ZeroFOX Integration

XGEN SOAR Integration

D3’s integration with ZeroFox brings automation and orchestration to ZeroFox’s AI-powered threat intelligence and digital risk protection capabilities. When ZeroFox finds threats against your brand, public-facing assets, customers, or employees, D3 jumps into action to investigate and coordinate an automation-powered response.
ZeroFOX Integration

Download Integration Guide



Integration Features

1
Better analysis of security alerts by combining ZeroFox’s full spectrum threat intelligence with D3’s high-fidelity incident data and MITRE ATT&CK correlation
2
Stronger protection of the public attack surface through AI-powered intelligence and automation-powered response
3
More comprehensive remediation of alerts by leveraging D3’s hundreds of integrations to act across the entire stack
4
Fewer manual steps for takedown requests and other actions through D3’s automated playbooks

Key Use Case

ZeroFOX Integration

#1: Brand Protection

Brand impersonation alerts created by ZeroFox can be escalated to D3 for analysis and response via a Brand Protection Playbook. D3 strips out the elements of the alertand checks them against integrated threat intelligence sources. If the URL is known to be malicious, D3 submits it to the firewall to be blocked. D3 then searches for emails containing the URL and runs a phishing email sub-playbook. D3 can also search an integrated SIEM to find internal hosts that have connected to the URL and determine if any data was lost. D3 can orchestrate specific actions in ZeroFox, such as triggering a takedown request, adding the URL to a threat feed, assigning the incident to a user, and sending an email notification to that user.
ZeroFOX Integration

#2: Threat Intelligence Enrichment

By integrating with D3 and ZeroFox you can automatically enrich events from your detection tools with ZeroFox threat intelligence, as well as assess their criticality through additional data enrichment and MITRE ATT&CK matrix correlation. D3 can then trigger an automated response playbook or guide human analysts efficiently through manual steps, all within a single window.
X ZeroFOX Integration