Entity Sources

On the Entity Sources page of the Integrations Marketplace, you can connect the Anomali Agentic SOC Operations to the external identity and asset management systems you already use. These connections automatically import and synchronize entity data such as users, groups, machines, and applications, eliminating the need for manual updates.

Once connected, entity sources support the following capabilities in the Anomali Agentic SOC Operations

  • Detection correlation: When a threat is detected, Anomali Agentic SOC connects it to the specific user, machine, or application involved, giving you immediate context for response.
  • Identity governance: See user accounts and group memberships in one place, across all your identity providers. For details, see Identities.
  • Asset visibility: Maintain a continuously updated inventory of machines and applications without building it manually. For details, see Assets.
  • Risk scoring and enrichment: Get risk scores on entity records based on detections, group memberships, and vulnerability findings. For details, see Entity Risk Scores.

Available Entity Sources

The following entity sources are available in the Integrations Marketplace:

Entity Source Category Entity Types Imported
AWS IAM Identity Users
Google Cloud IAM Identity Service accounts, IAM users
Google Workspace Identity Users, groups
Jira Assets (Insight) Asset Management Assets, applications
Microsoft Entra ID Identity & Directory Users, groups
Okta Identity & Directory Users, groups
Qualys VMDR Vulnerability Management Asset and vulnerability data
Rapid7 InsightVM Vulnerability Management Asset and vulnerability data
SCIM 2.0 Identity Users, groups
ServiceNow CMDB Asset & ITSM Machines, applications
Tenable.io Vulnerability Management Asset and vulnerability data

If you use more than one account or tenant for the same tool, you can connect multiple instances of the same entity source and manage them independently from the same page.