Entity Sources
On the Entity Sources page of the Integrations Marketplace, you can connect the Anomali Agentic SOC Operations to the external identity and asset management systems you already use. These connections automatically import and synchronize entity data such as users, groups, machines, and applications, eliminating the need for manual updates.
Once connected, entity sources support the following capabilities in the Anomali Agentic SOC Operations:
- Detection correlation: When a threat is detected, Anomali Agentic SOC connects it to the specific user, machine, or application involved, giving you immediate context for response.
- Identity governance: See user accounts and group memberships in one place, across all your identity providers. For details, see Identities.
- Asset visibility: Maintain a continuously updated inventory of machines and applications without building it manually. For details, see Assets.
- Risk scoring and enrichment: Get risk scores on entity records based on detections, group memberships, and vulnerability findings. For details, see Entity Risk Scores.
Available Entity Sources
The following entity sources are available in the Integrations Marketplace:
| Entity Source | Category | Entity Types Imported |
|---|---|---|
| AWS IAM | Identity | Users |
| Google Cloud IAM | Identity | Service accounts, IAM users |
| Google Workspace | Identity | Users, groups |
| Jira Assets (Insight) | Asset Management | Assets, applications |
| Microsoft Entra ID | Identity & Directory | Users, groups |
| Okta | Identity & Directory | Users, groups |
| Qualys VMDR | Vulnerability Management | Asset and vulnerability data |
| Rapid7 InsightVM | Vulnerability Management | Asset and vulnerability data |
| SCIM 2.0 | Identity | Users, groups |
| ServiceNow CMDB | Asset & ITSM | Machines, applications |
| Tenable.io | Vulnerability Management | Asset and vulnerability data |
If you use more than one account or tenant for the same tool, you can connect multiple instances of the same entity source and manage them independently from the same page.