This document explains how to set up the Dragos WorldView premium intelligence source in the TruSTAR platform.
Dragos WorldView provides actionable insights, analyses, alerts, and reports illuminating malicious activity and relevant recommendations.
- Source Type: Premium Intelligence
- Update Type: Feed-based
- Update Frequency: 6 Hours
- Parser: Yes
- Time to install: 10 minutes
- IP Address
- A subscription to Dragos WorldView
- Dragos WorldView API Key and API Secret
- Login into the TruSTAR Web App.
- Click the Marketplace icon on the Navigation Bar.
- Choose Premium Intel.
- Click Subscribe to Dragos.
- Enter your Dragos API Key and API Secret and then click Save Credentials & Request Subscription.
TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.
TruSTAR Report Mapping
The information retrieved from this intelligence source is stored in the Dragos Enclave using this format.
Dragos: IOC-Type + IOC -Value
Dragos UUID taken from indicator
Indicator JSON response with Product JSON response embedded on the ‘products’ field.
These responses are taken from:
Dragos Indicator Endpoint + Dragos Product Endpoint
No reported issues.
Please contact firstname.lastname@example.org if you have issues with this integration.