GUS Add-ons

Bolt on the platforms you already run.

Each add-on is a standalone, single-binary connector to one security platform. You bring the vendor license and credentials; GUS gains read access to triage with, and gated write access for response. Enable only what you use — every connected platform feeds the same triage loop and the same fleet memory.

Request access → How GUS triages
The catalog

Eleven connectors, one investigation.

Whatever GUS learns through one add-on — a verdict, an IOC, a host's history — is available to every other. The catalog below is the sensor mesh; the cross-correlation is the product.

Memory
Knowledge graph

The temporal, self-correcting memory every other add-on writes into.

EDR
SentinelOne

Threats, agents, and gated response actions — OT-tag guarded.

NDR
Darktrace

Model breaches, device detail, AI Analyst incidents.

SIEM / UEBA
Gurucul

Cases, anomalies, high-risk users, Windows/AD attack detection.

OT / ICS
Dragos

OT assets, zones, vulnerabilities, and notifications.

Firewall
Cisco FMC

Devices, access policies, objects — with double-gated deploys.

Threat intel
Recorded Future

IP, domain, hash, URL, and CVE enrichment on every IOC.

Exposure
Zafran

Findings and mitigations across your attack surface.

App control
ThreatLocker

Application-control posture and deny events.

Email security
Abnormal

Threats, cases, abuse campaigns, and gated remediation.

PAM
BeyondTrust

Managed accounts and secrets — retrieved to the OS keychain, never exposed.

Bring your own vendor license · read-first, writes gated · single binary, stdio only, no open ports.

Get started

Point GUS at your stack. Keep your guardrails.

Limited access for security teams working across IT and OT.

Request access → How it works

heygusai.io · info@heygusai.io