Dragos WorldView

Updated 1 month ago by TruSTAR

This document explains how to set up the Dragos WorldView premium intelligence source in the TruSTAR platform.

Dragos WorldView provides actionable insights, analyses, alerts, and reports illuminating malicious activity and relevant recommendations.

  • Source Type: Premium Intelligence
  • Update Type: Feed-based
  • Update Frequency: 6 Hours
  • Parser: Yes
  • Time to install: 10 minutes

Observables Supported

  • IP Address
  • MD5
  • SHA1
  • SHA256
  • Software
  • URL

Requirements

  • A subscription to Dragos WorldView
  • Dragos WorldView API Key and API Secret
TruSTAR Admin rights are required to activate this Premium Intelligence feed.

Getting Started

  1. Login into the TruSTAR Web App.
  2. Click the Marketplace icon on the Navigation Bar.
  3. Choose Premium Intel.
  4. Click Subscribe to Dragos.
  5. Enter your Dragos API Key and API Secret and then click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

TruSTAR Report Mapping

The information retrieved from this intelligence source is stored in the Dragos Enclave using this format.

Field

Explanation

Report Title

Dragos: IOC-Type + IOC -Value

External ID

Dragos UUID taken from indicator

Report Body

Indicator JSON response with Product JSON response embedded on the ‘products’ field.

These responses are taken from:

Dragos Indicator Endpoint + Dragos Product Endpoint

Tags

 

Deeplink

None

Client Type

Python SDK

Client MetaTag

TruSTASH

Known Issues

No reported issues.

Please contact support@trustar.co if you have issues with this integration.


How Did We Do?