Integrations
The Integrations view is a bring-your-own-key catalog of 77 security and workflow services you can connect, across:
- Data & Threat Intel — exploit databases, malware sandboxes, OSINT and recon sources, TTP libraries, threat-hunting rules, threat-intel platforms, and vulnerability intelligence.
- Internal / self-hosted tools — your own EDR, SIEM, log management, network security, SOAR, and vulnerability-management platforms (Splunk, Elastic, CrowdStrike, Nessus, OpenVAS, Wazuh, TheHive, OpenCTI, and more).
- Ticketing — Jira, GitHub/GitLab Issues, Linear, ServiceNow, PagerDuty, Asana, Azure DevOps, Zendesk.
- Communication — Slack, Discord, Microsoft Teams, Mattermost, Rocket.Chat, Email (SMTP/IMAP), and a generic webhook.

You store each service's API key and endpoint once. Credentials stay server-side — the agent calls the service through Hacker Sidekick's proxy and never sees the secret. Once configured, ask the agent to (for example) open a Jira ticket, look up a host, or post to Slack; non-GET requests ask for your approval first.
The full catalog
All 77 integrations, grouped the way the Integrations view groups them. Each is optional and off until you add a key — enable only what you use.
Data & Threat Intel
Exploit Intelligence — 0day.today · Metasploit Framework
Malware Analysis — ANY.RUN · Cuckoo Sandbox · Hybrid Analysis · Joe Sandbox
OSINT — BuiltWith · DNSdumpster · Hunter.io · SecurityTrails
TTPs — ATT&CK Navigator · Atomic Red Team · CALDERA · MITRE D3FEND
Threat Hunting — MISP Threat Hunting · Sigma Rules · TheHive Threat Hunting · YARA Rules
Threat Intelligence — Abuse.ch · AlienVault OTX · Anomali ThreatStream · GreyNoise · IBM X-Force Exchange · MISP · PassiveTotal (RiskIQ) · PhishTank · Recorded Future · ThreatConnect
Vulnerability Intelligence — Qualys VMDR · Rapid7 InsightVM · Snyk Vulnerability Database · Tenable.io
Internal / Self-hosted
EDR Platforms — Carbon Black · CrowdStrike Falcon · Microsoft Defender for Endpoint · SentinelOne
Log Management — Datadog Log Management · Graylog · Loki (Grafana Loki) · New Relic Logs
Network Security — Snort · Suricata · Zeek (Bro) · pfSense
SIEM Platforms — ArcSight · Azure Sentinel · Elastic Security · Google Chronicle · IBM QRadar SIEM · LogRhythm SIEM · Splunk · Sumo Logic
Security Information Sharing — TAXII Server
Security Orchestration (SOAR) — Demisto (Cortex XSOAR) · Phantom (Splunk SOAR) · Shuffle · TheHive
Threat Intelligence Platforms — OpenCTI
Vulnerability Management — Nessus · OpenVAS · Wazuh
Ticketing
Asana · Azure DevOps Work Items · GitHub Issues · GitLab Issues · Jira · Linear · PagerDuty · ServiceNow · Zendesk
Interaction
Communication — Discord · Email (SMTP/IMAP) · Mattermost · Microsoft Teams · Rocket.Chat · Slack
Integration — Generic Webhook
Also built in
Core threat-intel tools — MITRE ATT&CK, NVD/CVE, VirusTotal, Shodan, Censys, and Exploit-DB — ship ready to use through the built-in public-intel MCP server, so they need no key and aren't part of this bring-your-own-key catalog.
See also
- MCP servers — connect external tool servers
- Skills — packaged playbooks
- Approvals & safety
