Anomali ThreatStream is a threat intelligence platform (TIP) that automates the collection, curation, and analysis of threat data from global, open-source, and premium feeds.
This integration collects the following indicator types:
- IPv4
- Domain
- SHA256
Integrate Anomali ThreatStream with Datadog to enhance your security logs with threat intelligence, enabling analysis of matched Indicators of Compromise (IOCs) through pre-built dashboards. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
- Log in to the Anomali ThreatStream instance.
- Navigate to Settings > My profile.
- Under Account Information, click Reveal next to the API Key and copy it. Also, copy your Email.
- Identify your Anomali ThreatStream Domain using the URL of your Anomali ThreatStream instance.
- For example, if your Anomali ThreatStream instance URL is
https://ui.threatstream.com/, then your Anomali ThreatStream domain isui.threatstream.com.
- For example, if your Anomali ThreatStream instance URL is
- Provide the following details:
Parameter Description Domain Your Anomali ThreatStream domain. Email Email address associated with your ThreatStream account. API Key API key of your Anomali ThreatStream account. Collect IPv4 IOCs Enable to collect IPv4 IOCs. The default value is true.Collect Domain IOCs Enable to collect Domain IOCs. The default value is true.Collect SHA256 IOCs Enable to collect SHA256 IOCs. The default value is true. - Click Save.
Need help? Contact Datadog support.