Skip to main content

Telemetry Aggregation

CONNECTORS

Built in Connectors

Every scanner and every system of record, pulled into one schema.

AlloyGRC does not ask you to change what you run. Connectors pull vulnerabilities, compliance results, assets and identity from the tools you already own, land them in one described dataset, and hand work back to your ticketing.

Why it is a dataset, not an integration

Described once, spoken everywhere

A connector does not feed one screen. Its output is profiled in the Dataset Builder, its fields are given roles, and from then on the Dynamic Datatable, AREA, the sprint board, GenAI Dashboards and Ask Alloy all read the same described data. Add a source and every feature already knows what to do with it.

How the Dataset Builder describes data

Built in today

What each connector pulls

Vulnerabilities and compliance

Tenable Security Center

Vulnerability findings per asset, and compliance results from STIG benchmark audits: every check with its CAT severity, the expected and actual value, and the NIST SP 800-53 control, CCI and CSF function it maps to.

VulnerabilitiesSTIG benchmarkCSF mappingCAT severity
Vulnerabilities and asset management

Qualys

Detections per asset with CVSS, Qualys detection score and TruRisk, first and last detected dates and the ATT&CK tactics and techniques Qualys attaches. Asset inventory with agent status, last scan dates, operating system, hardware identity and criticality. Software inventory per asset. Every pull is kept as a dated snapshot.

VulnerabilitiesAssetsSoftware inventoryDated snapshots
Work out

Jira

Send a sprint or a grouped fix to Jira as tickets, opt in on every send, with the ticket key written back to the finding so the board and the ticket agree.

TicketsOpt in per sendKey written back
Identity

Active Directory

Sign in and role resolution from your directory. Remediation lanes resolve real owners and their email through it, so nothing about who fixes what is hand typed.

Sign inRolesOwner lookup
Identity state

MidPoint

Live account, role and entitlement state for the Access Control assessment agent, so the AC family is assessed from what exists rather than what was attested.

AccountsEntitlementsAC family
Avint feed

ATIP threat corpus

The enriched CVE corpus arrives daily from the Avint pipeline and is joined to every finding by CVE, so each connector's output carries actors, malware, exploits and ATT&CK context.

370,000 CVEsDailyJoined by CVE

Every source, one table

Today, in development, planned

The honest list. A source moves up a row only when its connector is in the product.

SourceKindWhat it pullsStatus
Tenable Security Center Vulnerabilities and complianceVulnerability findings and STIG benchmark compliance per asset Today
Qualys Vulnerabilities and asset managementDetections, asset inventory and software inventory, kept as dated snapshots Today
Jira Work outTickets out, opt in on every send, key written back to the finding Today
Active Directory IdentitySign in, role resolution and owner lookup Today
MidPoint Identity stateAccount, role and entitlement state for the AC agent Today
ATIP threat corpus Avint feedEnriched CVE records, daily, joined to findings by CVE Today
CrowdStrike Falcon Endpoint telemetryEndpoint detections and host telemetry beside the findings on the same asset In development
Qualys policy compliance ComplianceCompliance scan results alongside the vulnerability and asset pulls Planned
Microsoft Intune Work outHand remediation to endpoint management Planned
ATIP API Avint feedQuery the threat corpus from outside AlloyGRC Planned
Existing ATO import AuthorizationBring an authorized system straight into continuous monitoring Planned

How a connector works

Pull, normalize, join, serve

Four stages, the same for every source. The first two happen when the connector runs; the last two are why the data is useful everywhere.

STAGE 01

Pull

A scheduled pull from the tool's API or export. Each run lands as a dated snapshot, so history is never overwritten.

Raw snapshot

STAGE 02

Normalize

Fields are mapped to roles in the Dataset Builder: finding id, asset id, severity, dates, status. Scanner wording becomes one vocabulary.

Described dataset

STAGE 03

Join

Assets are tied to the systems you own through hardware identity, and every CVE picks up its ATIP record.

Findings scoped to systems

STAGE 04

Serve

Tables, AREA ranking, dashboards, the sprint board and Ask Alloy all read the same dataset. Work goes back out through Jira.

Every feature, one schema

Straight answers

Do we have to replace our scanner?

No. Tenable Security Center and Qualys are both read as they are. AlloyGRC ranks and scopes what they find; it does not discover anything itself.

We run something that is not listed.

Anything that lands in the AlloyGRC database can be profiled and described in the Dataset Builder and used by every feature. A dedicated connector adds the scheduled pull and the normalization, and we build them in the order customers need them.

Does scan data leave our environment?

No. Connectors run inside your deployment, pull into your database, and nothing is sent to Avint.

How are findings tied to our systems?

Through the asset's hardware identity, matched against the system inventory. A finding on an asset nobody owns stays visible as unassigned rather than disappearing.

Bring a scanner export. Leave with it ranked and scoped.

Ask for a demo and we will show a Tenable or Qualys pull landing, being described, and turning up ranked on the vulnerabilities page.