Enriching your TIP and Real Time Threat Feeds in the SIEM
Date: Wednesday October 22nd
Time: 10:00AM PT / 1:00PM ET
Topics:
- 10:00 – 10:20 AM PDT – Real Time Threat Feeds in the TIP
- 10:20 – 10:40 AM PDT – Enriching your SIEM
- 10:40 – 11:00 AM PDT – Automating DomainTools data in the SOAR
Through close partnerships with leading security vendors, DomainTools embeds our best-in-class domain profiles and predictive Risk Score directly within your preferred SIEM, SOAR, and TIP solutions.
Enriching your TIP
DomainTools integrations enable real-time threat detection and enhanced traffic management by leveraging DomainTools data into your preferred environment. The presentation, led by Austin Northcutt, will show how to get the most out of DomainTools data within a TIP solution such as Anomali Threatstream, CrowdStrike Falcon, or Maltego.
Real Time Threat Feeds in the SIEM
See how DomainTools SIEM integrations which provide enrichment of alerts and events that contain domain names, and in some cases show all instances of newly-created and/or high-risk domains seen in the customer’s environment. Andrew Bukta will discuss ways detection engineering teams, threat hunters, and other practitioners obtain critical situational awareness on domains observed in a protected environment.
Automating DomainTools data in the SOAR
Adversaries rarely operate as lone wolves and domains with malicious intent are rarely isolated. Adversaries will build their campaigns using several domains that may share a connected infrastructure. Full protection from and context into threat actors comes from understanding the connections of malicious infrastructure. Rob Fawcett will demonstrate how to make those connections and automate discovery into potentially malicious infrastructure using DomainTools SOAR integrations, which provide automation and additional content such as Guided Pivots for DNS attributes such as IPs, email addresses, and nameservers.
Please join us on Wednesday, October 22nd to better understand how to integrate your solutions, augment existing data sets, or build your own solutions leveraging our APIs.