For the complete documentation index, see llms.txt. This page is also available as Markdown.

Swimlane Threat Intelligence

The Dropzone AI Platform integrates with Swimlane Turbine, an AI automation security platform. Integrating Swimlane with Dropzone allows Dropzone to access Swimlane's threat intelligence, automatically respond to security incidents, and enrich investigation and incident response.

Integration Overview

To enable these integrations you will perform the following actions:

  • Configure your role-based access (or create a designated Dropzone user)

  • Obtain a Personal Access Token

  • Enable the Data source within your Dropzone tenant

Role Based Access Control - Create a Dropzone User

Swimlane Turbine uses Role-Based Access Control. You will need access to a user with read access permissions to the application and all fields within the application you want Dropzone to have access to. See here for more information.

Alternatively, you may create a designated Dropzone AI user by doing the following:

  • As an administrator, open the admin panel, then select "Users"

  • Click "+ Add User"

Add User
  • Name the user something memorable, such as "DropzoneAI"

  • Enter the first name, last name, username, display name, and email

Configure the new user
  • In the Password tab, input a password or have one be autogenerated upon creation

  • Record the username and password for use later in the Dropzone UI where they will be called "username" and "password," respectively

If you plan to create a personal access token, you may skip this step.

  • Exempt the Dropzone user from forced SSO

  • In the Groups & Roles tab, assign the user read permissions into the tenants you want Dropzone to have access to

  • Click "Save"

See Swimlane's User Management documentation for more information.

Obtain Personal Access Token

To obtain a Personal Access Token, do the following:

  • As an administrator, open the admin panel, then select "Users"

  • Locate the new Dropzone AI user (or a user you want Dropzone to use for access) and click them

  • In the personal access token tab, click "Generate Token"

  • Copy the token shown for use later in the Dropzone UI, where it is called "Personal Access Token"

Copy the personal access token

Enable SentinelOne

To enable the Data Source integration, you'll need the following information:

Dropzone Field
Source

Swimlane Host URL

Your Swimlane Host name, e.g. https://swimlane.example.gov

Personal Access Token

The Access token value you copied earlier

Username/Password

Your username/password, used in place of a Personal Access token

TI App name

The name of the Swimlane application you want Dropzone to access

The display name of the field in the application that contains the indicators of compromise (e.g. hashes, URLs, or IPs linked to the incident) you want Dropzone to use for investigation

IOC Subtype Field Name

The display name of the field that contains the machine-readable subtype used to route automation (e.g. ipv4_public, sha256, domain)

IOC Category Field Name

The display name of the field that holds the human-readable IOC category used to select enrichment sources (e.g. IP Address, FileHash, Domain)

Status Field Name

The display name of the field that indicates when threat intelligence enrichment is complete, e.g. Analysis Complete

To enable the Data Source integration, do the following:

  • Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app

  • In the bottom left hand corner, navigate to Settings > Integrations

Integrations Dropdown
  • Click "Library"

If you have previously integrated this application, click "Configured"

Click Library
  • In the Search bar, search Swimlane Threat Intel, then click "Configure"

The Swimlane Threat Intel Tile
  • Input the Swimlane Host URL, Personal Access Token (or Username/Password), and the TI App Name

The Swimlane Threat Intel Data Source Configuration (pt 1)
  • To guide Dropzone's threat intelligence enrichment, input the IOC Field Name, IOC Subtype Field Name, IOC Category Field Name, and Status Field Name

  • Input the value of the status field when enrichment is complete, e.g Yes, Complete, or Finished

The Swimlane Threat Intel Data Source Configuration (pt 2)
  • Check the box labeled "Create Record if Not Found" to enable Dropzone to create a Swimlane record if it cannot locate the IOC in question. This will trigger Swimlane's automation to run TI queries

This feature is only available if the service account you're using has edit access to the application. Contact your Dropzone Support Representative for more information.

  • Check the box labeled "Verify SSL" to verify SSL certificates when doing investigation

  • Enter your desired poll timeout and poll interval

The Swimlane Threat Intel Data Source Configuration (pt 2)
  • Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.

Last updated

Was this helpful?