oolak / Integrations
Integrations

Works with the tools you already have.

oolak doesn't replace your scanners, inventory or ticketing system. It connects them, so their data finally tells one story.

Scanners and testing tools

Bring in findings from the scanners and testing tools your teams already run.

Tenable Security Center and NessusImports scan results, launches targeted rescans and manages scans, freeze windows and policies.
Qualys VMDRImports network and agent findings and keeps their status up to date.
OpenVAS and GreenboneImports findings from open-source network scans on a schedule.
Burp SuiteImports web application findings and launches scans from oolak.
OWASP ZAPAdds dynamic web application testing results to the same list.
NucleiBrings in fast, template-based checks across web assets and IP addresses.
TrivyAdds container image, Kubernetes and software bill of materials findings.
SQLMapConfirms SQL injection findings with proof.
MobSFAdds findings from Android and iOS application testing.
SemgrepLinks code-level findings to the repositories they come from.
TruffleHogFinds leaked passwords and keys in code, logs and files.
BanditAdds security findings from Python code.
GoSecAdds security findings from Go code.
GitHub DependabotBrings in alerts about vulnerable third-party libraries.
File and CSV importAccepts Nessus, XML, JSON and CSV reports for networks without a direct connection.

Cloud and infrastructure

Discover servers, containers and cloud resources wherever they run.

Amazon Web ServicesDiscovers EC2 instances, security groups and networks, and imports Inspector and Security Hub findings.
Microsoft Azure virtual machinesDiscovers virtual machines, network cards and security boundaries.
Microsoft Azure applicationsTracks App Services, enterprise applications and app registrations.
Microsoft Azure platform servicesChecks the security posture of SQL, Key Vault, storage accounts and AKS.
Google CloudDiscovers Compute Engine instances, firewalls and subnets, and imports Security Command Center findings.
VMware vSphere and ESXiDiscovers every virtual machine and matches it with scanned IP addresses.
Microsoft Hyper-VLists Hyper-V virtual machines and the hosts they run on.
KubernetesDiscovers clusters, nodes and workloads and maps their vulnerabilities.
Red Hat OpenShiftTracks vulnerabilities across OpenShift projects.
Docker and OCI registriesReads images and their contents from your container registries.

Inventory and identity

Keep your asset list, IP plan and directories in step with what is really running.

NetBoxKeeps virtual machines, devices and IP addresses in sync in both directions.
Microsoft Active DirectoryLists computers and privileged accounts from your domain.
Microsoft Entra IDBrings in cloud identities, devices and their compliance status.
LDAP directoriesSigns users in and maps their groups to roles and teams.
SAML 2.0 and OpenID ConnectSigns users in through your single sign-on provider.
EfficientIP SOLIDserverKeeps DNS, DHCP and IP address plans in step.
BitwardenSupplies credentials for authenticated scans without storing them in oolak.
Red Hat SatelliteMatches patch status with open findings.
ManageEngineBrings in endpoint inventory and service desk tickets.

Ticketing and development

Open and update tickets where your teams already work.

DefectDojoSyncs findings, engagements and risk acceptances in both directions.
JiraOpens tickets, keeps their status in sync and closes them when a fix is confirmed.
ServiceNowOpens security incidents and change requests and keeps them in sync.
OpenText Service ManagerManages service desk tickets through their whole life cycle.
TrelloTurns findings into cards on a team board.
GitHubOpens issues and syncs security advisories for your repositories.
GitLabImports pipeline security reports and syncs issue boards.
JenkinsTriggers pipelines from workflows, for example to rebuild a patched image.

Monitoring and threat intelligence

Share evidence with your SIEM and enrich findings with outside intelligence.

Splunk and syslogSends every audit event as a standard syslog line, with secrets masked.
Microsoft DefenderBrings in Defender for Cloud alerts and Defender EASM discoveries.
DarktraceMatches unusual network activity with known weaknesses on the same host.
Trend MicroAdds host agent data and threat intelligence to triage.
Trend Vision OneMatches detections with exposed systems.
ShodanShows which of your public IP addresses are visible on the internet.
Have I Been PwnedWarns when e-mail accounts on your domains appear in a data breach.
0rce threat intelligenceAdds indicators and threat intelligence to findings.
GrafanaShows trends, fix times and SLA status on dashboards.
Uptime KumaShows which services are up next to their open vulnerabilities.
S3-compatible storageStores reports and evidence in your own object storage.

AI, automation and messaging

Connect AI assistants, automation tools and the chat apps your teams use.

Claude and MCP assistantsLets AI assistants answer questions about your findings with your permissions.
Local AI models and REST APIConnects local or private models and any agent through a documented API.
n8nConnects oolak events to your own automation flows.
CloudflareReads DNS zones and checks which services sit behind the WAF.
Cloudflare Zero TrustChecks device posture and access logs for remote users.
TailscaleReaches isolated networks for scanning without opening firewall ports.
SlackSends alerts and digests, and lets people approve requests from a message.
Microsoft TeamsSends alerts and digests, and lets people approve requests from a card.
E-mailSends alerts, digests and invitations through your own mail server.
WebhooksStarts workflows from any system and sends events anywhere.

Also supported

These sources connect in the same way, through the same settings and data feeds.

Rapid7 InsightVMCrowdStrike Falcon SpotlightAWS InspectorAWS Security HubGoogle Security Command CenterGrypeCensyssubfinder, dnsx and httpxAmazon Route 53Tenable Attack Surface ManagementrunZeroLansweeperMonday.com

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

How does a connector work?
Each connector is a set of data feeds such as vulnerabilities, assets, monitors, web applications or certificates. You switch each feed on or off, and every sync runs through typed contracts that are checked on every run.
What if a connection fails halfway?
Reads are strict and run in one transaction, so a failed page rolls the whole sync back instead of leaving half the data behind. Only safe, repeatable requests are retried.
Can oolak reach networks behind a firewall?
Yes. Connectors support corporate proxies, a DMZ integration gateway and custom certificate authorities, and every outbound request is checked against unsafe addresses.
Can we add our own scanner?
Yes. File and CSV import works for any tool, and new providers plug into the same contracts and data feeds.