> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pulsedive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrations

> Connect Pulsedive to your third-party solutions, including threat intelligence platforms (TIP), SIEM, and SOAR. Step-by-step setup guides for bulk ingestion, workflow enrichment, and blocklist integrations.

Pulsedive integrates with a range of third-party security solutions so you can access and act on threat intelligence in the tools you already use.
This section covers the most widely used vendor solutions that integrate with Pulsedive, with setup instructions for each.

## How Integrations Work

Pulsedive integrations fall into three categories depending on how data moves between Pulsedive and the other platform:

* **TAXII integrations:** Connect a solution directly to Pulsedive’s TAXII 2.1 server.
  The solution polls Pulsedive on a schedule and imports indicators in STIX 2.1 format, adding them to the customer’s threat intelligence store for use in detection and alerting.
  TAXII integrations require a Standard or Complete Pulsedive Feed plan.
* **Enrichment integrations:** These use the Pulsedive API.
  A plugin, connector, or library in the third-party solution queries Pulsedive on demand—from a playbook, an automated workflow, a CLI command, or a manual analyst action—and returns enrichment data for a specific indicator.
  Enrichment integrations for commercial use require a Team subscription or higher.
* **Blocklist integrations:** Pull a Pulsedive IP blocklist feed by URL for use in network-level blocking.

To find your Pulsedive API key, visit your [Pulsedive account](https://pulsedive.com/account).
To learn about Feed plans, visit [Feed](https://pulsedive.com/about/feed).

## Connecting Any TAXII-Compatible Platform

If your platform supports TAXII 2.1 but isn’t listed below, you can connect it manually using the following parameters:

* **API Root URL:** `https://pulsedive.com/taxii2/api/`
* **Username:** `taxii2`
* **Password:** Your Pulsedive API key
* **Collection IDs:**
  * **Indicators:** `a5cffbfe-c0ff-4842-a235-cb3a7a040a37`
  * **Threats:** `dc9ecfa5-7769-4cf3-b699-38a9776b431d`
  * **Test:** `981c4916-ebb2-4567-aece-54ae970c4230` (free with any API key, live sample data)

For full TAXII reference documentation, visit [STIX/TAXII](/taxii/overview).

## Available Integrations

<Columns cols={2}>
  <Card title="Microsoft Sentinel" icon="https://mintcdn.com/pulsedive-c1f2dc75/sqWmMRuxkhCR7v74/images/logos/sentinel-flat.svg?fit=max&auto=format&n=sqWmMRuxkhCR7v74&q=85&s=5c4bf72b55e4ea04e243ccec0d4ad242" href="/integrations/microsoft-sentinel" width="18" height="18" data-path="images/logos/sentinel-flat.svg">
    Import scored, deduplicated Pulsedive threat intelligence into Microsoft Sentinel over TAXII 2.1 to power detection, alerting, and investigation.
  </Card>

  <Card title="OpenCTI" icon="https://mintcdn.com/pulsedive-c1f2dc75/sqWmMRuxkhCR7v74/images/logos/opencti-flat.svg?fit=max&auto=format&n=sqWmMRuxkhCR7v74&q=85&s=c2636f1b694b446b133845a3a9b32aa8" href="/integrations/opencti" width="38" height="39" data-path="images/logos/opencti-flat.svg">
    Import scored, deduplicated Pulsedive threat intelligence into OpenCTI over TAXII 2.1 for correlation, investigation, and sharing.
  </Card>

  <Card title="Splunk Enterprise Security" icon="https://mintcdn.com/pulsedive-c1f2dc75/sqWmMRuxkhCR7v74/images/logos/splunk-flat.svg?fit=max&auto=format&n=sqWmMRuxkhCR7v74&q=85&s=f9dadcddb699ebc9b89133f301120992" href="/integrations/splunk-enterprise-security" width="4" height="4" data-path="images/logos/splunk-flat.svg">
    Bring Pulsedive threat intelligence into Splunk Enterprise Security as a URL-based CSV source for correlation and risk scoring.
  </Card>

  <Card title="Tines" icon="https://mintcdn.com/pulsedive-c1f2dc75/sqWmMRuxkhCR7v74/images/logos/tines-flat.svg?fit=max&auto=format&n=sqWmMRuxkhCR7v74&q=85&s=11c042818c9994f5e793fddc8ce469ef" href="/integrations/tines" width="500" height="500" data-path="images/logos/tines-flat.svg">
    Use Tines’s pre-built Pulsedive Stories and action templates to add threat intelligence enrichment to any security automation workflow.
  </Card>
</Columns>

## Pro Integrations

Pulsedive can proxy enrichment queries to VirusTotal, Shodan, and AbuseIPDB on your behalf using API keys you store in your Pulsedive account.
To configure this feature, visit [Account > Integrations](https://pulsedive.com/account/) and add your API key for each service.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.