybersecurity asset management tenant.
Cloud Security
Imports security findings from Azure.
Cloud Security
Connects a Cloudflare account to inventory zones, DNS records, and account-level assets.
Cloud Security
Connects a GCP project to investigate infrastructure exposure.
Cloud Security
Connects a Vercel account to inventory projects, deployments, and domains.
Cloud Security
Imports cloud assets and security findings from Wiz.
Code Repository / SCA
Code Repository / SCA
Connects the Bitbucket MCP server today. Scanning bitbucket.org repositories for vulnerable dependencies via API is coming soon.
Code Repository / SCA
Connects a GitHub organization to scan repositories for vulnerable dependencies, or connects the GitHub MCP server directly.
Code Repository / SCA
Connects a GitLab instance to scan projects for vulnerable dependencies, or connects the GitLab MCP server directly.
Communication & Collaboration
Communication & Collaboration
Connects by signing in to Atlassian. Nothing to pre-register and no client secret to manage; choose the site to connect during consent.
Communication & Collaboration
Sends messages to Google Chat spaces through webhooks.
Communication & Collaboration
Installs the Mallory chat bot in Microsoft Teams. DM Mallory or @-mention it in any chat or channel for live intel lookups: vulnerability details, threat actor profiles, breach research, and more.
Communication & Collaboration
Connects the Notion MCP server.
Communication & Collaboration
Installs the Mallory chat bot for live intel lookups in any channel, sends scheduled deliveries by incoming webhook, or connects the Slack MCP server directly.
EDR / XDR Tools
EDR / XDR Tools
Imports host and endpoint inventory from CrowdStrike Falcon, or connects the CrowdStrike MCP server for live lookups.
Identity & Access Management
Identity & Access Management
Imports users, groups, and applications from Microsoft Entra ID.
Identity & Access Management
Imports users, groups, and assigned applications from Okta.
Observability & Monitoring
Observability & Monitoring
Connects the Datadog MCP server.
Observability & Monitoring
Connects the Grafana Cloud MCP server.
Observability & Monitoring
Connects the Sentry MCP server.
Observability & Monitoring
Connects the Splunk MCP server.
Project Management
Project Management
Connects the Asana MCP server.
Project Management
Connects by signing in to Atlassian. Nothing to pre-register and no client secret to manage; choose the site to connect during consent.
Project Management
Connects the Linear MCP server.
Project Management
Connects the ServiceNow MCP server.
SOAR & Incident Response
SOAR & Incident Response
Connects the PagerDuty MCP server.
SOAR & Incident Response
Connects the Tines MCP server.
SOAR & Incident Response
Connects the Torq MCP server.
Threat Intelligence Platforms
Threat Intelligence Platforms
Curated feed of malicious hosts (C2 and distribution infrastructure) with DNS and IP context.
Threat Intelligence Platforms
Threat intelligence for IOC enrichment and lookup.
Threat Intelligence Platforms
Recent malware IOCs and publisher opinions from ThreatFox.
Threat Intelligence Platforms
Looks up file hashes, URLs, IPs, and domains in VirusTotal.
Vulnerability Management
Vulnerability Management
Imports projects, open-source components, and vulnerable dependencies from a Black Duck SCA instance.
Custom
Custom
Connects any MCP server by URL with your own credentials. Not on this list? This is how Mallory still works with it.