惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 【当耐特】
小众软件
小众软件
S
SegmentFault 最新的问题
GbyAI
GbyAI
量子位
爱范儿
爱范儿
L
LangChain Blog
Vercel News
Vercel News
A
About on SuperTechFans
腾讯CDC
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
月光博客
月光博客
博客园 - 聂微东
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
V
Visual Studio Blog
美团技术团队
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium

Socket

Fake Corepack Site Distributes Infostealer and Proxyware to ... Large-Scale GitHub Actions Abuse Powers a Distributed cPanel... New Study Identifies 53 Slopsquatting Targets Across 5 Front... White House Launches Gold Eagle Initiative to Manage Surge i... Suno Breached via Shai-Hulud Worm, Leaked Code Exposes AI Mu... Next.js moves to scheduled security releases - Socket 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windo... Compromised npm Packages in the AsyncAPI Namespace Deliver M... jscrambler npm Package Compromised in Supply Chain Attack - ... Fake Braintree NuGet Package Skims Credit Cards and Harvests... Compromised Injective SDK npm Package Exfiltrates Wallet Key... npm v12 Ships With Install Scripts Off by Default, Begins De... Malicious Go Module Exposes GitHub Malware Lure Network Span... pnpm 11.10 Hardens Registry Authentication to Block Token Re... Coordinated npm and PyPI Campaign Typosquats Popular Secure ... Node.js Considers Public Workflow for Security Reports Amid ... PolinRider: North Korea-Linked Supply Chain Campaign Expands... Risky Biz Podcast: AI Agents Are Raising the Stakes for Soft... Chrome and Firefox Extensions Posing as Free VPNs Add Clipbo... Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages - S... Rolldown Pulls Rust React Compiler Integration After Binary ... Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and Git... Frontier AI Is Now Critical Infrastructure - Socket The Code You Didn't Write Is Still Yours to Defend - Socket GitHub Actions Checkout Now Blocks Risky pull_request_target... Introducing Repository Access Permissions and Custom Roles -... Socket MCP Adds Org Alerts, Threat Feed Review, and Package ... Socket Firewall Now Blocks Malicious VS Code and Open VSX Ex... 140+ Mastra npm Packages Compromised in Coordinated Supply C... npm Package Uses Prompt Injection and Token Flooding to Disr...
Introducing Data Exports
Ola Adekola · 2026-04-24 · via Socket

Sidebar CTA Background

Secure your dependencies with us

Socket proactively blocks malicious open source packages in your code.

Install

Security teams often need alert data in their own infrastructure, alongside the rest of their security telemetry. We're excited to share that Socket alert data can now flow directly into your own cloud storage.

Today we're launching Data Exports, a new integration that automatically writes alert changes from Socket to a bucket you own in AWS S3, Google Cloud Storage, or Azure Blob Storage.

Data Exports lets you to choose the format that fits your downstream systems, and decide whether you want a full snapshot or only the changes since the last run.

Some teams need a durable archive of alert data in their own environment. Others need an easy path into internal pipelines, analytics workflows, or SIEM tooling that already ingests from object storage. Data Exports makes that possible without forcing you into a single destination or workflow.

Move Socket Alert Data Into the Systems You Already Use#

For many security teams, the hardest part of security operations is not generating findings. It is operationalizing them.

Data Exports helps bridge that gap by sending alert data directly to your cloud buckets. From there, you can retain the data on your own terms, feed it into internal analytics jobs, or make it available to tools that already pull from object storage.

Instead of starting with one narrow destination, we built a generic export path that works across the major cloud storage providers and supports common data formats. That gives you something useful immediately while creating a path for deeper integrations over time.

Designed to Fit Existing Cloud Environments#

Data Exports gives you a few key choices:

  • Provider: AWS S3, Google Cloud Storage, or Azure Blob Storage
  • Format: JSON, CSV, or Parquet
  • Mode: Full Snapshot or Incremental

Each provider uses the authentication model your team would expect for that environment. You provide the destination details and credentials for your chosen provider, and Socket handles the export flow from there.

Security programs rarely look identical across organizations. Some teams standardize on AWS. Others live in Google Cloud or Azure. Many already have internal retention, analytics, or ingestion patterns built around cloud storage.

Instead of asking you to adopt a new storage pattern just to get Socket alert data out, Data Exports lets you shape exports around the workflows you already have.

Here are the available export modes and formats:

  • Full Snapshot: A complete view of current alert data on every run
  • Incremental: A lighter-weight feed of what changed since the previous export
  • Parquet: Structured, analytics-friendly storage for downstream processing
  • JSON or CSV: Easy to inspect or move through existing ingestion pipelines

Easy to Configure Without Becoming a Project#

Data Exports is designed to be simple to set up. From the Data Export settings page, you can create a new integration, choose your cloud provider, enter your bucket details, add provider-specific credentials, pick an export format, and choose an export mode.

Socket also includes a Test Integration action so you can verify that the destination and credentials are correct before relying on scheduled exports.

After a successful test, Socket writes a test file to the destination bucket so you can confirm the connection end to end.

Exports are written on a daily cadence. Files are organized under a predictable path structure so they are easy to find and manage in downstream storage workflows.

base_path/socket-alerts/Y-M-D/org_slug_date_mode.file_type

That makes it easier to automate around exports, whether you are applying storage lifecycle policies, triggering ingestion jobs, or keeping an archive of alert data over time.

A Flexible Base for SIEM Integrations#

Data Exports is designed for customer-managed destinations where you control how exported data is retained on your side.

Starting with generic bucket exports gives you the immediate flexibility while aligning with how many SIEM and data platforms already ingest data from object storage. It also creates a foundation Socket can build on for more destination-specific SIEM integrations in the future.

Data Exports is available today on Enterprise plans. We'd love to hear from teams using this in production. If you have feedback on the export format, additional data you want included, or a SIEM platform you'd like us to prioritize, get in touch.