About ThreatQuotient
ThreatQuotient is a data-driven security operations platform that helps teams prioritize, automate & collaborate on security incidents; by enabling more focused decision-making; & maximizing limited resources by integrating existing processes & technologies into a unified workspace.
SIRP’s integration with Threat Quotient improves security operations by fusing together data sources, tools & teams to accelerate threat detection & response.
Supported Actions
1 | Push IP | Create an IP indicator on ThreatQ |
2 | Push Domain | Create a Domain indicator on ThreatQ |
3 | Push URL | Create a URL indicator on ThreatQ |
4 | Push Hash | Create a Hash indicator on ThreatQ |
5 | Get IP Reputation | Checks IP reputation from ThreatQ |
6 | Get Domain Reputation | Check Domain reputation from ThreatQ |
7 | Get URL Reputation | Check URL reputation from ThreatQ |
8 | Get Hash Reputation | Check Hash reputation from Threat Q |
Enable ThreatQ integration with SIRP
Copy ThreatQ API Credentials
To find API credentials, you need to first access ThreaQ's dashboard
Enable and Configure ThreatQ app in SIRP
First, log in to SIRP, then go to Apps from the left navigation bar
Locate the app named ThreatQ
Enable the app by clicking on the toggle button under the Status Column
Once you enable the App, click the configure option to integrate SIRP with ThreatQ.
Add the following details and click Save:
URL: <ThreatQ instance URL>
Username: <ThreatQ Username>
Password: <ThreatQ Password>
Client-ID <Copied Client-ID from the above steps