This document explains how to setup and use the Dragos WorldView premium intelligence source with the TruSTAR Web App.
The Dragos threat intelligence source, WorldView, provides actionable insights, analyses, alerts, and reports illuminating malicious activity and relevant recommendations.
- Source Type: Premium Intel
- Update Type: Feed-based
- Update Frequency: 6 Hours
- Time to install: 10 minutes
The integration pulls the following observables:
- IP Address
- A subscription to Dragos WorldView
- Dragos WorldView API Key and API Secret
- Login into the TruSTAR Web App.
- Click the Marketplace icon on the Navigation Bar.
- Choose Premium Intel.
- Click Subscribe to Dragos.
- Enter your Dragos API Key and API Secret and then click Save Credentials & Request Subscription.
TruSTAR will validate and enable the iSight integration within 48 hours. You will receive an email from us informing you as soon as it is enabled.
TruSTAR Report Mapping
Dragos: IOC-Type + IOC -Value
Dragos UUID taken from indicator
Indicator JSON response with Product JSON response embedded on the ‘products’ field.
These responses are taken from:
Dragos Indicator Endpoint + Dragos Product Endpoint
No reported issues.
Please contact firstname.lastname@example.org if you have issues with this integration.