Ingest Indicators from TruSTAR

Updated 1 month ago by Sachit Soni

TruSTAR offers two API commands to query TruSTAR Enclaves for Indicators and then return the information to an external tool. These indicators can be individual indicators or contained within an Intelligence Report.

Search Indicators

GET/1.3/indicators/search

Description: Searches for all indicators that contain the given search term. If no search term is provided, the search will filter on other (optional) parameters, from and to dates, Enclave, and tags. Results are ordered by last seen time, descending.

Notes

The integration must include a configuration page where the user can define the following:

  • One or more Enclave IDs to query for the indicators. TruSTAR suggests naming this field Observable Ingest Enclave IDs. If no Enclave IDs are specified, the commands will search all Enclaves that the user has access to in TruSTAR.


How Did We Do?