Integrations
ASTRA BASTION connects with 31+ enterprise security and DevOps tools. Normalize events to OCSF, trigger SOAR playbooks, and embed AI security into your existing workflows.
All integrations use webhook-based event forwarding with exponential backoff retry and dead-letter queues.
SIEM (8)
Forward normalized OCSF events to your security information and event management platform.
Splunk
GAHEC + saved searches
Microsoft Sentinel
GALog Analytics workspace
Google Chronicle
GAMALACHITE ingestion
IBM QRadar
GASyslog + REST API
Elastic Security
GAFleet agent + SIEM rules
Sumo Logic
BetaHTTP source + dashboards
LogRhythm
BetaOpen Collector + SmartResponse
Datadog
GALogs + Security Monitoring
SOAR (5)
Trigger automated playbooks for incident response and remediation workflows.
Cortex XSOAR
GAPlaybooks + incident sync
Swimlane
GATurbine workflows
Tines
GAStories + webhook actions
Torq
BetaHyperautomation flows
ServiceNow
GASecurity Incident Response
Identity Providers (8)
SSO, SCIM provisioning, and identity lifecycle management integration.
Okta
GASAML/OIDC + SCIM 2.0
Azure AD (Entra ID)
GASAML + Graph API
Auth0
GAUniversal Login + Actions
OneLogin
GASAML + user provisioning
Ping Identity
BetaPingFederate + PingOne
JumpCloud
BetaSAML + directory sync
Google Workspace
GASAML + Admin SDK
CyberArk
GAPAM + Identity Security
Cloud Security (5)
Correlate AI security findings with your cloud security posture management.
AWS Security Hub
GAASFF findings + EventBridge
Azure Defender
GAAlerts + Recommendations
GCP Security Command Center
GAFindings + sources
Palo Alto Prisma Cloud
BetaCSPM + CWPP alerts
Wiz
BetaIssues + graph queries
DevOps & CI/CD (5)
Embed AI security checks into your software delivery lifecycle.
GitHub
GAActions + SARIF + Code Scanning
GitLab
GACI/CD pipelines + SAST
Jenkins
GAPipeline plugin + webhooks
ArgoCD
BetaSync hooks + health checks
Terraform
BetaProvider + policy-as-code
How Integrations Work
Event Normalization
All internal events are normalized to OCSF v1.4.0 format (22 event types mapped to 7 OCSF classes) before forwarding to external systems.
Webhook Dispatch
Events are dispatched via HTTPS webhooks with HMAC-SHA256 signatures. Failed deliveries retry with exponential backoff (up to 5 attempts) before routing to a dead-letter queue.
Bi-Directional Sync
Supported integrations (SIEM, SOAR, Identity) offer bi-directional sync -- import findings, incidents, and user lifecycle events back into ASTRA for unified governance.