Exabeam Product Categories

May 13, 2026 · View on GitHub

The following table lists the out-of-the-box supported data sources grouped by product categories.

Product CategoryDescriptionProduct
File Systems and Object Storagenetapp ontap
nutanix unified storage
powermax
powerstore
access managementThese products establish, enforce and manage journey-time access controls to cloud, modern standards-based web, and legacy web applications.1password
active directory federation services
appsense application manager
auth0
aws bastion
azure ad identity protection
banyan security
citrix secure private access
cloud akamai
duo access
entrust identity enterprise
f5 access policy manager
forgerock
fortiauthenticator
jumpcloud
microsoft entra
microsoft intune
okta adaptive mfa
onelogin
onewelcome cloud identity platform
oracle access management
overlaps
ping identity
pingfederate
pingone
secureauth idp
secureauth login
securid
security access manager
shibboleth
simplesamlphp
symantec siteminder
symantec vip
windows device registration service
application security testingcheckmarx
contrast agent
asset managementThese products support the management of an organization's IT assets like endpoints, containers, IOT, and OT devices. These products provide all of the information about the assets in the organization.apex one
lanscope cat
qualys assetview
trellix application control
backup & recoveryThese products support data management for an organization. These products deliver backup, recovery, analytics, and data governance across data in the organization.cds
code42 crashplan
powerprotect data manager
powerprotect
rubrik cloud data management
veeam
browser isolationThese products provide an isolation layer when a user is accessing the web via browsers. With these products, code from websites won't run on the device that accesses it.symantec fireglass
cloud app security broker (casb)--aws guardduty
bitglass casb
cisco cloudlock
forcepoint casb
lacework
netskope casb
netskope security cloud
netskope webtx
palo alto aperture
saas security
skyhigh casb
symantec cloudsoc
cloud auditingThese products collect the audit logs of cloud platforms like Azure, AWS, and GCP.amazon s3
atlassian guard
aws cloudtrail
aws security hub
aws simple email service
azure ad activity logs
azure ad sign-in logs
azure container registry
azure kubernetes service
azure monitor
azure network watcher
cisco cloud security
cloudflare audit
gcp cloudaudit
google cloud platform
google workspace
m365 audit logs
microsoft 365
monday.com
oracle public cloud
saviynt
security command center
zero networks
cloud-native application protection platform (cnapp)microsoft defender for cloud
prisma access
prisma cloud
tanium cloud platform
wiz
code managementThese products are a hosting service for software development and version control. They provide an easy way to manage the code and collaborate.atlassian bitbucket
atlassian
github
gitlab
perforce
communication platformThese products provide a way to communicate with people in other places, like chat and video call software.anywhere365
cisco collaboration
cisco unified communications manager
sametime
slack
teams
zoom
content delivery network (cdn)adobe experience manager
cloudflare cdn
credential managementThese products allow users to store, generate, and manage their passwords for local applications and online services.adssp
keeper
lastpass
password manager pro
specops password
crm (customer relationship management)These products collect data from a range of different communication channels , including a company's website, telephone, email, live chat, marketing materials, and social media. They allow businesses to learn more about their target audiences and how to best cater for their needs.salesforce
zendesk
data warehouseaws redshift
informatica cloud
databaseThese products are services for storing and accessing data.amazon rds
cassandra db
confluent cloud
db2
mariadb
mongodb
mssql
mysql
oracle cloud infrastructure
oracle database
osquery
postgresql
progress database
snowflake
sonarg
sybase
teradata rdbms
database securityThese products provide a security layer to databases, through analayzing, detection, or prevention that is specific to databases.imperva securesphere
oracle audit vault and database firewall
trellix database security
ddos mitigation servicesarbor cloud
directory service auditingThese products collect the audit logs of directory services. Directory services map the names of network resources to their respective network addresses.edirectory
opendj
openldap
semperis dsp
sunone
dlp (data loss prevention)These products provide visibility into data usage and movement across an organization. They can include dynamic enforcement of security policies and address data-related threats.box shield
code42 incydr
commvault
cyberhaven dlp
data protection suite (dps)
digital guardian network dlp
forcepoint dlp
gtb technologies dlp
guardium
halcyon
infowatch dlp
microsoft purview
nightfall ai
omni dlp
proofpoint dlp
reveal
rsa dlp
symantec dlp
trellix dlp endpoint
trellix dlp prevent
document managementpro.file dms
edr (endpoint detection & response)These products provide endpoint system-level capabilities, including detection of security incidents, containment of incidents at the endpoint, investigation of security incidents, and remediation guidance.carbon black ces
carbon black edr
cisco secure endpoint
cortex xdr
cylance optics
cynet edr
digital guardian endpoint protection
endgame edr
ensilo
f5 websafe
falcon
identity threat detection & response
jamf protect
juniper advanced threat protection
lumension
malwarebytes endpoint detection and response
malwarebytes incident response
morphisec
rsa ecat
scalyr
singularity platform
symantec advanced threat protection
tanium core platform
trellix endpoint security (hx)
zscaler breach predictor
emailThese products are for sending and receiving emails.hcl notes
hmailserver
microsoft exchange
postfix
unix sendmail
email securityThese products provide the prediction, prevention, detection, and response framework that protects email access and protects against email attacks. They include gateways, email systems, user behavior, content security, and other supporting processes.abnormal security
armorblox
barracuda email security gateway
check point avanan
cisco email security
cisco secure email
clearswift secure email gateway
cofense phishme
forcepoint email security gateway
forcepoint email security
hornetsecurity cloud email security services
imsva
inky anti-phishing
ironport email
ironscales
kaspersky secure mail gateway
libraesva email security
microsoft defender for office 365
mimecast secure email gateway
mimecast targeted threat protection - url
phisher
phishing detection
proofpoint email protection
proofpoint enterprise protection
safesend
security awareness training
smg
symantec email security
tessian cloud email security
trellix email security - cloud edition
trellix email security
trend micro email security
trend micro scanmail
virtru
endpoint auditingThese products collect audit logs on endpoins.auditbeat
azure devops
azure monitor - vm insights
bind dns
event viewer - adfs
event viewer - adws
event viewer - application
event viewer - applocker
event viewer - azureadpasswordprotection-dcagent
event viewer - azureadpasswordprotection-proxyservice
event viewer - base-filtering-engine-connections
event viewer - bfe resorce flows
event viewer - bits-client
event viewer - capi2
event viewer - certificateservicesclient
event viewer - codeintegrity
event viewer - dfs-replication
event viewer - dhcp-client
event viewer - dhcp-server
event viewer - directory-service
event viewer - dnsclient
event viewer - dnsserver
event viewer - file replication service
event viewer - fileshareshadowcopyprovider
event viewer - grouppolicy
event viewer - iphlpsvc
event viewer - kerberos-key-distribution-center
event viewer - kernel-io
event viewer - kernel-pnp
event viewer - knownfolders
event viewer - licensing-platform
event viewer - liveid
event viewer - lsa
event viewer - networkprofile
event viewer - nps
event viewer - ntlm
event viewer - openssh
event viewer - powershell
event viewer - printservice
event viewer - remotedesktopservices
event viewer - security
event viewer - sentinelone
event viewer - setup
event viewer - smb
event viewer - system
event viewer - taskscheduler
event viewer - terminalservices-gateway
event viewer - terminalservices-licensing
event viewer - terminalservices-localsessionmanager
event viewer - terminalservices-remoteconnectionmanager
event viewer - terminalservices
event viewer - windows firewall
event viewer - winnat
event viewer - winrm
freebsd
macos
netlogon
openvms
solaris
sysmon
unix auditd
unix dhcpd
unix named
unix
z/os
epp (endpoint protection)These products are deployed on endpoint devices to prevent file-based malware, detect and block malicious activity from trusted and untrusted applications, and provide the investigation and remediation capabilities needed to dynamically respond to security incidents and alerts.absolute dds
airlock allowlisting
arctic wolf
assetview
azure atp
blackberry protect
bromium secure platform
check point anti-malware
check point endpoint security
cybereason
cylance protect
deep security
eset endpoint security
gravityzone
ibm security trusteer apex advanced malware protection
kaspersky av
kaspersky endpoint security for business
malwarebytes endpoint protection
microsoft defender for endpoint
microsoft defender
officescan
sophos endpoint protection
stellarone
stellarprotect
symantec endpoint protection
tls protect
traps endpoint security manager
trellix endpoint security
trellix intelligent sandbox
vbcorp
erp (enterprise resource planning)These products provide an integrated and continuously updated view of core business processes using common databases. They track business resources cash, raw materials, production capacity and the status of business commitments: orders, purchase orders, and payroll.sap
workday
esignature (electronic signature)These products gather metadata related to signing events and create an audit trail that is cryptographically sealed to ensure the authenticity of an electronically signed document.docusign esignature
onespan sign
signnow
event management & forwardingThese products are used for analayzing events and to transfer and store them in a different place.adauditplus
admanager plus
azure event hub
centrify audit and monitoring service
citrix gateway connector for exchange activesync
cribl
esector defesa logger
logbinder for sharepoint
logbinder for sql server
microfocus arcsight
quest change auditor for active directory
quest change auditor for sql server
quest intrust
rangeraudit
rsyslog
search
skyformation
file integrity monitoringThese products can determine if a file has been tampered with, updated, or corrupted.cimtrak
imperva file activity monitoring
nnt changetracker
tanium integrity monitor
file sharingThese products allow users to store their files outside their devices and share them with others.box cloud content management
cohesity dataplatform
dropbox
egnyte
emc isilon
hpe 3par storeserv
imanage
kiteworks
nasuni
netapp
netdocs
progress sharefile
synology nas
file transferThese products allow users to transfer files from one place to another.axway gateway
crushftp
ftp
goanywhere mft
liquidfiles
moveit transfer
sftp
titanftp
firewallThese products secure traffic bidirectionally across networks, and can detect and prevent rogue network traffic.aws network firewall
azure firewall
barracuda cloudgen firewall
check point ngfw
cisco adaptive security appliance
cisco firepower
cisco meraki mx appliance
cisco network security
cisco pix
f5 advanced firewall manager
forcepoint next-gen firewall
fortigate
fortinet enterprise firewall
fortinet utm
fortixdr
fw zscaler cloud
huawei enterprise network firewall
huawei unified security gateway
iptables fw
juniper srx series
next-gen web application firewall
nsx distributed firewall
palo alto ngfw
pfsense
sangfor ngaf
sonicwall
sophos utm
sophos xg firewall
sophos xgs firewall
threatblockr
watchguard
zyxel usg flex
generative ai appsai security
amazon q
chatgpt
copilot
gemini enterprise
openai
honeypotThese products can isolate and monitor an attack, and are capable of blocking or analyzing an attacker.botsink
trapx
zscaler deception
human capital management (hcm)These products include human resource functionality such as HR administration, talent management, workforce management, and HR service delivery. They may also include case management, knowledge base, and digital document management.successfactors
ics securitynozomi networks guardian
identity administrationThese products manage digital identity and access rights across multiple systems. They aggregate and crrelate disparate identity and access rights data that is distributed throughout the IT landscape to enhance control over user access.check point identity awareness
cisco identity and access management
cisco identity intelligence
identitynow
imprivata
micro focus netiq identity manager
one identity manager
sailpoint iiq
securelink
securityiq
vmware identity manager
xceedium
ids (intrusion detection system)corelight ids
infrastructure monitoring?--nexthink infinity
sysdig monitor
insider risk managementThese products measure, detect, and contain undesireable behavior of trusted accounts within an organization. They include capabilties to monitor insider behavior and evaluate whether the behavior falls within expectations of role and corporate risk tolerance. These risks can involve errors, fraud, information theft, or sabotage.activtrak
citrix security analytics
dtex intercept
forcepoint insider threat
logrhythm userxdr
micro focus arcsight intelligence
microsoft advanced threat analytics
observeit
proofpoint insider threat management
iot securityThese products provide security for information trasmittend by sensor-based things and other devices across an Internet of Things environment.armis platform
claroty
netskope iot security
ordr sce
symantec critical system protection
ip address management (ipam)These products are for planning and managing the assignment and use of IP addresses and closely related resources of a computer network.bloxone ddi
bluecat networks
infoblox nios
n3k
nokia vitalqip
ips (intrusion prevention system)These products are stand-alone physical and virtual applicances that inspect network traffic either on-premises or in the cloud. They are often located in network to inspect traffic that has passed through permimeter security devices. They provide detection via several methods.alert logic managed detection and response
cisco cognitive threat analytics
cisco sourcefire
damballa failsafe
fidelis xps
ixia threatarmor
managed isensor ips
ossec
proventia network ips
sentinel ips
snort
suricata
tippingpoint ngips
trellix network security platform
trellix web mps
zimperium mtd
load balancerThese products manage traffic, move packets efficienty across multiple servers, optimizes the use of network resources, and prevent network overloads.alteon
amazon route 53
avi networks software load balancer
aws elastic load balancer
big-ip f5 lbr
f5 local traffic manager
kemp loadmaster
managed detection and response (mdr)red canary managed detection and response
vigilance
managed security servicessymantec managed security services
mobile managementThese products support the management of mobile devices, wireless networks, and other mobile computing services in a business context.ibm mobile connect
lookout
mobileiron
vmware airwatch
ndr (network detection and response)awake security
cisco secure cloud analytics
cisco secure network analytics
extrahop reveal(x)
fidelis network
verizon ndr
vision one
networkcisco cyber vision
dnsmasq
trellix network security (nx)
network access control (nac)These products enable organizations to implement policies for controlling access to corporate infrastructure by both user-oriented devices and Internet of Things (IoT) devices. Policies can be based on authentication, endpoint configuration, or user role or identity.airespace wireless lan controller
aruba clearpass policy manager
cisco acs
cisco ise
cisco wireless networking
cisco wlc
forescout counteract
forticlient
fortinac
microsoft network policy server
packetfence
portnox clear
portnox cloud
sophos ztna
unifi access point
universal ztna
viascope ipscan
network analyzerThese products are used for analyzing network traffic.cisco netflow
cisco network monitoring and analytics
cloudflare insights
gigavue-hc2
irondefense
microsoft dhcp log
microsoft dns log
netmon
network security group flow logs
vectra cognito stream
vpc flow logs
zeek
network automation and orchestrationThese products automate the maintenance of virtual and physical network device configurations, providing an opportunity to lower costs, reduce human error, and improve compliance with configuration policies.f5 big-ip dns
f5 distributed cloud
msdhcp
powerdns recursor
swimlane turbine
network devicesThese products represent network devices and their operating systems.aruba wireless controller
arubaos
avaya ethernet routing switch
cisco ios
hpe comware
junos os
network infrastructure & managementThese products support management of the network environment and infrastructure in the organization.cisco network infrastructure and management
cisco secure firewall management center
exos
extremecloud iq
platform one
ruckus
zebra wlan management
network performance monitoringThese products leverage a combination of data sources to provide a holistic view of how networks (including corporate on-premises, cloud, multicloud, hybrid, and other networks) are performing. Based on network-derived performance data, these tools provide insight into the quality of the end-user experience.nagios
splunk stream
network security policy management (nspm)algosec firewall analyzer
firemon
panorama
trellix epolicy orchestrator
tufin securetrack
operational technology securityctd
dragos platform
otherThese products do not fit into one of the defined product categories.adaxes
akamai guardicore
apache subversion
apache tomcat
apc
aruba mobility master
attack analytics
buildkite
chcom
cisco data center
cisco dhcp
cisco ucs
clearsense
commvault threatwise
cortex xsoar
counterbreach
dxc technology
edocs
emp
f-secure client security
f-secure policy manager
f5 big-ip
fast enterprises gentax
fileauditor
filesite
gamma
harmony saas
hp ilo
hp virtual connect enterprise manager
ibm datapower
ibm mainframe
ibm resource access control facility
ibm
icdb
imss
infoblox netmri
jh
kasada
leap
mulesoft anypoint platform
mvision
namespace rdirectory
netwrix threat prevention
onapsis
pagerduty
pensando
phantom
pharos
picture perfect
portkey
postscript
powersentry
riverbed steelhead
rstudio server
ruid
rundeck
safend dps
sailpoint fam
seclore
servicenow
sitespect
smartdefense
smartsuite
sophos safeguard
stealthbits stealth defend
stealthintercept
sterling b2b integrator
swift
tanium threat response
terraform
thoughtspot
usb
vectra cognito detect
vmware nsx
vormetric
weblogin
xams
xplan
xsuite
zlock
physical access controlThese products help organizations to monitor and forbid entrance to physical locations in their organization, like a person entering an office or a building.accessit universal.net
aviglion acm
badge
badgepoint
brivo
ccure building management system
datawatch
galaxy
gallagher access control
generic badge access
genetec badge
honeywell pro-watch
honeywell siama
honeywell win-pak
icpam
identiv
johnson controls p2000
kaba exos
lenel onguard
lyrix
net2door
onguard
rightcrowd
rs2 technologies
securityexpert
sensormatik
siemens access control
swipes
symmetry access control
timelox
vanderbilt
printerThese products represent printers or the software that operates them.asupim
hp laserjet printer
hp print server
hp safecom
imagerunner advance
lexmark
ricoh printer
xerox
xps
printing managementysoft
privilege access managementThese products help organizations provide secure privileged access to critical assets and meet compliance requirements by managing and monitoring privileged accounts and access.admin by request
azure key vault
beyondinsight
beyondtrust privileged identity
beyondtrust secure remote access
beyondtrust
ca privileged access manager server control
centrify infrastructure services
cyberark endpoint privilege manager
cyberark privilege access manager
hashicorp vault
mastersam pam
megaflex
osirium
pam360
passwordstate
powertech identity and access manager
secret server
unix privilege management
wallix bastion
proxyThese products are server applications that act as an intermediary between a client requesting a resource and the server providing that resource.envoy
kong gateway
menlo security
microsoft web application proxy
ping access
squid
remote accessThese products allow users to take control of a remote machine.apache guacamole
beyondtrust remote support
microsoft rras
remotelyanywhere
secomea
sandboxingThese products are used for exceution of untested or untrusted programs or code, possibly from unverified or untrusted third parties, suppliers, users, or websites, without risking harm to the host machine or operating system. They are frequently used to test unverified programs that may contain a virus or other malicious code without allowing the software to harm the host device.check point threat emulation
deep discovery inspector
lastline
symantec content analysis system
targeted attack platform
secure enterprise browserermes browser security platform
island enterprise browser
security configuration management (scm)aws ssm
tripwire enterprise
security services edge (sse)blue coat proxysg
check point vsec virtual edition
cisco cloud web security
cisco gateway
cisco secure web appliance
cisco umbrella
cisco web security
digital arts i-filter for business
edgewave iprism
human bot defender
iboss cloud
ironport web security
mcafee siteadvisor
mcafee web gateway
microsoft cas
mimecast web security
proofpoint casb
secure web gateway
skyhigh security cloud
symantec virtual secure web gateway
symantec web security service
trend micro cloud app security
trend micro interscan web security
websense security gateway
zscaler internet access
siem (security information and event management)These products aggregate event data produced by security devices, network infrastructure, systems, and applications. They allow analysis of event data in real time for early detection of attacks and breaches. The event data can be combined with contextual data about users, assets, threats, and vulnerabilities.advanced analytics
akamai siem
audit log
correlation rule
darktrace
epic siem
eyeinspect
fortisiem
ibm sense
logrhythm
microsoft sentinel
netwrix auditor
ng analytics
qradar siem
rsa netwitness platform
skysea clientview
splunk es
splunk se
trellix central management
trellix enterprise security manager
trellix helix
varonis data security platform
wazuh
social networksgoogle plus
software-defined networkingcisco aci
threat intelligenceThese products deliver knowledge, information, and data about cybersecurity threats.centurylink managed security service
f5 ip intelligence
palo alto wildfire
recorded future threat intelligence
zerofox protection
unified endpoint management (UEM)These products provide agent and agentless management fo computers and mobile devices through a single console.citrix endpoint management
user authenticationThese products provide real-time corroboration of an identity claim by a person accessing an organization�s assets. They enable or provide one or more credential-based or signal-based authentication methods that can augment or replace legacy passwords.azure mfa
centrify authentication service
centrify zero trust privilege services
digipass for apps
gemalto mfa
rsa adaptive authentication
rsa authentication manager
secure computing safeword
securenvoy multi-factor authentication
silverfort authentication platform
swivel
thales
virtualization & containersThese products provide the abillity to create a virtual version of things like virtual computer hardware platforms, storage devices, and computer network resources.amazon eks
citrix virtual apps
citrix virtual desktop
openshift
ovirt
vcenter
vmware esxi
vmware horizon
vmware velocloud sd-wan
vmware view
vpn (virtual private network)These products can be used to achieve security and confidentiality for data in motion by means of encryption and access controls. Solutions may be implemented in software on end-user devices, servers, and appliances.anyconnect
avaya vpn
cato cloud
check point security gateway
cisco remote access security
citrix gateway
cognitas crosslink
fortinet vpn
globalprotect
ivanti pulse secure
ncp
netmotion wireless
nortel contivity vpn
open vpn
securenet
web application proxy-tls gateway
zscaler private access
vulnerability assessmentThese products provide capabilities to identify, categorize, and manage vulnerabilities. These include unsecure system configurations or missing patches, as well as other security-related updates in the systems connected to the enterprise network directly, remotely, or in the cloud.amazon inspector
qualys vmdr
rapid7 insightvm
tenable cloud security
tenable identity exposure
tenable vulnerability management
tenable web app scanning
vicarius vrx
waf (web application firewall)Theses products filter, monitor, and block HTTP traffic to and from a web service. By inspecting HTTP traffic, they can prevent attacks exploiting a web application's vulnerabilities.airlock security access hub
aws waf
barracuda waf
citrix web app firewall
cloudflare waf
f5 advanced web application firewall
f5 application security manager
f5 silverline
fortiweb web application firewall
imperva incapsula
magento waf
radware waf
redshield waf
sigsci
skudonet waf
web servernginx
nonstop
web server auditingThese products collect audit logs of web servers.apache
microsoft iis
microsoft wmi log
workload protectionThese products protect server workloads in hybrid, multicloud data center environments. They provide consistent visibility and control for physical machines, virtual machines (VMs), containers, and serverless workloads, regardless of location.aws cloudwatch
carbon black app control
cisco adc
illumio core
windows defender application control