Skip to content

Integrations Overview

WebDecoy integrates with popular security and DevOps tools to automate responses to detected threats. When a detection occurs, integrations can automatically block attackers, send notifications, or forward events to your security stack.

IntegrationTypeCapability
AWS WAFWAFAutomatic IP blocking
CloudflareWAFAutomatic IP blocking
CrowdStrikeSIEMFalcon LogScale event forwarding
DatadogSIEMEvent forwarding
FastlyCDN/WAFAutomatic IP blocking via ACLs
SlackNotificationReal-time alerts
VercelEdgeEdge middleware + auto blocking
WebhooksCustomSend events to any URL
Detection Created
Integration Rules Evaluated
├── AWS WAF → Block IP in WAF
├── Cloudflare → Block IP in WAF
├── CrowdStrike → Forward to Falcon LogScale
├── Datadog → Forward event
├── Fastly → Block IP via ACL
├── Slack → Send alert to channel
├── Vercel → Block IP at Edge + Edge Config
└── Webhook → POST to your endpoint
FeatureAWS WAFCloudflareCrowdStrikeDatadogFastlySlackVercelWebhooks
Auto-block IPs
Edge Detection
Notifications
Custom processing
Event forwarding
Dashboards
SIEM Integration

For basic automated protection:

  1. Cloudflare or AWS WAF - Block malicious IPs
  2. Slack - Get notified of high-risk detections

For comprehensive monitoring:

  1. Cloudflare - Automatic IP blocking
  2. Slack - Real-time team notifications
  3. CrowdStrike or Datadog - SIEM dashboards and alerting
  4. Webhooks - Custom automation
  1. Click Integrations in the sidebar
  2. View all available integration types
  3. See count of active integrations per type
  4. Click any integration to configure
  • ✅ Test integrations before relying on them
  • ✅ Start with notifications before automatic blocking
  • ✅ Set appropriate score thresholds
  • ✅ Monitor for false positives
  • ✅ Keep API credentials secure
  • ✅ Use dedicated API keys/tokens per integration
  • ✅ Start with high score threshold (75+)
  • ✅ Set reasonable block durations (24h default)
  • ✅ Monitor blocked IP list regularly
  • ✅ Have a process for unblocking false positives
  • ✅ Use “high risk only” to reduce noise
  • ✅ Create dedicated channels for alerts
  • ✅ Set up escalation for critical threats

Choose an integration to set up:

  • Cloudflare - Most popular WAF integration
  • CrowdStrike - Falcon LogScale SIEM integration
  • Fastly - Edge CDN with ACL-based blocking
  • Slack - Quick notification setup
  • Webhooks - Custom event processing