Cloud platforms
AvailableAmazon GuardDuty
By Amazon Web Services
Imports GuardDuty findings — unauthorized API calls, compromised credentials, anomalous network behaviour — from a tenant's own AWS account into the Qorionix SIEM incident queue. Read-only: does not archive, suppress or resolve findings in AWS.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
cloud alerts
AvailableSetup available in the console
More in Cloud platforms
Cloud platforms
AWS CloudTrail
Console sign-ins, IAM changes and every API call recorded by CloudTrail, pulled from the S3 bucket the trail writes to and parsed into named fields.
Cloud platforms
AWS IAM Identity Center
SAML 2.0 sign-in through AWS IAM Identity Center (formerly AWS SSO). SCIM user provisioning from Qorionix is not available.
Cloud platforms
Microsoft Defender for Cloud
Imports Microsoft Defender for Cloud security alerts — compromised VMs, anomalous sign-ins, SQL injection attempts — from a tenant's own Azure subscription into the Qorionix SIEM incident queue. Read-only: does not dismiss or resolve alerts in Azure.