This document explains how to install and configure the TruSTAR v2 Workflow App for Demisto.
The TruSTAR Workflow App for Demisto automatically sends triggered playbook tasks to TruSTAR for enrichment, and then sends back linked information to Demisto. You can search Indicators directly from Demisto to get relevant data throughout every step of your workflow.
Time to Install: 15-30 minutes for installation from the Demisto marketplace.
- Submit open cases in Demisto to your TruSTAR enclave. The link to the TruSTAR Intel Report is automatically added to the Demisto case.
- Enrich intelligence in open Demisto cases by querying TruSTAR Enclaves.
- Create playbooks to automate intelligence gathering, using TruSTAR API calls. You can also use those API calls in Demisto's War Room.
The following requirements and components need to be installed and activated for TruSTAR integration to work with Demisto
- Demisto Server v3.6 to 4.0 (more info here)
- Demisto Agent (D2) (more info here)
- Demisto Engine (more info here)
Installing and Configuring the TruSTAR Workflow App
- Login to your Demisto installation.
- Select Settings -> Integrations ->Servers and Services and type TruSTAR v2 in the search integration text box.
- Click Add Instance to install the TruSTAR Workflow App. You now see a Configuration dialog box.
- Enter the parameters explained in the table below.
TruSTAR API URL. Enter https://api.trustar.co\
TruSTAR Station URL. Enter https://station.trustar.co
TruSTAR API Key Finding Your API Keys
TruSTAR API Secret Key Finding Your API Keys
Trust any certificate.
Use system proxy settings.
- When you have finished entering the configuration parameters, click Test to check connectivity with TruSTAR.