Dragos WorldView
This document explains how to setup and use the Dragos WorldView premium intelligence source with the TruSTAR Web App.
Dragos WorldView provides actionable insights, analyses, alerts, and reports illuminating malicious activity and relevant recommendations.
- Source Type: Premium Intelligence
- Update Type: Feed-based
- Update Frequency: 6 Hours
- Time to install: 10 minutes
Data Types
The integration pulls the following Observables:
- SHA1
- SHA256
- Software
- MD5
- IP Address
- URL
Requirements
- A subscription to Dragos WorldView
- Dragos WorldView API Key and API Secret
Getting Started
- Login into the TruSTAR Web App.
- Click the Marketplace icon on the Navigation Bar.
- Choose Premium Intel.
- Click Subscribe to Dragos.
- Enter your Dragos API Key and API Secret and then click Save Credentials & Request Subscription.
TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.
TruSTAR Report Mapping
Field | Explanation |
Report Title | Dragos: IOC-Type + IOC -Value |
External ID | Dragos UUID taken from indicator |
Report Body | Indicator JSON response with Product JSON response embedded on the ‘products’ field. These responses are taken from: Dragos Indicator Endpoint + Dragos Product Endpoint |
Tags |
|
Deeplink | None |
Client Type | Python SDK |
Client MetaTag | TruSTASH |
Known Issues
No reported issues.
Please contact support@trustar.co if you have issues with this integration.