Knowledgebase
  • API
  • Web App
  • Support
  • Home
  • Contact

TruSTAR Platform Overview

1. Introducing TruSTAR

2. Product Architecture

3. Data Management

4. Data Processing

4.1 Data Processing: Collect

4.2 Data Processing: Prepare

4.3 Data Processing: Prioritize

4.4 Data Processing: Connect

5. Capabilities

5.1 Capabilities: Governance

5.2 Capabilities: Intelligence Workflows

5.3 Capabilities: Search

5.4 Capabilities: Scoring

5.5 Capabilities: Analytics

6. Interfaces

6.1 Interfaces: REST API

6.2 Interfaces: Integrations

6.3 Interfaces: Web App

7. Use Cases

7.1 Use Cases: Detect

7.2 Use Cases: Triage

7.3 Use Cases: Investigate

7.4 Use Cases: Disseminate

TruSTAR Ontology

Developer Portal

Building a Custom Integratiom

Case Management Integrations

Detection Integrations

Overview: Partner Resources

Requirements for Integrations

SOAR Integrations

Integrating Intelligence Sources with TruSTAR

Building an Observable-Query Intelligence Source Integration

Python SDK

REST API

Intelligence Sources

Digital Risk/ATO

Cyjax

Digital Shadows

RiskIQ Blacklist

RiskIQ PassiveTotal

Shape Blackfish

SpyCloud

Endpoint

Cisco AMP Threat Grid Analysis

Cisco AMP Threat Grid Indicator Query

Crowdstrike Falcon Detection

Crowdstrike Falcon Intelligence

Crowdstrike Falcon Reports

Threat Intelligence

AbuseIPDB

Alienvault OTX

Alienvault OTX Pulse

Bambenek C2 Domain Feed

Bambenek C2 IP Feed

Bambenek DGA Feed

Dragos WorldView

Facebook Threat Exchange

Farsight Security

Flashpoint

Hybrid Analysis

IBM X-Force

IBM X-Force Threat Intelligence

Intel 471 Adversary Intelligence

Intel 471 Alerts

Intel 471 Malware Intelligence

Mandiant iSight

NetLab 360 DGA Feeds

Recorded Future Hash Intelligence

Recorded Future IP Intelligence

Recorded Future URL Intelligence

Recorded Future Vulnerability Intelligence

Shodan

VirusTotal

urlscan

Trusted Community

A-ISAC

COVID-19 OSINT Community Enclave

F-ISAC

FS-ISAC

NCFTA CyFin

NCFTA TNT

Other

AWS GuardDuty

Cybersource

Joe Sandbox

MISP

TAXII Client

How Intelligence Sources are Updated

Intelligence Sources FAQ

Open Source Intelligence Tech Specs

Overview: Intelligence Sources

Workflow Apps

Case Management

Fast Incident Response

Install: TruSTAR for FIR

User Guide: TruSTAR for FIR

IBM Resilient

FAQ: TruSTAR for Resilient

Install: TruSTAR for Resilient

User Guide: TruSTAR for Resilient

JIRA

FAQ: TruSTAR for Jira

Install: TruSTAR for Jira

User Guide: TruSTAR for Jira

ServiceNow

FAQ: TruSTAR for ServiceNow

Install: TruSTAR for ServiceNow

User Guide: TruSTAR for ServiceNow

ServiceNow V2

Install: TruSTAR for ServiceNow V2

User Guide: TruSTAR for ServiceNow V2

Overview: Case Management Apps

Detection

Splunk ES

FAQ: TruSTAR for Splunk ES

Install: TruSTAR App for Splunk ES

User Guide: TruSTAR for Splunk ES

IBM QRadar

FAQ: TruSTAR for IBM QRadar

Install: TruSTAR for IBM QRadar

User Guide: TruSTAR for IBM QRadar

Overview: Detection Workflow Apps

Orchestration

Demisto

User Guide: TruSTAR for Demisto

Creating a Demisto Playbook

Indicator Retrieval in Demisto

Indicator Searches in Demisto

Listing TruSTAR Enclaves in Demisto

Phishing Triage Commands for Demisto

Report Commands in Demisto

Report Searches in Demisto

User Guide: TruSTAR for Demisto

Whitelisting with Demisto

FAQ: TruSTAR for Demisto

Install: TruSTAR for Demisto

Overview: Demisto

Splunk Phantom Cyber

FAQ: TruSTAR for Splunk Phantom Cyber

Install: TruSTAR for Splunk Phantom Cyber

User Guide: TruSTAR for Splunk Phantom Cyber

TAXII Applications

Anomali ThreatStream

LogRhythm

Palo Alto MineMeld

TAXII Client Basics

TAXII FAQ

TruSTAR TAXII Server

Threat Intelligence Platform

MISP (v2)

FAQ: TruSTAR for MISP (v2)

Install: TruSTAR for MISP (v2)

User Guide: TruSTAR for MISP (v2)

Other

TruSTAR Extension for Chrome

TruSTAR on Slack

Workflow Apps FAQ

Scripted Extensions

Enclave Scripts

Automated Sharing Between Enclaves

Script: Correlations Between Enclaves

Script: Deleting Reports

Script: Domain-level URL Filtering

Script: Exporting Indicators

Script: Moving Data Between Enclaves

Scripts: Uploading Data

Managed Connectors

ArcSight: Upload Events to TruSTAR

Azure Sentinel: Import Indicators from TruSTAR

Crowdstrike Falcon: Import Indicators from TruSTAR

Cybereason: Import Indicators from TruSTAR

MISP: Import Reports or Indicators from TruSTAR

Overview: Managed Connectors

Proofpoint: URL Decoder

SecureWorks: Send Indicators to TruSTAR

Splunk Enterprise: Import Indicators from TruSTAR

Splunk Phantom: Enrich Notable Events

Windows Defender: Import Indicators from TruSTAR

Report Correlation Email

Vetting and Tagging Indicators

TruSTAR Web App

UI Walkthrough

1. Start Here

2. Main Window

3. Filter and Refine Panel

4. Intelligence Reports

5. Indicators

6. Dashboard

7. Marketplace

8. TruSTAR Community Chat

9. User Settings

Reports

Copying a Report

Deleting a Report

Emailing a Report

Exporting Report Data

Moving a Report

Overview: Intelligence Reports

Redacting Data from a Report

Reports Graph View

Reports List View

Reports Panel

Submitting a Report

Tagging a Report

Updating a Report

Indicators

Deleting Indicators

Exporting Indicators

IOC List View

Observable Graph View

Overview: Indicators

Tagging Indicators

Threat Actors

Uploading Indicators

Whitelisting Indicators

Phishing Triage

Overview: Phishing Triage

Phishing Triage API

Phishing Triage Python SDK

Phishing Workflow in the TruSTAR Web App

Using Phishing Triage with Detection Tools

Using Phishing Triage with Orchestration Tools

Using Phishing Triage with a TAXII Client

User Settings

Editing Your Profile

Notifications

User Settings Overview

Admin Features

Single Sign-On (SSO)

Okta (SSO)

Ping Identity (SSO)

Salesforce (SSO)

Enclave Inbox

Automating Forwarding to an Enclave Inbox

Enclave Inbox

Setting up an Enclave Inbox with Proofpoint

Managing Users

Managing the Company Whitelist

Managing the Redaction Library

Setting Up Multi-Factor Authentication (MFA)

Setting up a Service Account

Other Features

MITRE ATT&CK Framework

Navigation Bar

Searching

Using Notes

Using the Filter and Refine Panel

Overview: TruSTAR Web App

Technology

TruSTAR Scoring

Normalized Indicator Scores

Priority Event Scores

Priority Indicator Scores

Auto-Whitelist

Enclaves

Redaction Library

FAQs

TruSTAR Policies

API Usage Policy

Privacy Policy

Contacting Support

Finding Enclave IDs

Finding Report IDs

Finding Your API Keys

Login FAQ

Observable Collection FAQ

Observables Supported by TruSTAR

Security FAQ

TruSTAR Glossary

Uploading Observables FAQ

All Categories ​>​ ​Developer Portal ​ > ​ ​Building a Custom Integratiom

Building a Custom Integratiom

5 articles

​Overview: Partner Resources

Start here to build a custom integration with the TruSTAR platform

Updated 2 months ago by TruSTAR

​Requirements for Integrations

Basic integration requirements

Updated 1 month ago by TruSTAR

Case Management Integrations

Recommended and optional commands for a Case Management integration

Updated 1 month ago by TruSTAR

Detection Integrations

Recommended and optional commands for integration with Detection tools

Updated 1 month ago by TruSTAR

SOAR Integrations

Recommended and optional commands for a SOAR integration

Updated 1 month ago by TruSTAR

Powered by HelpDocs (opens in a new tab)

Contact