Alerts by ATT&CK tactic
Group detections by MITRE technique and see which ones actually fire in your estate.
Infrastructure metrics, logs and monitors. Correlate alerts and telemetry with intelligence feeds and assets, and cut the noise your analysts wade through.
Live demo workspace with fictional data · no signup, no credentials needed

Datadog on its own answers half the question. Joined with the rest of your stack in Kimo, it answers the other half.
Group detections by MITRE technique and see which ones actually fire in your estate.
Measure detection and response times per team, severity and asset criticality.
Correlate indicators from alerts with OSINT and threat feeds in one view.
Kimo maps Datadog into clean, typed tables with primary keys and incremental cursors, so syncs stay fast and joins just work.
| Field | Type | Notes |
|---|---|---|
| ts | timestamp | Incremental cursor |
| metric | string | |
| host | string | |
| value | decimal | Measure |
| tags | json | Nested · flattened on demand |
A starter model Kimo suggests the moment Datadog is connected. Every join is editable.
Events and alerts joined with assets and threat intelligence on host and indicator.

Fictional data · hover the chart for daily values
No engineers, no pipelines to maintain. Kimo asks for the minimum access it needs and tells you exactly what it will read.
Use a dedicated key scoped to read access, so it can be rotated independently.
Keys are encrypted with a per-workspace key and never shown again.
Pick which objects to sync, starting with metrics.
Kimo tests the key, backfills history and keeps it fresh (real time).
Read-only, encrypted, revocable. Credentials are encrypted with a per-workspace key, never logged, and can be rotated without breaking your models.
Datadog is ingested as a stream. New records typically appear in models and maps within a few seconds.
Try it on the live demo workspace first, then connect your own account when you are ready.