Connectors automate the enrichment of detection data from third-party solutions by relying on their APIs. The available connectors mainly target EDR, NDR and SIEM solutions. This page lists all the connectors available in the BlackNoise platform.
From the Connectors page, configure a connector by entering its connection information — mainly:
- the provided to you as a user of the third-party solution;
- an .
For some connectors, an option lets you disable verification of the remote TLS certificate. Use it only when the third-party solution presents a self-signed certificate, or one signed by an internal authority that is not publicly recognized.
Once the connection information is filled in, click Save and Connect. BlackNoise runs connection tests; if they pass, the connector becomes .
You select connectors when creating a campaign: among those you have configured, you can choose one or more to enrich that campaign's results. See Security validation for the campaign creation steps. For each system event, the connector provides an access URL that opens the third-party tool's interface directly, pre-filtered to show only the information relevant to that event.
In addition, with some enriched connectors, each individual element detected by the tool is incorporated into the corresponding BlackNoise event, providing more detailed data.
This information streamlines analysts' work: they can quickly confirm that detection worked, validate technical qualification criteria — for example the severity or technical description reported by the detection tools against the identified threat — and check the countermeasures that were applied.