Rapid7 Product Connections
Describes how to leverage synergies between Rapid7 Digital Risk Protection (DRP) and other Rapid7 products.
Get IOC Data in SIEM & ICON
Users can now configure a Quick Action to ‘get an indicator by value’ from the Threat Intelligence database from any page within SIEM or Automation.
(This requires a connection to a user’s instance of DRP with Threat Intelligence enabled.)
Users can search for information about IP addresses, file hashes, domains, and URLs. The quick action provides the following data:
- Severity
- Status (active or retired)
- Score
- Is allowlisted
- First seen
- Last seen
- Last update
- Geo location
- Reporting feeds
- Tags
- Related malware, campaigns, and threat actors
This enables users to rapidly pivot between Rapid7 Insight platform solutions to expedite use cases. Specifically, users can easily enrich IOCs tied to alerts in SIEM by leveraging Threat Intelligence.