Filter Indicators from TruSTAR
TruSTAR offers two API commands to search TruSTAR Enclaves for Indicators using filter conditions, such as Indicator type, Enclave, or tags, and then return that information to the external tool.
Get Indicator Metadata
Description: Provide metadata associated with an indicator, including type, value, priority level, count, sightings, first seen, last seen, Enclave IDs, and tags.
Get Indicator Summaries
Description: Provides structured summaries about indicators, which are derived from intelligence sources on the TruSTAR Marketplace that the user has access to.
The integration must include a configuration page where the user can define the following:
- Indicator types to ingest. TruSTAR's list of supported types
- Filter criteria:
- Indicator Type
- Source or Enclave ID
- Time parameter for how long to keep Indicator in the external tool