Swimlane Threat Intelligence
The Dropzone AI Platform integrates with Swimlane Turbine, an AI automation security platform. Integrating Swimlane with Dropzone allows Dropzone to access Swimlane's threat intelligence, automatically respond to security incidents, and enrich investigation and incident response.
Integration Overview
To enable these integrations you will perform the following actions:
Configure your role-based access (or create a designated Dropzone user)
Obtain a Personal Access Token
Enable the Data source within your Dropzone tenant
Role Based Access Control - Create a Dropzone User
Swimlane Turbine uses Role-Based Access Control. You will need access to a user with read access permissions to the application and all fields within the application you want Dropzone to have access to. See here for more information.
Alternatively, you may create a designated Dropzone AI user by doing the following:
As an administrator, open the admin panel, then select "Users"

Click "+ Add User"

Name the user something memorable, such as "DropzoneAI"
Enter the first name, last name, username, display name, and email

In the Password tab, input a password or have one be autogenerated upon creation
Record the username and password for use later in the Dropzone UI where they will be called "username" and "password," respectively
Exempt the Dropzone user from forced SSO
In the Groups & Roles tab, assign the user read permissions into the tenants you want Dropzone to have access to
Click "Save"
See Swimlane's User Management documentation for more information.
Obtain Personal Access Token
To obtain a Personal Access Token, do the following:
As an administrator, open the admin panel, then select "Users"

Locate the new Dropzone AI user (or a user you want Dropzone to use for access) and click them
In the personal access token tab, click "Generate Token"
Copy the token shown for use later in the Dropzone UI, where it is called "Personal Access Token"

Enable SentinelOne
To enable the Data Source integration, you'll need the following information:
Swimlane Host URL
Your Swimlane Host name, e.g. https://swimlane.example.gov
Personal Access Token
The Access token value you copied earlier
Username/Password
Your username/password, used in place of a Personal Access token
TI App name
The name of the Swimlane application you want Dropzone to access
IOC Field Name
The display name of the field in the application that contains the indicators of compromise (e.g. hashes, URLs, or IPs linked to the incident) you want Dropzone to use for investigation
IOC Subtype Field Name
The display name of the field that contains the machine-readable subtype used to route automation (e.g. ipv4_public, sha256, domain)
IOC Category Field Name
The display name of the field that holds the human-readable IOC category used to select enrichment sources (e.g. IP Address, FileHash, Domain)
Status Field Name
The display name of the field that indicates when threat intelligence enrichment is complete, e.g. Analysis Complete
To enable the Data Source integration, do the following:
Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
In the bottom left hand corner, navigate to Settings > Integrations

Click "Library"

In the Search bar, search Swimlane Threat Intel, then click "Configure"

Input the Swimlane Host URL, Personal Access Token (or Username/Password), and the TI App Name

To guide Dropzone's threat intelligence enrichment, input the IOC Field Name, IOC Subtype Field Name, IOC Category Field Name, and Status Field Name
Input the value of the status field when enrichment is complete, e.g
Yes,Complete, orFinished

Check the box labeled "Create Record if Not Found" to enable Dropzone to create a Swimlane record if it cannot locate the IOC in question. This will trigger Swimlane's automation to run TI queries
Check the box labeled "Verify SSL" to verify SSL certificates when doing investigation
Enter your desired poll timeout and poll interval

Click "Test & Save" to finish
If you have any errors or questions, engage your Dropzone AI support representative.
Last updated
Was this helpful?