SOCRadar Alerts Now Feed External Threat Alarms Straight into Elastic Security
Many security teams already have external threat intelligence, but it often lives in a separate platform. Alarms about impersonating domains, leaked credentials or newly exposed assets are reviewed in one console and then manually re-entered into the SIEM or case tool when they matter. SOCRadar says this handoff costs time: each alarm needs a person to carry it across, and context such as the affected asset, related entities or current status is often lost, leaving the analyst with little more than a title.
The new SOCRadar Alerts integration (v0.1.0) is available natively through the Elastic integrations catalog in Elastic Security. It collects alarms through the SOCRadar API on a configurable polling interval, with an initial historical lookback so the first run backfills recent alarms. Each alarm arrives with its severity, status, alarm types, affected assets, related entities and details, mapped to ECS. The alarms come from SOCRadar's alarm engine, which correlates findings from Cyber Threat Intelligence, Brand Protection and External Attack Surface Management.
The integration also includes a built-in Kibana dashboard showing severity distribution, alarm categories, volume trends and recent incidents, so external threat signals sit alongside detections, logs and cases in one place.