# ThreatAware ## Docs - [Welcome](https://docs.threataware.com/index.md): Agentless cyber asset management — discover every device, validate every security control, automate every gap - [Quickstart](https://docs.threataware.com/quickstart.md): Zero to first integration in five minutes — the evaluator's path through ThreatAware Protect - [Platform Overview](https://docs.threataware.com/platform-overview.md): How ThreatAware Protect collects, deduplicates, and surfaces device data — and the shape of the UI you'll work in every day - [What's New](https://docs.threataware.com/whats-new.md): Recent improvements to ThreatAware Protect - [Onboarding](https://docs.threataware.com/onboarding.md): From provisioning to first connected integration — what to do in your first day of Protect - [Getting Started](https://docs.threataware.com/getting-started.md): Your first 24 hours — explore data, configure Vitals, wire your first Action, save your first view - [Take the In-Product Tour](https://docs.threataware.com/tour.md): Nine screens, two minutes — Protect's built-in onboarding tour - [Device Explorer](https://docs.threataware.com/device-explorer.md): The globe-of-devices home — live integration sync, real-time activity log, command bar - [Device Management](https://docs.threataware.com/device-management.md): The unified device inventory — every device from every connected source, deduplicated, filterable, exportable - [Network Inventory](https://docs.threataware.com/network-inventory.md): Devices detected by network-scanning integrations but not yet correlated to managed endpoints - [Coverage Explorer](https://docs.threataware.com/coverage-explorer.md): The tag-overlap visualiser inside Settings → Tags — find devices in multiple tags or no tags at all - [User Inventory](https://docs.threataware.com/user-inventory.md): Every person who touches a device or an account, correlated across your identity, MDM, and EDR sources - [Software Inventory](https://docs.threataware.com/software-inventory.md): Tag-scoped software list — every application installed on every device, per device-group - [X-Ray](https://docs.threataware.com/x-ray.md): See every raw field from every integration for any device — Protect's transparency layer - [Query Language](https://docs.threataware.com/query-language.md): The unified search syntax used across Devices, Users, Issues, Software, Logic Engine, and Action triggers - [Tags & Logic Engine](https://docs.threataware.com/tags-and-logic-engine.md): Dynamic tagging and computed columns — how the Logic Engine drives Vitals scope, action targeting, access control, and the Devices grid - [Security Monitoring (Vitals)](https://docs.threataware.com/security-monitoring.md): Continuous, three-stage validation that your security controls are actually protecting devices - [Vitals Configuration](https://docs.threataware.com/vitals-configuration.md): Define which security controls are required for which devices, and what 'configured correctly' means - [Issues](https://docs.threataware.com/issues.md): The real-time list of every detected problem across every connected source - [Stealth Devices](https://docs.threataware.com/stealth-devices.md): Beta capability that surfaces full-kernel-OS devices (desktops, laptops, servers, VMs) on your network that no management platform is tracking - [Action Center](https://docs.threataware.com/automation.md): Automate remediation — Continuous Actions for always-on hygiene, Snapshot Actions for time-bound projects - [Continuous Actions](https://docs.threataware.com/actions-continuous.md): Always-on remediation — devices entering the query auto-added, resolved devices auto-removed - [Snapshot Actions](https://docs.threataware.com/actions-snapshot.md): Time-bound projects with fixed scope, deadlines, and progress tracking - [Automation Templates](https://docs.threataware.com/automation-templates.md): Pre-built starting points for common Action automations - [Integrations](https://docs.threataware.com/integrations.md): Connect Protect to 100+ security and IT platforms via API or PowerShell relay — read-only, hourly sync - [PowerShell Relay](https://docs.threataware.com/powershell-relay.md): Connect on-premises tools to Protect without opening inbound firewall ports - [Multi-Tenancy](https://docs.threataware.com/multi-tenancy.md): Connect multiple tenants of the same integration — cross-mapping or strict isolation - [Reporting](https://docs.threataware.com/reporting.md): Dashboard, scheduled exports, and the AI-powered Reporting app builder — turning data into deliverables - [Scheduled Reports](https://docs.threataware.com/scheduled-reports.md): Recurring email exports of saved views — top-level overview - [Access Control & Governance](https://docs.threataware.com/access-control.md): Roles, teams, Single Sign-On (SSO), data-level permissions, and audit — control who sees what in Protect - [Settings](https://docs.threataware.com/settings/index.md): Where all tenant-wide configuration lives — the left rail of the Settings page mapped to every sub-area - [Settings → Integrations](https://docs.threataware.com/settings/integrations.md): The integration card list — connect, modify, monitor every external tool feeding Protect - [Settings → Users](https://docs.threataware.com/settings/users.md): Manage the people who log into Protect — invite, edit, deactivate, manage SSO/MFA - [Settings → Roles](https://docs.threataware.com/settings/roles.md): The four default roles (Super Admin, Analyst, Viewer, Limited Viewer) and how to define custom roles - [Settings → Teams](https://docs.threataware.com/settings/teams.md): Logical groups of users for sharing saved views, actions, Studio apps, and notifications - [Settings → Tags](https://docs.threataware.com/settings/tags.md): Tag definitions and the Logic Engine — the rules that decide which devices and users carry which tags - [Settings → Scheduled Reports](https://docs.threataware.com/settings/scheduled-reports.md): Recurring email exports of saved views — CSV, JSON, XLSX on daily, weekly, monthly, or quarterly schedules - [Settings → IP Locations](https://docs.threataware.com/settings/ip-locations.md): Define public IP locations for accurate device geolocation - [Settings → Timezone](https://docs.threataware.com/settings/timezone.md): Tenant default timezone + region, plus per-user overrides - [Settings → API Access](https://docs.threataware.com/settings/api-access.md): Generate and manage API keys for programmatic access to the Protect API - [Settings → Misc](https://docs.threataware.com/settings/misc.md): Miscellaneous tenant-wide toggles — inactive threshold, default homepage, retention, AI web access, feature flags - [Settings → Audit Log](https://docs.threataware.com/settings/audit-log.md): Every meaningful action in Protect — who did what, when, and from where - [Settings → Schemas](https://docs.threataware.com/settings/schemas.md): The canonical Device and User data schemas — what fields exist, what types, what the AI can see - [Query Syntax Reference](https://docs.threataware.com/reference/query-syntax.md): The complete tested grammar of Protect's query language — every operator, every field path, every value type - [Vitals States Reference](https://docs.threataware.com/reference/vitals-states.md): The four-boolean model behind every Vital — required, deployed, functioning, configuredCorrectly - [Role Permissions Matrix](https://docs.threataware.com/reference/role-permissions.md): Side-by-side comparison of what each default role can do, verified against the live Roles editor - [Keyboard Shortcuts](https://docs.threataware.com/reference/keyboard-shortcuts.md): Confirmed keyboard accelerators in ThreatAware Protect - [Troubleshooting](https://docs.threataware.com/reference/troubleshooting.md): Symptom → cause → fix matrices for every common issue across Protect - [FAQ](https://docs.threataware.com/reference/faq.md): Frequently asked questions across setup, devices, integrations, security, and billing - [Error Codes](https://docs.threataware.com/reference/error-codes.md): Reference for error codes and error messages surfaced across Protect — sync, actions, integration auth, API - [Webhook Payload Reference](https://docs.threataware.com/reference/webhook-payload.md): Outbound webhook payloads from Action automations — headers, body shape, retry behaviour - [Audit Log Events](https://docs.threataware.com/reference/audit-log-events.md): Catalogue of every event that appears in the Protect Audit Log, grouped by category - [Silent Failure](https://docs.threataware.com/silent-failure.md): The category of security failure that's invisible to single-tool consoles — and Protect's signature differentiator - [Glossary](https://docs.threataware.com/reference/glossary.md): Every term Protect uses, defined once — A-Z reference - [Security & Privacy](https://docs.threataware.com/trust/security.md): How Protect protects your data — encryption, isolation, certifications, residency - [Architecture](https://docs.threataware.com/trust/architecture.md): How Protect is built — cloud, isolation, integration patterns, data flow - [Certifications](https://docs.threataware.com/trust/certifications.md): ISO 27001, Cyber Essentials, GDPR — Protect's compliance posture - [Connection Guides](https://docs.threataware.com/connection-guides/index.md): Browse ThreatAware integration guides by category — or use the A-Z list in the sidebar - [Absolute](https://docs.threataware.com/connection-guides/absolute.md): Connect ThreatAware to Absolute to track and monitor managed devices and their security posture - [Action1](https://docs.threataware.com/connection-guides/action1.md): Connect ThreatAware to Action1 to monitor endpoint management and security - [ActZero](https://docs.threataware.com/connection-guides/actzero.md): Connect ThreatAware to ActZero to enhance your cyber asset visibility - [Addigy](https://docs.threataware.com/connection-guides/addigy.md): Connect ThreatAware to Addigy to monitor Mac device management and security - [Admin By Request](https://docs.threataware.com/connection-guides/admin-by-request.md): Connect ThreatAware to Admin By Request for privileged access management visibility - [Atera](https://docs.threataware.com/connection-guides/atera.md): Connect ThreatAware to Atera to track managed devices and security status - [Automox](https://docs.threataware.com/connection-guides/automox.md): Connect ThreatAware to Automox for patch management and endpoint compliance visibility - [AWS EC2 & SSM](https://docs.threataware.com/connection-guides/aws-ec2-ssm.md): Connect ThreatAware to AWS for EC2 instance and Systems Manager monitoring - [Microsoft Azure](https://docs.threataware.com/connection-guides/azure.md): Connect ThreatAware to Microsoft Azure for cloud infrastructure monitoring - [Azure AD](https://docs.threataware.com/connection-guides/azure-ad.md): Connect ThreatAware to Azure AD for enhanced security monitoring and device visibility - [Azure IaaS](https://docs.threataware.com/connection-guides/azure-iaas.md): Connect ThreatAware to Azure IaaS for enhanced security monitoring and device visibility - [BeyondTrust](https://docs.threataware.com/connection-guides/beyondtrust.md): Connect ThreatAware to BeyondTrust to monitor privileged account management and access controls - [BitDefender](https://docs.threataware.com/connection-guides/bitdefender.md): Connect ThreatAware to Bitdefender GravityZone for endpoint protection and threat management - [Carbon Black](https://docs.threataware.com/connection-guides/carbon-black.md): Connect ThreatAware to Carbon Black Cloud for endpoint security and threat detection - [Carbon Black EDR](https://docs.threataware.com/connection-guides/carbon-black-edr.md): Connect ThreatAware to Carbon Black EDR to monitor endpoint security and threat data - [Censornet](https://docs.threataware.com/connection-guides/censornet.md): Connect ThreatAware to Censornet for web filtering and security policy data - [Check Point Harmony](https://docs.threataware.com/connection-guides/checkpoint-harmony.md): Connect ThreatAware to Check Point Harmony to monitor endpoint protection and compliance - [Cisco AMP](https://docs.threataware.com/connection-guides/cisco-amp.md): Connect ThreatAware to Cisco AMP - [Cisco Umbrella](https://docs.threataware.com/connection-guides/cisco-umbrella.md): Connect ThreatAware to Cisco Umbrella to monitor DNS security and web filtering - [CloudFlare Zero Trust](https://docs.threataware.com/connection-guides/cloudflare-zero-trust.md): Connect ThreatAware to CloudFlare Zero Trust to integrate data and enhance your security monitoring capabilities - [Config Manager | SCCM](https://docs.threataware.com/connection-guides/config-manager-sccm.md): Connect ThreatAware to Config Manager | SCCM to track security posture and device inventory - [Connectwise Automate](https://docs.threataware.com/connection-guides/connectwise-automate.md): Connect ThreatAware to Connectwise Automate to enhance your cyber asset visibility - [Cortex XDR](https://docs.threataware.com/connection-guides/cortex-xdr.md): Connect ThreatAware to Cortex XDR to enhance your security posture and threat detection capabilities - [Crowdstrike](https://docs.threataware.com/connection-guides/crowdstrike.md): Connect ThreatAware to Crowdstrike to integrate data and enhance your security monitoring capabilities - [CyberArk](https://docs.threataware.com/connection-guides/cyberark.md): Connect ThreatAware to CyberArk Vault to track privileged account usage and security posture - [Cylance](https://docs.threataware.com/connection-guides/cylance.md): Connect ThreatAware to Cylance to monitor endpoint protection and threat data - [Cynet 360](https://docs.threataware.com/connection-guides/cynet-360.md): Connect ThreatAware to Cynet 360 for endpoint threat detection and response data - [Darktrace](https://docs.threataware.com/connection-guides/darktrace.md): Connect ThreatAware to Darktrace for enhanced security monitoring and device visibility - [Darktrace Agent](https://docs.threataware.com/connection-guides/darktrace-agent.md): Connect ThreatAware to Darktrace Agent to monitor network security and anomalies - [Darktrace EDR](https://docs.threataware.com/connection-guides/darktrace-edr.md): Connect ThreatAware to Darktrace EDR to enhance your security posture and threat detection capabilities - [Darktrace XDR](https://docs.threataware.com/connection-guides/darktrace-xdr.md): Connect ThreatAware to Darktrace to monitor AI-driven threat detection and incident response - [Dark Web ID](https://docs.threataware.com/connection-guides/dark-web-id.md): Connect ThreatAware to Dark Web ID to track security posture and device inventory - [Datto Autotask PSA](https://docs.threataware.com/connection-guides/datto-autotask-psa.md): Connect ThreatAware to Datto Autotask PSA to sync project and account data for enhanced asset management - [Datto RMM](https://docs.threataware.com/connection-guides/datto-rmm.md): Connect ThreatAware to Datto RMM for remote IT management and device monitoring - [Device42](https://docs.threataware.com/connection-guides/device42.md): Connect ThreatAware to Device42 for asset discovery and inventory management data - [DNS Filter](https://docs.threataware.com/connection-guides/dns-filter.md): Connect ThreatAware to DNS Filter for DNS security and filtering data - [Dropbox](https://docs.threataware.com/connection-guides/dropbox.md): Connect ThreatAware to Dropbox to track security posture and device inventory - [Druva Cloud Platform](https://docs.threataware.com/connection-guides/druva.md): Connect ThreatAware to Druva Cloud Platform to monitor data protection and compliance - [Duo](https://docs.threataware.com/connection-guides/duo.md): Connect ThreatAware to Duo to monitor authentication events and security controls - [Edgescan](https://docs.threataware.com/connection-guides/edgescan.md): Connect ThreatAware to Edgescan to monitor vulnerability assessments and security scanning - [Entra AD](https://docs.threataware.com/connection-guides/entrad.md): Connect ThreatAware to Entra AD to monitor directory services and enterprise applications - [ESET](https://docs.threataware.com/connection-guides/eset.md): Connect ThreatAware to ESET to monitor endpoint security and threat detection - [ESET Cloud](https://docs.threataware.com/connection-guides/eset-cloud.md): Connect ThreatAware to ESET PROTECT Cloud to monitor endpoint security and threat detection - [ESET OnPrem](https://docs.threataware.com/connection-guides/eset-onprem.md): Connect ThreatAware to ESET OnPrem to monitor endpoint security and threat detection - [F-Secure PSB](https://docs.threataware.com/connection-guides/f-secure-psb.md): Connect ThreatAware to F-Secure Protection Service for Business to monitor endpoint security - [FireFly](https://docs.threataware.com/connection-guides/firefly.md): ### Authorization/Setup Steps 1 - [Freshservice](https://docs.threataware.com/connection-guides/freshservice.md): Connect ThreatAware to Freshservice to sync IT service management and support data - [Google Devices](https://docs.threataware.com/connection-guides/google-devices.md): Connect ThreatAware to Google Workspace to inventory and monitor your Google-managed devices - [Google Users](https://docs.threataware.com/connection-guides/google-users.md): Connect ThreatAware to Google Cloud to monitor cloud infrastructure and instances - [GoTo Assist](https://docs.threataware.com/connection-guides/goto-assist.md): Connect ThreatAware to GoTo Assist for remote support monitoring and control - [Guardicore](https://docs.threataware.com/connection-guides/guardicore.md): Connect ThreatAware to Guardicore to integrate data and enhance your security monitoring capabilities - [Guardicore Assets](https://docs.threataware.com/connection-guides/guardicore-assets.md): Connect ThreatAware to Guardicore Assets to monitor asset discovery and segmentation posture - [Halo Service Desk](https://docs.threataware.com/connection-guides/halo-service-desk.md): Connect ThreatAware to Halo Service Desk to sync ticket and asset data for IT service management - [Heimdal](https://docs.threataware.com/connection-guides/heimdal.md): Connect ThreatAware to Heimdal Security to monitor endpoint threats and security events - [Huntress](https://docs.threataware.com/connection-guides/huntress.md): Connect ThreatAware to Huntress to monitor endpoint detection and response - [IBM QRadar](https://docs.threataware.com/connection-guides/ibm-qradar.md): Connect ThreatAware to IBM QRadar for enhanced security monitoring and device visibility - [Illumio](https://docs.threataware.com/connection-guides/illumio.md): Connect ThreatAware to Illumio PCE to monitor zero trust segmentation and policy compliance - [ISL Online](https://docs.threataware.com/connection-guides/isl-online.md): Connect ThreatAware to ISL Online for remote access and support monitoring - [Ivanti Security Controls](https://docs.threataware.com/connection-guides/ivanti-security-controls.md): Connect ThreatAware to Ivanti Security Controls to monitor endpoint protection and compliance - [Jamf](https://docs.threataware.com/connection-guides/jamf.md): Connect ThreatAware to Jamf Pro to monitor macOS and iOS device inventory and compliance - [Jamf Protect](https://docs.threataware.com/connection-guides/jamf-protect.md): Connect ThreatAware to Jamf Protect to monitor Apple device security and compliance - [JumpCloud](https://docs.threataware.com/connection-guides/jumpcloud.md): Connect ThreatAware to JumpCloud to track security posture and device inventory - [Kandji](https://docs.threataware.com/connection-guides/kandji.md): Connect ThreatAware to Kandji - [KnowBe4](https://docs.threataware.com/connection-guides/knowbe4.md): Connect ThreatAware to KnowBe4 to monitor security awareness training and phishing simulations - [UKG (Kronos)](https://docs.threataware.com/connection-guides/kronos.md): Connect ThreatAware to UKG to monitor workforce management and access control compliance - [Lansweeper](https://docs.threataware.com/connection-guides/lansweeper.md): Connect ThreatAware to Lansweeper for asset discovery and inventory management - [MaaS360](https://docs.threataware.com/connection-guides/maas360.md): Connect ThreatAware to MaaS360 - [Malwarebytes](https://docs.threataware.com/connection-guides/malwarebytes.md): Connect ThreatAware to Malwarebytes Nebula for endpoint threat detection and remediation - [Malware Bytes OneView](https://docs.threataware.com/connection-guides/malware-bytes-oneview.md): Connect ThreatAware to Malware Bytes OneView - [ManageEngine Patch](https://docs.threataware.com/connection-guides/manageengine-patch.md): Connect ThreatAware to ManageEngine Patch Manager to track patch deployment and update compliance - [McAfee MVISION](https://docs.threataware.com/connection-guides/mcafee-mvision.md): Connect ThreatAware to McAfee MVISION to track security posture and device inventory - [McAfee MVISION Cloud](https://docs.threataware.com/connection-guides/mcafee-mvision-cloud.md): Connect ThreatAware to McAfee MVISION Cloud to track security posture and device inventory - [Meraki Firewall](https://docs.threataware.com/connection-guides/meraki-firewall.md): Connect ThreatAware to Cisco Meraki Firewall to monitor network security and device communications - [Microsoft 365](https://docs.threataware.com/connection-guides/microsoft-365.md): Connect ThreatAware to Microsoft 365 to enhance your security posture and threat detection capabilities - [Microsoft Defender ATP](https://docs.threataware.com/connection-guides/microsoft-defender-atp.md): Connect ThreatAware to Microsoft Defender ATP - [Microsoft Entra AD](https://docs.threataware.com/connection-guides/microsoft-entra.md): Connect ThreatAware to Microsoft Entra AD to monitor identity and access management - [Microsoft GraphAPI Required Permissions](https://docs.threataware.com/connection-guides/microsoft-graphapi-required-permissions.md): Connect ThreatAware to Microsoft GraphAPI Required Permissions for enhanced security monitoring and asset tracking - [Microsoft Office 365](https://docs.threataware.com/connection-guides/microsoft-intune.md): Connect ThreatAware to Microsoft Intune and Office 365 for identity and device management - [N-Central](https://docs.threataware.com/connection-guides/n-central.md): Connect ThreatAware to N-Central for remote monitoring and management visibility - [Netskope](https://docs.threataware.com/connection-guides/netskope.md): Connect ThreatAware to Netskope to enhance your cyber asset visibility - [Nexthink](https://docs.threataware.com/connection-guides/nexthink.md): Connect ThreatAware to Nexthink for enhanced security monitoring and asset tracking - [Ninja RMM](https://docs.threataware.com/connection-guides/ninja-rmm.md): Connect ThreatAware to Ninja RMM for remote management and device monitoring - [ObserveIT](https://docs.threataware.com/connection-guides/observeit.md): Connect ThreatAware to ObserveIT to track security posture and device inventory - [Okta](https://docs.threataware.com/connection-guides/okta.md): Connect ThreatAware to Okta to enhance your cyber asset visibility - [OneLogin](https://docs.threataware.com/connection-guides/onelogin.md): Connect ThreatAware to OneLogin for identity and access management visibility - [Panda Security](https://docs.threataware.com/connection-guides/panda.md): Connect ThreatAware to Panda Security to monitor endpoint security and threat status - [Portnox Clear](https://docs.threataware.com/connection-guides/portnox-clear.md): Connect ThreatAware to Portnox Clear to integrate data and enhance your security monitoring capabilities - [Qualys VM](https://docs.threataware.com/connection-guides/qualys-vm.md): Connect ThreatAware to Qualys VM to integrate data and enhance your security monitoring capabilities - [Rapid7](https://docs.threataware.com/connection-guides/rapid7.md): Connect ThreatAware to Rapid7 InsightIDR for security monitoring and threat detection data - [Rapid7 InsightVM](https://docs.threataware.com/connection-guides/rapid7-insightvm.md): Connect ThreatAware to Rapid7 InsightVM for enhanced security monitoring and device visibility - [RealVNC](https://docs.threataware.com/connection-guides/realvnc.md): Connect ThreatAware to RealVNC for remote access device management and monitoring - [SCCM](https://docs.threataware.com/connection-guides/sccm.md): Connect ThreatAware to SCCM - [SentinelOne](https://docs.threataware.com/connection-guides/sentinel-one.md): Connect ThreatAware to SentinelOne for endpoint protection and threat visibility - [ServiceNow](https://docs.threataware.com/connection-guides/servicenow.md): Connect ThreatAware to ServiceNow to sync IT assets and incident management data - [Snow](https://docs.threataware.com/connection-guides/snow.md): Connect ThreatAware to Snow for software asset management and license tracking - [SonicWall Capture Client](https://docs.threataware.com/connection-guides/sonicwall-capture-client.md): Connect ThreatAware to SonicWall Capture Client for endpoint protection and threat management - [Sophos](https://docs.threataware.com/connection-guides/sophos.md): Connect ThreatAware to Sophos to enhance your security posture and threat detection capabilities - [Symantec](https://docs.threataware.com/connection-guides/symantec.md): Connect ThreatAware to Symantec to integrate data and enhance your security monitoring capabilities - [Symantec Endpoint Protection](https://docs.threataware.com/connection-guides/symantec-endpoint-protection.md): Connect ThreatAware to Symantec Endpoint Protection to integrate data and enhance your security monitoring capabilities - [Symantec Endpoint Protection Manager](https://docs.threataware.com/connection-guides/symantec-sepm.md): Connect ThreatAware to Symantec Endpoint Protection Manager (SEPM) for on-premises endpoint protection monitoring - [Syxsense](https://docs.threataware.com/connection-guides/syxsense.md): Connect ThreatAware to Syxsense to monitor endpoint security and vulnerability management - [Tanium](https://docs.threataware.com/connection-guides/tanium.md): Connect ThreatAware to Tanium to integrate data and enhance your security monitoring capabilities - [TeamViewer](https://docs.threataware.com/connection-guides/teamviewer.md): Connect ThreatAware to TeamViewer to monitor remote access and device management - [Tenable IO](https://docs.threataware.com/connection-guides/tenable-io.md): **Tenable IO Connection Guide** **Connect Tenable IO** 1 - [Tenable Nessus](https://docs.threataware.com/connection-guides/tenable-nessus.md): Connect ThreatAware to Tenable Nessus for vulnerability scanning and assessment data - [ThreatLocker](https://docs.threataware.com/connection-guides/threatlocker.md): Connect ThreatAware to ThreatLocker to enhance your cyber asset visibility - [Trend Micro Apex One](https://docs.threataware.com/connection-guides/trend-micro-apex-one.md): Connect ThreatAware to Trend Micro Apex One for endpoint protection and threat detection - [API Reference](https://docs.threataware.com/api-reference/introduction.md): Programmatic access to ThreatAware platform - [Get Users](https://docs.threataware.com/api-reference/users.md): Retrieve all user data that has been collected from your integrations - [Get Inventory](https://docs.threataware.com/api-reference/inventory.md): Retrieve specific integration data and filter by type - [Get Devices](https://docs.threataware.com/api-reference/devices.md): Access all your data related to your environment's devices - [Get Alerts](https://docs.threataware.com/api-reference/alerts.md): Request a list of all alerts throughout your entire environment - [Get Vitals](https://docs.threataware.com/api-reference/vitals.md): Retrieve security control health status across all integrations - [Get Portal Users](https://docs.threataware.com/api-reference/settings-users.md): Retrieve data for all users registered on the ThreatAware platform - [Get Roles](https://docs.threataware.com/api-reference/settings-roles.md): Retrieve data for all roles registered on the platform - [Get Teams](https://docs.threataware.com/api-reference/settings-teams.md): Retrieve data for all teams registered on the platform ## OpenAPI Specs - [openapi](https://docs.threataware.com/api-reference/openapi.json) ## Optional - [Website](https://threataware.com) - [Insights](https://threataware.com/insights)