Integrations

What connects, and how far along it is.

Every integration below carries a status, and the statuses mean something specific. A list that shows everything as available is a list you have to verify yourself, which makes it worse than a shorter honest one.

What the statuses mean

GA

Implemented, tested, and exercised end to end in a running deployment. If it says GA, it has done the job it describes on real data.

Beta

Implemented and tested, including against recorded vendor payloads, but not yet validated against a live tenant of that vendor. The code paths are complete; the thing that is missing is proof from the vendor’s own system.

Planned

Not implemented. Named because you would reasonably ask, and it is quicker to say no here than to have you find out during an evaluation.

Beta is doing real work in this table. Several integrations are complete code with full test coverage that have never spoken to the vendor they are written for, and calling those GA would be the easiest lie on this website to tell.

PSA — where the work gets tracked

A Fix First recommendation becomes a ticket in the system your technicians already work in. Re-running the recommendation updates that ticket rather than opening a second one.

IntegrationStatusNotes
HaloPSABetaFull provider implementation; not yet run against a live Halo instance.
ConnectWise ManageBetaAs above.
Datto AutotaskBetaAs above.
JiraBetaAs above.
ServiceNowBetaAs above.

All five are built on one provider abstraction with declared capabilities, so a PSA that cannot close a ticket through its API says so before a technician clicks the button rather than failing at it.

RMM — where approved remediation runs

Exploit Hound is not an RMM and does not patch anything itself. It submits named actions from a fixed catalogue to the endpoint tool you already run.

IntegrationStatusNotes
NinjaOneBetaImplemented against the documented v2 API and tested against recorded payloads. No live NinjaOne tenant yet.
Datto RMMPlannedNot implemented.
ConnectWise RMM / AutomatePlannedNot implemented.
N-ablePlannedNot implemented.
SyncroPlannedNot implemented.

The console will not present a beta provider as generally available: the lifecycle travels with the integration, and a test asserts that no provider claims GA until it has completed a real patch-and-verify cycle.

Identity

IntegrationStatusNotes
Active DirectoryBetaRead-only LDAP assessment, gated behind written authorization. Complete and tested; no live directory has been assessed in a production deployment yet.
Microsoft Entra IDBetaRead-only Microsoft Graph. The OAuth path is validated against Microsoft; the mapping of live Graph payloads is not.
Microsoft 365BetaAssessed through the same Entra connection.
Google WorkspacePlannedNot implemented.

Cloud

IntegrationStatusNotes
Microsoft AzureBetaReader role only. Assesses exposure and privilege relationships; not a cloud posture platform. Not yet run against a live subscription.
AWSPlannedNot implemented.
Google CloudPlannedNot implemented.

Notifications

IntegrationStatusNotes
EmailGAIn use for alerting in running deployments.
WebhooksGASigned, with retry history.
SlackBetaMessage formatting implemented; not yet exercised against a live workspace.
Microsoft TeamsBetaAs above.
PushoverGAIn use for operational alerting.

All of these share one deduplicated event pipeline rather than each feature growing its own notifier, so a burst of related findings does not become a burst of messages.

API and data out

IntegrationStatusNotes
REST APIGAThe console runs on it, so every endpoint it uses is exercised continuously.
WebhooksGASigned events for findings, tickets, remediation and verification.
Syslog exportPlannedNot implemented. Agents ingest syslog data; Exploit Hound does not currently emit syslog to a SIEM.

Need one of the planned ones?

The PSA and RMM layers are provider abstractions, so adding a vendor is one implementation against a declared interface rather than a change spread through the application. If a planned integration is what decides your evaluation, say so — it is a useful thing for us to know and a reasonable thing to prioritise.

Tell us what you need

Start with what's actually exposed.

Point Exploit Hound at the assets you are authorized to assess and see the connected picture — not another list.

v2.21.0 Exploit Hound 2.21.0 · Continuous Threat Exposure Management