Smart SOAR Integration

D3’s integration with TruSTAR enables enrichment of Smart SOAR incidents with TruSTAR’s aggregated intelligence feeds for rapid assessment of threats. Because TruSTAR brings together internal and external intelligence, it can provide detailed data for Smart SOAR investigations. The connections between indicators submitted through Smart SOAR and indicators previously ingested by TruSTAR can be visualized in TruSTAR’s constellation graphs.

Integration features

Enrich Smart SOAR incidents with TruSTAR's feeds and threat intelligence resources
Enable users to correlate incidents with reports available on TruSTAR
Customize searches for indicators in TruSTAR directly from the Smart SOAR interface
Automate intelligence gathering

Key Use Cases

1

Automated Enrichment

Analysts are expected to rapidly investigate incidents, without compromising the process. For many, this means manually cross-referencing and copying hashes and other data from TruSTAR. Over a year in a SOC, this means hundreds of hours per analyst plus some degree of human error. Smart SOAR can automatically query TruSTAR for indicators and other relevant data related to new alerts. An analyst can search via the Smart SOAR console, and instantly bring over additional field-data. Plus, it’s agile. You can change the integration parameters via our easy-to-use admin tool.
2

Potential Phishing Analysis

When a potential phishing email is escalated to Smart SOAR, either through an email protection system or manually by the recipient, Smart SOAR extracts the sender’s domain and the URL of any links in the message. Smart SOAR can then use TruSTAR to look up those extracted indicators and reveal any associated malicious activity. Based on the result, the Smart SOAR user can then trigger a response playbook to block the IP, blacklist the sender, notify the email recipient, and orchestrate any other appropriate actions.

Meet Our Friends

Our Connected SOAR Security Alliance brings hundreds of vendors together, allowing customers to benefit from our deep industry relationships and fully vendor-agnostic, independent SOAR platform.

X TruSTAR Integration

Get Started with D3 Security

One platform to stop alert overwhelm. Transform how your security team works, by focusing its resources on real threats.