Skip to main content
Both integrations are optional. xorlab protects email without either of them, and analysts can do everything described here by hand in the web interface. They rest on two interfaces:
  • Outbound, over Syslog: verdicts, extracted threat intelligence, and the full analyst and admin audit trail. This is what a SIEM ingests, and what a SOAR uses as a playbook trigger.
  • Inbound, over HTTPS: the List API, which lets a playbook or script change list entries without a human in the web interface.
Prerequisites