Configure the Deep Instinct Monitor

Access Deep Instinct threats on your RocketCyber dashboard

Overview

The Deep Instinct App is designed to retrieve all threat data from the Deep Instinct dashboard. It is designed to operate across all tenants (customers) where Deep Instinct malware protection is deployed.

Required Permissions

The account that you logon to the Deep Instinct dashboard and generate the API Token with must have access to the threat data. As of this date, in order to use the Deep Instinct API integration, the predefined and default role of Master Admin is required. This is necessary in order to read threat details and perform threat actions from the RocketCyber SOC.

How to Set Up

  1. Find your Deep Instinct API Key
    1. Log in to the Deep Instinct portal.  Copy the url you use to do this, as it will be needed later.  It should be something like https://partner1.poc.deepinstinctweb.com/login/
    2. Go to the Settings / Integration & Notifications on the left and select API Connectors
      deepinstinct-api-connectors
    3. Click Add Connector >
    4. Complete the 3 fields in the API Connector window:
      1. Name your API - RocketCyber SOC
      2. Tenants - Select "All Tenants"
      3. Permission - Select "Read and Remediation"

        deepinstinct-add-api-connector
    5. Click Create
    6. Copy the generated API token

      deepinstinct-copy-api-key
    1. Set up your Antivirus-RocketCyber mapping if you have not already done so
    2. Add the API Token to your Deep Instinct App configurations
      1. Go to your RocketCyber dashboard
      2. Enable the Deep Instinct App in the App Store if you have not already done so
      3. Click the gear on the Deep Instinct App to access the configuration menu
      4. Set up customer mapping so your detections are routed to the correct customer
      5. Paste the API Token into the API Token box
      6. Click Authenticate
      1. Enjoy the convenience of Deep Instinct threats delivered directly to your RocketCyber dashboard and the ability to take remediation action with the RocketCyber SOC!