This document explains how to install and configure the TruSTAR integration with Demisto.
The TruSTAR App for Demisto automatically sends triggered playbook tasks to TruSTAR for enrichment, and then sends back deeplink information to Demisto. You can search IOCs directly from Demisto to get relevant data throughout every step of your workflow.
Time to Install: 15-30 minutes for installation from the Demisto marketplace.
- Submit open cases in Demisto to your TruSTAR enclave. The deeplink to the TruSTAR report is automatically added to the Demisto case.
- Enrich intelligence in open Demisto cases by querying TruSTAR enclaves.
- Create playbooks to automate intelligence gathering, using TruSTAR API calls. You can also use those API calls in Demisto's War Room.
The following requirements and components need to be installed and activated for TruSTAR integration to work with Demisto
- Demisto Server v3.6 to 4.0 (more info here)
- Demisto Agent (D2) (more info here)
- Demisto Engine (more info here)
Installing and Configuring the TruSTAR App
The TruSTAR integration is available on Demisto's integration page for download.
- Login to your Demisto installation.
- Select Settings -> Integrations -> and type TruSTAR in the search integration text box.
- Select Add Instance to install the TruSTAR App. You now see a Configuration dialog box.
- Enter the parameters explained in the table below.
Name you assign to the instance. It must be unique for each instance you set up.
TruSTAR Station URL. Enter https://station.trustar.co
TruSTAR API Key
Authentication Key to connect to TruSTAR station. This is used for making API calls. Available under Settings-> API in your TruSTAR Station account. How to find your API Key
TruSTAR API Secret
Secret Key to connect to TruSTAR station. This is used for making API calls. Available under Settings-> API on TruSTAR Station. How to find your API Secret
- When you have finished entering the configuration parameters, click Test to check connectivity with TruSTAR.