Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Live integration

Connect Datadog to RansomLeak

Turn a Datadog detection into coaching for the person involved, and stream training and human-risk events into Datadog. A detection becomes an assigned lesson through a Workflow action, and the response includes coaching, not just another alert.

Last updated September 2026

Overview

The Datadog integration runs in two directions. A Datadog detection can assign a RansomLeak exercise to the people involved, so the response includes coaching. And training and human-risk events stream into Datadog, so awareness data sits alongside the signals you already watch.

The two halves are independent. Run either on its own, or both together:

  • A detection assigns a lesson, via a Workflow action
  • Training events stream in as logs and metrics
  • Failures as high-signal events, plus hourly risk gauges
  • Coaching assigned within about a minute

Turn a detection into coaching

When a detection fires on risky user activity, a Datadog Workflow action calls RansomLeak and assigns the matching exercise to the person involved. It uses the assignment API, so it fits the detection rules and playbooks you already maintain. No agent on your side does the work; the coaching is a downstream step in the workflow.

  1. In RansomLeak, go to Admin → Integrations and generate an API token for the assignment API.

  2. In Datadog, add a Workflow Automation with an HTTP Send POST request action that calls RansomLeak's assignment endpoint, with the token as a Bearer header.

  3. Map the request body to the signal: the exercise to assign and the affected user's email. RansomLeak resolves the person and assigns the module within about a minute.

The same assignment endpoint powers our service-desk and SOAR integrations, so a Datadog detection, a Jira ticket, or a SOAR playbook can all end the same way: a short lesson for the person involved, and a completion you can act on.

Stream training events to Datadog

Install the RansomLeak integration from Datadog and approve access once. RansomLeak creates one API key in your Datadog org and uses it only to send training and human-risk data, as logs, metrics, and events tagged by tenant.

  1. In Datadog, open Integrations, find RansomLeak, and click Connect Accounts. Enter your RansomLeak subdomain and sign in.

  2. Approve access in Datadog. You land back on Admin → Integrations → Datadog in RansomLeak, which shows Connected.

  3. Open the RansomLeak Overview dashboard in Datadog. Hourly metrics arrive straight away; logs arrive as people complete training.

You can also start in RansomLeak: choose your Datadog site and select Connect with Datadog. If you prefer not to use OAuth, select Use an API key instead and paste a Datadog API key.

Data How it arrives
Training completedLog and count metric, as it happens.
Training failedLog, count metric, and a high-signal event you can alert on.
Learning path completedLog, count metric, and an event.
Enrollments, completion rate, overdue users, team risk scoreHourly metrics under ransomleak.*, for the dashboard and monitors.

How it fits together

The two directions close a loop. A detection in Datadog can trigger coaching, and the result of that coaching streams back into Datadog as data you can watch and alert on.

  • Detection fires on a named user
  • A lesson is assigned to that user
  • Completion streams back to Datadog

Training and human-risk events also reach any SIEM through the same export and webhooks, so the awareness data is not locked to Datadog. See the integrations overview for the full set of destinations.

Permissions and data handling

The event stream asks Datadog for one permission: to create an API key in your org. RansomLeak stores that key encrypted and uses it only to send data. The detection-to-coaching loop uses a RansomLeak API token your Workflow holds.

  • API keys and tokens encrypted at rest
  • User IDs and outcomes only, no names, emails or training content
  • Uninstall or disconnect stops the stream

Disconnecting in RansomLeak revokes our access. Datadog doesn't let integrations delete their own key, so revoke the RansomLeak key under Organization Settings → API Keys afterwards. Uninstalling the tile in Datadog also revokes access. For how RansomLeak handles data, see the privacy policy and the security and compliance page.

Frequently asked questions

Does RansomLeak integrate with Datadog?

Yes, both ways. A Datadog detection can assign a RansomLeak exercise to the people involved through a Workflow action, and training and human-risk events stream into Datadog so they sit in the dashboards and monitors your SOC already watches.

How does a Datadog detection assign training?

You add a Datadog Workflow Automation with an HTTP "Send POST request" action that calls RansomLeak's assignment API with an API token. The action passes the exercise and the user, by email, from the signal, and RansomLeak assigns the matching module within about a minute. You build it on the detection rules and playbooks you already run.

What training data streams into Datadog?

Every completed or failed exercise arrives as a log (source:ransomleak) and a count metric, failures and finished learning paths also as events, and every hour RansomLeak sends enrollments by status, completion rate, overdue users and the Human Risk Score per team. The RansomLeak Overview dashboard and monitors ship with the integration.

What do I need to set this up?

For the event stream, install the RansomLeak tile in Datadog and approve access (or paste a Datadog API key instead). For the detection-to-coaching loop, a RansomLeak API token that your Datadog Workflow action uses to call the assignment API. The two are independent, so you can run either or both.

Does completion write back to Datadog?

Training and human-risk events stream into Datadog continuously, so a completion shows up there on its own. If your Workflow passes a callback, RansomLeak also posts the result back when the exercise finishes, so the playbook can act on it.

Is the detection-to-coaching loop a one-click feature?

No, and that is deliberate. The outbound event stream is a one-click connection from the Datadog tile. The detection-to-coaching loop is a Datadog Workflow you configure against RansomLeak's assignment API, the same open endpoint our service-desk and SOAR integrations use, so it fits the playbooks you already maintain.

Next guide Assign from Jira Service Management The same idea for your service desk: a ticket becomes an assigned lesson for the person involved.

Need a hand?

Email support@ransomleak.com and we will help you connect Datadog to your tenant.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.