CYJAX Intelligence Now Lands Directly Inside Google SecOps and Microsoft Sentinel
CYJAX intelligence is now built directly into Google SecOps SIEM and Microsoft Sentinel, giving analysts structured, normalised threat data inside the platforms they already use. Four feeds are live in Google SecOps and eight endpoints are available in Microsoft Sentinel's Content Hub.

Key Takeaways
- CYJAX intelligence is now built directly into both Google SecOps SIEM and Microsoft Sentinel, with no separate console, no manual export, and no delay between detection and action
- Google SecOps supports four feeds at launch (Indicators of Compromise, Incident Reports, Domain Monitor alerts, Data Breach records) as structured UDM events, with native dashboards included from day one
- Microsoft Sentinel is live in the Content Hub now, with eight endpoints landing in dedicated Log Analytics tables, ready for KQL, workbooks and analytic rules
Intelligence that sits outside the platform an analyst is already working in gets used less, and used later. This month, that gap closes. CYJAX intelligence is now natively available inside Google SecOps SIEM and Microsoft Sentinel, structured, normalised and ready to drive correlation, hunting and detection from day one.
"Analysts shouldn't have to leave the platform they live in to make use of our intelligence," said Rob Campbell, Head of Product at CYJAX. "Landing natively in Google SecOps and Microsoft Sentinel means CYJAX data is there at the point of decision, not in a separate tab."
Google SecOps SIEM
CYJAX intelligence is now available within Google SecOps SIEM as structured UDM (Unified Data Model) events, arriving already normalised to Google's schema. That means it sits directly alongside the rest of a tenant's telemetry rather than as a separate, siloed source, unlocking correlation against existing log data, retroactive hunting across historical events, and detection rule authoring with no additional transformation work required.
Four feeds are supported at launch:
- Indicators of Compromise — for correlation against network and endpoint telemetry
- Incident Reports — contextual reporting on threat actor activity and campaigns
- Domain Monitor alerts — impersonation and look-alike domain detections
- Data Breach records — exposure of credentials and organisational data
Each feed is configured as its own third-party API feed within Google SecOps, rather than a single combined pipeline. That distinction matters operationally: high-volume sources such as Indicators of Compromise can be polled more frequently, while lower-volume sources like Incident Reports can be polled on a longer interval, so ingestion cadence can be matched to how each feed actually behaves rather than applying one setting across all four.
Native dashboards are included as part of the integration, giving teams a working view of CYJAX data inside Google SecOps from the point of setup, ahead of any custom detection or reporting work.
Microsoft Sentinel
The CYJAX solution is now live in the Microsoft Sentinel Content Hub, Microsoft's central catalogue of solutions and data connectors for Sentinel. Installation follows the standard Content Hub process: install the solution, add a CYJAX API key, and select which of the available endpoints to bring in.
Eight endpoints are available:
- Indicators of Compromise
- Tweetmon — monitored social media threat activity
- Incident Reports
- Pastes — exposed data identified on paste sites
- Data Leaks
- Domain Monitor
- TOR Exit Node — TOR network exit node tracking
- Ransomware Operations — ransomware group and campaign activity
Data from each endpoint lands in its own dedicated custom table within Log Analytics, keeping CYJAX data cleanly separated from other log sources while remaining fully queryable. From there, it's ready for KQL queries, Sentinel workbooks for visualisation and reporting, and analytic rules for automated alerting, giving teams everything they need to build detection logic on CYJAX intelligence using the same workflows they already rely on for the rest of their Sentinel data.
Next steps
To set up either integration, contact your account manager.
Get Started with CYJAX CTI
Empower Your Team. Strengthen Your Defences.CYJAX gives you the intelligence advantage: clear, validated insights that let your team act fast without being buried in noise.



