12-22-2020 09:17 AM - edited 12-22-2020 09:19 AM
Can AMP share information with other 3rd party Threat Hunting capabilities? I am thinking of a use case where you would be integrating the data in to an in house application that correlates Threat data alongside the outputs from the likes of Talos etc.
12-22-2020 11:16 AM - edited 12-22-2020 11:21 AM
HI John,
it is actually pretty easy to integrate AMP and his events into 3rd party tool for example SIEM tool using API calls. Integration using APIs is pretty easy and convenient. Thanks to the SIEM logic we have get rid of all known false positives and only relevant events are then inspected and sent to our ticketing system. In addition all AMP events coming to SIEM are also correlated with events from other security tools which gives us nice overview about what is going on in the network. This includes also data from CTR tool (which includes information from TALOS). l hope this help a bit
01-06-2021 11:21 PM - edited 01-06-2021 11:22 PM
Thank you for the info!
12-22-2020 11:20 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide