Above the stack you already run.
Kaska doesn't scan, block or replace. It is designed to read the tools you already own through a common connector framework, keep only the signal it needs, and connect it all around the asset.
Your tools in. Understanding out.
Every lane of your security stack.
Representative vendors in each category. Integrations are built to one common model, so adding a vendor is focused work, not a rebuild.
Microsoft Sentinel · Splunk · IBM QRadar · Google Chronicle · Palo Alto Cortex · Elastic
CrowdStrike · SentinelOne · Microsoft Defender · Trend Micro · VMware Carbon Black
Okta · Microsoft Entra ID · SailPoint · Saviynt · Ping Identity
CyberArk · BeyondTrust · ManageEngine · Arcon
Palo Alto · Fortinet · Check Point · Cisco · Zscaler · Cloudflare
Cloudflare · Imperva · F5 · Radware · AWS WAF
Proofpoint · Mimecast · Microsoft · Cisco · Barracuda
AWS Security Hub · Microsoft Defender for Cloud · Google SCC
Tenable · Qualys · Rapid7
Forcepoint · Varonis · Microsoft Purview · BigID
Claroty · Dragos · Nozomi
Veeam · Commvault · Rubrik
ServiceNow · RSA Archer · MetricStream · OneTrust
Vendors listed are those the connector framework is built for. Integration status varies by vendor and version, and is confirmed for your stack before any commitment.
Known-exploited vulnerabilities and attacker techniques.
CISA KEV and MITRE ATT&CK supply the exploitability and technique context behind prioritisation, with no customer credentials required.
Additional intelligence sources supported, under evaluation: NVD / CVE · EPSS · abuse.ch.
Two intelligence paths, because two kinds of data are required.
Your SIEM and XDR correlate events into incidents. Kaska consumes that result — the incident — and does not re-do the correlation. Supported today: IBM QRadar, Microsoft Sentinel, Splunk, CrowdStrike XDR.
Every security tool knows things its alerts never say: which controls are enforced, which are only configured, what is misconfigured, what is exposed, what it has found. Kaska reads this directly from each tool.
External attack surface and OSINT, the Kaska vulnerability database, asset and software bill-of-materials intelligence, and the probabilistic engine.
Only one of these paths is available from an aggregator. Both are needed to answer whether a control is actually working.
Two connection methods. Nothing out of your control.
However the intelligence reaches Kaska, the connection itself works one of two ways.
SIEM, cloud, identity and email tools are designed to connect through vendor APIs, with no agent or appliance.
Tools behind the perimeter, such as firewalls, EDR, PAM and OT, are designed to reach Kaska through one light, outbound-only collector.
Read-only access wherever possible. Connector credentials are encrypted at rest, and only the minimum signal is kept.
We'll map it to Kaska.
Share the tools you run. We'll confirm integration fit and status for each before any commitment.