Works with your stack.
No rip-and-replace. LexChain connects to your existing security tools and starts correlating immediately.
Security Information & Event Management
Splunk
Full integration with Splunk Enterprise and Splunk Cloud. Ingest alerts and enrich with context.
Elastic Security
Native support for Elastic SIEM detections and alerts via API integration.
Microsoft Sentinel
Direct connection to Azure Sentinel incidents and entity data.
Endpoint Detection & Response
CrowdStrike Falcon
Ingest detections and behavioral telemetry from Falcon platform.
SentinelOne
Full threat and storyline data ingestion via Singularity API.
VMware Carbon Black
Alert and watchlist data from Carbon Black Cloud.
Identity & Access Management
Okta
Authentication events, user context, and suspicious activity alerts.
Azure Active Directory
Sign-in logs, risky users, and identity protection alerts.
Duo Security
MFA authentication logs and security events.
Cloud Security & Infrastructure
Amazon Web Services
CloudTrail, GuardDuty, and Security Hub findings integration.
Google Cloud Platform
Security Command Center and Cloud Audit Logs integration.
Microsoft 365
Office 365 audit logs and Microsoft Defender alerts.
Don't see your tool?
LexChain provides a comprehensive REST API for custom integrations. Ingest alerts from any source using our standardized schema.