Anomali - TAAM Integration

This document applies to Classic/Legacy Integrations. You may continue to use these integration configurations. While no active development is happening for these integrations, we continue to provide Classic/Legacy Integrations in the product. You do not have to move to MSI Integrations. If your support engineer or TSC recommends or you choose to move to MSI Integrations, you can take advantage of the latest features and functionality. For more information, see the MSI Integration documentation in the Integrations Overview.

API Calls

The following API calls are used by the Validation Platform to bring in the Threat Actor information. Since Anomali allows you to mark Threat Actors as important, this information is also conveyed to the Threat Actor profiles in the platform.

PurposeCall
Retrieve the Threat Actor list/api/b1/actors
Retrieve Threat Actor details/api/v1/actor/<threat actor ID>
If there are others sources going into Anomali, that information will also be captured and brought into the Validation Platform.

Prerequisites

Information to gather before you start:

  • Identify the host, port, and protocol.
  • Identify the username and authentication token. Any account that has API access can be used.

Configuration

To add the Anomali Threat Intelligence Integration

  1. Go to Settings > Integrations.

  2. In the Threat Intelligence Platform Integrations table, click Add Integration > Anomali.
  3. Enter the Host.

  4. Enter the Port.
  5. Select the Protocol.
  6. Enter the Username.
  7. Enter the Auth token.
  8. Enter the Sync Interval in hours (default: 24 hours).
  9. (Optional) Assign a Name.

  10. Click Submit. The integration automatically starts to sync after it is added.

Add Anomali Integration

Set up Proxy Assignment

If all outbound connections go through a proxy, you may want to set up a proxy definition and assignment for your integration. For information on setting up your proxy rules, see Proxy Rules.

  • June 3, 2022
  • October 25, 2023
In This Article