Install: TruSTAR for Demisto

Updated 1 month ago by Elvis Hovor

This document explains how to install and configure the TruSTAR Workflow App v2 for Demisto.

This App automatically sends triggered playbook tasks to TruSTAR for enrichment, and then sends TruSTAR information back to Demisto. You can search Indicators directly from Demisto to get relevant data throughout every step of your workflow.

Time to Install: 15-30 minutes for installation from the Demisto marketplace.

Features

  • Submit Demisto cases to your TruSTAR enclave. The link to the TruSTAR Intel Report is automatically added to the open Demisto case.
  • Enrich intelligence in Demisto cases by querying TruSTAR Enclaves for Intel Reports or Indicators.
  • Create playbooks to automate intelligence gathering, using TruSTAR API calls. You can also use those API calls in the Demisto War Room.

Requirements

The following components must be installed and activated to use the TruSTAR App:

  • Demisto Server v5.0 or greater (more info here)
  • Demisto Agent (D2) (more info here)
  • Demisto Engine (more info here)
  • Content package 20.7.0 
While the TruSTAR App does not require specific port allocations or firewall exceptions, you do need to follow firewall and port guidelines for installing Demisto. Check here for details. For certain functions, the TruSTAR Workflow App will need access to the URL station.trustar.co over port 443.

Installing the App

  1. Login to your Demisto installation.
  2. Select Settings -> Integrations ->Servers and Services and type TruSTAR v2 in the search integration text box.
  3. Click Add Instance to install the App. You now see a Configuration dialog box.
  4. Enter the parameters explained in the table below.

Configuration Parameter

Required

Description

server

Yes

TruSTAR API URL. Enter https://api.trustar.co\

station

Yes

TruSTAR Station URL. Enter https://station.trustar.co

key

Yes

TruSTAR API Key Finding Your API Keys

secret

Yes

TruSTAR API Secret Key Finding Your API Keys

insecure

No

Trust any certificate.

proxy

No

Use system proxy settings.

  1. When you have finished entering the configuration parameters, click Test to check connectivity with TruSTAR.


How Did We Do?