Install: TruSTAR for Demisto
This document explains how to install and configure the TruSTAR Workflow App v2 for Demisto.
This App automatically sends triggered playbook tasks to TruSTAR for enrichment, and then sends TruSTAR information back to Demisto. You can search Indicators directly from Demisto to get relevant data throughout every step of your workflow.
Time to Install: 15-30 minutes for installation from the Demisto marketplace.
- Submit Demisto cases to your TruSTAR enclave. The link to the TruSTAR Intel Report is automatically added to the open Demisto case.
- Enrich intelligence in Demisto cases by querying TruSTAR Enclaves for Intel Reports or Indicators.
- Create playbooks to automate intelligence gathering, using TruSTAR API calls. You can also use those API calls in the Demisto War Room.
The following components must be installed and activated to use the TruSTAR App:
- Demisto Server v5.0 or greater (more info here)
- Demisto Agent (D2) (more info here)
- Demisto Engine (more info here)
- Content package 20.7.0
Installing the App
- Login to your Demisto installation.
- Select Settings -> Integrations ->Servers and Services and type TruSTAR v2 in the search integration text box.
- Click Add Instance to install the App. You now see a Configuration dialog box.
- Enter the parameters explained in the table below.
TruSTAR API URL. Enter https://api.trustar.co\
TruSTAR Station URL. Enter https://station.trustar.co
TruSTAR API Key Finding Your API Keys
TruSTAR API Secret Key Finding Your API Keys
Trust any certificate.
Use system proxy settings.
- When you have finished entering the configuration parameters, click Test to check connectivity with TruSTAR.