Cloudflare
Ingests WAF events, DNS analytics, audit logs, and Logpush data. Powers the Perimeter battery with DDoS detection, WAF bypass attempts, origin exposure monitoring, DNS hijack detection, and bot attack identification.
Data FeedsVimy integrates with the tools you already use. Each connector feeds security telemetry into the platform and simultaneously maps to compliance controls. No rip-and-replace โ Vimy is the brain that sits on top.
Every connector you add delivers security telemetry, activates detections, and collects compliance evidence โ simultaneously.
Every connector feeds raw events into Vimy's telemetry pipeline. Events are normalized to OCSF, enriched with threat intelligence and entity context, and made queryable in seconds.
Normalized events flow to the detection engine. Each connector activates detection specifications specific to that data source โ the more connectors, the more coverage.
Every event that passes through the pipeline automatically maps to compliance controls across your active frameworks. Connect Cloudflare, and perimeter-related SOC 2 controls start collecting evidence immediately.
These connectors are live, tested, and actively processing telemetry for Vimy customers today.
Ingests WAF events, DNS analytics, audit logs, and Logpush data. Powers the Perimeter battery with DDoS detection, WAF bypass attempts, origin exposure monitoring, DNS hijack detection, and bot attack identification.
Data FeedsIngests Admin SDK audit events, login activity, OAuth grant events, and directory changes. Powers the Identity battery with impossible travel detection, MFA fatigue monitoring, OAuth abuse detection, and privilege escalation tracking.
Data FeedsIngests cloud server events, firewall changes, API audit logs, and cloud resource modifications. Powers the Infrastructure battery with unauthorized access detection, firewall tampering alerts, and resource anomaly monitoring.
Data FeedsA lightweight Go binary deployed on your servers. Runs in user space with zero kernel access. Observes authentication events, process execution, file integrity, network connections, resource utilization, and cryptographic inventory. All analysis happens server-side โ the agent watches, the platform thinks.
Data FeedsSetup: One-line install script ยท ~2 minutes per server
Managed from the Agent Fleet page โ deploy, update, and monitor agents across your entire infrastructure from a single dashboard.
These connectors are defined in the platform and will be activated as each battery reaches production. Request early access to prioritize a specific connector for your environment.
System log events, authentication, MFA, user lifecycle
Sign-in logs, audit logs, conditional access, directory changes
Message metadata, phishing indicators, forwarding rules, DMARC/SPF/DKIM
Mail flow, message trace, transport rules, threat protection
EDR events, device compliance, threat detections, process activity
Threat events, agent status, device inventory, deep visibility
ATP alerts, device health, vulnerability assessments
CloudTrail, GuardDuty, Security Hub, IAM events
Activity logs, Security Center, resource changes
Firewall logs, VPN events, IPS alerts, traffic analysis
Firewall logs, threat prevention, URL filtering, WildFire
Audit logs, file sharing, integration activity, user events
Audit log, secret scanning, repository events, OAuth apps
Login history, setup audit trail, event monitoring
Project events, permission changes, integration activity
Incident management, change records, CMDB updates
Incident routing, escalation, on-call management
Device compliance, configuration profiles, app management
Vimy connectors are read-only and agent-optional. No firewall changes, no persistent credentials stored in plaintext โ each connector authenticates via OAuth or API token scoped to the minimum required permissions. New connectors are added without redeployment and activate automatically for the batteries that need them.
Every connector you activate increases your detection coverage and your compliance posture simultaneously. Vimy's Fog of War page shows you exactly which MITRE ATT&CK techniques you cover and which you don't โ so you can make informed decisions about which connectors to add next.
Your Fog of War coverage score improves with every new connector.
30-minute demo. We'll map your existing tools to Vimy's batteries and show you what lights up on day one.