Case Management Integrations
Integrating a Case Management tool with TruSTAR provides the ability to enrich data in TruSTAR and then return that enriched data to the tool as well as share it with other teams in your organization.
Related Link: Partner Resources explains configuration details required for all integrations.
Recommended Functionality
Case Management integrations focus on working with reports (or events). TruSTAR recommends including these commands in your integration:
- Submit a Report
- Enrich Observables in a Report using Get Indicator Summaries or Get Indicator Metadata. You can also filter Observables using these commands.
- Copy a report to another Enclave. As part of sharing a report, you can choose to redact terms in the report using the Company Safelist stored in TruSTAR.
- Move a report to another Enclave. As part of sharing a report, you can choose to redact terms in the report using the Company Safelist stored in TruSTAR.
- Add Indicators to Company Safelist
Optional Functionality
You can use these commands to add functionality for Indicators:
You can include two additional commands that support the triage of Phishing emails: