Integration Types in BitLyft AIR®

Integration Types in BitLyft AIR®

BitLyft AIR® offers a flexible, modular approach to integrating with your security ecosystem. Integrations in BitLyft AIR® are categorized into four distinct types, each designed to perform a specific function within your security operations workflow:

  1. Log Ingestion & Analytics

  2. Remediation

  3. Log Enrichment

  4. Platform

Each integration type plays a unique role in enabling detection, investigation, and response across your environment. Below is a breakdown of each category.


1. Log Ingestion & Analytics

Purpose:
Collect log data from your systems and apply rules or policies to generate alerts.

Use Cases:

  • Ingest logs from Microsoft 365, cloud platforms, and identity providers.

  • Define detection rules or policies to analyze log data in real-time

  • Automatically generate alerts when suspicious behavior is detected

How it Works:
These integrations are responsible for securely pulling or receiving log data into the BitLyft AIR® platform. Once ingested, logs are parsed, normalized, and analyzed against defined detection content (rules and correlation logic). Alerts are created based on matching criteria, allowing security teams to take action quickly.

Examples:

  • Microsoft 365 Audit Logs

  • Identity Providers (IDP) telemetry


2. Remediation (Actions & Playbooks)

Purpose:
Execute automated incident response actions or playbooks to mitigate threats.

Use Cases:

  • Resetting compromised user credentials

  • Disabling access for suspicious accounts

  • Phishing emails

How it Works:
Remediation integrations connect to third-party systems and expose actions that can be triggered manually or automatically by playbooks. These can range from simple one-step responses to complex, multi-step workflows. Each action is logged and traceable for auditing and compliance.

Examples:

  • Microsoft 365: Reset Password

  • Okta: Suspend Device

  • Duo: Get Authentication Logs

  • One Login: Lock User Account


3. Log Enrichment

Purpose:
Enhance ingested log data with external or contextual information to improve alert accuracy and investigation.

Use Cases:

  • Add GeoIP data to network connection logs

  • Enrich IPs/domains with threat intelligence reputation scores

  • Correlate IOCs with known malicious indicators

How it Works:
Enrichment integrations operate passively in the background. When a relevant field (e.g., IP address, domain, file hash) is detected in log data or alerts, BitLyft AIR® queries external sources to append context. This information is visible in the alert details and is used in playbooks or during analyst investigations.

Examples:

  • MaxMind GeoIP

  • VirusTotal

  • AlienVault


4. Platform

Purpose:
Connect BitLyft AIR® to external platforms that provide services such as alert ingestion, SIEM functionality, or log storage.

Use Cases:

  • Integrate with Graylog for centralized alert handling

  • Ingest alert data from third-party detection platforms

  • Provide log forwarding to external systems

How it Works:
Platform integrations facilitate the overall interoperability of BitLyft AIR® with the customer’s broader security architecture. These integrations enable BitLyft AIR® to provide automated incident response.

Examples:

  • Graylog


Summary Table

Integration Type

Function

Examples

Integration Type

Function

Examples

Log Ingestion

Collect logs, generate alerts via policies

Microsoft 365

Remediation

Execute response actions or playbooks

Microsoft 365, Okta

Log Enrichment

Add context to data (GeoIP, threat intel)

VirusTotal, MaxMind

Platform

Connect to SIEMs and alerting platforms

Graylog


Managing Integrations in BitLyft AIR®

You can view, enable, configure, or disable integrations from the Integrations section in the BitLyft AIR® web console. Each integration includes:

  • A summary of its capabilities

  • Required credentials or API tokens

  • Status indicators (Connected, Disconnected, Error)

  • Documentation links for setup guidance