IT Brief India - Technology news for CIOs & IT decision-makers
India
Dashlane expands SIEM integrations with browser telemetry

Dashlane expands SIEM integrations with browser telemetry

Wed, 7th Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Dashlane has expanded SIEM integrations for its Omnix product to include Panther SIEM, Datadog Cloud SIEM and CrowdStrike Falcon Next-Gen SIEM, extending existing links with Microsoft Sentinel and Splunk.

The move is intended to bring browser-based credential telemetry into the security information and event management platforms many security operations teams already use. The integrations feed data such as at-risk credential use and visits to suspected phishing domains into those systems without requiring a separate console.

Security teams commonly rely on identity providers, endpoint detection and response tools, cloud monitoring products and log aggregation systems to detect threats. Yet those systems often do not show what happens inside a web browser, where employees enter passwords, log into software services and encounter phishing pages.

That browser gap has become more significant as staff use a growing number of sanctioned and unsanctioned software tools during the working day. Dashlane said some credential-related activity may not be captured by the wider security stack, particularly when users are not logged into a password manager or when logins take place outside approved single sign-on systems.

The blind spot

Dashlane argued that three issues recur for security teams. First, browser-based credential risk does not usually reach the SIEM because identity and endpoint tools do not generate that data. Second, shadow IT and unmanaged software-as-a-service logins may go untracked, leaving no record in the SIEM. Third, credential information often sits in a separate password management environment, forcing analysts to piece together incidents manually.

Omnix captures credential-related events in the browser as they happen, whether or not single sign-on or a password vault is in use, according to Dashlane. Those signals can then be correlated with identity, endpoint, network, cloud and observability data already collected by the SIEM.

The approach reflects a broader shift in security operations towards consolidating more data types into existing monitoring and response workflows. Many security teams have tried to reduce the number of separate dashboards analysts must check during an incident, both to speed response times and cut the complexity of investigations.

Added platforms

The new integrations cover three established names in the security monitoring market. Panther is known for cloud-native security operations and detection engineering. Datadog Cloud SIEM is part of Datadog's broader observability and monitoring platform. CrowdStrike Falcon Next-Gen SIEM extends CrowdStrike's presence from endpoint security into log management and security analytics.

By adding those products, Dashlane is broadening the range of SIEM environments into which its browser-based telemetry can flow. That gives organisations a more consistent workflow across different security stacks, rather than requiring teams to switch to a separate tool to review credential risk, the company said.

One use case highlighted by Dashlane is phishing. Omnix uses an AI phishing model to assess suspicious websites before credentials are entered and then alerts employees, according to the company. The resulting events can then be shown directly within the SIEM used by the security team.

Dashlane also said the integrations can shorten the time needed to identify credential-related threats. Issues that previously took days or weeks to uncover can instead be detected in seconds when browser telemetry is available alongside other operational and security data, it argued.

That claim points to a longstanding problem for security operations centres. When relevant evidence is split between password tools, identity systems, endpoint logs and cloud services, analysts often spend significant time correlating timelines and confirming whether a user's credentials were exposed, weak, reused or entered into a malicious site.

A statistic cited by the company underlines the visibility challenge around risky password behaviour. Dashlane said that when an employee uses a risky password, there is a 53% chance that person is not logged into their password manager, meaning the broader security stack may not register the activity.

Market context

The expansion also reflects the growing importance of credential security in security operations. Credentials remain one of the most common routes into corporate systems, whether through phishing, password reuse or weak password practices. At the same time, browser-based work has become central to how employees access business applications, making the browser a key point of exposure.

For vendors in password management and security awareness, that has created an opportunity to position browser telemetry as a missing source of operational security data. SIEM vendors, meanwhile, have been trying to ingest and correlate a broader mix of signals as customers demand faster detection and response within existing workflows.

Dashlane said browser-native credential telemetry is becoming a standard signal in the modern security operations centre, much as endpoint detection and identity logs have become routine parts of monitoring and investigation.