# Home

## What is Dropzone?

Dropzone's AI SOC Analyst replicates the techniques of elite analysts to autonomously investigate every security alert.

We ingest alerts from tools you already have (check out all of our integrations [here](https://www.dropzone.ai/integrations)) and enrich them with context from data sources you already have, along with threat intelligence and other data sources that come with your Dropzone AI subscription.

These docs will walk you through how to set up and tune your Dropzone AI SOC analyst, and then integrate Dropzone further into your workflows. Dropzone is designed to work the way that you want it to, and your Dropzone team is here to walk with you through everything along the way.

Have any questions? Check out our FAQ or contact your Dropzone team today!

## Demo Dropzone

Want to check out Dropzone a bit more before your purchase, or show someone new how it works without giving them access to your data? We have a few options:

Sign up for our [Guided Demo](https://www.dropzone.ai/self-guided-demo), which gives a quick walkthrough of Dropzone before ending in a demo environment you can play around in.

Download [COACH](https://www.dropzone.ai/coach), our free web extension that guides analysts through investigations. You'll be able to preview the workflow our AI analyst explores, like the questions posed to determine a conclusion, and it's a great tool for junior analysts on your team.


# Dropzone 101

This section will give you the tools you need to get started using Dropzone.

We have included a list of a few common terms and definitions that will be used throughout the documentation in the **Common Terms and Definitions** Section. The **Getting Started** section will give you a high level overview of what the platform does and how it works as well as how you can access your tenant grant users access.


# Common Terms and Definitions

This section will give allow you to look up common terms and definitions as it relates to Dropzone. As you utilize the platform these terms will become second nature.


# Alert Sources

The Dropzone platform creates Investigations based on alerts that it receives via connected customer systems, for example cloud native alerting, EDR, workforce solutions, and SIEM.

Common Alert Sources include AWS GuardDuty, CrowdStrike, Microsoft Defender, and Splunk.

Some typical features of alert sources:

* Require API-access to your corporate systems, such as API keys, or sharing your resources with a customer-specific Dropzone service account
* May have filtering to investigate only some portion of available alerts, such as only HIGH or CRITICAL
* Can "backfill" alerts from before you enabled the Alert source to capture and investigate historical alerts
* Dropzone can "write back" to some Alert sources, such as select ticketing systems

## Configuration Options

Alert sources have a number of common configuration options:

| Type                       | Purpose                                                                            | Examples                                              |
| -------------------------- | ---------------------------------------------------------------------------------- | ----------------------------------------------------- |
| API parameters and secrets | Access credentials and configuration used by Dropzone authenticate to service APIs | URL endpoints, Client IDs, Client secrets, API tokens |
| Ingest filters             | Select which types of events you want to investigate                               | High and Critical alerts only                         |
| Ingest frequency           | How often the source is polled for more actionable events                          | 60 seconds                                            |

Each integration documentation page will go into details about which values you'll need and how to find them.

<figure><img src="/files/pvNqWm6fk8mjD3yBBeU8" alt=""><figcaption><p>An example Alert Source configuration with severity selector</p></figcaption></figure>

## Backfilling Alerts

When you enable an Alert Source it starts looking for new alerts immediately. You may also wish to "backfill" to pull in historical alerts for processing.

On all Alert Source configuration pages, after the configuration section, you'll find "Backfill alerts":

<figure><img src="/files/6DAIErYIusX4ulQRs5ht" alt=""><figcaption><p>Backfill Time Selection</p></figcaption></figure>

Simply pick a time range you wish to pull for historical alerts and hit "Save".

Instantly a new backfill progress section will appear and you can watch:

<figure><img src="/files/XfoyIWVE81ceZajkfxWZ" alt=""><figcaption><p>Backfill Time Complete</p></figcaption></figure>


# Data Sources

Data Sources enrich the information Dropzone uses to perform alert investigations and respond to interactive chat. Dropzone has support for many Threat Intelligence (TI) feeds, tools, and corporate systems such as identity, directory, and SIEM tools.

For example when investigating possible malicious URLs or IP addresses it may query a TI source, and when understanding systems access it may first make API calls to your cloud provider to find user activity details and then query your corporate directory services to look up user metadata or login history.

Common Data Sources include corporate systems such as Microsoft Entra ID and Google Workspace, Threat Intel tools such as CrowdStrike Falcon Intelligence and VirusTotal, and built in tooling such as WHOIS and PDF Analysis.

{% hint style="info" %}
Enabling more data sources enhances Dropzone analysis, just like more institutional knowledge improves a SOC analyst's capabilities. The Dropzone platform dynamically determines which sources may be useful for enriching investigations, so you should consider enabling as many as you can.
{% endhint %}

## Configuration Options

Data sources typically have a minimal number of configuration options:

| Type                       | Purpose                                                                            | Examples                                              |
| -------------------------- | ---------------------------------------------------------------------------------- | ----------------------------------------------------- |
| API parameters and secrets | Access credentials and configuration used by Dropzone authenticate to service APIs | URL endpoints, Client IDs, Client secrets, API tokens |
| Search filters             | Limit what data will be returned                                                   | Ticket project filters                                |

Each integration documentation page will go into details about which values you'll need and how to find them.

<figure><img src="/files/flFtVzaiQZ6IJhkQtDIO" alt=""><figcaption><p>An example Data Source with issue filter</p></figcaption></figure>


# Investigations

**Investigations** are the core workflow in Dropzone. They represent the automated analysis of security alerts using the Dropzone AI SOC Analyst, combining alert data, contextual enrichment, and investigative reasoning into a single, reviewable case.

Investigations help security teams move from raw alerts to actionable conclusions quickly and consistently, reducing manual effort while maintaining analyst oversight.

***

## What Is an Investigation?

An investigation is created when Dropzone ingests a security alert from a connected alert source. The AI SOC Analyst then:

* Collects relevant data from integrated tools
* Enriches alerts with context and evidence
* Analyzes activity using investigative logic
* Produces a conclusion and supporting findings

Each investigation captures the full lifecycle of this process, from alert ingestion through final review.

***

## Investigation Outcomes

Every investigation results in a conclusion that reflects the AI’s assessment of the activity, such as:

* **Malicious** – Confirmed threat or attack
* **Suspicious** – Potentially malicious activity requiring attention
* **Benign** – Legitimate or expected behavior
* **Inconclusive** – Insufficient evidence to determine intent

These conclusions help teams quickly understand risk and prioritize response.

## Key Investigation Components

At a high level, investigations include:

* **Alert context** – Details about the triggering alert
* **Findings** – Key evidence and investigative insights
* **Evidence** – Data pulled from integrated tools
* **Conclusion** – The AI’s assessment of the activity
* **Review state** – Status indicating whether the investigation has been reviewed

Each component is designed to support fast understanding and informed decision-making.

## Prioritization and Workflow

Investigations are organized by priority—such as **Urgent**, **Notable**, or **Informational**—to help teams focus on the most critical work first.

They move through a clear workflow, from creation and analysis to review and closure, enabling scalable operations without sacrificing control.

## Why Investigations Matter

Investigations are the foundation of Dropzone’s value. They:

* Reduce alert fatigue by automating analysis
* Provide consistent, repeatable investigative outcomes
* Preserve transparency through evidence and reasoning
* Enable analysts to focus on high-impact decisions

By combining automation with human review, investigations allow teams to scale security operations while maintaining confidence and accountability.

## What’s Next

This overview introduces what investigations are and how they fit into the platform.\
For detailed guidance, see our [Best Practices Guide for Reviewing investigations](/best-practices/deep-dive-into-investigation-reviews)


# Getting Started

This section will give you a high level overview of what the platform does and how it works as well as how you can access your tenant grant users access.

The **What's Needed to Use Dropzone** section will give a high level overview of how dropzone works.

The **Accessing Your tenants** section will show you how to connect to a tenant either with your username/password or with various SAML v2 options.

The **Roles and Permissions** sections will discuss the RBAC model used in Dropzone along with information on how to add and disable users.

The **Onboarding with Dropzone** page will give you an idea of what to expect in your onboarding journey with the Customer Success team.


# What's Needed to Use Dropzone

To get started with Dropzone, you'll need at minimum one **Alert Source** and one **Data Source**. This gives Dropzone alerts to investigate and the contextual information needed to perform thorough analysis.

## Alert Sources

We recommend starting with your primary security monitoring platform, typically your:

* **SIEM**, for example:
  * Splunk
  * Microsoft Sentinel
  * Panther
* **Cloud-native security services**, for example:
  * AWS GuardDuty
  * Microsoft Defender
  * Google Cloud Security Command Center

These serve as your “single pane of glass” for security events and provide the most comprehensive alert coverage.

Dropzone also integrates with additional alert-producing tools, including:

* **EDR platforms**, such as:
  * CrowdStrike
  * SentinelOne
  * Palo Alto Cortex XDR
* **Email security tools**
* **Identity platforms**, such as:
  * Okta
  * Microsoft 365
  * Google Workspace
* And many other security tools

## Data Sources

For Data Sources, the more you enable, the more powerful Dropzone becomes. Think of it like giving a SOC analyst access to more institutional knowledge—each additional data source enhances the platform’s ability to provide context, correlate information, and make informed decisions.

Dropzone supports 100+ integrations across technologies such as:

* **Threat intelligence**, for example:
  * CrowdStrike Falcon Intelligence
  * VirusTotal
  * Hybrid Analysis
  * GreyNoise
  * PhishTank
  * And more
* **Corporate systems**, for example:
  * Microsoft Entra ID
  * Google Workspace
  * Active Directory
  * Jira
  * ServiceNow
* **Cloud platforms**, for example:
  * AWS
  * Azure
  * Google Cloud

The platform intelligently determines which data sources are relevant for each investigation, so you can confidently enable as many as possible without worrying about information overload.

Check out all of our integrations [here](https://www.dropzone.ai/integrations).


# Accessing Your Dropzone Tenants

When starting with Dropzone, we will invite you and your team members to the tenant via email with a prompt to set up a username and password.

If you’d like to move to SSO/SAML, please notify your Dropzone team to assist in the transition.&#x20;

Note that even if your team moves to SSO, there will still be a username/password sign in option available on the log in page, but your team’s credentials will not work.

## Login Options

| Method                 | MFA                                              | User Management                                         |
| ---------------------- | ------------------------------------------------ | ------------------------------------------------------- |
| Username/Password      | Yes, via TOTP, e.g. Google Authenticator         | Invite and manage users via the Dropzone UI             |
| Sign in with Google    | Enforced at Google per your policies             | Invite and manage users via the Dropzone UI             |
| Sign in with Microsoft | Enforced at Microsoft per your policies          | Invite and manage users via the Dropzone UI             |
| Custom SAML provider   | Enforced at your SAML provider per your policies | Manage users and roles via your Identity Provider (IDP) |


# Direct Login Links/Local Auth

Dropzone environments can authenticate using a username/password, or federate against Google or Microsoft providers, or against your SAML IDP. In the unauthenticated case when you visit your Dropzone URL it will send you to the login page:

For federated / SAML logins, you can save clicks by bookmark a more specific URL that will log you in directly, as if you clicked the login button of your choice.

Assuming your domain is https\://*mycompany*.dropzone.app you could use the following links instead.

| Login Option                  | URL                                                                                            |
| ----------------------------- | ---------------------------------------------------------------------------------------------- |
| Log in with Google            | https\://*mycompany*.dropzone.app/oidc/authenticate/?idp=google                                |
| Log in with Microsoft         | https\://*mycompany*.dropzone.app/oidc/authenticate/?idp=entra                                 |
| Log in with your SSO provider | https\://*mycompany*.dropzone.app/oidc/authenticate/?idp=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxxx |

For the customer SSO provider case reach out to your Customer Success representative and they can get you the uuid that is associated with your corporate SSO and use that in place of the `xxxx....xxxx` placeholder above.

{% hint style="warning" %}
Impatient and geeky? To find this uuid from your Dropzone representative, from the login page right click on your corporate SSO login button, select "Inspect", and you'll find it as the value associated with the `data-identity-provider-id`, as seen here:

```
   <button data-identity-provider-id="01234567-0000-0000-0000-ba9876543210">
```

{% endhint %}

## Okta Direct Login Link via Bookmark App <a href="#okta-bookmark-app" id="okta-bookmark-app"></a>

While you can't create an "IDP-initiated" SAML app for Dropzone, you can achieve a similar effect

* Create the Okta app as described in [Okta SAML](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/dropzone-101/getting-started/accessing-tenants/okta-saml.md)
  * Be sure to Click "Do not display application icon to users" - this app stays hidden
* Make a new Okta "Bookmark App" by following the instructions on [Okta's Bookmark App](https://support.okta.com/help/s/article/create-a-bookmark-app) site
  * Share it to the same users as the SAML app
  * Use a url like shown in the table earlier that ends in *`?idp=xxxxx...`* specific to your login button


# Managing Users with SAML/SSO

Dropzone AI supports most SAML Identity Providers (IDPs). When using SAML your Identity Provider enforces both "authn" and "authz". An individual clicks a SAML login button, is authenticated against your IDP, and then your IDP sends them back to Dropzone along with cryptographically-signed information indicating who they are and what role they should have.

{% hint style="info" %}
When using SAML, we suggest not simultaneously allowing logins via username/password or the Google/Microsoft federation buttons to assure user management and role management is consistent.
{% endhint %}

## SAML Attributes

Your SAML provider must provide the following attributes:

Your IDP must send the user's email address as the "Name ID" field, in EMAIL format.

## SAML Configuration

All SAML connections require that the IDP (your SAML provider) and the SP (the Dropzone environment) exchange some values to establish security.

These can be exchanged via your support representative.

## SAML troubleshooting

Debugging SAML logins is tricky because so much of what happens is inside large XML encoded blobs in HTTP. We suggest using the SAML Chrome Panel to help debug.

* Install the chrome extension
* Open the chrome developer tools panel
* Go to your tenant, e.g. <https://mycompany.dropzone.app/>
* The "SAML" panel should open in the developer tools - click it
* Click your SSO login button
* Look in the SAML control panel to see what data your IDP is sending to Dropzone \*\* It must have your email address in the saml2:Subject section \*\* It must include all the attributes listed in the table above, first\_name, dropzone\_role, etc

Here we have a user Wendell Bagg with email address <wbagg@example.com> logging in. He will receive the admin role on Dropzone AI. (You may need to click the images to see more details.)

{% hint style="info" %}
You may find when working on SAML that it is easiest to start testing with hard-coded attributes on a user's profile before moving to group-based algorithms that select attributes.
{% endhint %}

{% hint style="info" %}
SAML settings always override any locally applied settings in Team Admin. This means that if you are not properly sending dropzone\_admin then when a user logs in with SSO it will remove their role, which is equivalent to being denied access.

We suggest testing SSO with just one user and making it work before encouraging others.
{% endhint %}

Getting Help

If you have any questions about which login options are right for you, engage your Dropzone AI support representative at <CS-Support@Dropzone.ai>


# Signing in with Okta

{% hint style="success" %}
This document details configuring Okta SAML for authentication with Dropzone. This is more advanced than using federated buttons such as "Log in with Google" and "Log in with Microsoft" but offers more customization, especially useful for customers with more than one Dropzone environment.
{% endhint %}

Enabling SAML with Okta involves the following steps:

* Adding Dropzone Role Attribute to User Profile
* Assigning Dropzone Role Attributes to users
* Creating the SAML application in Okta
* Assigning Users to the Dropzone Application
* Providing your SAML IDP details to your Dropzone support representative
* Updating your SAML application with details from your Dropzone support representative

{% hint style="info" %}
There are multiple ways you can configure Okta successfully with Dropzone AI; we show the simplest version here. However you are welcome to use whatever works best. Perhaps you wish to set the `user.dropzone_role` via the Application profile, or via [Okta Expression Language](https://developer.okta.com/docs/reference/okta-expression-language/) with custom logic. See [Advanced Okta](#advanced) for possibilities.

As long as the values come down where we expect them, in the correct form, the "how" is up to you.
{% endhint %}

## Create the Dropzone Role on User Profile

Dropzone needs to know which role a user should receive when logging into your tenant. There are multiple ways you can configure this, but the most common is to add a field to the user profile or to the Okta application profile.

To create the Dropzone User Profile Role, do the following:

* In the left sidebar of your Okta admin console, navigate to Directory > Profile Editor

<figure><img src="/files/2AzNgdeSRwFrlns1t2Zc" alt=""><figcaption><p>Click Profile Editor</p></figcaption></figure>

* Select the "User (default)" profile

<figure><img src="/files/AuR0Non9a66iFe4c8P2z" alt=""><figcaption></figcaption></figure>

* Under "Attributes," click "Add Attribute"
* Next to Data type, select "string"
* Name the role something memorable, such as "dropzone\_role"
* Assign the display and variable names as something memorable, such as "dropzone\_role"
* In the description section, input a memorable description, such as "Dropzone AI Access Level"

{% hint style="info" %}
You may choose a different "Variable Name", but later in this document when you specify SAML attributes you'll need to adjust from `user.dropzone_role` to the name you used here.

If you store the role somewhere other than the Okta profile then you will need to adjust the SAML attribute value `user.dropzone_role` to match.
{% endhint %}

<figure><img src="/files/hjg2sBSMHOtv4ilBHa2o" alt=""><figcaption><p>Fill out the attribute details (pt 1)</p></figcaption></figure>

* Check the box labeled "Define enumerated list of values"
* In the "Attribute Members" section, create the following new values:

| Display Name         | Value                  |
| -------------------- | ---------------------- |
| admin                | `admin`                |
| member               | `member`               |
| restricted-read-only | `restricted-read-only` |

{% hint style="info" %}
Be sure the "Values" of the attributes match **exactly** `admin`, `member`, and `restricted-read-only`. The "Display Name" may be something more descriptive if you wish.
{% endhint %}

<figure><img src="/files/QMpFgRGTAK3qeNXNrgBP" alt=""><figcaption><p>Fill out the attribute details (pt 2)</p></figcaption></figure>

* Leave the "Restriction", "Attribute length", "Attribute required", and "Default value" sections unchecked/blank
* In the User permission section, select "Read Only"
* Click Save

<figure><img src="/files/Ns27J3LZcChNwLbWv3pz" alt=""><figcaption><p>Fill out the attribute details (pt 3)</p></figcaption></figure>

## Assign Dropzone Role Attributes to Users

Next, you must assign the `dropzone_role` profile value to the users you want to have access to the Dropzone AI platform.

To assign roles to users, do the following:

* In the left sidebar, navigate to to Directory > People
* Select a user you want to have access to Dropzone AI

<figure><img src="/files/1nlA0KVni6uzZ6qj5IOV" alt=""><figcaption><p>Select a user</p></figcaption></figure>

* Navigate to "Profile"
* Click Edit

<figure><img src="/files/eHOezYvMNnzLQfhcgHLr" alt=""><figcaption><p>Edit the user's User Profile</p></figcaption></figure>

* Locate the Dropzone AI Access Level (or `dropzone_role`) section and assign the access level for this user

<figure><img src="/files/9BxaUuIMfwtqeAkdQ4ln" alt=""><figcaption><p>Set the User's `dropzone_role` Value</p></figcaption></figure>

* Click Save

Repeat for all users who should have Dropzone access

## Create the Okta Application

* In the left sidebar, navigate to Applications > Applications
* Click "Create App Integration"

<figure><img src="/files/PT1wU7jbiZb9X7JaOkoY" alt=""><figcaption></figcaption></figure>

* Select SAML 2.0, then click "Next"

<figure><img src="/files/QstzCgrKmF26pzG1p0gr" alt=""><figcaption></figcaption></figure>

* In the "General Settings" section, name the application something memorable, such as "Dropzone AI"
* If you wish, you may assign the application a logo using one of the following Dropzone icons:
  * [transparent](https://go.dropzone.ai/img/logos/logomark-transparent-color.png)
  * [white background](https://go.dropzone.ai/img/logos/logomark-blue-on-white.png)
  * [black background](https://go.dropzone.ai/img/logos/logomark-blue-on-black.png)
* Click "Do not display application icon to users"
* Click "Next"

{% hint style="warning" %}
Be sure you do not enable an Okta tile (application icon) for this Application. Dropzone AI does not support IDP-initiated login flows, so the tile will not function properly.

However you can make an Okta "Bookmark Application" that will enable single-click logins to your Dropzone tenant - see [Direct Login Links](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/dropzone-101/getting-started/accessing-tenants/managing-users/direct-login-links.md#okta-bookmark-app) for details.
{% endhint %}

<figure><img src="/files/vqTkiiH1ed0sioEkW7SS" alt=""><figcaption><p>General Application Settings</p></figcaption></figure>

* Next to "Single sign-on URL", if you have received a "Dropzone SAML ACS Url" from Dropzone, input it there

{% hint style="info" %}
Likely this value is is *<https://login.dropzone.ai/samlv2/acs>*
{% endhint %}

* In the Audience URI section, if you have received a "Dropzone SAML Entity ID" from Dropzone, paste it here
* If not, input a placeholder of <https://login.dropzone.ai/samlv2/sp/00000000-0000-0000-0000-000000000000>
* Next to "Name ID Format", select "Email Address"
* Select your desired Application username

<figure><img src="/files/8JWiXDyGAp3PElCIkoQK" alt=""><figcaption><p>Application SAML Settings</p></figcaption></figure>

* Click "Next"
* Click "This is an internal app we have created"
* Click "Finish"

<figure><img src="/files/oPX37qa9oQUmZ1nTBMaL" alt=""><figcaption></figcaption></figure>

* Navigate to the the "Sign On" section of the application
* In the "Attribute statements" section, click "Add expression"

<figure><img src="/files/LfExhfuwNwPw9CdW9iwS" alt=""><figcaption><p>Add more attributes to the application</p></figcaption></figure>

Add the following attributes individually:

| Name          | Value                        |
| ------------- | ---------------------------- |
| First Name    | `user.profile.firstName`     |
| Last Name     | `user.profile.lastName`      |
| Full Name     | `user.profile.full_name`     |
| Dropzone Role | `user.profile.dropzone_role` |

<figure><img src="/files/nCvlG6Lnp5L6aeBtEtBn" alt=""><figcaption><p>Example - Add the Dropzone Role</p></figcaption></figure>

{% hint style="info" %}
If you chose a different "Variable Name" on the user profile, or are using a different field entirely, update `user.profile.dropzone_role` to match.
{% endhint %}

## Assign Users to the Dropzone Application

Once you are done configuring the application, you must assign users to it.

To assign users or groups to the application, do the following:

* Navigate to the application's "Assignments" section
* Click "Assign"

<figure><img src="/files/lhviTnuyWUwD8ksPGGeM" alt=""><figcaption></figcaption></figure>

* Locate the user/group you want to have access to Dropzone, then click "Assign"

<figure><img src="/files/5fbt204Sr6GnxpfjtBpm" alt=""><figcaption></figcaption></figure>

* Click "Assign and continue"
* Assign the user/group the [entitlements](/dropzone-101/getting-started/accessing-tenants/managing-users/okta-saml) you wish for them to have, then click "Assign entitlements"

<figure><img src="/files/9Sde2gBrZCObjcJdZ7ip" alt=""><figcaption></figcaption></figure>

Repeat until you've added all the people/groups who should have access

## Gather Application Data for Dropzone

Dropzone needs two pieces of information from your Okta environment to enable the SAML trust.

* Navigate to the application's "Sign On" section
* In the right "About" section, click "View SAML setup instructions"

<figure><img src="/files/Vtqk6puruF0H8TwoOZbS" alt=""><figcaption><p>The Sign On About section</p></figcaption></figure>

Find the following two pieces of information:

* Identity provider Single Sign-On URL
  * This is a url, typically on an .okta.com domain
* X.509 Certificate
  * This is a multi-line string, starting with `-----BEGIN CERTIFICATE-----` and ending with `-----END CERTIFICATE-----`

<figure><img src="/files/LZcwLNA0eEKQJJpBY80d" alt=""><figcaption><p>Copy IDP details</p></figcaption></figure>

Provide these to your Dropzone support representative. Typically this is done via the Dropzone SAML Request form.

### Update Your SAML Application

Dropzone will enable SAML and provide you two values to add to the "SAML Settings" in the "General" tab of your SAML app:

* ACS URL - paste this into "Single Sign-On URL" field
* Entity ID - paste this into the "Audience URI (SP Entity ID)" field

Update these values in your Okta Application and save.

## Advanced Okta

Okta has powerful configuration capabilities, including [Okta Expression Language](https://developer.okta.com/docs/reference/okta-expression-language/) which can be used to simplify your Dropzone role provisioning, as an alternative to manually setting roles on a user's profile directly.

{% hint style="warning" %}
This section is here as a reference, not a requirement. Use whatever method you're most comfortable with that balances your administration duties and meets your security standards.
{% endhint %}

### Advanced Okta - Drozone Role via Group Membership

Some customers use Okta Groups coupled with Okta Expression language to populate the `dropzone_role` attribute automatically. As an example, say you had the following groups:

* access-dropzone-admin
* access-member
* access-read-only

You could use the following

```
user.isMemberOfGroupName("access-dropzone-admin") ? "admin" :
user.isMemberOfGroupName("access-dropzone-member") ? "member" :
user.isMemberOfGroupName("access-dropzone-read-only") ? "restricted-read-only" :
null
```

The values (e.g. `admin`, `member`, `restricted-read-only` on the right side above) must match exactly the values we expect, however the groups can be anything that matches your internal naming standands.

<figure><img src="/files/CYPyIwE7ne8EM00YnH5P" alt=""><figcaption><p>Okta Expression Language to populate the <code>dropzone_role</code> attribute</p></figcaption></figure>

## Getting Help

If you have any errors or questions, engage your Dropzone AI support representative.


# Signing in with Google Workspace

{% hint style="success" %}
This document details configuring Google Workspace SAML for authentication with Dropzone. This is more advanced than using the "Log in with Google" button which is an alternate login option.
{% endhint %}

Enabling SAML with Google Workspace involves the following steps:

* Deciding who should have access to Dropzone
* Adding Dropzone Role Attributes To Your Users
* Creating a SAML application in Google Workspace
* Providing your SAML IDP details to your Dropzone support representative
* Updating your SAML application with details from your Dropzone support representative

### Deciding who should have access to Dropzone

When you create your SAML application you need to assign it to a Google Workspace Organizational Unit (OU) and/or to one or more Google Groups.

If you do not have an OU or Google Group that contains the users you want having Dropzone access, create it at this time.

### Add Dropzone Role Attributes To Your Users

Google Workspace supports per-user attributes - see the [Google Custom User Attribute Documentation](https://support.google.com/a/answer/6208725?hl=en#zippy=%2Cadd-a-new-custom-attribute) for details.

You'll need an attribute to hold the user's Dropzone role. You can add this to an exiting "attribute category" or use one you already have.

The role value must be named exactly

Make a new attribute that will hold a user's Dropzone role by following the documentation linked earlier. The name you choose is up to you - we suggest `dropzone_role`.

{% hint style="info" %}
If you're a user of [gam](https://github.com/GAM-team/GAM) you could create the schema via

```
$ gam create schema dropzone field dropzone_role type string
```

{% endhint %}

Once it's created you need to update the role attribute to each user who will have access to your Dropzone environment. You can find this in the user's "User Information" tab in <https://admin.google.com>

Roles are defined on the [Team Admin page](/dropzone-101/getting-started/accessing-tenants).

The valid roles values are as follows:

| role value             | Role Name            | Permissions                                                                                              |
| ---------------------- | -------------------- | -------------------------------------------------------------------------------------------------------- |
| `admin`                | Admin                | Full write access; create and update integration configuration; create response automation; manage users |
| `member`               | Member               | Minimal write access; create context memory, add investigation feedback; ask questions of the AI         |
| `restricted-read-only` | Restricted Read Only | Read-only access; view investigations and dashboards; no ad-hoc chat                                     |

{% hint style="warning" %}
You must make sure these values are exact or the user will not be able to log into Dropzone.
{% endhint %}

<figure><img src="/files/QlvYjgZelRnsnRizA8Da" alt=""><figcaption><p>Example of setting a user to the `member` Dropzone role</p></figcaption></figure>

{% hint style="info" %}
If you're a user of [gam](https://github.com/GAM-team/GAM) you could update a user's role like this:

```
$ gam update user wendell.bagg dropzone.role member
```

{% endhint %}

Add the role to all users who will have Dropzone access.

### Create a SAML Application in Google Workspace

You may wish to start by reading [Google's SAML Documentation](https://support.google.com/a/answer/6087519)

* Go to <https://admin.google.com>
* Go to Apps > "Web and mobile apps" in the sidebar
* Select "Add app" > "Add custom SAML app"
* Provide a name, optional description, and optional application icon
* Click Continue

<figure><img src="/files/j44pHpiffpf3K6ITUzdu" alt=""><figcaption><p>Set Custom App Details</p></figcaption></figure>

On the IDP Metadata page:

* Copy the **SSO URL** (*NOT the Entity ID*) and provide to Dropzone
* Download the certificate file and provide to Dropzone
* Click Continue

<figure><img src="/files/3WERjSYfBqXdaWIRICHB" alt=""><figcaption><p>Gather SAML Details for Dropzone</p></figcaption></figure>

On the Service Provider Details page:

* In the "ACS URL" field put `https://login.dropzone.ai/samlv2/acs`
* In the "Entity ID" field put the value that Dropzone provided
  * If you do not have one yet, put `tbd`
* Set the "Name ID Format" to `EMAIL`
* Set the "Name ID" to "Basic Information > Primary Email"
* Click Continue

<figure><img src="/files/NeHpCBawjrMPxZLqJ7YN" alt=""><figcaption><p>Set SP details</p></figcaption></figure>

* On the Attributes page, click "ADD MAPPING" three times to create new fields
* Set the attributes as follows

| Google Directory Attributes    | App Attributes  |
| ------------------------------ | --------------- |
| Basic Information > First Name | `first_name`    |
| Basic Information > Last Name  | `last_name`     |
| Basic Information > Full Name  | `full_name`     |
| Dropzone > dropzone\_role      | `dropzone_role` |

* Leave Group membership (optional) blank
* Click Finish

<figure><img src="/files/lW7j944KpM0bpoUn6jiB" alt=""><figcaption><p>Configure Custom Attributes</p></figcaption></figure>

### Assign The SAML App to Users

Following the instructions at [Google's SAML Documentation](https://support.google.com/a/answer/6087519), assign the new SAML app to an OU and/or one or more Google Groups.

### Provide Your SAML IDP Details to Dropzone

Send the values you captured earlier to your Dropzone support representative:

* SSO URL
* Certificate file

### Update Your SAML Application

Dropzone will enable SAML and provide you two values to add to the "Service Provider Details" in your SAML app:

* ACS URL
* Entity ID

Update these values in your SAML app.

## Getting Help

If you have any errors or questions, engage your Dropzone AI support representative.


# Signing in with Microsoft Entra

{% hint style="success" %}
This document details configuring Microsoft Entra ID SAML for authentication with Dropzone. This is more advanced than using federated buttons such as "Log in with Google" and "Log in with Microsoft" but offers more customization, especially useful for customers with more than one Dropzone environment.
{% endhint %}

Enabling SAML with Microsoft Entra ID involves the following steps:

* Creating Dropzone Role Groups in Microsoft Entra ID
* Assigning users to Dropzone Role Groups
* Creating the SAML application in Microsoft Entra ID
* Assigning Users to the Dropzone Application
* Providing your SAML IDP details to your Dropzone support representative
* Updating your SAML application with details from your Dropzone support representative

{% hint style="info" %}
There are multiple ways you can configure Microsoft Entra ID successfully with Dropzone AI; we show a group-based version here because it maps cleanly to Entra claim conditions.

As long as the values come down where we expect them, in the correct form, the "how" is up to you.
{% endhint %}

## Create Dropzone Role Groups

Dropzone needs to know which role a user should receive when logging into your tenant. In Microsoft Entra ID, the simplest way to do this is to create one group for each Dropzone role.

To create a role group, do the following:

* As an admin, in your Microsoft Entra ID [homepage](https://entra.microsoft.com/#home), navigate to Groups > All Groups

<figure><img src="/files/s3UtRLwKajib5lFPGaCx" alt=""><figcaption><p>Click All Groups</p></figcaption></figure>

* Click "New Group"

<figure><img src="/files/jWoUwrZcpRmbrM3CN0t8" alt=""><figcaption></figcaption></figure>

Create groups for the Dropzone [roles](https://docs.dropzone.ai/dropzone-101/getting-started/roles-and-permissions) you plan to use. For each group, do the following:

* Under "Group Type," select "Security"
* Under "Group Name," name the group one of the following Role Names:

| Group Purpose                 | Dropzone Role Value    | Role Name            | Permissions                                                                                              |
| ----------------------------- | ---------------------- | -------------------- | -------------------------------------------------------------------------------------------------------- |
| Administrators                | `admin`                | Admin                | Full write access; create and update integration configuration; create response automation; manage users |
| Members                       | `member`               | Member               | Minimal write access; create context memory, add investigation feedback; ask questions of the AI         |
| Restricted Access - Read Only | `restricted-read-only` | Restricted Read Only | Read-only access; view investigations and dashboards; no ad-hoc chat                                     |

* Under "Membership Type," select "Assigned"

<figure><img src="/files/5PCRhP7zf5HT5ziRZe3x" alt=""><figcaption><p>For the purpose of this documentation, the "Member" group is displayed</p></figcaption></figure>

* Under "Members," click "No members selected"

<figure><img src="/files/t1Q75NmqxiTSgIP1EeuN" alt=""><figcaption></figcaption></figure>

* Add the users you want to receive this role, then click "Select"

{% hint style="warning" %}
Each Dropzone user should be assigned to exactly one Dropzone role group. If a user matches multiple claim conditions, Microsoft Entra ID evaluates the matching conditions in order, which can produce unexpected role assignments.
{% endhint %}

<figure><img src="/files/PvKdm2HBepc6XgqQdCJW" alt=""><figcaption></figcaption></figure>

* Click "Create"

## Create the Microsoft Entra Application

* In your Microsoft Entra ID [homepage](https://entra.microsoft.com/#home), click "Enterprise Apps"

<figure><img src="/files/J7fxE681Su1eWRehwQVY" alt=""><figcaption></figcaption></figure>

* Click "New application"

<figure><img src="/files/aFnc90Z22qbFRIBUS1Ka" alt=""><figcaption></figcaption></figure>

* Click "Create your own application"

<figure><img src="/files/3eLQ2ZZPfkZmAapslsgd" alt=""><figcaption></figcaption></figure>

* Name the application something memorable, such as Dropzone AI
* Select "Integrate any other application you don't find in the gallery"
* Click "Create"

<figure><img src="/files/HPiNwfgYwcrIpJ5nVmU2" alt=""><figcaption><p>Create the application</p></figcaption></figure>

{% hint style="warning" %}
Dropzone AI does not support IDP-initiated login flows, so launching Dropzone directly from the Microsoft My Apps tile may not function properly.
{% endhint %}

* In the newly created application, navigate to Manage > Single sign-on

<figure><img src="/files/BAmlyEgviykIgAA1xkAT" alt=""><figcaption><p>Click Single sign-on</p></figcaption></figure>

* Select SAML

<figure><img src="/files/oQzF3ypxO5siKrGHXTyY" alt=""><figcaption></figcaption></figure>

* Click the Edit button in the "Basic SAML Configuration" section

<figure><img src="/files/mKoi5pVqMZX6xaqCCL3e" alt=""><figcaption></figcaption></figure>

* Under "Identifier (Entity ID)," click "Add identifier" and input your Dropzone SAMl Entity ID

{% hint style="info" %}
If you have not received a SAML Entity ID from Dropzone, enter a placeholder of \_<https://login.dropzone.ai/samlv2/sp/00000000-0000-0000-0000-000000000000\\>\_
{% endhint %}

<figure><img src="/files/iCTCcMnG4O1nolrza8Fa" alt=""><figcaption><p>Input your Dropzone SAML Entity ID</p></figcaption></figure>

* Under "Reply URL (Assertion Consumer Service URL)," click "Add reply URL" and input your Dropzone SAML ACS URL

{% hint style="info" %}
Likely, this value is \_<https://login.dropzone.ai/samlv2/acs\\>\_. If you have not received a SAML ACS URL from Dropzone, contact your Dropzone support representative.
{% endhint %}

<figure><img src="/files/7fAdeS2f1KSmnFIbacuv" alt=""><figcaption><p>Input your Dropzone SAML ACS URL</p></figcaption></figure>

* Leave the other values blank
* Click "Save" when done, then exit the window

<figure><img src="/files/tak8HOizzKfFZXahOu8k" alt=""><figcaption></figcaption></figure>

* Click the Edit button in the "Attributes and Claims" section

<figure><img src="/files/aMHPQTFDtY5qTZTwBBRo" alt=""><figcaption><p>Edit Attributes and Claims</p></figcaption></figure>

* Click "Add new claim"

<figure><img src="/files/UO2BlMT3hxUNtR6qUlcM" alt=""><figcaption></figcaption></figure>

* Create claims with the following attributes, then click "Save"

| Name           | Namespace   | Source Attribute           |
| -------------- | ----------- | -------------------------- |
| first\_name    | Leave blank | user.givenname             |
| last\_name     | Leave blank | user.surname               |
| full\_name     | Leave Blank | user.displayname           |
| dropzone\_role | Leave Blank | See below for instructions |

<figure><img src="/files/OF0evexXDCDa0iiUqXEy" alt=""><figcaption><p>For the purpose of this documentation, the first_name claim has been shown</p></figcaption></figure>

### Configure the `dropzone_role` Claim

In your Entra Enterprise Application, the `dropzone_role` claim should use claim conditions to return the correct Dropzone role value based on group membership.

* Name the claim "dropzone\_role"
* Leave the Namespace section blank
* Click "Claim Conditions"
* Add a claim condition for each Dropzone role group you created earlier

{% hint style="warning" %}
Microsoft Entra ID evaluates claim conditions in order. If a user matches more than one condition, the condition order can affect which \`dropzone\_role\` value is returned.

Make sure to add the conditions in the order shown below and assign each user to exactly one Dropzone role group to avoid unexpected role assignments.
{% endhint %}

| User Type | Scoped Groups                 | Source    | Value                |
| --------- | ----------------------------- | --------- | -------------------- |
| Members   | Dropzone Restricted Read Only | Attribute | restricted-read-only |
| Members   | Dropzone Members              | Attribute | member               |
| Members   | Dropzone Admins               | Attribute | admin                |

{% hint style="info" %}
The Scoped Group names shown above are examples. Select the Entra groups that correspond to your Dropzone roles.
{% endhint %}

<figure><img src="/files/7Dy1Ozy4LczVaVxt8xrw" alt=""><figcaption><p>Configure the `dropzone_role` claim</p></figcaption></figure>

* Click "Save" when done

## Assign Users to the Dropzone Application

* In your Microsoft Entra ID [homepage](https://entra.microsoft.com/#home), click "Enterprise Apps" and find the application you just created
* Navigate to Manage > Users and Groups

<figure><img src="/files/fZBq3363WPHWWy2pLicX" alt=""><figcaption></figcaption></figure>

* Click "Add user/group"

<figure><img src="/files/TQBiAPxwLDZEJeqKD0u3" alt=""><figcaption></figcaption></figure>

* Click "Users and groups"

<figure><img src="/files/ku1ze2wu9wCZoPtnR1JY" alt=""><figcaption></figcaption></figure>

* Add the users and groups you want to have access, then click "Assign"

## Configure with Dropzone

* Navigate back to the application
* Navigate to Managers > Single-sign on
* In the "SAML Certificates" section, next to "Certificate (Base64)," click "Download"

<figure><img src="/files/0s5isdUh7FRokPEEpNIO" alt=""><figcaption></figcaption></figure>

* In the "Set Up" section, copy the login URL and Microsoft Entra Identifier

<figure><img src="/files/ntmfXmyn8h6VU8XmyOFL" alt=""><figcaption></figcaption></figure>

Send the following values to your Dropzone support representative:

| Microsoft Entra ID Value   | Send to Dropzone  |
| -------------------------- | ----------------- |
| Login URL                  | IDP SSO URL       |
| Microsoft Entra Identifier | IDP Entity ID     |
| Certificate (Base64)       | X.509 Certificate |

{% hint style="info" %}
Typically this is done via the Dropzone SAML Request form.
{% endhint %}

### Update Your SAML Application

Once you have provided this information to Dropzone (if we have not already), Dropzone will enable SAML and provide you two values to add to the "Basic SAML Configuration" section of your SAML app.

* Navigate back to your Enterprise Application
* Navigate to Manage > Single sign-on
* In the Basic SAMl Configuration section, click "Edit" and input the following:
  * ACS URL - paste this into the "Reply URL (Assertion Consumer Service URL)" field
  * Entity ID - paste this into the "Identifier (Entity ID)" field
* Click "Save"

{% hint style="info" %}
Only proceed with this step if you did not receive an ACS URL or Entity ID to begin with.
{% endhint %}

## Advanced Microsoft Entra ID

Microsoft Entra ID has multiple ways to manage group membership and claim values. You may use dynamic groups, existing access groups, or other identity governance workflows if they produce the expected `dropzone_role` SAML claim.

{% hint style="warning" %}
This section is here as a reference, not a requirement. Use whatever method you're most comfortable with that balances your administration duties and meets your security standards.
{% endhint %}

The values `admin`, `member`, and `restricted-read-only` must match exactly the values we expect, however the groups can be anything that matches your internal naming standards.

If you have any errors or questions, engage your Dropzone AI support representative.


# Roles and Permissions

## Login Roles and Permissions

Dropzone AI users are assigned a role that determines what access they have to the Dropzone environment.

The following table describes the roles and permissions available to Dropzone AI users:

| Role Name                | Permissions                                                                                                                                   |
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------- |
| **Admin**                | Full write access; create and update integration configuration; create response automation; manage users; create and update custom strategies |
| **Member**               | Minimal write access; create context memory, add investigation feedback; ask questions of the AI                                              |
| **Restricted Read Only** | Read-only access; view investigations and dashboards; view custom strategies; no ad-hoc chat                                                  |

## Role Source

Dropzone AI users get their role from one of two places:

* If logging in via a **SAML/SSO provider**, Dropzone uses the role provided by your IDP (Identity Provider).
* If logging in via **username/password**, **federated Google**, or **Microsoft** buttons, Dropzone uses the role set in **Team Admin**.

{% hint style="info" %}
Most Dropzone customers who enable SAML/SSO will disable federated Google/Microsoft login and username/password authentication. This is the preferred configuration, as it lets your IDP (Identity Provider) stay in charge of what access an individual has.
{% endhint %}

{% hint style="warning" %}
Role changes made via **Team Admin** are overridden by SAML settings when a user logs in.
{% endhint %}

## Managing Users via Team Admin

The following describes how to manage users via the Team Admin interface.

{% hint style="info" %}
If you are using SAML/SSO, see the instructions for setting up your specific SAML system (for example, Google Workspace or Okta). When using SAML/SSO, you do not need to perform any local Team Admin user management.
{% endhint %}

* Navigate to your Dropzone AI tenant home page (for example, `https://mycompany.dropzone.app`).
* Click your person icon on the far right and select **Team Admin**.
* From the Team Admin page, you can see the users who have accounts in this Dropzone environment.

{% hint style="warning" %}
If you use SAML/SSO, this list may be incomplete. It only shows users you’ve explicitly invited via Team Admin and those who have logged into Dropzone via SAML. Your IDP may allow additional users who have not logged in yet, and they will not appear here.
{% endhint %}

## Adding a User

To add a user:

* From the Team Admin page, click the **Add User** button.
* Enter the name and email address of the user you want to invite.
* Select the role from the dropdown.
* Click **Save** to invite the user.

## First-Time Sign-In

Once you've invited a user via the Team Admin page, the user can log in.\
Which authentication methods you've enabled determines how the user signs in:

* If you allow **password authentication**, the user will receive an email with a one-time link to accept the invite and set up a password.
* If you do **not** allow password authentication, the user must log in using a federated **Google** or **Microsoft** button.

## Activating / Deactivating Users

Users appear in one of two states:

* **Active**
  * Able to log in
  * Click **Deactivate** to disable login access
* **Deactivated**
  * Not able to log in
  * Click **Reactivate** to allow login again

## Deleting Users

Dropzone does not currently allow you to delete users. Instead, users can be **deactivated**.

Keeping the user in the system ensures their previous actions remain properly accounted for in audit logs and historical records.


# Onboarding with Dropzone

Welcome to the start of a successful partnership!

Our structured onboarding program is designed to ensure you achieve full value from Dropzone. By completing this set of goals, you transition seamlessly from the functionality based Onboarding Phase to the sustained excellence and partnership based Maintenance Phase .

This transition signifies that you are fully equipped to maximize the platform's capabilities, enabling us to move from weekly, hands-on support to a more strategic, monthly partnership.

## Weekly Syncs (\~4 Weekly Sessions)

The Onboarding Phase can take as little as two weeks and as much as two-months. This structured program focused on knowledge transfer and practical implementation, measured by the successful completion of the milestones below which follows the PoC phase.

| Topic                                          | Description                                                                                                 |
| ---------------------------------------------- | ----------------------------------------------------------------------------------------------------------- |
| Analyst Training                               | Intended for end users and analysts to get an understanding of what Dropzone is and how investigations work |
| Admin Training                                 | Advanced training going over configuration and management of Dropzone                                       |
| Fine Tuning                                    | Understanding how to adjust the behavior of the AI Analyst                                                  |
| Context Memory Cleanup & Maintenance           | Recurring cleanup of stale Context Memory records and Custom Strategies                                     |
| Integrations - Initial Setup                   | Successful connection and configuration of initial alert/data sources                                       |
| Containment Actions - Covering Use Cases       | Defining and validating use cases for automated alert containment                                           |
| Response Actions - Notifications & Escalations | Configuring effective and timely notification and escalation workflows                                      |
| AI Interviewer Introduction                    | Understanding and deploying the AI Interviewer for relevant scenarios                                       |
| Custom Strategies - Covering Use Cases         | Ensuring outcomes match expectations with Custom Strategies                                                 |
| Integrations - Advanced & Roadmap              | Discussing and planning advanced integrations and future roadmap alignment                                  |
| Response Actions - Covering Use Cases          | Advanced configuration of diverse and complex response actions                                              |
| API / Swagger / Automation Options             | Exploring and planning for automation using our API and documentation                                       |
| Company Roadmap & Alignments                   | Strategic discussion on long-term goals                                                                     |

## Bi-Weekly Sync (\~2 Sessions)

After the initial weekly sessions we move to Bi-Weekly syncs. This is an opportunity to extend onboarding and revisit topics that may require additional discussion or work on further fine tuning of the platform. These are optional sessions based on the comfort level of the user base.

## Maintenance Phase (Ongoing)

After initial onboarding the focus shifts from implementation to continuous improvement and strategic growth. We believe that moving to a monthly cadence reflects the depth of your success and comfort with the platform, allowing us to focus our time together on high-level strategy rather than daily operational support. This ensures efficient use of your team's time while maintaining a strong, supportive partnership for long-term success.


# The Platform

This section contains documentation for all major areas of the Dropzone platform. It serves as a high-level guide to help users understand **where things live**, **what each section is used for**, and **how different parts of the platform fit together**.

Use this section as a starting point before diving into feature-specific or best-practice documentation.

***

## Platform Navigation at a Glance

The Dropzone platform is organized around a few core workflows:

* Investigating security alerts
* Reviewing and prioritizing findings
* Managing users, access, and configuration
* Customizing how Dropzone behaves for your environment

Each section below corresponds to a primary area of the UI.

***

## Dashboard

The **Dashboard** provides a high-level view of activity across your Dropzone tenant.

From the Dashboard, you can:

* Monitor investigation volume and outcomes
* Track key performance metrics such as time to investigate and analyst time saved
* Review trends and summaries across investigations
* See top assets and response metrics at a glance

The Dashboard is typically the first place users land when logging in.

***

## Investigations

The **Investigations** section is where alerts are analyzed and reviewed.

Here you can:

* View investigations by priority (Urgent, Notable, Informational)
* Review AI-completed investigations
* Examine findings, evidence, interviews, and remediations
* Approve investigations or modify conclusions
* Leave notes and feedback to improve future investigations

This area represents the core day-to-day workflow for SOC analysts.

***

## Chat

The **Chat** interface provides a lightweight way to query integrated data sources using natural language.

Chat supports:

* **Session-scoped chats** for freeform exploration
* **Investigation-scoped chats** that include investigation context and entities

Chat is designed for fast, tactical lookups and enrichment—not full investigations—and complements the Investigations workflow.

***

## Context Memory

**Context Memory** stores institutional knowledge that helps Dropzone understand your environment.

Context Memory captures:

* Facts about users, devices, systems, and networks
* Organizational context not visible in telemetry
* Exceptions, known behaviors, and environment-specific details

This knowledge is applied automatically during investigations to improve accuracy and reduce manual research.

***

## Team Admin Section

The **Team Admin** section is where user access and permissions are managed.

From Team Admin, administrators can:

* Invite and manage users
* Assign roles (Admin, Member, Restricted Read-only)
* Activate or deactivate user accounts
* Review who has access to the tenant

This section is primarily used by Admins and security leaders.

***

## Tenant Tree

The **Tenant Tree** allows users to navigate between multiple Dropzone tenants.

This is especially useful for:

* MSSPs
* Organizations with multiple environments
* Teams managing separate business units or regions

The tenant tree makes it easy to switch context without logging out.

***

## Fleet Dashboard

The **Fleet Dashboard** is a rollup view allowing you to see all your tenants in one place.

{% hint style="info" %}
Note that you will only see the Tenant Tree and Fleet Dashboard if you have a multi-tenant setup of Dropzone. Ask your Sales or Customer Support team if you are unsure if this would provide value to your organization.
{% endhint %}

***

## Settings

The **Settings** area contains configuration and tuning controls for how Dropzone operates.

Settings is where more advanced functionality lives and is primarily used by Admins.

### Settings Overview

Within Settings, you can configure:

* **Custom Strategies**\
  Define organization-specific logic that influences investigation conclusions, priorities, analysis guidance, and investigation questions.
* **Response Actions and Automations**\
  Execute custom Python scripts in response to investigation or system events.
* **System Info**\
  View tenant configuration, investigation thresholds, and performance benchmarks.
* **System Events**\
  Audit activity across the tenant and export logs for analysis.
* **Integrations**\
  Manage alert sources, data sources, connectors, and API keys.

Settings allows teams to tailor Dropzone to their environment, workflows, and risk tolerance.

***

## How to Use This Folder

Each subfolder in **Platform** provides deeper documentation for that specific area of the UI, including:

* Feature explanations
* Links to Best practices
* Setup guides
* Usage examples

If you’re new to Dropzone, start with:

1. **Dashboard**
2. **Investigations**
3. **Chat**

Admins and advanced users should also review:

* **Settings**
* **Context Memory**
* **Custom Strategies**

***

## Summary

This section provides a map of the Dropzone experience. It explains what each part of the platform does and where to find it, helping users quickly orient themselves and understand how different workflows connect.

For detailed configuration or best practices, refer to the individual documents within each section.


# The Dashboard

The Dropzone Dashboard provides a summary view of investigations.

## What You’ll See

* **Key performance metrics**\
  Starting on the top right you will see Key Permformance Metrics. The metrics are lifetime investigations, median time to investigate, and analyst time saved.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Time saved is calculated using the customer-defined Time Saved metric located under <strong>Settings → System Info</strong>.</p></div>
* **Investigation analytics**\
  Below the Key Permformance Metrics you will see the Investigation Analytics on the top left. This interactive donut chart and monthly bar chart display investigation conclusions.
* **Top assets panel**\
  On the bottom left is the Top Assets panel which shows the frequently investigated assets with a visual threat distribution.
* **Response metrics**\
  To the right of Top Assets the Response Metrics section shows performance indicators tracking your SOC response times. Clicking the **View Details** button will give the following detailed view
* **Investigation MITRE Tactic** To the far right is the Investigation MITRE Tactic overview showing the frequency of MITRE tactic investigation counts
* **Status Bar** Finally at the bottom is the status bar showing a high level overview of that status of your connected Data Sources, Alert Sources, and Communicators


# Tenant Tree (if applicable)

If you have multiple tenants, you will see an icon above the Dashboard to select which tenant you would like to review.  Note that anyone with permissions to any tenant in your organization via SAML/SSO will see all tenants in your tenant tree dropdown menu, so if needed we can set up different tenant families for your organization.&#x20;

While the tenant tree is designed to allow you to switch between tenants it works hand and hand with the **Fleet Dashboard** which provides an overview of tenants in your organization.


# Fleet Dashboard (if applicable)

The **Fleet Dashboard** is designed for organizations that manage multiple Dropzone tenants or environments, such as Managed Security Service Providers (MSSPs) or large enterprises with multiple business units.

Its purpose is to provide a **centralized, consolidated view** of investigations, alerts, and key metrics across all tenants—eliminating the need to log into or switch between individual environments.

## What the Fleet Dashboard Does

The Fleet Dashboard acts as a command center for multi-tenant security operations. It allows teams to monitor activity, assess workload, and identify issues across all managed environments from a single view.

Key capabilities include:

* **Unified visibility** across all connected tenants
* **At-a-glance metrics** to understand overall workload and trends
* **Quick access to tenant-level details** without losing fleet context

## How the Fleet Dashboard Works

### Unified Fleet View

The dashboard aggregates data from all connected tenants into a single interface. Summary metrics—such as total investigations—are displayed at the top, providing immediate insight into overall activity across the fleet.

Below the summary, tenant-specific data is displayed, allowing users to see how investigations and alerts are distributed across environments.

This approach enables rapid monitoring and reduces the need for repetitive manual navigation.

### Tenant-Level Drilldown

From the Fleet Dashboard, users can drill into individual tenants to view their specific investigation and alert data. This allows analysts and administrators to investigate issues in a single environment while maintaining awareness of the broader fleet.

### Sorting and Filtering

The Fleet Dashboard supports sorting and filtering by attributes such as:

* Investigation count
* Investigation status
* Alert or investigation type

These controls make it easier to prioritize work, identify hotspots, and balance workloads across tenants.

### Role-Based Access

Access to the Fleet Dashboard is controlled through role-based permissions. This ensures that only authorized users can view or manage multi-tenant data, supporting least-privilege access and operational separation where required.

## Typical Use Cases

### MSSPs and Multi-Environment Teams

The Fleet Dashboard is especially valuable for MSSPs and organizations responsible for multiple client or business-unit environments. It simplifies oversight and enables efficient management at scale.

### Centralized Operations Management

Security leaders and administrators can quickly assess the health and workload of all tenants, identify trends, and respond to issues—without toggling between separate dashboards.

### Reporting and Compliance

The fleet-level roll-up view supports easier compliance tracking and executive reporting. Planned enhancements will further expand reporting capabilities.

## Summary

The Fleet Dashboard is a centralized command center for multi-tenant security operations in Dropzone. By consolidating visibility, reducing navigation overhead, and enabling fleet-wide insight, it helps teams save time, reduce complexity, and operate more effectively across all managed environments.

{% hint style="info" %}
Note that you will only see the Tenant Tree and Fleet Dashboard if you have a multi-tenant setup of Dropzone. Ask your Sales or Customer Support team if you are unsure if this would provide value to your organization.
{% endhint %}


# Investigations

<figure><img src="/files/aq5XRRKizZpmlWSJ3F4n" alt=""><figcaption><p>The Dropzone Investigations Summary Page</p></figcaption></figure>

## What You’ll See Here

* **Investigations by priority**\
  Tabs showing Dropzone’s recommendation on what to review first:

  * **Urgent**
  * **Notable**
  * **Informational**

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>These priority levels can be influenced using <strong>Custom Strategies</strong>.</p></div>
* **Not yet processed investigation status**

  * **Queued**\
    Alerts that have been ingested by Dropzone and are waiting to be investigated.
    * This stage is used when there are already 10 investigations running at once (the current system limit).
  * **Running**\
    Alerts that are currently being investigated by your Dropzone analyst.
  * **Stopped**\
    Alerts that have been ingested but not investigated by Dropzone for a variety of reasons, such as exceeding thresholds set in **System Info** or encountering an error.

    * To investigate these alerts, click **Stopped** and then **Retry**.
    * **Stopped alerts do not count against your license.**

    <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Best practice:</strong> Want to know when an investigation is stopped? Work with your Dropzone team member to set up a notification <strong>Response Action</strong>.</p></div>
  * **Below investigation priority are filters and a search bar allowing you to narrow the view only to investigations you want to see**\
    Filters are of the following types
  * **Review Status** - Dropzone learns by reviewing investigations. This will show you how many you have reviewed.
  * **Conclusion** - The goal of Dropzone is to provide accurate conclusions. Fine tuning will allow you to influence how this happens.
  * **Insight Tag** - Insights about the content of the investigation added by the analyst during an investigation
  * **Alert Type**
  * **MITRE Tactic**
  * **Attach Surface**
  * **Source**

  <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Dropzone will save your last session upon exit. This means you will be able to continue your work where you left off instead of having to add filters every time.</p></div>
* **List of Alerts meeting filter criteria** Below the filters are all alerts matching the search criteria that have been specified. The summary of alerts shows important information about the alerts including the date/time, the title, entities involved, source of the alert, initial Conclusion, and priority.
  * **Alert Title** - The Alert Title is a link that will open the detailed view of the investigation.
  * **Conclusion** - This can be changed directly from the summary page by clicking the dropdown. This works just like changing the conclusion from the detail page.
  * **Priority** - This can be changed directly from the summary page by clicking the dropdown. This works just like changing the conclusion from the detail page.

{% hint style="warning" %}

```
You can **bulk edit** Conclusion and Priority status by selecting multiple items (Checking the box to the left of the alert) which will pop up an option to update all rows that have been selected at the same time.
```

{% endhint %}

* **Full investigation write-ups**

  * Click into any investigation to see the detailed view:
    * The overall **Summary**
    * Detailed investigative context in **Findings**
    * Supporting artifacts in the **Evidence Locker**
    * Recommended **Remediations** (for *Malicious*, *Suspicious*, and *Inconclusive* alerts only)
    * A **Notes** section for team collaboration
    * A **Changelog** showing the full investigation lifecycle from ingestion to approval

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Best practice:</strong> Check out our guides on how to <a href="/pages/lT8pvRhm4ySYwo9ratQf">review an investigation</a> and <a href="/pages/AfUKOGnHyIdASa9SCqL0">leave context memory</a>.</p></div>


# Chat

The Dropzone security chatbot is a lightweight assistant designed to accelerate analyst workflows by providing quick, conversational access to integrated tools and data sources. Unlike the full Dropzone agent, the chatbot does not conduct autonomous investigations or make decisions. It is intended to be a low-friction interface to help analysts answer tactical questions faster.

<figure><img src="/files/YEaEJq11y0CJ3Ei7v8J7" alt=""><figcaption><p>The Dropzone Chat Interface</p></figcaption></figure>

The chatbot supports two distinct modes of interaction tailored for different workflows:

## Investigations

* Ask questions about a specific investigation, which pulls from all investigation details including extracted entities and alerts.
* Note that the chat can’t pull alerts directly from your source systems—only information that is included in the investigation within Dropzone.

## Session Scoped Chats

* These are freeform and will not include any investigation or alert context.
* Many of our customers utilize these chats as a search engine within their connected alert and data sources. This is a context aware agent that is trained in security principles.

## Best Practices

* **Be specific, actionable, and time-bound**
  * Instead of asking “What happened?”, try: “Was the file X downloaded by users other than Y in the last Z days?”
  * Be “entity” specific:
    * **Users:** user email address, employee ID number
    * **Devices:** hostnames, asset tags
    * **Files:** file names, hashes (SHA256, MD5)
    * **Network indicators:** IP addresses, domains
    * **Platforms:** specific tools (e.g., “in SentinelOne” or “from Okta”)
    * **Timeframes & locations:** specific dates, time windows, or geo-locations
* **Stay tactical, not strategic**
  * The chatbot excels at tactical lookups—retrieving data, answering point-in-time questions, and surfacing facts. It does not perform investigative reasoning, hypothesis testing, or behavioral baselining like the full Dropzone agent.
  * Avoid asking subjective or open-ended questions like:
    * “Is this normal?”
    * “What do you think happened here?”
    * “Is this suspicious?”
  * Instead, break down your question into specific lookups:
    * “What other devices have been observed with the process hash in the last 48 hours?”
    * “Has IP AAA.BBB.CCC.DDD communicated with internal systems before?”
* **Follow up and iterate**
  * Chatbot sessions support lightweight follow-up questions that reference prior responses—especially in investigation-scoped chats. This allows you to progressively narrow focus or explore pivots without repeating the full context.
  * Use short, incremental follow-ups to gather additional contextual information.


# Context Memory

Context Memory in Dropzone AI captures and distills institutional knowledge—details that aren’t directly observable in security telemetry, but that experienced analysts and documented processes consider essential to investigations. It augments the AI SOC Analyst’s understanding of alert entities with learned organizational facts, reducing manual research and accelerating decision-making.

Context Memory helps Dropzone’s AI apply organization-specific reasoning during investigations by proactively identifying facts that are not present in alert payloads or security systems, but are critical to assessing risk or ruling out benign behavior.

If you find yourself adding entries that describe workflows, decision trees, or *if/then* logic, it’s likely a sign you’re designing a **Custom Strategy** rather than a memory fact. Context Memory should be used to capture facts about entities—what something is, who owns it, or how it’s typically used—not prescriptive steps on how to interpret it.

\## How to Create Context Memory

### Learning from Investigations

* When an analyst changes a **Conclusion**, that outcome can be remembered, and the Dropzone agent synthesizes the documented notes into additional Context Memory.
* When providing feedback, reference specifics from the investigation:
  * ✅ “Application *Foo* is allowed in our environment”
  * ✅ “Emily Eaton is approved to run `certutil.exe`”
    * These are high-value, specific facts.
  * ❌ “This is allowed”
    * This is not specific enough to be useful.

### Manual Notes and Guidance

* Just like senior analysts writing notes or runbooks, teams can manually add information to Context Memory that is not tied to a specific investigation
* There is no limit to the number of Context Memory items you can add and adding Context Memory does not slow down investigations
* It is good practice to periodically clean up Context Memory to avoid outdated information or conflicts as new items are added

### Automated Ingestion

* Backfill institutional knowledge using exports from systems such as:
  * Confluence
  * Jira
  * ServiceNow
* These sources can be programmatically ingested into the Dropzone platform.

## Building Context Memory Over Time

Just as training and coaching are most impactful during a new hire’s first 30 days, early investment in Context Memory gives Dropzone a strong foundation for long-term reference.

During onboarding, we recommend reviewing a set number of investigations per day to ensure your Dropzone analyst aligns with your team’s policies and expectations.

## Best Practices

* Continually add to your Context Memory bank by adjusting conclusions or uploading new facts as your environment evolves.
* Periodically review your Context Memory bank to ensure Dropzone has up-to-date information about your organization.

{% hint style="info" %}
Want to learn more about Context Memory? Check out our [**Context Memory Best Practices Guide**](/best-practices/context-memory).
{% endhint %}


# Settings

The **Settings** area in Dropzone is where advanced configuration, tuning, and administrative controls live. This includes organization-specific logic, automation, system visibility, and performance controls that influence how investigations run and how results are operationalized.

Settings is primarily used by **Admins** and power users to tailor Dropzone to their environment, workflows, and risk tolerance.


# AI Interviewer

The **AI Interviewer** enables automated, human-in-the-loop validation of investigation findings by conducting intelligent interviews with users involved in an alert.

This capability helps confirm or refute AI-derived conclusions using direct human input, improving accuracy while reducing analyst workload.

## How the AI Interviewer Works

1. **Initial Investigation Completion**\
   The AI completes an investigation and determines that human verification is required. This investigation will have an initial conclusion which can be used to create auto-approval rules for starting interviews. If a scenario does NOT cover auto approval then the interview will go into **pending** state until it is approved.
2. **Interview Proposal**\
   The system generates a proposed interview with targeted, context-aware questions.
3. **Auto-Approval Check**\
   Rules determine whether the interview is automatically approved or requires manual approval.
4. **Interview Execution**\
   The AI conducts the interview with the identified user using the configured communication channel.
5. **Result Integration**\
   Interview responses are incorporated directly into the investigation’s findings and final conclusion.

{% hint style="info" %}
Any changes to conclusion will be noted in the **change log** of the investigation and the entire will be available in the **investigations** detailed view for audit or review.
{% endhint %}


# Custom EBS Volume Encryption

Dropzone provides a CloudFormation Template (CFT) to automatically create Key Management Service (KMS) keys with the permissions Dropzone needs to encrypt the elastic block storage (EBS) volumes that back your Dropzone instance. Providing your own keys allows you full control over your data with the ability to cut off Dropzone's access as you see fit.

The key in your primary instance region is used to encrypt all data on your Dropzone instance. Because KMS keys are only usable within the key's region, Dropzone requires a second key in the region used to maintain a remote copy of instance backups.

Each key is created with automatic rotation enabled. To prevent accidental deletions, each key is retained if the CloudFormation stack is ever deleted.

Download the CFT YAML using the following link: <https://dropzone-public.s3.us-west-2.amazonaws.com/cloud-formation-templates/DropzoneAWSKeys_EBSVolumeKeys.yaml>

{% hint style="info" %}
An optional value for the `AliasName` value can be provided if you would like to change the default alias name given to the key.
{% endhint %}

## Deploying the CloudFormation Template

Dropzone supports two methods of deployment: Command Line Interface (CLI) deployment or Manual.

The user/role used to deploy this CFT must have the following permissions in your AWS account:

| Permission Name                       | Purpose                                                                                                                                                           |
| ------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| cloudformation:CreateChangeSet        | Allows the user to execute the [CreateChangeSet](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_CreateChangeSet.html) action               |
| cloudformation:DescribeChangeSet      | Allows the user to execute the [DescribeChangeSet](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_DescribeChangeSet.html) action           |
| cloudformation:ExecuteChangeSet       | Allows the user to execute the [ExecuteChangeSet](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_ExecuteChangeSet.html) action             |
| cloudformation:DescribeStacks         | Allows the user to execute the [DescribeStacks](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_DescribeStacks.html) action                 |
| cloudformation:DescribeStackEvents    | Allows the user to execute the [DescribeStackEvents](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_DescribeStackEvents.html) action       |
| cloudformation:DescribeStackResources | Allows the user to execute the [DescribeStackResources](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_DescribeStackResources.html) action |
| cloudformation:GetTemplate            | Allows the user to execute the [GetTemplate](https://docs.aws.amazon.com/AWSCloudFormation/latest/APIReference/API_GetTemplate.html) action                       |
| kms:CreateKey                         | Allows the user to create a unique KMS key                                                                                                                        |
| kms:DescribeKey                       | Allows the user to see the details of the KMS key                                                                                                                 |
| kms:PutKeyPolicy                      | Allows the user to attach a [key policy](https://docs.aws.amazon.com/kms/latest/developerguide/key-policies.html) to the KMS key                                  |
| kms:EnableKeyRotation                 | Allows the user to enable automatic rotation of the KMS key material                                                                                              |
| kms:CreateAlias                       | Allows the user to create a user-friendly name for the KMS key                                                                                                    |
| kms:UpdateAlias                       | Allows the user to associate an existing AWS KMS alias with a different KMS key                                                                                   |
| kms:DeleteAlias                       | Allows the user to delete the name of the KMS key                                                                                                                 |

### CLI Deployment

To complete CLI deployment, do the following:

* As an authenticated user with the required permissions and default AWS profile configured, `cd` into the directory where you downloaded the CFT
* Input the following text

```
# Replace xxxxxx with the region values provided by your Dropzone representative
INSTANCE_REGION=xxxxxx
BACKUP_REGION=xxxxxx

for region in $INSTANCE_REGION $BACKUP_REGION ; do
  aws cloudformation deploy --region "$region" \
    --template-file DropzoneAWSKeys_EBSVolumeKeys.yaml \
    --stack-name dropzone-ebs-key

  echo "$region $(aws cloudformation describe-stacks --region "$region" \
    --stack-name dropzone-ebs-key \
    --query 'Stacks[0].Outputs[?OutputKey==`KeyArn`].OutputValue' \
    --output text)"
done
```

* This should generate the key ARN values
* Send the lines with the key ARNs back to Dropzone to be applied to your instance

### Manual Deployment

You will need to deploy the CFT twice, once in the instance region and again in the backup region.

To complete manual deployment, do the following:

* Log into your AWS account
* Go to the CloudFormation console, <https://console.aws.amazon.com/cloudformation/>
* Click on "Create Stack" > "With new resources (standard)"

<figure><img src="/files/ZNBVfHb3ehBhPzk7jj0a" alt=""><figcaption><p>Create Stack Button</p></figcaption></figure>

{% hint style="warning" %}
If this is your first stack, then the option will not have "With new resources"

<img src="/files/XdYtPZEUWQDwAg0v61gv" alt="Create Stack Button" data-size="original">
{% endhint %}

* In the "Prerequisite - Prepare template" section, select "Upload a template file"
* Upload the CFT YAML file you downloaded earlier
* Click "Next"
* Enter a "Stack name", e.g. "Dropzone-AI"

<figure><img src="/files/h2XGkoJRztbyv9Zt4fwY" alt=""><figcaption><p>Stack Name</p></figcaption></figure>

* In the Parameters section, input the values for the parameters that were defined in the template
* Click "Next"
* On the "Configure stack options" page, click "Next"
* On the "Review and create" page, click "Submit"

<figure><img src="/files/x107LliDtoQ9Ykgl2ck9" alt=""><figcaption><p>Create the stack via the Submit button</p></figcaption></figure>

* Once the stack creation is complete, click "Resources"
* Record the key ARN value shown
* Once you are done, send both the primary and backup region key ARNs back to Dropzone to be applied to your instance


# Custom Strategies

*Available to Admins only*

**Custom Strategies** allow organizations to inject domain-specific judgment into Dropzone’s investigation outcomes. These strategies influence how the AI SOC Analyst determines both:

* **Conclusions:** Malicious, Suspicious, Benign
* **Priorities:** Urgent, Notable, Informational

Custom Strategies are applied during the **Report phase** of an investigation and enable teams to:

* Override default interpretations of investigative findings
* Encode institutional policies and known patterns
* Provide consistent guidance for recurring or edge-case alert types

Custom Strategies are best suited for **decision logic** that applies broadly across investigations. If you find yourself encoding conditional logic, workflows, or policy enforcement, a Custom Strategy is likely the right tool.

To learn more about how to create great Custom Strategies read our [Custom Strategies Best Practices Guide](/best-practices/custom-strategies)


# Response Actions and Automations

*Available to Admins only*

**Response Actions** (also referred to as Response Automations) allow you to automatically execute custom Python code when investigations complete. This enables seamless integration with external systems and consistent, repeatable response workflows.

Response Actions are commonly used to:

* Notify external systems
* Trigger remediation workflows
* Enrich tickets or records
* Apply policy-driven actions at scale

\### How Response Automations Work

### Execution Model

* **Trigger Events**\
  Dropzone has over 50 triggers to fire your Response Action. These range from Investigations complete with a specific status to a change of an API key.
* **Sandboxed Environment**\
  Code runs in an isolated container using **Python 3.11**.
* **Data Injection**\
  Investigation context and stored secrets are injected automatically as Python dictionaries. You can use the example script here to see the investigation variable and all information available to you using Response Actions.

{% hint style="info" %}
The variables avaiable can change depending on the trigger you use. Keep this in mind when planning/creating Response Actions.
{% endhint %}

* **Result Capture**\
  All output, errors, and execution status are logged for auditing and troubleshooting.

{% hint style="info" %}
Want to learn more? Check out our [**Building Reponse Automations and Actions Best Practices Guide**](/best-practices/how-to-build-response-automations-and-actions)
{% endhint %}


# System Events

*Available to Admins only*

**System Events** provide a complete audit trail of activity across your Dropzone tenant.

Use System Events to:

* Monitor user and system activity
* Export logs for external analysis
* Build custom reports or visualizations
* Support compliance and auditing workflows

System Events give administrators full visibility into how the platform is being used and how investigations progress over time.


# System Info

The **System Info** page provides a centralized view of your organization’s configuration, investigation limits, and performance benchmarks.

This information helps you:

* Understand how Dropzone is operating in your environment
* Track performance improvements over time
* Establish baselines for investigation throughput and efficiency

## Key Configuration Areas

* **Tenant Name**\
  Update the tenant name displayed on the Dashboard.
* **Generated Titles**\
  Enable AI-generated investigation titles for improved clarity and consistency.
* **Alert Deduplication**\
  Reduce alert noise by grouping related alerts together.
* **Investigation Thresholds**\
  Set limits based on time or alert source to prevent investigation overload or usage spikes.

System Info is especially important for tuning Dropzone during onboarding and as alert volume or operational needs evolve.


# On-prem Support - Dropzone Connector

Dropzone AI connects to APIs via its Data Source and Alert integrations. Many of these are reachable across the internet, such as third-party Threat Intelligence sources, corporate SaaS tools, and public cloud APIs. However many corporate systems may be behind firewalls and VPNs for security reasons.

Customers are able to enable Dropzone to reach restricted systems by running a lightweight Dropzone Private Network Connector Client docker container within their secure environment. This process connects out to the Dropzone tenant network and establishes a reverse tunnel.

<figure><img src="/files/ZGEfueJOZw6mXGfL0zBg" alt=""><figcaption><p>Dropzone Private Network Connector Architecture</p></figcaption></figure>

## Private Network Connector Security

The Dropzone Private Network Connector Client establishes an outbound HTTPS session, inside which [websockets](https://en.wikipedia.org/wiki/WebSocket) is used to establish a two-way TCP session. Over this TCP session a secure [SSH](https://en.wikipedia.org/wiki/Secure_Shell) session is established. Both client and server are mutually authenticated at two layers of the stack for maximum security:

* Dropzone server verification via TLS certificate verification
* Dropzone server via SSH server key verification
* Dropzone client connector via SSH \`password' verification

The Dropzone integrations that require access to the protected resources tunnel their connections through this Private Network Connector Client container, so their source IP is from within your datacenter.

The Private Network Connector Client can be run on any host capable of running Docker containers, such as a physical server, VM, or inside your public/private cloud environment.

For additional security you may restrict what outbound connections can be made from the connector machine to your internal resources. Examples include:

* Putting the connector machine on a firewall DMZ
* Enabling cloud-native restrictions on the connector machine (e.g. AWS Security Groups)
* Running local firewall rules on the connector machine (e.g. `iptables`, shorewall)

Just make sure that the connector machine can reach the machines you want integrated, on the ports/protocols needed, DNS, and your tenant machine on port 443.

## Connector FAQ

What are the network egress requirements for the Network Connector Client? : The Connector only needs outbound HTTPS (port 443) to your Dropzone environment.

How do I find my container image? : It is available for download from the Dropzone tenant - see the [Dropzone Connector Installation](/platform/settings/connector/connector-installation) page for details.

How often will I need to update the Connector Client? : Dropzone maintains backward compatiblity, so upgrades are only required to access new features or bug fixes. We always inform customers when new features are pushed, but you are not typically required to upgrade. We release a few versions per year.

What is the expected behaviour during network issues or other Connector Client failures? : When the connector is unavailable any investigations that would use on-prem resources will fail to reach them, which may decrease investigation accuracy. However the investigations will use whatever other sources are unaffected. Any alert sources that are unreachable will be retried when connectivity is restored.

What are the system requirements for running the Connector Client? : See the [Dropzone Connector Installation](/platform/settings/connector/connector-installation) page for system requirements.

## Connector Installation / Administration

We describe how to run the Dropzone connector in the [Dropzone Connector Installation](/platform/settings/connector/connector-installation) page.


# Dropzone Connector Installation

{% hint style="success" %}
Before proceeding, see the [Dropzone Connector Overview](/platform/settings/connector) for more information about when you would require the Dropzone Connector in your environment.
{% endhint %}

## Enabling the Private Network Connector Client <a href="#enable" id="enable"></a>

Running the Private Network Connector Client requires a machine that meets the following requirements:

* System
  * has Docker Engine (Docker CE) installed
  * capable of running x86\_64 Linux docker containers
  * has at least 1 GB of available memory
  * has at least 1 GB of available disk space
  * has access to at least one CPU core
    * assure it is not running on a system that will 'steal' CPU; doing so will introduce instability
* Network
  * can reach the resources (e.g. splunk) you want available for Dropzone integrations
  * can connect outbound port 443 to the connector server
    * the connector server is the same as your tenant name with `-connector` after the first component. For example if your tenant is https\://*mycompany*.dropzone.app then your connector server is *mycompany*-connector.dropzone.app port 443
  * has access to DNS that can look up your tenant DNS name and internal resources
* Availability
  * is up 24x7

This may be a machine dedicated to this container, or a multi-use resource that meets your security policy.

Henceforth we will call this machine the `connector-client-host`.

To install the Private Network Connector Client, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* Navigate to Settings > System Info

<figure><img src="/files/VDXkATwTwQqJXyMlAtxf" alt="" width="169"><figcaption><p>Settings > System Info Dropdown</p></figcaption></figure>

* Under Advanced Settings, check the box labeled "Enable Integration Connector"

<figure><img src="/files/iMqYEg01dfksHE5xeCnm" alt="" width="169"><figcaption><p>Click Enable Integration Connector</p></figcaption></figure>

* In the bottom left, click "Save"

<figure><img src="/files/47E9w59oJJf6n9riWGMB" alt="" width="169"><figcaption><p>Enable the Integration Connector</p></figcaption></figure>

* Once done, navigate to Settings > Connectors

<figure><img src="/files/et9hKsRhGTjaRqlS3klh" alt="" width="169"><figcaption><p>System > Connectors Dropdown</p></figcaption></figure>

* On the "Main" connector tile, click "Configure"

<figure><img src="/files/awYToLDmWtf13hgkQoSV" alt="" width="276"><figcaption><p>"Main" Connector Tile</p></figcaption></figure>

* The configuration drawer will slide out from the right hand side

<figure><img src="/files/LgZMCDdzuvEM42BIiagB" alt="" width="375"><figcaption><p>"Main" Connector Configuration</p></figcaption></figure>

* Download the Private Network Connector Client docker image by clicking on the link
* Upload the Private Network connector Docker image to the connector-client-host, e.g. via `scp`
* Load the docker image on the connector-client-host

  ```bash
  connector-client-host$ sudo docker load -i connector.tar.gz

  # Or, if sudo is not needed
  connector-client-host$ docker load -i connector.tar.gz
  ```
* Copy the command in the Dropzone UI and run it on the connector-client-host:

  ```bash
  connector-client-host$ sudo docker run --detach --name connector --env OPTIONS='--auth ...

  # Or if sudo is not needed
  connector-client-host$ docker run --detach --name connector --env OPTIONS='--auth ...
  ```
* Verify the connector is running by using `docker ps`

  ```bash
  connector-client-host$ docker ps
  CONTAINER ID IMAGE     COMMAND      CREATED         STATUS       NAMES
  1c92972436d9 connector "/app/init"  3 seconds ago   Up 2 seconds dropzone-connector-client
  ```
* Click Close
* Refresh the page and you should see that `Main` is now in "Connected" state:

<figure><img src="/files/tzeVmYGyHgmYPmZe2Ew9" alt="" width="268"><figcaption><p>Main Now Connected</p></figcaption></figure>

When enabling Data and Alert sources that need on-prem access, be sure to specify this Private Network Connector Client.

## Alternate Launch Options

The Dropzone UI System > Connector page provides a default `docker run` command that will work for most scenarios. This section describes alternate options for your `docker run` that may be appropriate for your environment.

### Outbound HTTP Proxy

The Dropzone connector supports using an outbound HTTP proxy, such as [Squid](https://www.squid-cache.org/), a setup for locked down DMZs for example.

To use an explicit HTTP proxy, update the `docker run` provided by the Dropzone UI by passing the `HTTPS_PROXY` flag into the environment:

```bash

## Send the outbound tunnel request via http://proxy.example.com:3128 
## Replace with your actual proxy url/port
##
$ docker run ... --env HTTPS_PROXY=http://proxy.example.com:3128 ...
```

You will need to configure your proxy to allow outbound `CONNECT` to the host *tenant*-connector.dropzone.app port 443.

## Troubleshooting

The following troubleshooting steps may be useful in conjunction with your Dropzone support team.

### Restarting the Private Network Connector Container

It is always safe to delete and relaunch the connector, for example if it does not come back properly after a reboot or system failure.

```bash
$ docker stop connector
$ docker rm connector
$ docker run ...    <-- command you got from the Dropzone interface
```

### Testing Internal Connectivity

The connector service runs in a docker container on a host in your network. If it is unable to reach to your internal systems then you will get an error when configuring your integration in the Dropzone UI such as `Error 111 - Connection Refused`.

#### Test from the Host

Testing from the host where you're running the connector is sufficient in almost all cases. Using tools such as `curl`, `telnet`, netcat (`nc`, `ncat`, etc), or `openssl` are good ways to test any network ACLs that may be preventing your traffic.

Examples:

```bash
# See if splunk is available
$ curl -k -v https://our-splunk.example.com

# Same, showing certificate
$ openssl sclient -connect our-splunk.example.com:443

# just test the port is open or not
$ telnet our-splunk.example.com:443
$ nc our-splunk.example.com:443
```

#### Test From Inside the Connector

It's possible your docker host can reach your targets, but the connector container cannot. this could be caused by DNS inconsistencies, or having an IP address range for your connector network (traditionally 172.17.0.0/16) that overlaps your target's networks. In these cases, it may be helpful to test from within the connector container directly.

The Dropzone connector container has a very minimal configuration and does not include tools such `curl`, `telnet`, netcat (`nc`, `ncat`, etc), however it does include `openssl` which can be used to help troubleshoot.

Here is an example of making a `curl`-like request for <https://www.example.com>:

```bash

$ host="www.example.com"
$ printf "GET / HTTP/1.0\nHost: $host\n\n" | \
    docker exec -i dropzone-connector-client   \
    openssl s_client -connect $host:443 -servername $host -quiet
```

If you see the expected HTML output, then the connector has network connectivity to the target.

### Testing Outbound Network Connectivity

If the connector fails to connect there could be a network issue or an IPS device that is preventing it from establishing the websocket connection. Running the following from the host where the connector runs can help identify this situation:

```bash
# the first part of your tenant hostname, e.g. "mycompany"
# if your tenant is https://mycompany.dropzone.app
$ tenant=mytenant

$ curl --http1.1 -i -N \
    -A "Go-http-client/1.1" \
    -H "Connection: Upgrade" \
    -H "Upgrade: websocket" \
    -H "Host: $tenant-connector.dropzone.app:443" \
    -H "Sec-WebSocket-Key: AAAAAAAAAAAAAAAAAAAAAA==" \
    -H "Sec-WebSocket-Protocol: chisel-v3" \
    -H "Sec-WebSocket-Version: 13" \
    "https://$tenant-connector.dropzone.app:443"
```

When successful, you should see an HTTP handshake and websocket upgrade like this:

```
HTTP/1.1 101 Switching Protocols
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Accept: ICX+Yqv66kxgM0FcWaLWlFLwTAI=

SSH-chisel-v3-server
```

{% hint style="success" %}
If your network requires an HTTP Proxy for outbound connectivity to the connector server, add an `-x` option to your `curl` command above. For example if you use squid on squid.example.com port 3128, you'd add `-x squid.example.com:3128` to the command.
{% endhint %}

Any device along the path that is interfering will likely provide feedback when this command is run.

### EDR/Firewall/IPS Considerations

The Dropzone Connector Client establishes outbound encrypted connections to your Dropzone SaaS environment which contain reverse tunnels to your on-prem systems. Unfortunately, because this traffic pattern can resemble a Command and Control (C2) client/server setup, some EDR, firewall, or networking tools may flag or block this traffic.

{% hint style="warning" %}
If the connector is mysteriously not working, check to see if your EDR is blocking the container process, or if an upstream network device is interfering with the connections.
{% endhint %}

Your security tools should allow you to allowlist the Connector Client binary or associated network traffic. Make the related changes and it should be able to support a reliable connection for your on prem services.

## Connector Healthchecks

The default Dropzone Private Network Connector Client `docker run` command is set to automatically restart the container if it fails. However here are additional ways you can healthcheck the container.

### External Healthcheck

From outside the container you can use `curl` or other web tools to hit the `/ping` endpoint. For example, assuming the connector has received IP address 172.17.0.3, you would use the following

```bash
$ curl -i 172.17.0.3:8000/ping
HTTP/1.1 204 No Content
Date: Sat, 19 Apr 2025 11:43:00 GMT
Server: Python/3.11 aiohttp/3.12.13
```

Similarly, you could use `nsenter` to run `curl` from your host within the container network:

```bash
$ sudo nsenter -t $(docker inspect --format '{{ .State.Pid }}' dropzone-connector-client ) -n  curl -v http://127.0.0.1:8000/ping`
```

### Internal Healthcheck

From within the container (e.g. if you are using `docker compose`) you can use `python` to healthcheck the `/ping` endpoint.

```bash
python3 -c "import http.client, sys; c=http.client.HTTPConnection('127.0.0.1',8000,timeout=5); c.request('GET','/ping'); sys.exit(0 if c.getresponse().status==204 else 1)"`
```

## Upgrading the Private Network Connector Client

Dropzone updates the connector client infrequently to improve reliability, performance, or security.

Follow these steps to upgrade.

* Identify the machine where you are currently running the connector (henceforth called "connector-client-host")
* Follow the steps in [Enabling the Private Network Connector Client](#enable) above to but not including running the new container
  * Download the connector docker image
  * Copy the image to your connector-client-host
  * Load the docker image (but do not run it yet)
* Log into the connector-client-host (e.g. via `ssh`)
* Permanently stop the old Dropzone connector container
  * If you followed the default `docker run` instructions then it will be named `dropzone-connector-client`, but you may have named it differently

```bash
# Verify it not running
$ docker ps | grep dropzone
CONTAINER ID  IMAGE                COMMAND          NAMES
44726f707a6f  dropzone-connector   "/app/main.py"   dropzone-connector-client

# Stop and remove it
$ docker stop dropzone-connector-client
$ docker rm dropzone-connector-client

# Verify it is not running
$ docker ps | grep dropzone
CONTAINER ID  IMAGE                COMMAND          NAMES
```

* Start the new connector container by copy/pasting the command from your Dropzone UI
  * This is described above in [Enabling the Private Network Connector Client](#enable)

## Disabling the Private Network Connector Client

You may disable the Private Network Connector Client at any time. This is typically done when you are migrating the Connector Client to a different host virtual machine.

{% hint style="warning" %}
Disabling your Private Network Connector Client will prevent the Dropzone platform from reaching your "on-prem" services. You should only disable it when migrating to a new Connector Client host, or when no longer needed such as at the end of your POC or contract.
{% endhint %}

To disable it, simply run the necessary `docker` commands.

```bash
# Stop and remove it
$ docker stop dropzone-connector-client
$ docker rm dropzone-connector-client

# Verify it is not running
$ docker ps | grep dropzone
CONTAINER ID  IMAGE                COMMAND          NAMES
```

As soon as the container is stopped the remote access is instantly terminated.

You can verify by going to System > Connectors and you should see "Not connected"

<figure><img src="/files/awYToLDmWtf13hgkQoSV" alt="" width="276"><figcaption><p>Connector now Disconnected</p></figcaption></figure>

***

If you have any errors engage your Dropzone AI support representative.


# Account and Team Admin

The Team Admin page is used to manage users in Dropzone, specifically if using local Authorization.

For a breakdown of the Roles and Permissions possible please visit our [Roles & Permissions page](/dropzone-101/getting-started/roles-and-permissions)

For additional information on using SSO please visout our [Managing Users with SAML/SSO page](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/dropzone-101/getting-started/accessing-tenants/managing-users.md)


# Metrics Guide

## Introduction

While reviewing Response Metrics on your dashboard, you'll encounter several acronyms such as **MTTD**, **MTTA**, **MTTI**, and **MTTC**. Understanding these terms is essential for effectively managing your Security Operations Center (SOC) workflows.

We totally get that these metrics can seem like alphabet soup, especially if you're new to them or if there's one that's unfamiliar. In fact, [**we at Dropzone AI coined the term Mean Time to Conclusion (MTTC)**](https://www.dropzone.ai/blog/understanding-soc-metrics-introducing-mean-time-to-conclusion-mttc) to help illustrate how our product fits seamlessly into your existing Security Operations Center (SOC) workflows. Whether you’re new to these concepts or just need a refresher, we’re here to make everything clear and manageable.

This guide is designed to offer a comprehensive understanding of these key metrics. We’ll break down each term, explore how they connect, and show you how Dropzone AI can streamline and enhance your SOC operations for greater efficiency and effectiveness.

We invite you to explore this guide to gain deeper insights into these important metrics and discover how they can benefit your organization.

## Key SOC Metrics

Let's kick things off talking about what metrics Dropzone measures, and how each measurement is defined:

| **Metric**             | <p><strong>Mean Time to Detect</strong><br><strong>(MTTD)</strong></p>                  | <p><strong>Mean Time to Acknowledge</strong><br><strong>(MTTA)</strong></p>                                   | <p><strong>Mean Time to Investigate</strong><br><strong>(MTTI)</strong></p>                                                      | <p><strong>Mean Time to Conclusion</strong><br><strong>(MTTC)</strong></p>                                                                          |
| ---------------------- | --------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Definition**         | The average time your security tools take to detect suspicious activity after it occurs | The average time between an alert being generated and an analyst acknowledging it                             | The average time it takes an analyst to dive into an alert and identify is activity is a false positive or needs to be escalated | <p>The average time from when suspicious activity happens to when a conclusion is made<br><br>Or in other words, the sum of the other 3 metrics</p> |
| **Why It Matters**     | The quicker you detect an incident, the less damage can be done by attackers            | Alerts are like hot potatoes—you don't want them sitting around! A speedy MTTA means your team is on the ball | Efficiency is key. A lower MTTI means quicker resolutions                                                                        | MTTC shows how efficiently your SOC handles all alerts, benign or malicious                                                                         |
| **Dropzone AI's Role** | We don't directly influence MTTD but ensure visibility into this metric                 | We reduce MTTA by kicking off investigations immediately when alerts pop up                                   | We automate routine tasks, slashing MTTI                                                                                         | By reducing both MTTA and MTTI, we make a big dent in MTTC, boosting SOC performance                                                                |

## Understanding MTTC

So, what's the big deal with MTTC? Glad you asked!

**MTTC covers the entire journey of an alert:**

1. **Detection:** When your security system spots something fishy
2. **Acknowledgment:** When the alert is logged, and someone (or something) starts looking into it
3. **Investigation:** The nitty-gritty analysis to figure out what's going on
4. **Conclusion:** Deciding whether it's a false alarm or if action is needed

### Why MTTC Matters

Traditional metrics are great, but they often focus on specific parts of the process. **MTTC gives you the whole picture.**

* **Comprehensive Insight:** See how efficiently your SOC handles *all* alerts
* **Efficiency Measurement:** Spot bottlenecks and areas ripe for improvement
* **Resource Optimization:** Allocate your team's time where it counts
* **Stronger Security Posture:** Faster conclusions mean threats are nipped in the bud

## The Power of Statistical Measures

We believe in going beyond just averages. That's why Dropzone AI captures three key statistical measures for each metric: **Mean, Median, and the 95th Percentile**.

| **Measurement** | **Mean (Average)**                                                       | **Median**                                                               | **95th Percentile**                                                   |
| --------------- | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | --------------------------------------------------------------------- |
| **What It Is**  | Add up all the times and divide by the number of investigations          | The middle value when you line up all the times from shortest to longest | The time under which 95% of your cases fall                           |
| **Pros**        | Gives you an overall sense of performance                                | Not swayed by outliers. Represents the "typical" case                    | Highlights the slowest 5% of cases—those alerts that take the longest |
| **Cons**        | Can get thrown off by outliers (those really long or really short times) | Doesn't show the range of variation                                      | Might overemphasize rare, extreme cases                               |

### **Why Use All Three?**

* **Full Spectrum Analysis:** Understand both the typical and exceptional cases
* **Outlier Detection:** Spot those pesky alerts that take too long
* **Informed Decisions:** Make smarter choices about where to focus your efforts

## How Dropzone AI Supercharges Your Metrics

### Making a Real Impact

#### Slashing MTTA:

* **Parallel Processing**: Dropzone AI handles multiple investigations at once, so nothing gets left behind
* **Immediate Action**: We start processing alerts the right after they're detected

#### Reducing MTTI:

* **Automation**: We handle the routine investigation steps, freeing your analysts for more complex tasks
* **Consistent Performance:** Faster investigations across the board

#### MTTC Improvement:

* **Combined Effect**: By cutting down MTTA and MTTI, we significantly lower your MTTC

### Transparency and Collaboration

We believe in open conversations and teamwork.

* **Shared Insights**: Get detailed metrics and reports at your fingertips
* **Open Communication**: Provided metrics facilitate discussions on time saved, efficiency gains, and areas for improvement - Let's discuss how to make things even better
* **Value Demonstration**: See the tangible benefits Dropzone AI brings to your SOC

***

## Frequently Asked Questions (FAQ)

### How is MTTC different from MTTD and MTTR?

**MTTC** covers the whole journey of every alert, from detection to final decision, whether it's benign or malicious. **MTTD** focuses on how quickly your tools detect incidents, and **MTTR** measures the time to respond to incidents requiring action.

### Does MTTC include benign alerts?

Absolutely! **MTTC** accounts for all alerts. By including benign ones, you get insights into how efficiently you're handling everything that comes your way.

### Will focusing on MTTC improve our security posture?

You bet! Lowering **MTTC** means faster threat mitigation, better resource use, and a more proactive security stance overall.

### Why doesn't Dropzone AI measure MTTR?

**MTTR** deals with actions after the investigation phase (like containment and recovery). Since we focus on triage and investigation (**MTTA** and **MTTI**), we don't measure **MTTR** directly. But by speeding up the earlier phases, we help the overall response process move faster.

### Can Dropzone AI reduce times across all metrics?

We don't influence **MTTD** (that's before the alert gets to us), but we definitely help with **MTTA** and **MTTI**. By reducing those, we make a significant dent in **MTTC**.

### How does Dropzone AI's transparency benefit our SOC?

Transparency fosters collaboration. You'll see where time is saved, understand our impact, and we can work together to keep improving.

### Why provide mean, median, and 95th percentile for each metric?

Because one size doesn't fit all! Using all three measures gives you a comprehensive understanding, helping you make more informed decisions.

### How can the 95th percentile help improve our operations?

It shines a light on the slowest cases. By analyzing these outliers, we can find ways to streamline processes and reduce delays.

### Can Dropzone AI affect MTTD at all?

Not directly. **MTTD** is about detection before we step in. But we provide visibility into **MTTD** so you have all the info you need.

### How does Dropzone AI facilitate open conversations about performance?

With detailed metrics and transparent reporting, we enable data-driven discussions, performance tracking, and collaborative planning.

***

*This document is intended for Dropzone AI customers to enhance understanding of key SOC metrics, the benefits of using mean, median, and 95th percentile measures, and how Dropzone AI improves Mean Time to Conclusion (MTTC) and overall SOC performance through transparency and collaborative insights.*


# Dropzone Integrations

The Dropzone platform supports four types of integrations. Many integrations span multiple categories. For example, CrowdStrike can function as both an alert source and a data source. In addition to these integration types, Dropzone includes Enrichment Tools that enhance investigations without requiring third-party configuration. These are available on the full [Integrations page](https://www.dropzone.ai/integrations) and directly in your tenant under Provided Integrations. Dropzone also offers an API for additional flexibility when integrating with your existing tools and workflows.

Click into each category below to learn more about the integration type and review setup documentation.

[Alert Sources](https://docs.dropzone.ai/integrations/alert)

The Dropzone platform creates Investigations based on alerts from Alert Sources. Dropzone has support for many Alert Sources, such as SIEMs, Clouds providers, EDR, and ticketing systems.

[Data Sources](https://docs.dropzone.ai/integrations/data)

Data Sources enrich the information Dropzone uses to perform alert investigations and respond to interactive chat. Dropzone has support for many Threat Intelligence (TI) feeds, tools, and corporate systems such as identity, directory, and SIEM tools.

{% hint style="info" %}
Enabling more data sources enhances Dropzone analysis, just like more institutional knowledge improves a SOC analyst's capabilities. The Dropzone platform dynamically determines which sources may be useful for enriching investigations, so you should consider enabling as many as you can.
{% endhint %}

[Communicators](https://docs.dropzone.ai/integrations/communicator)

Communicator Integrations allow the Dropzone platform to ask questions of your employee base and use their responses to improve the quality of analysis via our AI Interviewer feature. Want to notify your team of an investigation? You’re able to do that and so much more via our Response Actions feature (more information here).

[Remediators](https://docs.dropzone.ai/integrations/remediator)

Remediator Integrations enable the Dropzone platform to take containment and remediation actions during malicious instances, when initiated by you. These integrations give you the ability to respond directly within Dropzone, helping you reduce dwell time and mitigate threats more effectively. Want 0-click remediations? You’re able to set those up and so much more via our Response Actions feature (more information here).

{% hint style="warning" %}
Our documentation lags our product functionality - there are many integrations that currently lack pages here on <https://docs.dropzone.ai>. If you don't see something you need, engage your Dropzone AI team.
{% endhint %}


# Alert Integrations

These integrations are Alert Sources.

The Dropzone platform creates Investigations based on alerts from Alert Sources. Dropzone has support for many Alert Sources, such as SIEMs, Clouds providers, EDR, and ticketing systems.

For more details about Alert sources see the [Alert Sources](/dropzone-101/terms-and-defs/alert-sources) page.


# Amazon Web Services (AWS)

## Amazon Web Services (AWS)

The Dropzone AI platform integrates with Amazon Web Services (AWS) APIs for ingesting alerts (AWS GuardDuty) and enriching investigations with data from AWS such as CloudWatch.

Dropzone creates a separate IAM role for each customer. This document describes how to enable the Dropzone role to access your AWS environment and configure the Dropzone platform.

### Integration Overview

To enable these integrations you will perform the following actions:

* Enable Cross-Account Access
  * Create an IAM role in your account(s)
  * Attach policies to the role
* Enable the Dropzone Data Source
* Enable the Dropzone Alert Source

The Dropzone platform has a dedicated IAM role for your organization. You enable cross-account access for this IAM to gain access to specific roles within your AWS accounts.

{% hint style="info" %}
These instructions will work for any account, but you may have different methods for applying them, for example if you are using Control Tower or deploying changes via Infrastructure as Code.
{% endhint %}

You must complete these steps for all AWS accounts you wish accessible by Dropzone.

### Enable Cross-Account Access

You need to enable Dropzone to acces your AWS environments for it to pull alerts and run investigations. There are several ways you can achieve this:

| Toolset                                 | Documentation                                                           | Description                                                                                                                                                                                                                           |
| --------------------------------------- | ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Set up roles via the Management Console | [documentation](/integrations/alert/aws_alert/aws-console_alert)        | Set up roles and create policies in the AWS Console. Several manual steps, highly documented                                                                                                                                          |
| Set up Role Chaining                    | [documentation](/integrations/alert/aws_alert/aws-role-chain_alert)     | Use a central Hub role to access multiple accounts via a consistent role pattern                                                                                                                                                      |
| Use AWS CloudFormation                  | [documentation](/integrations/alert/aws_alert/aws-cloudformation_alert) | Set up roles by running Dropzone's CFTs and copy/pasting in a small number of values                                                                                                                                                  |
| Use Infrastructure-as-Code / CLI / etc  | see your provider's information                                         | You can create your own IaC by looking at the role and policy information in the [management console](/integrations/alert/aws_alert/aws-console_alert) documentation. Dropzone does not provide any pre-canned IaC code at this time. |

The following policies are required for full Dropzone functionality:

| Policy                           |
| -------------------------------- |
| `AWSCloudTrail_ReadOnlyAccess`   |
| `AmazonEC2ReadOnlyAccess`        |
| `AmazonGuardDutyReadOnlyAccess`  |
| `AmazonRoute53ReadOnlyAccess`    |
| `AmazonS3OutpostsReadOnlyAccess` |
| `AmazonS3ReadOnlyAccess`         |
| `AmazonSSMReadOnlyAccess`        |
| `IAMReadOnlyAccess`              |

Be sure to use one of the above options to enable the cross-account access before moving on to enabling the integrations.

## Enable Amazon Web Services

The Alert source integration allows Dropzone AI to pull alerts from AWS GuardDuty for investigation.

You'll need the following information:

| Dropzone Field | Source                                                 |
| -------------- | ------------------------------------------------------ |
| Default Region | The AWS region you run most of your services in        |
| Role ARNs      | The ARNs of the AWS roles you created in your accounts |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the Alert Source heading, enter an AWS region into the "Default Region" field, such as "us-west-1"

{% hint style="success" %}
This should be the region that the majority of your monitored resources live in
{% endhint %}

* Unless using role chaining, leave the Hub Role ARN field blank
* Under "Role ARNs," click "Add Item," then input the role ARNs that you created earlier. Input each role ARN individually

<figure><img src="/files/uf7R3LluiHC3gXxcY3mX" alt=""><figcaption><p>The AWS Alert Source configuration (pt 1)</p></figcaption></figure>

* Under "Minimum Severity Level," select the minimum alert severity level you want Dropzone to investigate alerts for
* If you wish to allow Dropzone to investigate alerts that have been archived, check the box next to "Include Archived Alerts"
* If you wish, you may exclude AWS GuardDuty alerts by [finding type](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_finding-types-active.html). To do so, under the AWS "GuardDuty Alert Exclusions" section, click "Add Item." Then input the alert type you wish to exclude in the form of a string

<figure><img src="/files/Wl005ohj0ou0QmihZ6kD" alt=""><figcaption><p>The AWS Alert configuration (pt 2)</p></figcaption></figure>

* Input your desired poll interval and poll lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The AWS Alert configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The AWS Alert configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Cross-Account Access via CloudFormation

{% hint style="info" %}
There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See [the AWS documentation](/integrations/alert/aws_alert) for more info.
{% endhint %}

Dropzone provides CloudFormation Templates (CFTs) that assist you in creating the IAM Role you need to integrate with Dropzone. The new role includes a custom trust policy, an AWS-managed ReadOnlyAccess policy, and an inline policy granting specific permissions for secure and streamlined Dropzone operations.

There are two CFTs available:

| Name             | CFT Link                                                                                                              | Purpose                                                                                                                                                                                                                        |
| ---------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ReadOnly         | [link](https://dropzone-public.s3.us-west-2.amazonaws.com/cloud-formation-templates/DropzoneAWSRole_ReadOnly.yaml)    | This policy provides read-only access to all your AWS resources. Use this if you do not want to edit your role if more permissions are required in the future.                                                                 |
| Minimum ReadOnly | [link](https://dropzone-public.s3.us-west-2.amazonaws.com/cloud-formation-templates/DropzoneAWSRole_MinReadOnly.yaml) | This policy provides read-only access to only those AWS resources currently needed by Dropzone. Use this if you are prepared to edit your Policies in the future if Dropzone adds new functionality that requires more access. |

Both create a Custom Trust Policy that ensures secure role assumption by Dropzone, using the provided External ID and User ARN.

The current Minimum ReadOnly access list is as follows:

| Policy                           |
| -------------------------------- |
| `AWSCloudTrail_ReadOnlyAccess`   |
| `AmazonEC2ReadOnlyAccess`        |
| `AmazonGuardDutyReadOnlyAccess`  |
| `AmazonRoute53ReadOnlyAccess`    |
| `AmazonS3OutpostsReadOnlyAccess` |
| `AmazonS3ReadOnlyAccess`         |
| `AmazonSSMReadOnlyAccess`        |
| `IAMReadOnlyAccess`              |

## Find the Dropzone IAM Role Information

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the "Connection" section, record the `ARN` and `EXTERNAL ID` values, for use later in the AWS CloudFormation UI

<figure><img src="/files/VS7fvETTaeuuyJjHd8bB" alt="" width="296"><figcaption><p>The AWS Connection Information</p></figcaption></figure>

## Running the CloudFormation Template

You will need to repeat these instructions for each account you want to be visible to Dropzone.

* Log into your AWS account
* Go to the CloudFromation console, <https://console.aws.amazon.com/cloudformation/>
* Click on "Create Stack" > "With new resources (standard)"

<figure><img src="/files/ZNBVfHb3ehBhPzk7jj0a" alt=""><figcaption><p>Create Stack Button</p></figcaption></figure>

{% hint style="warning" %}
If this is your first stack, then the option will not have "With new resources"

<img src="/files/XdYtPZEUWQDwAg0v61gv" alt="Create Stack Button" data-size="original">
{% endhint %}

* In the "Prerequisite - Prepare template" section, select "Choose an exiting template"
* In the "Specify template" section, select "Amazon S3 URL"
* In the "Amazon S3 URL" field, input the link to the CFT you've chosen to use (e.g. ReadOnly) from the table at the top of this document

<figure><img src="/files/Vkr6gBzHnjP4IWUkmEmA" alt=""><figcaption><p>Template specification</p></figcaption></figure>

* Click "Next"
* Enter a "Stack name", e.g. "Dropzone-AI"

<figure><img src="/files/h2XGkoJRztbyv9Zt4fwY" alt=""><figcaption><p>Stack Name</p></figcaption></figure>

* In the Parameters section fill out the information you gathered from the Dropzone UI

<figure><img src="/files/8noXAX3toLD4mNi2tSNj" alt=""><figcaption><p>Stack Paramaters</p></figcaption></figure>

* Click "Next"
* On the "Configure stack options" page click "Next"
* On the "Review and create" page click "Submit"

<figure><img src="/files/x107LliDtoQ9Ykgl2ck9" alt=""><figcaption><p>Create the stack via the Submit button</p></figcaption></figure>

* Once the stack creation is complete, click Outputs
* Record the RoleARN value shown for use later in the Dropzone UI where it will referred to as "Role ARNs"

<figure><img src="/files/RdvHgsrtVXuLqgICpA6L" alt=""><figcaption><p>Output Role ARN</p></figcaption></figure>

* If you have additional AWS accounts, repeat the process for each of them

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in [the AWS documentation](/integrations/alert/aws_alert)


# Cross-Account Access via Console

{% hint style="info" %}
There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See [the AWS documentation](/integrations/alert/aws_alert) for more info.
{% endhint %}

The following steps walk you through creating a role and granting it to the Dropzone-provided role in the AWS console. This also has the information you'd need to create your own Infrastructure-as-Code configuration if you choose.

### Find the Dropzone IAM Role Information

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the "Connection" section, record the `ARN` and `EXTERNAL ID` values, for use later in the AWS CloudFormation UI

<figure><img src="/files/VS7fvETTaeuuyJjHd8bB" alt="" width="296"><figcaption><p>The AWS Connection Information</p></figcaption></figure>

### Create the Role

Next you'll create a role in the AWS account you want monitored and available.

You'll need the following information:

| Value                         | Used In                           | Source                                                                    |
| ----------------------------- | --------------------------------- | ------------------------------------------------------------------------- |
| Dropzone-provided ARN         | AWS Role Custom Trust Policy JSON | `ARN` value from the AWS Data Source "Connection" section                 |
| Dropzone-provided External ID | AWS Role Custom Trust Policy JSON | `External ID` value from the AWS Data Source "Connection" section         |
| AWS Account ID                | Custom Permissions Policy JSON    | Find this in the user/role dropdown in the upper right of the AWS console |

* Log in to the AWS Management Console for the account where you want to create the role
* Open the Identity Access and Management (IAM) dashboard

<figure><img src="/files/yfaZ0ANCaRbvtsE866me" alt=""><figcaption><p>IAM</p></figcaption></figure>

* From the left navigation, select "Access Management" > Roles
* Click "Create Role"

<figure><img src="/files/ET6xbbywEpOt7f6lxwg8" alt=""><figcaption><p>Create Role</p></figcaption></figure>

* Click "Custom Trust Policy"

<figure><img src="/files/yfRkpcM6e0WHzSEDxuRR" alt=""><figcaption><p>Custom Trust Policy Selection</p></figcaption></figure>

* In the text field below, paste the following policy, replacing the `<Dropzone-provided User ARN>` and `<Dropzone-provided External ID>` strings with the values from the Dropzone UI you recorded earlier:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "<Dropzone-provided User ARN>"
            },
            "Action": "sts:AssumeRole",
            "Condition": {
                "StringEquals": {
                    "sts:ExternalId": "<Dropzone-provided External ID>"
                }
            }
        }
    ]
}
```

* In the bottom right, click "Next"
* You'll now be on the "Add Permissions" page where you can add AWS pre-built policies

<figure><img src="/files/ZHmxDUdjfW6Erql2vRzD" alt=""><figcaption><p>Add Permissions page</p></figcaption></figure>

* You may add policies in one of two ways. You may add the `ReadOnlyAccess` policy, which will allow Dropzone to have all policies needed even in the future, or add the following policies one-by-one

| Policy                           |
| -------------------------------- |
| `AWSCloudTrail_ReadOnlyAccess`   |
| `AmazonEC2ReadOnlyAccess`        |
| `AmazonGuardDutyReadOnlyAccess`  |
| `AmazonRoute53ReadOnlyAccess`    |
| `AmazonS3OutpostsReadOnlyAccess` |
| `AmazonS3ReadOnlyAccess`         |
| `AmazonSSMReadOnlyAccess`        |
| `IAMReadOnlyAccess`              |

* Click "Next" when done adding policies
* Give the new role the name "Dropzone\_AI"

<figure><img src="/files/YFkjMJLExLpojbirPXJk" alt=""><figcaption><p>Role Name</p></figcaption></figure>

* In the bottom right, click "Create Role"

<figure><img src="/files/ET6xbbywEpOt7f6lxwg8" alt=""><figcaption><p>Create Role</p></figcaption></figure>

* Navigate to "Identity and Access Management (IAM)" > "Access Management" > "Roles"
* Search for the new role and click on it

<figure><img src="/files/KniWYbKwhS4MevEZ67ng" alt=""><figcaption><p>Find the Role</p></figcaption></figure>

* In the middle of the page, you'll see "Permissions Policies"

<figure><img src="/files/nUO7GZM4BHJ0I5u2xbxv" alt=""><figcaption><p>Permissions Policies</p></figcaption></figure>

* Click "Add Permission"
* Select "Create Inline Policy"

<figure><img src="/files/v428C8z9WKh16GkiyTnt" alt=""><figcaption><p>Create Inline Policy Option</p></figcaption></figure>

* In the text field, paste the following policy, replacing the `<your_accountnumber>` strings with this AWS account ID:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "CloudTrailStartQuery",
            "Effect": "Allow",
            "Action": [
                "kms:Decrypt",
                "kms:GenerateDataKey",
                "cloudtrail:StartQuery"
            ],
            "Resource": [
                "arn:aws:kms:*:<your_accountnumber>:key/*",
                "arn:aws:cloudtrail:*:<your_accountnumber>:eventdatastore/*"
            ]
        },
        {
		 "Sid": "EKSReadOnly",
		 "Effect": "Allow",
		 "Action": [
		     "eks:Describe*",
		     "eks:List*"
		 ],
		 "Resource": "*"
	  }

    ]
}
```

<figure><img src="/files/XvGi5l1VAwNO7J2Txgcx" alt=""><figcaption><p>Custom Permissions JSON</p></figcaption></figure>

* Click "Next"
* Give the new permission the name "Dropzone\_AI\_Additional"
* Click "Create Policy"

You should be returned to the `Dropzone_AI` role page and see the policies you've added, including the custom policy.

* Record the ARN for this role for use later in the Dropzone UI when configuring the Dropzone Data and Alert Sources, where it will be referred to as the "Role ARN"

<figure><img src="/files/qobQa6BPQcbqz1G5i1xL" alt=""><figcaption><p>AWS Role Page</p></figcaption></figure>

## Repeat For Additional AWS Accounts

Repeat the steps taken in the "Create the Role" section for all other AWS accounts you want visible to Dropzone.

{% hint style="info" %}
Make sure you're keeping a list of all the role ARNs you create along the way - you'll need them later.
{% endhint %}

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in [the AWS documentation](/integrations/alert/aws_alert)


# Cross-Account Access via Role Chaining

## Enable AWS Cross-Account Access via Role Chaining

Dropzone supports an advanced multi-account access pattern using role chaining. This allows Dropzone to access a large number of AWS accounts by authenticating with a single "Hub" role, which then assumes "Target" roles in your member accounts. This simplifies configuration by reducing the number of explicit credentials needed in Dropzone and enables flexible pattern-based access.

### Architecture

The role chaining pattern involves three main components:

* Dropzone Identity: The initial identity (AWS User/Role) that assumes the Hub Role
* Hub Role: A central role (e.g., in a Security or Management account) that trusts Dropzone and has permission to assume Target Roles
* Target Roles: Roles in your member/workload accounts that trust the Hub Role

<figure><img src="/files/q37YjmvjfNrG7lGEOwTX" alt=""><figcaption><p>The Role Chaining Pattern</p></figcaption></figure>

### Create the Hub Role

* See the [Cross-Account Access via Console](/integrations/alert/aws_alert/aws-console_alert) page for instructions on how to create a role in AWS
  * You must create the Hub role (e.g. `DropzoneChainHub`) in your central account; this role acts as the gateway for Dropzone
* In the place of the "Trust Policy," input the following:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "<Dropzone-provided User ARN>"
            },
            "Action": "sts:AssumeRole",
            "Condition": {
                "StringEquals": {
                    "sts:ExternalId": "<Dropzone-provided External ID>"
                }
            }
        }
    ]
}
```

* Add the permissions policies listed in the [Cross-Account Access via Console](/integrations/alert/aws_alert/aws-console_alert) page
* Once you have created the role, add the following custom permission policy:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "sts:AssumeRole",
            "Resource": "arn:aws:iam::*:role/DropzoneChainTarget"
        }
    ]
}
```

{% hint style="info" %}
For the purposes of this documentation, the Target Account roles are named `DropzoneChainTarget` and the Hub Role is named `DropzoneChainHub`.

This policy allows the Hub role to assume the target roles in your member accounts. You can restrict the resource to specific role names or paths.
{% endhint %}

### Create the Target Roles

* See the [Cross-Account Access via Console](/integrations/alert/aws_alert/aws-console_alert) page for instructions on how to create a role in AWS
  * You must create a role (e.g. `DropzoneChainTarget`) in each member account you want Dropzone to access
* In the place of the "Trust Policy," input the following:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::<MY_HUB_ACCOUNT_ID>:role/DropzoneChainHub"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
```

{% hint style="info" %}
This policy allows the Hub Role to assume the target role. Be sure to replace `<MY_HUB_ACCOUNT_ID>` with the AWS Account ID where the Hub role resides.
{% endhint %}

* Add the permissions policies listed in the [Cross-Account Access via Console](/integrations/alert/aws_alert/aws-console_alert) page

## Enable the Dropzone Alert Source

* Follow instructions in the [Amazon Web Services](/integrations/alert/aws_alert) overview page to enable the Alert Source
* In the Hub Role ARN field, input the ARN of the Hub Role you configured earlier, e.g. `arn:aws:iam::936862572175:role/DropzoneChainHub`
* In the Role ARNs field, input the ARNs of the Target Roles you configured earlier, e.g. `arn:aws:iam::{account_id}:role/DropzoneChainTarget`

Once done, Dropzone will use the Hub role to discover and assume the Target role in any relevant AWS account during investigations.

If you have any errors engage your Dropzone AI support representative.


# Cato Networks

## Cato Networks

The Dropzone platform integrates with [Cato Networks](https://www.catonetworks.com/), a cloud-native Secure Access Service Edge (SASE) platform that provides capabilities such as SD-WAN, secure web gateway (SWG), firewall-as-a-service (FWaaS), zero trust network access (ZTNA), and cloud access security broker (CASB).

By integrating with Cato Networks, Dropzone AI can leverage network and VPN telemetry to enhance security investigations by analyzing network traffic associated with alerts, identifying devices behind IP addresses, and correlating user and VPN activity across the environment.

## Obtain Account ID and API Key

Cato Networks requires an Account ID and an API key to enable. You will need access to an account administrator with the Editor privilege to generate keys.

To locate your Account ID, do the following:

* Log in to your Cato Networks account
* In the URL, locate the four-digit integer and copy it for use later in the Dropzone UI where it is called "Account ID"

<figure><img src="/files/7xurzA63UKzv4qFuoulz" alt=""><figcaption><p>The Account ID</p></figcaption></figure>

To generate an API key, do the following:

* In the upper banner of your Cato Networks homepage, click "Administration"

<figure><img src="/files/lHRIw2C5VrvZoRrQKOEj" alt=""><figcaption><p>Navigate to "Administration"</p></figcaption></figure>

* In the right, click "API Management"

<figure><img src="/files/bNxijCshBbOhgoWOs0AK" alt=""><figcaption><p>Click "API Management"</p></figcaption></figure>

* Click "\* New"

<figure><img src="/files/39MqHGdOFF4mQAZN5OYr" alt=""><figcaption><p>Click New</p></figcaption></figure>

* Name the API key something memorable, such as Dropzone AI
* Under "API Permission," click "View"
* Under "Allow access from IPs," click "Any IP"
* If you wish, assign the API key an expiration date
* Click "Apply"

<figure><img src="/files/AUShMCOoJv19DOR5X8r9" alt=""><figcaption><p>Create New API Key</p></figcaption></figure>

* Copy the API key shown for use later in the Dropzone UI where it is called "API Key"

### Enable Cato Networks

To enable the Dara Source integration, you will need the following information:

| Dropzone Field         | Source                                                                 |
| ---------------------- | ---------------------------------------------------------------------- |
| Cato Networks API FQDN | The FQDN of your Cato Networks API instance, e.g. api.catonetworks.com |
| Account ID             | The Account ID value you copied earlier                                |
| API Key                | The API key value you copied earlier                                   |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Cato Networks, then click "Configure"

<figure><img src="/files/rRqL8CVcWuisJ6cKAMOE" alt=""><figcaption><p>The Cato Networks tile</p></figcaption></figure>

* Under the Alert Source heading, input the Cato Networks API FQDN, Account ID and API Key

<figure><img src="/files/Qol31NM7khVWgNLCgezx" alt=""><figcaption><p>The Cato Networks Alert Configuration (pt 1)</p></figcaption></figure>

* In the Action Filter section, select the events you want Dropzone to ingest

{% hint style="info" %}
Cato Networks assigns actions to each event that occurs in your account, which Dropzone then uses to filter. For more information, click [here](https://support.catonetworks.com/hc/en-us/articles/5131416221085-Understanding-Event-Fields)
{% endhint %}

<figure><img src="/files/5uvwFvnZr3btGtlxLHPR" alt=""><figcaption><p>The Cato Networks Alert Configuration (pt 2)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Cato Networks Alert Configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Cato Networks Alert Configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Check Point Harmony Email & Collaboration

{% hint style="warning" %}
This is a beta feature that requires manual enablement by Dropzone support for your tenant. The integration will not be visible in the Dropzone UI until it has been enabled. Please contact your Dropzone AI support representative before attempting to set up this integration.
{% endhint %}

The Dropzone AI platform integrates with Check Point Harmony Email & Collaboration APIs. This document describes how to set up OAuth credentials in the Check Point Infinity Portal and install them into the Dropzone platform.

The integration automatically ingests the following email security alert types from Check Point Harmony:

* `phishing` - Phishing email alerts
* `malware` - Malware email alerts
* `suspicious_phishing` - Suspicious phishing email alerts
* `suspicious_malware` - Suspicious malware email alerts
* `anomaly` - Admin-blacklisted emails and other anomalies

## Create Oath credentials

Check Point Harmony requires an Account API Key to enable. To create an Account API Key, do the following:

* In your Check Point Infinity Portal, navigate to ⚙️ > API Keys

<figure><img src="/files/f3sCtqESRb6bxYqSUSjA" alt=""><figcaption></figcaption></figure>

* Navigate to New > New account API key

<figure><img src="/files/gJDQLvN3bN9l4nQNbhjB" alt=""><figcaption><p>Click "New Account API Key"</p></figcaption></figure>

* Under "Service," select Email & Collaboration
* In the Expiration field, select an expiration date and time for the API Key

{% hint style="warning" %}
To avoid repeating this process, Dropzone advises assigning a lengthy expiration date. Once the API key expires, you will need to generate a new one.
{% endhint %}

* In the Description field, enter a memorable description for the API Key, such as "Dropzone AI"
* Click "Create"

<figure><img src="/files/37GiDvcncKytpwNOJBL4" alt=""><figcaption><p>Create the API Key</p></figcaption></figure>

* Copy the Client ID, Secret Key, and Authentication URL shown for use later in the Dropzone UI where they are called "Client ID," "Secret Key," and "Authentication URL (API Endpoint)" respectively

{% hint style="warning" %}
You can always obtain the Client ID from the API Keys table, but you cannot retrieve the Secret Key or Authentication URL after the Create a New API Key window is closed. Be sure to record all three values before you leave the page.
{% endhint %}

* Click "Close"

<figure><img src="/files/bOblJYR2cYwWRykgejeV" alt=""><figcaption><p>Copy the API Key details</p></figcaption></figure>

For additional information, see the [Check Point Infinity Portal API Keys Documentation](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Portal-Admin-Guide/Content/Topics-Infinity-Portal/API-Keys.htm).

## Enable Check Point Harmony

The Alert source integration allows Dropzone AI to pull alerts from Check Point Harmony Email & Collaboration for investigation.

You'll need the following information:

| Dropzone Field                    | Source                                            |
| --------------------------------- | ------------------------------------------------- |
| Client ID                         | The "Client ID" value you copied earlier          |
| Secret Key                        | The "Secret Key" value you copied earlier         |
| Authentication URL (API Endpoint) | The "Authentication URL" value you copied earlier |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Check Point, then click "Configure"

<figure><img src="/files/rRRGNdeyEcgaVZJ45Vgd" alt=""><figcaption><p>The Check Point Tile</p></figcaption></figure>

* Input the Client ID, Secret Key, and Authentication URL

<figure><img src="/files/EpghG4k2SY4ha2dqFHIn" alt=""><figcaption><p>The Check Point Harmony Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Enabled Severities," select which severity levels to ingest from Check Point Harmony
* Under "Enabled States," select which [event states](https://sc1.checkpoint.com/documents/Harmony_Email_and_Collaboration/Topics-Harmony-Email-Collaboration-Admin-Guide/Managing-Security-Events/Events-Page.htm) to ingest from Check Point Harmony

{% hint style="info" %}
If all severities or all states are disabled, no alerts will be fetched.
{% endhint %}

<figure><img src="/files/4BhgC2uyN1YbbNrTkkdo" alt=""><figcaption><p>The Check Point Harmony Alert Source Configuration (pt 2)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Check Point Harmony Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Check Point Harmony Alert Source Configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish

You should begin ingesting alerts immediately.

{% hint style="info" %}
This integration supports backfilling historical alerts via the AlertBackfill system. Backfills are processed in 1-hour chunks. See the [Alert Sources overview](/dropzone-101/terms-and-defs/alert-sources) for more information on backfilling.
{% endhint %}

If you have any errors engage your Dropzone AI support representative.


# CrowdStrike

{% hint style="info" %}
Note that this is separate from the "CrowdStrike Falcon Intelligence" Threat intelligence data source.
{% endhint %}

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create API credentials in the CrowdStrike dashboard
* Install the credentials into your Dropzone tenant (Data Source and Alert Source)
* Select integration parameters, such as which alert types to sync

## Create an API Key

* As an Admin, go to your CrowdStrike dashboard, e.g. https\://*falcon.us-#*.crowdstrike.com/
* From the menu in the upper left, navigate to Support and Resources > API clients and keys

<figure><img src="/files/sYgCICJsGcFEZFanrpV9" alt="" width="375"><figcaption><p>Click API clients and keys</p></figcaption></figure>

* On the right, click "Create API Client"

<figure><img src="/files/9K9if4XaMkcMrfXPmJEf" alt=""><figcaption><p>Create API Client</p></figcaption></figure>

* On the "Create API Client" page, input "Dropzone AI" in the client name field. Under "Description," write "Dropzone AI Integration Key"

<figure><img src="/files/gLXKDfOdpiPyshDN5q55" alt=""><figcaption><p>Create API Client Screen</p></figcaption></figure>

* Enable the following scopes:

| Scope                         | Read | Write | Used By                        |
| ----------------------------- | ---- | ----- | ------------------------------ |
| Alerts                        | ✓    |       | Alert Source, Data Source      |
| API Integrations              | ✓    |       | Alert Source, Data Source      |
| Cases                         | ✓    | ✓     | Alert Source, Data Source      |
| Correlation Rules             | ✓    |       | Alert Source                   |
| Detections                    | ✓    |       | Alert Source, Data Source      |
| Hosts                         | ✓    | ✓     | Data Source, Remediator Source |
| NGSIEM                        | ✓    | ✓     | Data Source                    |
| Incidents                     | ✓    |       | Alert Source, Data Source      |
| Quarantined Files             | ✓    |       | Data Source                    |
| Real Time Response            | ✓    | ✓     | Data Source                    |
| Event Streams                 | ✓    |       | Data Source                    |
| Threatgraph                   | ✓    |       | Data Source                    |
| Identity Protection Entities  | ✓    |       | Data Source                    |
| Identity Protection Timeline  | ✓    |       | Data Source                    |
| Identity Protection GraphQL   |      | ✓     | Data Source                    |
| Sandbox (Falcon Intelligence) | ✓    | ✓     | Data Source                    |
| Indicators of Compromise      | ✓    | ✓     | Remediator Source              |

{% hint style="info" %}
Some of these scopes are only necessary for the Data Source or Remediator integration. If you don't intend to perform those integrations, you may ignore them.
{% endhint %}

* Write permission details
  * `Cases`: Write permissions are only required when used in Response Actions
  * `Hosts`: Write permissions are only required when used in Remediator Containment Actions
  * `NGSIEM`: Write permissions are required when NextGen SIEM is enabled in order to execute NGSIEM queries ([docs](https://www.falconpy.io/Service-Collections/NGSIEM.html#startsearchv1))
  * `Real Time Response`: Write permissions are required when File Retrieval is enabled ([docs](https://www.falconpy.io/Service-Collections/Real-Time-Response.html#rtr_executeactiverespondercommand))
    * Dropzone *only* uses Real Time Response to perform `get <file>` commands
  * `Identity Protection GraphQL`: Write permissions are required when Identity Protection is enabled in order to execute queries for user directory information ([docs](https://www.falconpy.io/Service-Collections/Identity-Protection.html#api_preempt_proxy_post_graphql))
  * `Sandbox (Falcon Intelligence`: Write permissions are only required when File Detonation is enabled in order to upload collected or attached files in the Falcon Sandbox
  * `Indicators of Compromise`: Write permissions are only required when used in Remediator Containment Actions
* Read permission details
  * `Correlation Rules`: Read permission is only required when Next-Gen SIEM is enabled. When granted, the Dropzone alert poller looks up the CQL of the correlation rule that fired an NG SIEM alert and attaches it to the alert, which Dropzone uses to build higher-fidelity evidence queries during investigation. If the scope is not granted, Dropzone falls back to synthesizing an evidence query from the alert content and no error is raised ([API reference](https://developer.crowdstrike.com/api-reference/collections/correlation-rules/)).
* When done, click "Create"
* Copy the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

<figure><img src="/files/Zx5mxxH4fgn6Z32n0Bhn" alt=""><figcaption><p>Copy your API Credentials</p></figcaption></figure>

## Enable Crowdstrike

The Alert source integration allows Dropzone AI to pull alerts from CrowdStrike for investigation.

You'll need the following information:

| Dropzone Field | Source                                   |
| -------------- | ---------------------------------------- |
| Client ID      | The "Client ID" value you copied earlier |
| Client Secret  | The "Secret" value you copied earlier    |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search CrowdStrike, then click "Configure"

<figure><img src="/files/Wv7ZdJQpOMEXUBCsDeE4" alt=""><figcaption><p>The Crowdstrike Tile</p></figcaption></figure>

{% hint style="success" %}
Make sure you're using the Cloud and EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.
{% endhint %}

* Under the Alert Source header, input the Client ID and Client Secret. If you use a non-default URL for the CrowdStrike API, configure the API Base URL as well

<figure><img src="/files/uWUHlkyyF7WeiiNHDXBH" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you wish to enable endpoint detection, check the box labeled "Enable Endpoint Detection." Then select the severity levels you want Dropzone to investigate alerts for
* Under Exlusions, you may choose to exclude alerts by display name. To do so, click "Add Item," then input a list of [Python regexes](https://docs.python.org/3/library/re.html) of the alerts you wish to exclude

<figure><img src="/files/ByIUyzsnszDE018qQ5jl" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to enable CrowdStrike's [Next-Gen SIEM](https://developer.crowdstrike.com/docs/ng-siem/) cases, check the box labeled "Enable Next-gen SIEM Cases"
* Input the minimum case severity you want Dropzone to investigate
* Under "Enabled Next-Gen SIEM Case statuses," select the Case statuses you want Dropzone to investigate

<figure><img src="/files/1lVvPYO4rJc9EU7n22EN" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 3)</p></figcaption></figure>

* Under "Case Name Regex Filters," you may choose to filter cases by name. To do so, click "Add Item," then input a list of regexes. Under "Case Name Filter mode," select whether to include or include the cases

<figure><img src="/files/xHeoBdE5HWa8xttRbahf" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 4)</p></figcaption></figure>

* If you wish to enable CrowdStrike's [Next-Gen SIEM](https://developer.crowdstrike.com/docs/ng-siem/) alerts, check the box labeled "Enable Next-gen SIEM Alert"
* Check the box labeled "Include Third Party Sources" if you want Dropzone to be able to ingest Next-gen alerts from other sources integrated into Crowdstrike
* Check the box labeled "Include Falcon Cloud Security Alert" if you want Dropzone to be able to ingest alerts from Crowdstrike's \[Falcon Cloud Security]
* Check the box for each severity level of alerts you want Dropzone to investigate

<figure><img src="/files/q4KUW2q14jBp8AyGqNFt" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 5)</p></figcaption></figure>

* Under "Next-Gen SIEM Alert Exlusions," you may choose to exclude alerts by display name. To do so, click "Add Item," then input a list of regexes to exclude alerts

<figure><img src="/files/615HWaveduLqs71mdpfH" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to enable Drozone to investigate alerts and cases from specific devices, check the box labeled "Enable Device Tag Filtering"
* Input each device tag individually

<figure><img src="/files/snw886YtGdjFs1iZzIS0" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to enable Dropzone to investigate [identity protection alerts](https://www.crowdstrike.com/wp-content/uploads/2021/06/CrowdStrike-Falcon-Identity-Protection-Modules_DataSheet.pdf), check the box labeled "Enable Identity Protection Alerts"
* Select the severity levels you want Dropzone to investigate alerts for

<figure><img src="/files/SiRZLEV9hWSgjCaiSyYd" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 7)</p></figcaption></figure>

* Input your Crowdstrike UI Domain for ticket linkback
* If you wish to enable Dropzone to fetch original third party alerts, check the box labeled "Fetch Original Third Party Alerts" under "Next-Gen SIEM Alert Enrichment Options"

<figure><img src="/files/nGFum7MfvREUqEjVlCuO" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 8)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/X3lpri9ttCQVhvCj2KzQ" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 9)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/SZ8KkmrQwertPjVhzM0J" alt=""><figcaption><p>The CrowdStrike Alert Source Configuration (pt 10)</p></figcaption></figure>

* Click "Test & Save" to finish

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.


# Datadog

{% hint style="info" %}
Datadog is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Datadog](https://www.datadoghq.com/) security SIEM. Many customers ingest other alert sources into DataDog (e.g. IDPs) and integrate Dropzone into DataDog rather than the source systems.

## Create an API Key and Application Key

Datadog requires both an API Key and an Application Key to enable.

To obtain an API Key, do the following:

* In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
* Navigate to Organization Settings > API Keys

<figure><img src="/files/0UVoscMOXYNi13t4rJ9D" alt=""><figcaption><p>Navigate to API Keys</p></figcaption></figure>

* Click "New Key"

<figure><img src="/files/x4CaASHGv1jYYroCRBW0" alt=""><figcaption><p>Click "New Key"</p></figcaption></figure>

* Name your token something memorable, such as "dropzone.ai," then click "Create Key"

<figure><img src="/files/8MjtFMjYRKyFt6nAanj3" alt=""><figcaption><p>Create Key</p></figcaption></figure>

* Copy the key generated for use later in the Dropzone UI where it is called "API Key," then click "Finish"

<figure><img src="/files/sFaw2roj8koldmHRDPl9" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

To obtain an Application Key, do the following:

* In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
* Navigate to Organization Settings > Application Keys

<figure><img src="/files/0UVoscMOXYNi13t4rJ9D" alt=""><figcaption><p>Navigate to Application Keys</p></figcaption></figure>

* Click "New Key"

<figure><img src="/files/x4CaASHGv1jYYroCRBW0" alt=""><figcaption><p>Click "New Key"</p></figcaption></figure>

* Name the key something memorable, such as "dropzone.ai," then click "Create Key"

<figure><img src="/files/8MjtFMjYRKyFt6nAanj3" alt=""><figcaption><p>Create Key</p></figcaption></figure>

* In the "Scope" section, select "Edit"

<figure><img src="/files/yBJPzyjiAenAnU4dCuJH" alt=""><figcaption><p>Edit Scopes</p></figcaption></figure>

* Assign the key the following scopes, then click "Save":
  * logs\_read\_data
  * security\_monitoring\_signals\_read

<figure><img src="/files/4uHaDV8wUzoi0fTmhqnF" alt=""><figcaption><p>Assign scopes</p></figcaption></figure>

* Copy the key generated for use later in the Dropzone UI where it is called "Application Key," then click "Finish"

<figure><img src="/files/7pJkEbj7NVPT736R8RwF" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

## Enable Datadog

To enable the Data Source integration, you will need the following information:

| Dropzone Field  | Source                                                                    |
| --------------- | ------------------------------------------------------------------------- |
| API Key         | The API key value you generated earlier                                   |
| Application Key | The Application key value you generated earlier                           |
| Datadog site    | The same as your url in Datadog, eg datadoghq.com, us3.datadoghq.com, etc |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Datadog, then click "Configure"

<figure><img src="/files/ZQ5t9PorhUsEVvyKlEYB" alt=""><figcaption><p>The Datadog Tile</p></figcaption></figure>

* Under the Alert Source heading, input the API Key, Application Key, and your Datadog site

<figure><img src="/files/68iODx6vRsQ0DlJELj1E" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the "Enabled Severities" section, choose the severity levels of alerts you want Dropzone to investigate
* Under "Enabled Sources," check the box for each known Datadog Security Monitoring Signal source you want to retrieve signals for

<figure><img src="/files/4wPq0iRHiUo2kB0eFKWF" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 2)</p></figcaption></figure>

* In the "Signal Rule Filters" section, you may choose Datadog [security signal names](https://docs.datadoghq.com/security/application_security/security_signals/#signals-explorer-columns) to include/exclude from searches. To do so, click "Add Item," then input the signals you wish to filter. Under "Rule Filter Mode," select whether to include or exclude those signals from investigation

<figure><img src="/files/JFXtVtrUYEBJ7uJwsaPE" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 3)</p></figcaption></figure>

* In the "Excluded Tags," you may exclude [tags](https://docs.datadoghq.com/getting_started/tagging/) from analysis. To do so, click "Add Item," then input the tag Field Name (or "Key") and Value. Continue adding tags until done

<figure><img src="/files/ebBSGCKhNrwR3rmLaDXZ" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and lookback

<figure><img src="/files/2qn1FRWfM87n9ApeByn9" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Datadog Alert Source Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Elasticsearch

{% hint style="info" %}
Elasticsearch is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Elasticsearch](https://www.elastic.co/elasticsearch) security SIEM. Many customers ingest other alert sources into Elasticsearch (e.g. IDPs) and integrate Dropzone into Elasticsearch rather than the source systems. Dropzone supports both Cloud deployments and On-premise deployments.

## Create an API Key and Obtain a Cloud ID

Elasticsearch requires an API Key and an Elasticsearch Cloud ID to enable.

{% hint style="info" %}
If you are using the Elasticsearch Serverless Projects-Based Model or an On-premise Elasticsearch using the Dropzone connector, you will not need to provide a Cloud ID.
{% endhint %}

To obtain an API Key, do the following:

* Navigate to your [Elastic Cloud home page](https://cloud.elastic.co/home) or deployment
* Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
* Click "Open"

<figure><img src="/files/PXmvCvibGBliQSYhnvdu" alt=""><figcaption><p>Click Manage</p></figcaption></figure>

* In the Deployment overview page, click "Management" in the bottom left corner
* Click the icon next to Stack Management
* Navigate to API keys

<figure><img src="/files/XDgF81JGmBJWq5K88PpB" alt=""><figcaption><p>Navigate to API keys</p></figcaption></figure>

* Click "Create an API key"

<figure><img src="/files/DkUP31l4baq6F1LHnyCl" alt=""><figcaption><p>Click "Create an API key"</p></figcaption></figure>

* Name the API key something memorable, such as Dropzone.AI
* Under type, select User API key
* Click "Create API Key"

<figure><img src="/files/shnCOTRV4rvtCqDjcAWT" alt=""><figcaption><p>Create an API key></p></figcaption></figure>

* Copy the API key generated for use later in the Dropzone UI, where it is called "API Key"

<figure><img src="/files/hwFibYrVZLnlbB9SXz4x" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

To obtain your Elasticsearch Cloud ID, do the following:

* Navigate to your [Elastic Cloud home page](https://cloud.elastic.co/home)
* Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
* Click "Open"

<figure><img src="/files/PXmvCvibGBliQSYhnvdu" alt=""><figcaption><p>Click Open</p></figcaption></figure>

* In the upper right of the Overview page, click "Endpoint & API Keys"

<figure><img src="/files/uu9irhBm3AFwQYsItBEn" alt=""><figcaption><p>Click Endpoint &#x26; API Keys</p></figcaption></figure>

* Check "Show Cloud ID"
* Copy the value shown for use later in the Dropzone UI, where it is called "Elasticsearch Cloud ID"

<figure><img src="/files/sA1j5TvX0alpjBcTF2hU" alt=""><figcaption><p>Copy the Elasticsearch Cloud ID</p></figcaption></figure>

## Enable Elasticsearch

To enable the Alert Source integration, you will need the following information:

| Dropzone Field         | Source                                                                                              |
| ---------------------- | --------------------------------------------------------------------------------------------------- |
| Elasticsearch Cloud ID | The cloud ID value copied earlier. Only necessary if you have an Elastic Cloud Hosted deployment    |
| Elasticsearch Server   | The server for your Elasticsearch project, e.g. <https://my-project.es.us-west-2.aws.elastic.cloud> |
| API Token              | The API token value generated earlier                                                               |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Elasticsearch, then click "Configure"

<figure><img src="/files/H5iMmLXgqjwWRewbnduY" alt=""><figcaption><p>The Elasticsearch Tile</p></figcaption></figure>

* Under the Alert Source heading, if your Elasticsearch integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* If you have a Cloud deployment, check the box labeled "Connect with Elastic Cloud ID," then input the Elasticsearch Cloud ID and API Key

<figure><img src="/files/CEy0ArbPW9LvvDMCnzZQ" alt=""><figcaption><p>The Elasticsearch Alert Cloud ID Configuration</p></figcaption></figure>

* Otherwise, input the Elasticsearch Server, Port, and API Key

<figure><img src="/files/h7lcOHGYZ6OQyb4e1aAP" alt=""><figcaption><p>The Elasticsearch Alert Configuration (pt 1)</p></figcaption></figure>

* If you wish to enable namespace-based multitenancy, check the box labeled "Utilize namespace for multi-tenant environment." Otherwise, leave blank. See the bottom of this documentation for further information

<figure><img src="/files/lJGH1eowjlNdr5JQQ8gP" alt=""><figcaption><p>The Elasticsearch Multi-tenant Namespace Configuration</p></figcaption></figure>

* Under the heading Elasticsearch Alert Queries, click "Add item" to add Elasticsearch Alert Queries for Dropzone to investigate

<figure><img src="/files/rcdosCSCGKpD2c5V6Kql" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 2)</p></figcaption></figure>

* You may use the Elasticsearch [Kibana alerts](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html), or create your own custom index and query string
* To use your own custom index and query string, uncheck the box labeled "Use Kibana Alerts." Input your custom index and query string into the areas labeled "Custom Index" and "Query String", then click "Add Item"

<figure><img src="/files/KIUQ1qnJPO9ZWbV0xfrr" alt=""><figcaption><p>The Elasticsearch Kibana Alert Configuration (pt 3)</p></figcaption></figure>

* To use Elasticsearch Kibana Alerts, check the box labeled "Use Kibana Alerts"
  * In the "Kibana Alert Index" section, input an Index pattern for Kibana security alerts
  * You may choose to allow Dropzone to inject only specific Kibana alert [schema](https://www.elastic.co/guide/en/security/current/alert-schema.html) under the heading "Kibana Alert Status Allowlist". If you do, click "Add Item" to add specific Kibana alert statuses. Otherwise, leave blank

<figure><img src="/files/HozOLQX5vkNUqrixma2Y" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 4)</p></figcaption></figure>

* Under the heading "Kibana Alert Severities", check the box for each severity level you want Dropzone to investigate alerts for

<figure><img src="/files/MkqiOjMOxmCaNrDnqdvX" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 5)</p></figcaption></figure>

* You may choose to allow Dropzone to allow or exclude select Kibana Alert [Rules](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html#_rules)
  * If you wish to include an Alert Rule, click "Add item" under the heading "Kibana Alert Rule Allowlist". If you wish to exclude a rule, click "Add Item" under the section labeled "Kibana Alert Rule Exclusion List". Otherwise, leave blank

<figure><img src="/files/3SSLPGlUeL6MS6SYc0xL" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 6)</p></figcaption></figure>

* Once you have finished adding your Elasticsearch Alert Queries, click "Add item" at the end of the Kibana Alerts section

<figure><img src="/files/ey1uzdpjsXOzQI1w1gtj" alt=""><figcaption><p>Click Add Item</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 7)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Elasticsearch Alert Source Configuration (pt 8)</p></figcaption></figure>

* Click "Test & Save" to finish

## Multitenancy Configuration Using Namespaces

The Elasticsearch integration supports multitenancy based on the Elastic data stream naming scheme. This approach allows you to leverage Elasticsearch's built-in data organization capabilities while maintaining proper tenant separation within Dropzone.

### Understanding Elastic Namespaces

Elastic data streams follow a structured naming convention: **{type}-{dataset}-{namespace}**

The namespace component is a user-configurable arbitrary grouping that provides flexibility in organizing data. For example, you might have data streams like `logs-nginx.access-production` or `logs-nginx.access-staging`, where `production` and `staging` are different namespaces.

For more details on the Elastic data stream naming scheme, see [An introduction to the Elastic data stream naming scheme](https://www.elastic.co/blog/an-introduction-to-the-elastic-data-stream-naming-scheme).

### Enabling Namespace-Based Multitenancy

When the multitenant configuration is selected and the multitenant map is enabled in Dropzone, you can map Elasticsearch namespaces to tenants within the multitent map. This enables alert investigation to only search for data within a specific namespace related the alert.

To configure namespace-based multitenancy:

1. Define your namespace-to-tenant mappings to specify which Elasticsearch namespaces should be associated with which Dropzone tenants
2. Enable the multitenant configuration option in your Elasticsearch integration settings

<figure><img src="/files/lJGH1eowjlNdr5JQQ8gP" alt=""><figcaption><p>The Elasticsearch Multi-tenant Namespace Configuration</p></figcaption></figure>

3. Ensure your Elasticsearch data streams follow the standard naming convention with appropriate namespace values
4. (Optional) Specify namespaces with alerts that are desired to be investigated otherwise all alerts with a namespace will be ingested.

{% hint style="warning" %}
If this configuration is enabled and an alert is ingested without the namespace specified, the alert will be dropped and will not be investigated.
{% endhint %}

If you have any errors engage your Dropzone AI support representative.


# ExtraHop

## ExtraHop

The Dropzone AI Platform integrates with [ExtraHop](https://www.extrahop.com/), a Network Detection and Response (NDR) platform that provides real-time, packet-level visibility across hybrid and multi-cloud environments.

### Integration Overview

To enable these integrations you will perform the following actions:

* Grant REST API Access
* Locate your RevealX 360 API Endpoint
* Generate RevealX 360 API Credentials
* Enable the Alert source in your Dropzone AI tenant

### Grant REST API Access

To grant REST API Access, do the following:

* As a user with system and access administration privileges, log in to ExtraHop RevealX 360
* In the top right of the page, navigate to System Settings > All Administration
* Click "API Access"
* In the Manage API Access section, click "Enable"

### Locate your API Endpoint

In the API Access page of your RevealX360 account, locate your endpoint in the "API Endpoint" section. The hostname does not include the /oauth2/token.

Copy the value shown for use later in the Dropzone UI, where it is called "Hostname."

### Create API Credentials

To create API Credentials, do the following:

* As a user with system and access administration privileges, log in to ExtraHop RevealX 360
* In the top right of the page, navigate to System Settings > All Administration
* Click "API Access"
* Click "Create Credentials"
* Name the credentials something memorable, such as "Dropzone AI"
* Grant the credentials the following privilege levels:
  * Full [NDR Module Access](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges:~:text=access%20module%20features.-,NDR%20Module%20Access,-Allows%20the%20user)
  * Full [NPM Module Access](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges:~:text=and%20threat%20briefings.-,NPM,-Module%20Access)
  * [Full Read-Only](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges)

{% hint style="info" %}
Full NPM Module Access is only required if you wish to ingest [performance detections](https://docs.extrahop.com/26.3/detections-overview/#:~:text=to%20take%20action.-,Modules,-and%20detections) as an alert source.
{% endhint %}

* In the "Packet Access" section, do not enable packet retrieval
* Click "Save"
* Copy and save the ID and Secret values shown for use later in the Dropzone UI, where they are called "ID" and "Secret" respectively
* Click "Done"

## Enable ExtraHop

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                   |
| -------------- | ------------------------------------------------------------------------ |
| ID             | The ID value you copied earlier                                          |
| Secret         | The Secret value you copied earlier                                      |
| Hostname       | The hostname of your ExtraHop API, e.g. *example.api.cloud.extrahop.com* |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ExtraHop, then click "Configure"

<figure><img src="/files/4hRZozdpBJlgnHajkuBJ" alt=""><figcaption><p>The ExtraHop tile</p></figcaption></figure>

* Under the Alert Source header, input the ID, Secret, and Hostname

<figure><img src="/files/496AoguxnokKgRLPrV6Q" alt=""><figcaption><p>The ExtraHop Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Detection filters," select which [detection categories](https://docs.extrahop.com/26.3/detections-overview/#triage:~:text=tuning%20rules.-,Category,-You%20can%20filter) you want Dropzone to ingest. By default, all are selected
* Check the box labeled "Recommended for triage" to limit your detections to those [recommended for triage](https://docs.extrahop.com/26.3/detections-overview/#triage)
* Input your minimum [risk score severity](https://docs.extrahop.com/26.3/risk-scores-overview/#:~:text=to%20take%20action.-,Risk,-score%20severity)

<figure><img src="/files/kzU78r2UWkN8YPktq1Ax" alt=""><figcaption><p>The ExtraHop Alert Source Configuration (pt 2)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The ExtraHop Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The ExtraHop Alert Source Configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Gem

{% hint style="info" %}
Gem is a Alert Source integration. The Dropzone platform creates Investigations based on alerts from Alert Sources.
{% endhint %}

Gem is a SIEM focusing on Cloud Detection and Response (CDR).

## Create an API Key

Dropzone requires a Gem Client ID and Client Secret.

To obtain these, follow the instructions available on Gem's [documentation site](https://docs.wiz.io/) for creating a Client ID and Client Secret.

## Enable Gem

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Gem, then click "Configure"

<figure><img src="/files/SS41kGQdUh3P8X9YksTP" alt=""><figcaption><p>The Gem Alert Tile</p></figcaption></figure>

* Input your Gem server domain (e.g. *app.gem.security*, *eu-west-1.app.gem.security*)
* Input the Client ID and Client Secret you created earlier

<figure><img src="/files/DfBc4DU2t3eAaYEfSaMf" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 1)</p></figcaption></figure>

* Input your desired poll interval and lookback
* Click "Comment Investigation Results to ticket" if you want Dropzone to push investigation results back to Gem

<figure><img src="/files/UURVbctaixyQ7WLAYn13" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 3)</p></figcaption></figure>

* Click "Test & Save"

If you have any errors or questions, engage your Dropzone AI support representative.


# Google GCP

The Dropzone AI platform integrates with GCP (Google Cloud Platform) APIs for ingesting alerts and enriching investigations with data from GCP such as VM and service account information. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Determine which section of your GCP environment to enable Dropzone visibility
* Grant IAM access to the Dropzone service account
* Enable the Alert and Data sources

## Determine Dropzone Visibilty Scope

Dropzone requires some IAM access to query your GCP environment.

You will later be granting the Dropzone service account access to a portion of your GCP environment, at either a folder level or for the whole organization.

For example, in the screenshot below, if you were to grant access via the `production` folder then Dropzone would have access to the `Project FreezeRay` project, and any other folders or projects you add to `production` in the future. However, it would not be available to `alligator-apples`. If you grant access via the top level org, `example.net` then it would apply to all folders and projects going forward.

<figure><img src="/files/SwuhoAMkeH6Zja3kYlNV" alt=""><figcaption><p>Resource Selection</p></figcaption></figure>

When enabling the integration you will be supplying the ID of the top level folder or organization, and Dropzone will recurse through all objects thereunder when making Data Source queries.

When you've chosen your folder or org, record the ID value for use later in the Dropzone UI where it is called "Parent Resource"."

## Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search GCP, then click "Configure"

<figure><img src="/files/uZXk0llyhxXWTW8n33O9" alt=""><figcaption><p>The GCP Tile</p></figcaption></figure>

* Record the "SERVICE ACCOUNT EMAIL" field for use in the GCP Console interface

<figure><img src="/files/VfKuvjIPFeZdcmf8pPAx" alt="" width="320"><figcaption><p>SERVICE ACCOUNT EMAIL</p></figcaption></figure>

## Grant GCP Access to Dropzone Service Account

* Go to the GCP cloud console at <https://console.cloud.google.com>

<figure><img src="/files/FWqwQeKiCrUfSf0ccFdl" alt=""><figcaption><p>Project Dropdown</p></figcaption></figure>

* Click the current project dropdown
* Click "All"
* Select the organization or the folder you've chosen for Dropzone visibility

<figure><img src="/files/SwuhoAMkeH6Zja3kYlNV" alt=""><figcaption><p>Resource Selection</p></figcaption></figure>

* From the left menu, navigate to IAM & Admin > IAM

<figure><img src="/files/1ccZLmrW4Ps825cHCDyM" alt=""><figcaption><p>IAM &#x26; Admin Menu</p></figcaption></figure>

* Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

<figure><img src="/files/0uECVydR5SIVpg2uGRxJ" alt=""><figcaption><p>Input the email address from the Dropzone UI Service Account Email</p></figcaption></figure>

* Click "Select a role"

<figure><img src="/files/ZpHdRdEqTkgHXOdzmkZv" alt=""><figcaption></figcaption></figure>

* Add the following roles:

| Role Name                                                                                                         | Purpose                                    | Used By                  |
| ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------ | ------------------------ |
| [Security Center Admin Viewer](https://cloud.google.com/iam/docs/understanding-roles#securitycenter.adminViewer)  | View GCP entity details and configurations | Alert Source Integration |
| [Browser](https://cloud.google.com/iam/docs/understanding-roles#browser)                                          | View GCP resources                         | Data Source Integration  |
| [Cloud Asset Viewer](https://cloud.google.com/iam/docs/understanding-roles#cloudasset.viewer)                     | View cloud assets                          | Data Source Integration  |
| [Compute Viewer](https://cloud.google.com/iam/docs/understanding-roles#compute.viewer)                            | View compute resources                     | Data Source Integration  |
| [Folder Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.folderViewer)               | View folders                               | Data Source Integration  |
| [Logs Viewer](https://cloud.google.com/iam/docs/understanding-roles#logging.viewer)                               | View GCP logs                              | Data Source Integration  |
| [Organization Role Viewer](https://cloud.google.com/iam/docs/understanding-roles#iam.roleViewer)\*                | View organization roles                    | Data Source Integration  |
| [Organization Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.organizationViewer)\* | View organization resources                | Data Source Integration  |
| [Private Logs Viewer](https://cloud.google.com/iam/docs/understanding-roles#logging.privateLogViewer)             | View private logs                          | Data Source Integration  |
| [Security Reviewer](https://cloud.google.com/iam/docs/understanding-roles#iam.securityReviewer)                   | Review security configurations             | Data Source Integration  |
| [Storage Object Viewer](https://cloud.google.com/iam/docs/understanding-roles#storage.objectViewer)               | View storage objects                       | Data Source Integration  |
| [Tag Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.tagViewer)                     | View tags                                  | Data Source Integration  |

\* These roles should only be included if the top-level parent is an organization.

{% hint style="info" %}
Some of these roles are only necessary for the Data Source integration. If you don't intend to perform that integration, you may ignore them.
{% endhint %}

* Continue adding roles via the "Add another role" button until complete

<figure><img src="/files/Xjb4bdpmU1hVHIEvtW0s" alt=""><figcaption><p>Add another role</p></figcaption></figure>

* Click "Save"

## Enable GCP

The Alert Source integration allows Dropzone AI to pull alerts from GCP for investigation.

You'll need the following information:

| Dropzone Field  | Source                                                        |
| --------------- | ------------------------------------------------------------- |
| Parent Resource | The ID of the org or folder where you granted Dropzone access |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search GCP, then click "Configure"

<figure><img src="/files/uZXk0llyhxXWTW8n33O9" alt=""><figcaption><p>The GCP Tile</p></figcaption></figure>

* Under the Alert Source heading, input the "Parent Resource" ID
* Select the "Parent Resource Type" that matches the resource you've selected

<figure><img src="/files/VQBz8xyeBaYbf3BvdhJ1" alt=""><figcaption><p>The GCP Alert Source Configuration (pt 1)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The GCP Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The GCP Alert Configuration (pt 3)</p></figcaption></figure>

* Click "Test & Save" to finish

You should begin ingesting alerts immediately.

If you have any errors or questions, engage your Dropzone AI support representative.


# Google Security Operations

{% hint style="info" %}
Google Security Operations is a SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.
{% endhint %}

Dropzone integrates with [Google Security Operations](https://cloud.google.com/security/products/security-operations) to investigate different security alerts across many of Google's security products.

## Integration Overview

To enable these integrations you will perform the following actions:

* Identify your service account address
* Grant IAM access to the Dropzone service account
* Obtain your Google Account Details
* Complete Google Cloud Mapping
* Enable the Alert and Data sources

Alternatively, Dropzone also supports [Service Account Impersonation](https://docs.cloud.google.com/iam/docs/service-account-impersonation) as a method of authentication. This allows an already-authenticated principal to temporarily act as a target service account and use its permissions, often by requesting short-lived credentials instead of downloading long-lived keys. See Google Cloud's [documentation](https://docs.cloud.google.com/docs/authentication/use-service-account-impersonation) for further information.

{% hint style="info" %}
If you choose to use Service Account Impersonation, be sure to grant (or ask your administrator to grant) the principal you're using the [Service Account Token Creator](https://docs.cloud.google.com/iam/docs/roles-permissions/iam#iam.serviceAccountTokenCreator) role.
{% endhint %}

## Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Security Operations, then click "Configure"

<figure><img src="/files/7KI64qtojWxIco9PVALt" alt=""><figcaption><p>The Google SecOps Tile</p></figcaption></figure>

* Copy the "SERVICE ACCOUNT EMAIL" field for use in the Google Console interface

<figure><img src="/files/zoqV89980XI4lPCjAj8a" alt="" width="320"><figcaption><p>Copy the service account email</p></figcaption></figure>

## Grant IAM Access to Dropzone AI

* Navigate to the Google Console page of the project your SecOps instance is in
* In the upper left hand corner, open the navigation menu

<figure><img src="/files/MZxgKryMsfjPIGg0PrmC" alt=""><figcaption><p>Open the navigation menu</p></figcaption></figure>

* Navigate to IAM & Admin > IAM

<figure><img src="/files/yuJsgHqdiasRnCFoCv7i" alt=""><figcaption><p>Navigate to IAM</p></figcaption></figure>

* Under "View by principals," click "Grant Access"

{% hint style="info" %}
To be able to complete this step, you will need the `resourcemanager.projects.setIamPolicy` permission.
{% endhint %}

<figure><img src="/files/7nUYn0CIHkWERBDtlwEx" alt=""><figcaption><p>Click "Grant Access"</p></figcaption></figure>

* Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

<figure><img src="/files/JlwJAp89wkRDp0lTR5Px" alt=""><figcaption><p>Input the email address from the Dropzone UI Service Account Email</p></figcaption></figure>

* Click "Select a role"

<figure><img src="/files/Dm12Cp9FGA3Wzs3J2cxi" alt=""><figcaption><p>Click "Select a role"</p></figcaption></figure>

* Search the "[Chronicle API Viewer](https://docs.cloud.google.com/iam/docs/roles-permissions/chronicle#chronicle.viewer)" role, then click it

{% hint style="info" %}
If you want Dropzone to be able to edit Cases/Alerts after investigation (e.g. by changing stages, modifying priority, or adding comments) select the Chronicle API Editor role.
{% endhint %}

<figure><img src="/files/mrdamGFcavSuQNlU2BeV" alt=""><figcaption><p>Assign the Chronicle API Viewer role</p></figcaption></figure>

* Click "Save"

<figure><img src="/files/dU5laYUIPdTCDfv7cQAS" alt=""><figcaption><p>Click "Save"</p></figcaption></figure>

## Obtain Account Details

To obtain your Instance Name, do the following:

* Return to the Google Console page of the project your SecOps instance is in
* In the upper left hand corner, open the navigation menu

<figure><img src="/files/MZxgKryMsfjPIGg0PrmC" alt=""><figcaption><p>Open the navigation menu</p></figcaption></figure>

* Navigate to Security > Detection and Controls > Google SecOps

<figure><img src="/files/EmPtS8BzJwrtWZnJJt2S" alt=""><figcaption><p>Navigate to Google SecOps</p></figcaption></figure>

* In the Google SecOps page, click the carrot next to "Instance Details"

<figure><img src="/files/C38x9OwvTLi4WagL0qGS" alt=""><figcaption><p>Reveal the Instance Details</p></figcaption></figure>

* Copy the Customer ID shown for use later in the Dropzone UI where it is called "Instance Name"

<figure><img src="/files/2LazT7IOChRmSPYeKTta" alt=""><figcaption><p>Copy the Instance Name</p></figcaption></figure>

To obtain your Project ID, do the following:

* In the upper left, click on the project icon

<figure><img src="/files/dXEF8882EAY40hffTpC9" alt=""><figcaption><p>Click the project icon</p></figcaption></figure>

* Using the search bar, locate the project your SecOps instance is in
* Under "ID," copy the ID value shown for use later in the Dropzone UI where it is called "Project ID"

<figure><img src="/files/GUYyeX9rnIkWFapXg0jG" alt=""><figcaption><p>Copy the Project ID</p></figcaption></figure>

## Cloud Identity Mapping

If you want Dropzone to be able to have SOAR access, (e.g. managing [cases](https://cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview)), you must map the service account to your platform's access control parameters. This will provide the service account with access to SOC Roles and Environments required to perform automated tasks or API operations.

To do Cloud Identity mapping, do the following:

* As an admin, log into your Google SecOps instance
* In the left sidebar, navigate to Settings > SOAR Settings
* Navigate to Advanced > Group Mapping
* Click "+ Add"
* In the IDP/User group field, enter the full service account email address or the workload identity principle string
* Assign the service account the appropriate [SOC role and Environments](https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/control-access-to-platform)

{% hint style="success" %}
Dropzone needs read access to all security event data and case/alert content in your tenant, plus the ability to comment on, tag, and change the status of cases and alerts it has been given for investigation.
{% endhint %}

* Click "Save"

## Enable Google SecOps

To enable the Alert Source integration, you will need the following information:

| Dropzone Field                 | Source                                                          |
| ------------------------------ | --------------------------------------------------------------- |
| Instance Name                  | The "Customer ID" value you copied earlier                      |
| Project ID                     | The "Project ID" value you copied earlier                       |
| Customer-Owned Service Account | The email of the service account Dropzone will be impersonating |

{% hint style="info" %}
The Customer-Owned Service Account is only necessary if you wish to use Service Account Impersonation as your authentication method.
{% endhint %}

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Security Operations, then click "Configure"

<figure><img src="/files/7KI64qtojWxIco9PVALt" alt=""><figcaption><p>The Google Security Operations Tile</p></figcaption></figure>

* Under the Alert Source heading, input the Instance Name and Project ID
* If you are using Service Account Impersonation, input the Customer-Owned Service Account value

<figure><img src="/files/16MoW8lNWYTiX9gvJxMV" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 1)</p></figcaption></figure>

* To enable Dropzone to investigate [alerts](https://cloud.google.com/chronicle/docs/investigation/investigate-alert), check the box labeled "Enable alerts." If you wish to enable Dropzone to filter by priority, check the box labeled "Enable priority filtering," then check the priority levels you wish for Dropzone to ingest

<figure><img src="/files/2ZMmuvJ4QnQd17eqPoop" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to investigate [cases](https://cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview), check the box labeled "Enable cases"
* Input your SOAR API Key and SOAR Instance Hostname
* Check the box labeled "Include Closed Cases" to include closed cases in Dropzone investigations

<figure><img src="/files/GESy8Zsat1HRecJ1OsB4" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish to only include certain [stages](https://cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/what-actions-can-you-take-on-a-case) in Dropzone investigation, check the box labeled "Enabled stage filtering," then check the stages you wish for Dropzone to ingest

<figure><img src="/files/Yox6hAjm4j6AiXnXZXmU" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to enable priority filtering, check the box labeled "Enable priority filtering," then check the priority levels you wish for Dropzone to ingest

<figure><img src="/files/XRGSh0YMz5mj622kLXnN" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to enable filtering by case [title](https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/whats-on-the-cases-screen#:~:text=Case%20queue%20header%3F-,Case,-top%20bar%20%2D%20left), check the box labeled "Enable case title filtering," then click "Add Item"
* Input case titles individually by clicking "Add Item" for each one
* Under "Filter Mode," select whether to include or exclude the cases matching the filters

<figure><img src="/files/dzPoPiYcWzY1GMksjOGk" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 7)</p></figcaption></figure>

* If you wish to enrich Dropzone investigation with [CrowdStrike Recon](https://www.youtube.com/watch?v=0PjOLMuLIrA) information, check the box labeled "Enable case enrichment options," then check the box labeled "Fetch Crowdstrike Recon notifications"

<figure><img src="/files/lBXOeac2x37hXLhQsmUB" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 8)</p></figcaption></figure>

* Input your desired Poll interval and lookback

<figure><img src="/files/OgHRdfu7kIUCDy2SncMj" alt=""><figcaption><p>The Google SecOps Alert Source Configuration (pt 9)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/b6KSgzFkKKaK5o0L50aF" alt=""><figcaption><p>Click "Test &#x26; Save" to finish</p></figcaption></figure>

If you have any errors, engage your Dropzone AI support representative.


# Google Workspace

The Dropzone AI platform integrates with Google Workspace APIs for ingesting alerts such as phishing reports and enriching investigations with data from Google Workspace such as directory information. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Enable domain-wide delegation in Google Workspace
* Create a Google Workspace admin role
* Select integration parameters, such as which alert types to sync

The Dropzone platform has a dedicated service account for your organization. This service account uses [domain-wide delegation](https://support.google.com/a/answer/162106) to gain access to specific API scopes within your organization.

## Enable Domain-Wide Delegation

To grant access to the Google service account used by your Dropzone platform, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Workspace, then click "Configure"

<figure><img src="/files/JwSD8JPmLvapxLHofHAp" alt=""><figcaption><p>The Google Workspace Tile</p></figcaption></figure>

* Record the "CLIENT ID" field which will be used in the Google Admin interface

<figure><img src="/files/SIp1nVLvHLZ4oky9W14h" alt=""><figcaption><p>Copy the CLIENT ID</p></figcaption></figure>

Next, enable the Dropzone AI application domain-wide delegation access to your Google Workspace environment.

As a full Google Workspace admin, do the following:

* Navigate to your [admin workspace](https://admin.google.com)
* In the sidebar, navigate to Security > Access and Data Control > API Controls
* At the bottom, click [Manage Domain Wide Delegation](https://admin.google.com/ac/owl/domainwidedelegation)
* Click "Add New" API Client
* Enter the Client ID in the pop up
  * This is the \~21 digit number you recorded from the Dropzone UI earlier
* Grant access to the following scopes by copy/pasting them into the "OAuth Scopes" line one-by-one
  * <https://www.googleapis.com/auth/apps.alerts>
  * <https://www.googleapis.com/auth/gmail.readonly>
  * <https://www.googleapis.com/auth/drive.readonly>
    * Required when enabling the optional Google Drive Query feature
  * <https://www.googleapis.com/auth/admin.directory.user.readonly>
  * <https://www.googleapis.com/auth/admin.reports.audit.readonly>
  * <https://www.googleapis.com/auth/admin.reports.usage.readonly>
  * <https://www.googleapis.com/auth/admin.directory.group.readonly>
* Click "Authorize" to finish

## Choose or Create a Google Workspace Admin Account

Dropzone uses the Google Workspace Admin API to find information from your environment using a user within your org that has an Admin Role with necessary privileges.

{% hint style="info" %}
The user you select could be a real human or a dedicated integration user. We suggest the latter to assure that personnel changes do not affect your integration. The integration user does not need a Google Workspace license, so it may be a free ["Cloud Identity"](https://support.google.com/cloudidentity/answer/7319251) user.
{% endhint %}

Note that Dropzone may request more permissions in the future as we add features.

{% hint style="info" %}
Regardless of which privileges you enable for your admin role, the Dropzone platform is restricted to the scopes that you granted in the "Set Up Domain Wide Delegation" section above.
{% endhint %}

To create and associate the new role, do the following:

* Navigate to [Account > Admin Roles](https://admin.google.com/ac/roles) > Create New Role

<figure><img src="/files/TXBClptQiWF7r9T3qNK1" alt="" width="375"><figcaption><p>Create new Google Workspace Role</p></figcaption></figure>

* Name the role something memorable, such as "Dropzone AI Role." Input a description, such as "Dropzone AI integrations," then click "Continue"

<figure><img src="/files/niGuJNJYRCv5JipjSiuY" alt="" width="177"><figcaption><p>Name the new Role</p></figcaption></figure>

* You'll now be on the "Select Privileges" page
* On this page enable the following:
  * Admin console privileges
    * Organizational Units > Read
    * Users > Read
    * Google Vault > Manage Audits
    * Gmail > Email log search
    * Gmail > Access Admin Quarantine
    * Gmail > Access Restricted Quarantines
    * Security Center > "This user has full ..." > Audit and Investigation > View
    * Security Center > "This user has full ..." > Audit and Investigation > View sensitive content
    * Security Center > Activity Rules > View
    * Security Center > Activity Rules > Manage
    * Alert Center > Full access
    * DLP > View DLP rule
    * DLP > Manage DLP rule
    * Reports
  * Admin API privileges
    * Organizational Units > Read
    * Users > Read
    * Groups > Read
    * Reports

<figure><img src="/files/MWj3OJbqEzb4IMFyMJJN" alt="" width="196"><figcaption><p>Enable permissions</p></figcaption></figure>

* Once done, click "Continue"

{% hint style="warning" %}
There are two sections of this user interface, the "Admin Console Privileges" at top and "Admin API Privileges" further down the page; make sure you configure all the permissions from both sections.
{% endhint %}

* Assign the new role to a Google Workspace user:
  * Go to <https://admin.google.com>
  * In the sidebar, navigate to [Account > Admin Roles](https://admin.google.com/ac/roles)
  * Hover over the role you created and click "Assign Admin"

<figure><img src="/files/P6OUUzABsb83b1PFSZaS" alt="" width="375"><figcaption><p>Assign admin option</p></figcaption></figure>

* Click "Assign Members" to add the role to the user you want for the Dropzone integration
  * Pick an existing admin or an account you created specifically for the Dropzone integration

<figure><img src="/files/gJSotF6kIRdG3sXpISpa" alt="" width="250"><figcaption><p>Assign an admin to the role</p></figcaption></figure>

## Enable Google Workspace

The Alert source integration allows Dropzone AI to pull alerts from Exchange Online and Microsoft Defender for investigation. Dropzone can investigate phishing emails via multiple mechanisms. An overview of them is shown below.

| Method                           | Notes                                                                                                                                                                                                                   | Requirements                                                                                                                                                                                         | Configuration                                                                                         |
| -------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| Google Workspace Phishing Alerts | Dropzone processes Google Workspace phishing alerts. \[Google phishing alerts may take up to 4 hours to appear]\(<https://support.google.com/a/answer/9104586> after users click the "Report Phishing" button in Gmail) | None - this is a built-in Google Workspace capability                                                                                                                                                | Leave "Enable mailbox-based phishing analysis" unchecked                                              |
| Dedicated phishing mailbox       | Dropzone polls a dedicated Google Workspace account for phishing emails to analyze                                                                                                                                      | You must instruct your employees to forward suspected emails to a dedicated email box, or have a third-party reporting tool (typically a Gmail add-on) that creates the emails in the target mailbox | Check "Enable mailbox-based phishing analysis" and fill out "Phishing Processing via Mailbox" section |

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field | Source                                                     |
| -------------- | ---------------------------------------------------------- |
| Admin Email    | The email address of the admin in the new Dropzone AI role |
| Customer ID    | Your Google Workspace customer id                          |

The Customer ID can be found can be found at admin.google.com > Account > Account Settings (<https://admin.google.com/ac/accountsettings>) or in the output of `gam info domain`. It's typically a \~9 character string starting with `C`.

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Workspace, then click "Configure"

<figure><img src="/files/JwSD8JPmLvapxLHofHAp" alt=""><figcaption><p>The Google Workspace Tile</p></figcaption></figure>

* Under the Alert Source heading, input the "Admin Email" and "Customer ID"

<figure><img src="/files/FcLHMnGUzGUo22dPfPIu" alt=""><figcaption><p>The Google Workspace Alert Source configuration (pt 1)</p></figcaption></figure>

* If you wish, you may input [Google Workspace alert types](https://developers.google.com/workspace/admin/alertcenter/reference/alert-types) to exclude from Dropzone's investigation. To do so, under the "Alert types to exclude" section, click "Add Item," then input the alert types

<figure><img src="/files/bXzlx9xW9UN6GRonaVRQ" alt=""><figcaption><p>The Google Workspace Alert Source configuration (pt 2)</p></figcaption></figure>

If you wish to utilize Google Workspace Phishing Alerts, you do not need to perform any extra steps, and may proceed to inputting your desired poll interval and lookback.

If you want to process phishing emails from a dedicated mailbox, do the following:

* In the "Phishing Account Email Address" section, enter the email address of your dedicated phishing account
* If you wish for only some of the messages in this phishing account to be processed, input a [Gmail filter](https://support.google.com/mail/answer/6579?hl=en)
  * For example, some third-party tools may modify the subject to include "Phishing Alert," in which case you can use a Gmail filter like `subject:"Phishing Alert"` to limit processing to these messages
* If you use a third-party tool that includes the original email as an attachment then check the "Prefer RFC822 message attachment, when present" button

<figure><img src="/files/01lpQuBc4zrcBCfmsZU5" alt=""><figcaption><p>The Google Workspace Alert Source configuration (pt 3)</p></figcaption></figure>

* Once you are done selecting your Phishing Ingest Mechanism, input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Google Workspace Alert Source configuration (pt 4)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Google Workspace Alert Source configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.


# Jira

{% hint style="info" %}
Dropzone's integration is only with the Jira Cloud, however support for on-prem Jira Datacenter is on the roadmap.
{% endhint %}

The Dropzone platform supports [Jira](https://confluence.atlassian.com/jira), a project management and issue tracking tool from Atlassian.

## Create an API Key

Jira requires an API key to enable. The API key is associated with an account, so you may wish to create a dedicated service user rather than using your own.

To obtain an API Key, do the following:

* Log into your Jira account e.g. https\://*mycompany*.atlassian.net as the API user for Dropzone AI
* Click on your user icon and click "Manage Account"

<figure><img src="/files/OvKYfe26C8hNJ2JzlJKl" alt=""><figcaption><p>Go to "Manage Account"</p></figcaption></figure>

* In the top banner, bavigate to "Security"

<figure><img src="/files/j2PtR79iEESwbh6lMbst" alt=""><figcaption><p>Navigate to "Security"</p></figcaption></figure>

* Under "API tokens," click "Create and manage API tokens"

<figure><img src="/files/o2DgsE4lLAdZqyssaagv" alt=""><figcaption><p>Click "Create and manage API tokens"</p></figcaption></figure>

* Click "Create API token"

<figure><img src="/files/YIfI69lZBcrrotPGMD2b" alt=""><figcaption><p>Create API token</p></figcaption></figure>

* Enter a name to identify the API key, such as Dropzone.ai, then click "Create"

<figure><img src="/files/inY8UjUmZhImrM2WKfJ2" alt=""><figcaption><p>Create API token</p></figcaption></figure>

* Store the API token shown in a secure location for use later in the Dropzone UI where it is called "API Token"

<figure><img src="/files/qroUH4dhTIGVszUf1JBQ" alt=""><figcaption><p>Copy API token</p></figcaption></figure>

## Enable Jira

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                    |
| -------------- | ------------------------------------------------------------------------- |
| Server         | The same as your company server url in Jira, eg *mycompany*.atlassian.net |
| Username       | The username of the account that created the API                          |
| API Token      | The API token value you generated earlier                                 |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Jira, then click "Configure"

<figure><img src="/files/hp3fx5SdeVP3vmXgdFqq" alt=""><figcaption><p>The Jira Tile</p></figcaption></figure>

* Under the Alert Source heading, input the Server, Username, and API Token
* In the "Ticket alert workflow" section, select an option from the "Alert Extraction Strategy"
  * Ask your Dropzone support representative if you do not know which to use

<figure><img src="/files/GXOwe9mp60yWcgkvXGRA" alt=""><figcaption><p>The Jira Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Jira Issue Filter," you must input a Jira [JQL](https://support.atlassian.com/jira-service-management-cloud/docs/use-advanced-search-with-jira-query-language-jql/) search query to identify Jira tickets that contain alerts to investigate
* Input your desired Poll interval and lookback
* If you want Dropzone to push its investigation results back to Jira, check the box labeled "Comment Investigation Results to ticket"

<figure><img src="/files/zYRKhkF1JWkXDZ6joGlb" alt=""><figcaption><p>The Jira Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Jira Alert Source Configuration (pt 3)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Microsoft (MS 365 etc)

## Microsoft Integrations

Dropzone AI integrates with [Microsoft 365/Microsoft Defender](/integrations/alert/ms_alert/ms365_alert), as well as [Microsoft Sentinel](/integrations/alert/ms_alert/mssentinel_alert). This document serves as an overview for performing certain steps of their integration. Further information on how to perform the integrations for Microsoft 365/Defender and Microsoft Sentinel can be found on their separate pages.

### Integration Overview

To enable these integrations you will perform the following actions:

* Register a new application in Microsoft Entra Admin Center
* Locate your Client ID, Tenant ID, and create a Client Secret
* Assign the necessary API permissions to the application

## Register a New Application in Microsoft Entra Admin Center

{% hint style="info" %}
Microsoft's documentation for registering an application is available at <https://learn.microsoft.com/en-us/graph/auth-register-app-v2>
{% endhint %}

* Sign into [your Entra home](https://entra.microsoft.com/#home) as an administrator
* In the left sidebar, navigate to Identity > Applications > App Registrations

<figure><img src="/files/mFaEVw1wpFkCEEMa7Sfi" alt=""><figcaption><p>Navigate to App Registrations</p></figcaption></figure>

* Click "New Registration"
* Name the new application something memorable, such as "Dropzone AI"
* Under "Supported account types," select "Single tenant only"
* Leave the "Redirect URI (optional)" section blank
* Click "Register"

<figure><img src="/files/9AbohV9WTuA3SewCwQX6" alt=""><figcaption><p>Registering the Dropzone AI Application</p></figcaption></figure>

### Client ID, Tenant ID, and Client Secret

Once the application has been created, it will redirect you to the application's Overview page.

{% hint style="info" %}
Microsoft's documentation for creating client credentials for an application is available [here](https://learn.microsoft.com/en-us/graph/auth-register-app-v2#add-credentials)
{% endhint %}

* In the Overview page, copy the Application ID and the Directory ID for use later in the Dropzone UI, where they are called "Client ID" and "Tenant ID" respectively

<figure><img src="/files/zunIChYt6aZjHD85FGd3" alt=""><figcaption><p>Copy the integration details</p></figcaption></figure>

* Next to "Client credentials," click "Add a certificate or secret"

<figure><img src="/files/cuSiEu3RFJ9VDrhuYuIJ" alt=""><figcaption><p>Add a certificate or secret</p></figcaption></figure>

* Under the Client secrets heading, click "New client secret"

<figure><img src="/files/jsnERSPOmIq2ZDjdYoeg" alt=""><figcaption><p>Create a new client secret</p></figcaption></figure>

* Enter a description for the client secret, such as "Dropzone AI Integration Secret," and choose an appropriate expiration date. Click "Add"

{% hint style="warning" %}
Your Dropzone integration will stop working when the client secret expires. Consider setting a calendar reminder to update the key prior to expiration. For convenience's sake, we recommend picking a longer expiration date, to limit the number of times the client secret must be updated.
{% endhint %}

<figure><img src="/files/P9t3i6nbYpA71oWlW0yC" alt=""><figcaption><p>Add client secret</p></figcaption></figure>

* Under "Value," copy the Client Secret Value for use later in the Dropzone UI, where it is called "Client Secret"

<figure><img src="/files/l30qWVyN22HrZyY1vkCB" alt=""><figcaption><p>Copy the Client Secret Value</p></figcaption></figure>

{% hint style="danger" %}
This value is not shown after you leave this page - be sure to record it immediately.
{% endhint %}

## Set Application Permissions

* In the application's sidebar, navigate to Manage > API permissions

<figure><img src="/files/8Xmu3EMucRPxeMnAHOk7" alt=""><figcaption><p>Navigate to API permissions</p></figcaption></figure>

* Click "Add a permission"

<figure><img src="/files/NpypKLRBGFE0uE4GV9Bw" alt=""><figcaption><p>Add a permission</p></figcaption></figure>

{% hint style="info" %}
Depending on the integration you are performing, you will need to add different permissions. See ([Microsoft 365/Microsoft Defender](/integrations/alert/ms_alert/ms365_alert) or [Microsoft Sentinel](/integrations/alert/ms_alert/mssentinel_alert) for more details). For the purpose of this overview, the Microsoft Graph API has been used.
{% endhint %}

* In the search bar, input the desired API, such as "Microsoft Graph" and select it

<figure><img src="/files/aPROhoZxRlOREvrVn9BN" alt=""><figcaption><p>Select Microsoft Graph</p></figcaption></figure>

* Click "Application permissions"
* In the search bar, input the name of the permission your integration requires, then check the box next to it. Continue to do so until all permissions have been added, then click "Add permissions"

<figure><img src="/files/jVxcXTcAFR4E5p05pFCS" alt=""><figcaption><p>For example, add the SecurityEvents.Read.All permission</p></figcaption></figure>

Once back in the Application API permissions page, you should now see the permissions, such as the following:

<figure><img src="/files/1JYHQTNZWFWv2kmNAJLv" alt=""><figcaption><p>(Example permissions)</p></figcaption></figure>

* Click "Grant admin consent for \[mycompany.net]"

<figure><img src="/files/nKTcgGobOtW8J851R42c" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

* Click "Yes"

<figure><img src="/files/6t1bTqpO5FLj1cjlgnEu" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

You should now see all the required permissions listed with a green check mark

<figure><img src="/files/GreXghX5th0kMak7bvbI" alt=""><figcaption><p>(Completed permissions)</p></figcaption></figure>


# Microsoft 365 / Microsoft Defender

## Microsoft 365 / Microsoft Defender

The Dropzone AI platform integrates with Entra ID, Exchange Online, and Microsoft Defender via the Microsoft Graph API. This document describes how to set up API credentials and install them into the Dropzone platform.

### Integration Overview

To enable these integrations you will perform the following actions:

* Register a new application in Microsoft Entra Admin Center
* Locate your Client ID, Tenant ID, and create a Client Secret
* Enable Dropzone Certificate Credentials
* Assign necessary API permissions to the application
* Install the credentials into your Dropzone tenant (Data Source and Alert Source)
* Select integration parameters, such as which alert types to sync

See the [Microsoft Integrations](/integrations/alert/ms_alert) page for instructions on how to register a new application, locate your Client ID and Tenant ID, and create a Client Secret.

## Set Application Permissions

General instructions on how to assign API permissions to the application can be found in the [Microsoft Integrations](/integrations/alert/ms_alert) page.

MS 365/MS Defender can utilize the following APIs:

| API                                   | Purpose                                                                                                                                                              |
| ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Microsoft Graph                       | Required for the integration to function                                                                                                                             |
| Microsoft Cloud Apps Security.        | Required to query investigations from Microsoft Cloud Apps. When enabled, Dropzone is able to analyze cloud apps events                                              |
| Windows Defender ATP - Live Response. | Required to extract quarantined files from Defender alerts. When enabled, Dropzone is able to independently analyze the files which will improve conclusion accuracy |
| Office 365 Exchange Online Management | Required to enable Office 365 Exchange Online Management, specifically to support retrieving quarantined emails during phishing analysis                             |

## Microsoft Graph Permissions

* In the API permissions page, click "Add a permission"
* Under the Microsoft API header, select "Microsoft Graph"

<figure><img src="/files/7ucvU7fOJt0pTZQNDMws" alt=""><figcaption><p>Select Microsoft Graph</p></figcaption></figure>

* Click "Application Permissions"

<figure><img src="/files/oSiXAegQZauD3wcHDF3q" alt=""><figcaption><p>Select Application Permissions</p></figcaption></figure>

Add the following permissions:

| Permission                             | Purpose                                                                                                                | Used By                                                                           |
| -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| AuditLog.Read.All                      | Retrieve audit information such as user MFA and administrator access status, for alert investigation and chat          | Data Source Integration, Alert Source Integration - Microsoft Entra ID Protection |
| Calendars.Read                         | Allow access to Microsoft Calendar, for use in investigations to determine user OOO / travel status                    | Data Source Integration - Calendar Features                                       |
| Calendars.ReadBasic.All                | Retrieve basic calendar information for use in investigations to determine user OOO / travel status                    | Data Source Integration - Calendar Features                                       |
| MailboxSettings.Read                   | Retrieve mailbox settings, such as OOO or vacation status                                                              | Data Source Integration - Calendar Features                                       |
| Presence.Read.All                      | Retrieves presence information, such as availability status, location, etc                                             | Data Source Integration - Calendar Features                                       |
| Directory.Read.All                     | Retrieve directory information such as users, group membership, directory roles, etc, for alert investigation and chat | Data Source Integration                                                           |
| Mail.Read                              | Retrieve phishing emails for analysis; retrieve phishing alerts in some configurations                                 | Alert Source and Data Source Integrations                                         |
| ThreatHunting.Read.All                 | Investigating Microsoft Defender alerts                                                                                | Alert Source Integration                                                          |
| SecurityAlert.Read.All                 | Pulling Microsoft Defender alerts                                                                                      | Alert Source Integration                                                          |
| SecurityIncident.Read.All              | Pulling Microsoft Defender alerts                                                                                      | Alert Source Integration                                                          |
| ThreatSubmission.Read.All              | Pulling Phishing Alerts                                                                                                | Alert Source Integration                                                          |
| IdentityRiskEvent.Read.All             | Pulling Microsoft Entra ID Risk information                                                                            | Alert Source Integration - Microsoft Entra ID Protection                          |
| IdentityRiskyUser.Read.All             | Pulling Microsoft Entra ID Risk information                                                                            | Alert Source Integration - Microsoft Entra ID Protection                          |
| IdentityRiskyServicePrincipal.Read.All | Pulling Microsoft Entra ID Risk information                                                                            | Alert Source Integration - Microsoft Entra ID Protection                          |
| User.Read.All                          | Allow Dropzone to read all user profile properties when investigating suspicious alerts                                | Remediator Integration                                                            |
| User.RevokeSessions.All                | Allow Dropzone to revoke user sessions of users indicated in suspicious alerts                                         | Remediator Integration                                                            |
| User.EnableDisableAccount.All          | Allow Dropzone to suspend accounts indicated in suspicious alerts                                                      | Remediator Integration                                                            |

<figure><img src="/files/UpR006DSi2UIYDblppvh" alt=""><figcaption><p>Example - adding the "User.Read.All" permission</p></figcaption></figure>

* Once done selecting all the permissions, click "Add permissions"

{% hint style="info" %}
Some of these permissions are only necessary for the Data Source and Remediator integrations. If you don't intend to perform those integrations, you may ignore them.

Enabling Dropzone's Data Source Calendar Features is optional. Enabling Dropzone's Alert Source Microsoft Entra ID Protection feature is optional.
{% endhint %}

* Click "Grant admin consent for \[mycompany.net]"

<figure><img src="/files/nKTcgGobOtW8J851R42c" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

* Click "Yes"

<figure><img src="/files/6t1bTqpO5FLj1cjlgnEu" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

## Microsoft Cloud Apps Security Permissions

* In the API permissions page, click "Add a permission"
* Navigate to "APIs my organization uses"
* Type "Microsoft Cloud App Security" in the search bar

<figure><img src="/files/EnT5pdj0RtLd2YnFYkwQ" alt=""><figcaption><p>Microsoft Cloud App Security</p></figcaption></figure>

* Click "Microsoft Cloud App Security"
* Click "Application permissions"

Add the following permissions:

| Permission         | Purpose                       |
| ------------------ | ----------------------------- |
| investigation.read | Read Cloud App investigations |

* Once done selecting all the permissions, click "Add permissions"
* Click "Grant admin consent for \[mycompany.net]"
* Click "Yes"

## Windows Defender ATP - Live Response

* In the API permissions page, click "Add a permission"
* Navigate to "APIs my organization uses"
* Type "WindowsDefenderATP" in the search bar

<figure><img src="/files/ZcYygS7l1OCdcoFjlbUz" alt=""><figcaption><p>WindowsDefenderATP</p></figcaption></figure>

* Click "WindowsDefenderATP"
* Click "Application permissions"

Add the following permissions:

| Permission           | Purpose                                                                              |
| -------------------- | ------------------------------------------------------------------------------------ |
| File.Read.All        | Read file profiles. Note that this is different from the "Files.Read.All" permission |
| Library.Manage       | Extract quarantined files for analysis                                               |
| Machine.LiveResponse | Extract quarantined files for analysis                                               |
| Machine.Read.All     | Read machine details                                                                 |
|                      |                                                                                      |

<figure><img src="/files/WKUEGs2SCUhLA1vBgjKt" alt=""><figcaption><p>Example - adding the "File.Read.All" permission</p></figcaption></figure>

* Once done selecting all the permissions, click "Add permissions"
* Click "Grant admin consent for \[mycompany.net]"
* Click "Yes"

#### Locate Organization ID

* Sign into [Entra home](https://entra.microsoft.com/#home) as an administrator
* In the left navigation, select Manage > Custom domain names

<figure><img src="/files/iF2UvM2aURIBqJNklUO3" alt=""><figcaption><p>Azure Custom Domain Names</p></figcaption></figure>

* In the domain list you'll find one that ends in `.onmicrosoft.com`. Record this domain for use later in the Dropzone UI where it is called "Organization ID"

<figure><img src="/files/aN2dMYKjVzxyicMq9XKi" alt=""><figcaption><p>Azure Custom Domain Names List</p></figcaption></figure>

## Locate Cloud Apps Information

* Go to <https://security.microsoft.com/>
* In the left navigation, select Settings
* Select Cloud Apps

<figure><img src="/files/ejvXtOAeTtDaTNnN7BJk" alt=""><figcaption><p>Defender Cloud Apps API URL</p></figcaption></figure>

Record the "API URL" for use later in the Dropzone UI where it is called "Portal URL".

## Enable Microsoft 365/Microsoft Defender

The Alert Source integration allows Dropzone AI to pull alerts from Exchange Online and Microsoft Defender for investigation.

You'll need the following information:

| Dropzone Field  | Source                                           |
| --------------- | ------------------------------------------------ |
| Client ID       | The "Application (client) ID" you copied earlier |
| Tenant ID       | The "Directory (tenant) ID" you copied earlier   |
| Client Secret   | The client secret "value" you copied earlier     |
| Organization ID | The "Organization ID" you copied earlier         |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search MS 365/Defender, then click "Configure"

<figure><img src="/files/PPFAKUr9HhU3pWHSgJfh" alt=""><figcaption><p>The Microsoft 365/Defender Tile</p></figcaption></figure>

* Under the Alert Source heading, input the Client ID, Tenant ID, and Client Secret
* Select your Microsoft cloud environment from the dropdown
* Input your chosen [log-ingestion delay](https://learn.microsoft.com/en-us/azure/azure-monitor/logs/data-ingestion-time#indexing-time)

<figure><img src="/files/HLtVa0nZgcPtz0wPbqkH" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 1)</p></figcaption></figure>

* Select whether you want to ingest alerts or incidents from Microsoft Defender
* Select which Microsoft Defender Detection Sources you wish to allow Dropzone to investigate alerts/incidents from

<figure><img src="/files/ohOSt3kmSrYwniL7ezVg" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 2)</p></figcaption></figure>

* In the "Enabled Alert Severity Levels" section, select the severity levels of alerts you want Dropzone to investigate
* In the "Enabled Status Filters" section, select the [incident statuses](https://learn.microsoft.com/en-us/defender-xdr/manage-incidents?tabs=queue#:~:text=asset%20management.-,Change,-the%20incident%20status) you want Dropzone to investigate

<figure><img src="/files/3vSYMc7UdDemjmmikXY2" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 3)</p></figcaption></figure>

* To enable Dropzone to ingest Microsoft Email Alerts, check the box labeled "Email Threat Submissions"
* If you wish to exclude emails from analysis, select the categories of emails you want Dropzone to ignore (e.g. Allowed by Policy, Allowed Due To User Override, etc)

<figure><img src="/files/hpdQvQAtY54Y1RTK6hHr" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 4)</p></figcaption></figure>

* To enable Dropzone to ingest [Microsoft Entra ID Protection](https://learn.microsoft.com/en-us/entra/id-protection/overview-identity-protection) data, check the box labeled "Enable Microsoft Entra ID Protection ingestion"
* Select the types of [Risk reports](https://learn.microsoft.com/en-us/entra/id-protection/concept-risk-reports) you want Dropzone to investigate

<figure><img src="/files/4DbCDuZAxOwgpTf9zQbo" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration - Entra ID (pt 1)</p></figcaption></figure>

* Under "Risk levels," you may select the [levels](https://learn.microsoft.com/en-us/entra/id-protection/concept-risk-detection-types#:~:text=Risk-,levels,-ID%20Protection%20categorizes) of risk you want Dropzone to investigate from the dropdown

<figure><img src="/files/HBBzK5fhoVN5oAjpf6VR" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration - Entra ID (pt 2)</p></figcaption></figure>

* Under "Risk states," you may select the states of risk you want Dropzone to investigate from the dropdown

<figure><img src="/files/A5YFSG6z8oCpYoPwFyN7" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration - Entra ID (pt 3)</p></figcaption></figure>

* If you wish for Dropzone to use a specified mailbox for Phishing Analysis, check the box labeled "Enable Mailbox-based Phishing Analysis"
* Input the email address for your phishing account
* Input any desired [filters](https://learn.microsoft.com/en-us/graph/filter-query-parameter)

{% hint style="success" %}
This will allow your organization to limit the scope of Dropzone AI's Mail.Read permissions. See the [Mail-Enabled Security Group](/integrations/alert/ms_alert/ms365_email_group) documentation for instructions on how to create a designated phishing account.
{% endhint %}

<figure><img src="/files/lcGpQN4fphlRCzIEDQEU" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 5)</p></figcaption></figure>

* If you wish to enable Dropzone to retrieve quarantined emails for phishing analysis, check the box labeled "Enable PowerShell API" in the PowerShell API Configuration section. Enter the Organization ID you saved earlier (which should end in .onmicrosoft.com)

<figure><img src="/files/3xGtbxWG2f44Dd73qSVR" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 6)</p></figcaption></figure>

* In the Defender Alert and Incident Exclusions, you may further customize your MS Defender alerts by checking the boxes labeled "Prelude Security," "Custom File Exclusion," and "Title Exclusion"

<figure><img src="/files/lfl5ba6AIj0YFKjvtPYX" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 7)</p></figcaption></figure>

* If you wish to customize your ingestion of [Data Loss Prevention alerts](https://learn.microsoft.com/en-us/purview/dlp-alert-investigation-learn), in the DLP Enforcement Mode section, select a DLP enforcement mode to filter the layers by. If you do not select an enforcement mode, all DLP alerts will be ingested

<figure><img src="/files/pBBIca7GcT89uG24wwYw" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 7)</p></figcaption></figure>

* If you wish to enable Dropzone to ingest MS Defender incidents in stages to reduce data volume, check the box labeled "Enable Paginated Queries," then input your desired paginated query page size
* Input your desired poll interval and lookback

<figure><img src="/files/CWpZaGRZl6PloMcVdDFB" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 8)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button

<figure><img src="/files/pH1cSwRcV2Wyw7QKJEjn" alt=""><figcaption><p>The Microsoft 365/Defender Alert Configuration (pt 9)</p></figcaption></figure>

* Click "Test & Save" to finish

<figure><img src="/files/pvAAFxWe2piE0VEuHQs8" alt=""><figcaption><p>Click Test &#x26; Save</p></figcaption></figure>

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.


# Microsoft Security Group

The Dropzone platform can ingest email and phishing alerts from cross-organizational email accounts. If you wish to restrict the access of Dropzone's analysis, you can create a dedicated mail-enabled security group and create an Application Access Policy which restricts access to a finite and enumerated list of mailboxes

## Create a Mail-Enabled Security Group

* Navigate to your [Microsoft Exchange Admin Center](https://admin.exchange.microsoft.com/#/)
* In the left sidebar, navigate to Recipients > Groups

<figure><img src="/files/26muTQqrV5IbyoHX2vcQ" alt=""><figcaption><p>Click "Groups"</p></figcaption></figure>

* Click "Add a group"

<figure><img src="/files/GbebxRwqLtXW7GBw5Ncx" alt=""><figcaption><p>Add a Group</p></figcaption></figure>

* Select "Mail-enabled security," then click "Next"

<figure><img src="/files/pMXuUUpfc6LSyei81VE2" alt=""><figcaption><p>Click "Mail-enabled Security"</p></figcaption></figure>

* Name the group something memorable, such as "DropzoneAllowedInboxes," then click "Next"

<figure><img src="/files/MIhRay4UISgPzUymdwoJ" alt=""><figcaption><p>Assign a group name</p></figcaption></figure>

* Click "+ Assign Owners" and assign your desired owner from the list, then click "Add"

<figure><img src="/files/D04n2zuOS27rskOodsyo" alt=""><figcaption><p>Assign an owner</p></figcaption></figure>

* Click "+ Add Members" and add your desired members. Members will receive all emails sent to this email address, and will be able to send emails to it for Dropzone to analyze

<figure><img src="/files/VwDTDIycEvDNFczMzi5g" alt=""><figcaption><p>Add group members</p></figcaption></figure>

* In the "Edit Settings" section, create a memorable group email address, such as "<dropzone-allowed-inboxes@mycompany.net>"
* If you want people outside of your organization to be able to send emails to the group, check the box under "Communication"
* For added security, you may check the box under "Approval" to require owner permission to join the group

<figure><img src="/files/ZRmQ34v0kdHzMAfVkIQX" alt=""><figcaption><p>Configure the group email address</p></figcaption></figure>

* Click "Next," then click "Create Group"

<figure><img src="/files/FRQWitfLFwmVAUCU0zYg" alt=""><figcaption><p>Create the group</p></figcaption></figure>

See Microsoft's [documentation](https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-mail-enabled-security-groups) for more information

## Create an Application Access Restriction Policy

* Follow steps on the [Microsoft Integrations](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/integrations/alert/ms_alert/readme.md) page to create a new application in Microsoft Entra Admin Center (or use an existing application)
* Record your Client ID
* Navigate to your [Exchange Admin Center](https://admin.cloud.microsoft/exchange#/)
* In the upper right, click the terminal icon

<figure><img src="/files/WViqWidB1dvzfsdAJotr" alt=""><figcaption><p>The terminal icon</p></figcaption></figure>

* If you are not on Powershell, click "Switch to Powershell"
* Connect to Exchange Online by inputting the following code:

`Connect-ExchangeOnline`

* Input the following restriction policy

{% hint style="info" %}
Be sure to replace the AppID variable with the Client ID copied earlier and the GroupEmail variable with email address you just created
{% endhint %}

````$appid
$GroupEmail = "dropzone-allowed-inboxes@mycompany.net"

New-ApplicationAccessPolicy -AppId $AppId `
    -PolicyScopeGroupId $GroupEmail `
    -AccessRight RestrictAccess `
    -Description "Restricts Dropzone to specific inboxes only"```

* To test that Dropzone can only access the desired mailboxes, input the following code:
```Test-ApplicationAccessPolicy -AppId $AppId -Identity "allowed-mailbox@example.com"```
```Test-ApplicationAccessPolicy -AppId $AppId -Identity "any-other-mailbox@example.com"```

Allowed mailboxes should result in Granted, while denied mailboxes should return Denied

If you have any errors, engage your DropzoneAI support representative.
````


# Microsoft Sentinel

## Microsoft Sentinel

{% hint style="success" %}
Microsoft Sentinel is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Microsoft Sentinel](https://learn.microsoft.com/en-us/azure/sentinel/) security SIEM. Many customers ingest other alert sources into Microsoft Sentinel (e.g. IDPs) and integrate Dropzone into Microsoft Sentinel rather than the source systems.

### Integration Overview

To enable these integrations you will perform the following actions:

* Register a new application in Microsoft Entra Admin
* Locate your Client ID, Tenant ID, and create a Client Secret
* Assign necessary API permissions to the application
* Assign roles to the application in Microsoft Sentinel
* Locate your Workspace Name and Workspace ID

See the [Microsoft Integrations](/integrations/alert/ms_alert) page for instructions on how to register a new application, locate your Client ID and Tenant ID, and to create a Client Secret.

### Set Application Permissions

General instructions on how to assign API permissions to the application can be found in the [Microsoft Integrations](/integrations/alert/ms_alert) page.

Enabling MS Sentinel will require the following APIs and permissions:

| API             | Permissions               |
| --------------- | ------------------------- |
| Log Analytics   | `Data.Read`               |
| Microsoft Graph | `SecurityEvents.Read.All` |

To add the Log Analytics API, do the following:

* In the API permissions page, click "Add a permission"
* Navigate to "APIs my organization uses"
* In the search bar, input "Log Analytics API," and select it

<figure><img src="/files/y0lNbvqOTCACuono7Rwu" alt=""><figcaption><p>Select Log Analytics API</p></figcaption></figure>

* Click "Application permissions"
* In the search bar, input "Data.Read" and select it. Click "Add permissions"

<figure><img src="/files/QLuZAWYsOXpDpFzQgfzO" alt=""><figcaption><p>Add the Data.Read permission</p></figcaption></figure>

* Once back in the Application API permissions page, click "Grant admin consent for \[mycompany.net]"

<figure><img src="/files/nKTcgGobOtW8J851R42c" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

* Click "Yes"

<figure><img src="/files/6t1bTqpO5FLj1cjlgnEu" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

If your integration requires access to security alerts via Microsoft Graph, do the following:

* In the API permissions page, click "Add a permission"
* Under the Microsoft API header, select "Microsoft Graph"

<figure><img src="/files/7ucvU7fOJt0pTZQNDMws" alt=""><figcaption><p>Select Microsoft Graph</p></figcaption></figure>

* Click "Application permissions"
* Check the permission "SecurityEvents.Read.All," then click "Add permissions"

<figure><img src="/files/jVxcXTcAFR4E5p05pFCS" alt=""><figcaption><p>Add the SecurityEvents.Read.All permission</p></figcaption></figure>

* Once back in the Application API permissions page, click "Grant admin consent for \[mycompany.net]"

<figure><img src="/files/nKTcgGobOtW8J851R42c" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

* Click "Yes"

<figure><img src="/files/6t1bTqpO5FLj1cjlgnEu" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

### Assign Roles in Microsoft Sentinel

To allow the application to access Microsoft Sentinel data, you must assign the application roles based on your desired access level.

* Navigate to [your Azure portal](https://portal.azure.com)
* Under the "Azure Services" heading, navigate to Microsoft Sentinel

<figure><img src="/files/KQBmhRjA7BMpTWzW7a1g" alt=""><figcaption><p>Navigate to Microsoft Sentinel</p></figcaption></figure>

* Select the Log Analytics Workspace you wish to analyze

<figure><img src="/files/CI94g8EcSk2jpupwdQYV" alt=""><figcaption><p>Select your workspace</p></figcaption></figure>

* Navigate to Configuration > Settings

<figure><img src="/files/rUuELoLWHKh310WXozqe" alt=""><figcaption><p>Navigate to Settings</p></figcaption></figure>

* Click on "Workspace settings"

<figure><img src="/files/s8i3MWmkqgG49GpHRbVD" alt=""><figcaption><p>Click on Workspace settings</p></figcaption></figure>

* Navigate to "Access control (IAM)"

<figure><img src="/files/2YPqtg5kekYZvCn2bRzg" alt=""><figcaption><p>Click on Access control (IAM)</p></figcaption></figure>

* Select Add > Add role assignment

<figure><img src="/files/ihAPqecFisIRxjncGWo8" alt=""><figcaption><p>Add a role assignment</p></figcaption></figure>

* Select a [role](https://learn.microsoft.com/en-us/azure/sentinel/roles) based on your desired access level:
  * Read-only access: Log Analytics Reader or Microsoft Sentinel Reader
  * Read and write access: Microsoft Sentinel Responder or Microsoft Sentinel Contributor

{% hint style="info" %}
If you wish to enable Ticket Sync, you must assign the application a Read and write access role.
{% endhint %}

<figure><img src="/files/9kQV6HNPCiYEW8V95rOX" alt=""><figcaption><p>Select your role</p></figcaption></figure>

{% hint style="info" %}
For the purpose of this documentation, the Log Analytics Reader role has been selected.
{% endhint %}

* Once you have selected your role, click "Members"
* Next to "Assign access to," select "User, group, or service principal"
* Click "Select members"

<figure><img src="/files/fgggpOPjLbOrpyFz1Wbl" alt=""><figcaption><p>Click Select members</p></figcaption></figure>

* Search for your application (such as Dropzone AI Sentinel Integration) and click "Select"

<figure><img src="/files/YMoN05jrevkVCfe0F6XY" alt=""><figcaption><p>Assign members</p></figcaption></figure>

* In the bottom left hand corner, click "Review + assign" twice

<figure><img src="/files/b9FRKrRs2rNSOo88FaCr" alt=""><figcaption><p>Click Review + assign</p></figcaption></figure>

### Workspace IDs

To obtain your Workspace Name and Workspace ID, do the following:

* Navigate to [your Azure portal](https://portal.azure.com)
* Under the "Azure Services" heading, navigate to Microsoft Sentinel

<figure><img src="/files/P5OIltBBJg5by3nLF3cc" alt=""><figcaption><p>Navigate to Microsoft Sentinel</p></figcaption></figure>

* Select the Workspace you wish to analyze

<figure><img src="/files/CI94g8EcSk2jpupwdQYV" alt=""><figcaption><p>Select your workspace</p></figcaption></figure>

* In the left sidebar, navigate to Configuration > Settings

<figure><img src="/files/rUuELoLWHKh310WXozqe" alt=""><figcaption><p>Navigate to settings</p></figcaption></figure>

* Click on "Workspace Settings"

<figure><img src="/files/s8i3MWmkqgG49GpHRbVD" alt=""><figcaption><p>Navigate to settings</p></figcaption></figure>

* Copy the Workspace ID, Subscription ID, and Resource Group shown for use later in the Dropzone UI

<figure><img src="/files/KWLIc6NYPEhdIS0KC6DI" alt=""><figcaption><p>Copy the integration details</p></figcaption></figure>

## Enable Microsoft Sentinel

To enable the Alert Source integration, you will need the following information:

| Dropzone Field  | Source                                 |
| --------------- | -------------------------------------- |
| Client ID       | The Application ID copied earlier      |
| Tenant ID       | The Directory ID copied earlier        |
| Client Secret   | The Client Secret Value copied earlier |
| Workspace ID    | The Workspace ID copied earlier        |
| Subscription ID | The Subscription ID copied earlier     |
| Resource Group  | The Resource group copied earlier      |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom right corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Microsoft Sentinel, then click "Configure"

<figure><img src="/files/tJDymzu1jtTXP4KMgrdy" alt=""><figcaption><p>The Microsoft Sentinel Tile</p></figcaption></figure>

* Under the Alert Source heading, input the Client ID, Tenant ID, and Client Secret

<figure><img src="/files/wANaEfXLZmf5xVdoVgco" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 1)</p></figcaption></figure>

* Under the Workspaces heading, click "Add item." Input the details of your workspace, then click "Add item" again

<figure><img src="/files/cIcUDouyxgXz19FgwEoS" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 2)</p></figcaption></figure>

* Under the heading "Enabled severity levels," check the boxes for each incident severity level you want Dropzone to ingest alerts for
* Under the heading "Enabled statuses," check the box for each incident status you want Dropzone to investigate alerts for

<figure><img src="/files/ObCI11lXuysa5NeA3kHL" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 3)</p></figcaption></figure>

* If you wish, you may add [KQL](https://learn.microsoft.com/en-us/kusto/query/?view=microsoft-fabric) queries to investigate. To do so, click "Add Item" under the KQL Queries heading, then input the Query. Click "Add item" again when done

<figure><img src="/files/YqkZQLfXQgndgiqo7v1k" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 4)</p></figcaption></figure>

* If you wish, you may adjust your ticket sync settings. To do so, under the "Ticket Sync — Update Ticket Status" header, check the box labeled "Update status on investigation change"

{% hint style="info" %}
Dropzone has several stages to its investigation process: Start, Completed/In Review, Reviewed, and Reopened. During those stages, Dropzone can write updates to the Sentinel ticket status. Shown below is a reasonable default.
{% endhint %}

<figure><img src="/files/HWLAhZmrUD9yhTqmHq2o" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 5)</p></figcaption></figure>

* If you want Dropzone to be able to investigate email alerts, check the box under the heading "Microsoft Defender Email Fetching"

<figure><img src="/files/AplzS39VQvH6FYTVTy4f" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 6)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="/files/2qn1FRWfM87n9ApeByn9" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 7)</p></figcaption></figure>

* If you wish for Dropzone to update the ticket status over the course of the investigation, check the box labeled "Update ticket status on investigation change," then select the status parameters

<figure><img src="/files/gMRliNdBlYHelrX4x04y" alt=""><figcaption><p>The Microsoft Sentinel Alert configuration (pt 8)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>Click "Test &#x26; Save" to finish</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Microsoft 365 Exchange Online Management

{% hint style="info" %}
This configuration is only required if you are using Dropzone AI to analyze Quarantined Emails in Microsoft Defender for Office 365.
{% endhint %}

To enable Office 365 Exchange Online Management, you must first install Dropzone Certificate Credentials.

Some Dropzone actions use x509 certificate based authentication, for example retrieving quarantined emails during phishing analysis. In this section we will set up the Dropzone certificate as trusted by Microsoft.

{% hint style="info" %}
Each Dropzone tenant uses a unique Dropzone certificate for maximum security.
{% endhint %}

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search MS 365/Defender, then click "Configure"

<figure><img src="/files/PPFAKUr9HhU3pWHSgJfh" alt=""><figcaption><p>The Microsoft 365/Defender Tile</p></figcaption></figure>

* Under "Connection," click "*mycompany*.dropzone.app.crt" and download the file

<figure><img src="/files/MY8GtT3kZ0PP2mJLh2J8" alt=""><figcaption><p>Download your Dropzone certificate</p></figcaption></figure>

* Return to the Application Overview for your new application
  * <https://entra.microsoft.com>
  * Applications > App Registration > All Applications > Dropzone AI
* In the left side bar, click "Certificates & Secrets"

<figure><img src="/files/04q91OeZCfvzXuCpzMcH" alt=""><figcaption><p>Certificates &#x26; Secrets</p></figcaption></figure>

* Navigate to Certificates, then click "Upload Certificate"

<figure><img src="/files/5oTsFxKxPEDgx9nOX2K3" alt=""><figcaption><p>Upload Certificate</p></figcaption></figure>

* Select the certificate file you downloaded from the Dropzone UI earlier
* For description, use "Dropzone AI"

<figure><img src="/files/FGLAMh9R5XrsyYtdoL9L" alt=""><figcaption><p>Upload Certificate File</p></figcaption></figure>

You should now see the certificate in the UI, including a 'thumbprint' (a cryptographic hash of the certificate.)

<figure><img src="/files/HzzjUsJeeEleveE9A6SG" alt=""><figcaption><p>Certificate installed</p></figcaption></figure>

Once you have installed your Dropzone credentials, you may assign the Office 365 Exchange Online Management permissions. To do so, do the following:

* In the left sidebar, return the API permissions page
* Click "Add a permission"
* Select "APIs my organization uses"
* Type "Office 365 Exchange Online" in the search bar

<figure><img src="/files/nHQa6g88A2q3nvTp8VDy" alt=""><figcaption><p>Office 365 Exchange Online</p></figcaption></figure>

* Click "Application permissions"

Add the following permissions:

| Permission             | Purpose           |
| ---------------------- | ----------------- |
| `Exchange.ManageAsApp` | Read file details |

* Once done selecting all the permissions, click "Add permissions"
* Click "Grant admin consent for \[mycompany.net]"
* Click "Yes"

### Create and Authorize Service Account

Next we need to run PowerShell commands to grant permissions. You may use whatever PowerShell environment you prefer. The examples below were performed using Azure's interactive Cloud Shell. You may find some of the [Microsoft Azure Documentation](https://learn.microsoft.com/en-us/powershell/azure/authenticate-interactive?view=azps-13.0.0) useful.

* Open your powershell environment
  * For example go to <https://portal.azure.com> and click on the Cloud Shell icon

<figure><img src="/files/eGWb6Dy01PXtUGlZ98jR" alt=""><figcaption><p>Azure Cloud Shell Icon</p></figcaption></figure>

* Connect to Entra ID and get information about the application we configured. The value for the `-AppID` parameter is the "Application (Client) ID" you recorded earlier

  ```
  PowerShell 7.4.5

  # Connect to "AzureAD"
  PS /home/wbagg> <b>Connect-AzureAD</b>
  VERBOSE: Authenticating to Azure ...
  VERBOSE: Building your Azure drive ...
  Loading personal and system profiles took 8788ms.

  # Run the following to get the object-id of our application, replacing
  # application-id with the actual Application (Client) ID of our new app
  #
  #    PS /home/wbagg> <b>Get-AzADServicePrincipal -AppID "<application-id>" | Select-Object DisplayName, AppId, Id | Format-List
  # 
  # For example:
  PS /home/wbagg> <b>Get-AzADServicePrincipal -AppID aaaaaaaa-1111-2222-3333-444444444444 | Select-Object DisplayName, AppId, Id | Format-List

  DisplayName : Dropzone AI
  AppId       : aaaaaaaa-1111-2222-3333-444444444444
  Id          : 44726f70-7a6f-6e65-5761-734865726521

  ```
* Note this `Id` field which we'll use in the next command, which we refer to as the `object-spid` (Service Principal ID)
* Connect to Exchange Online and Create an Exchange Online Service Principal for our Application

```
# Connect to ExchangeOnline
PS /home/wbagg> Connect-ExchangeOnline

# Run the following to create the service principal, replacing
# application-id and object-spid from the earlier values
#
#    PS /home/wbagg> New-ServicePrincipal -AppId "<application-id>" -ObjectId "<object-spid>" -DisplayName "Dropzone AI"
#
# for example
PS /home/wbagg> New-ServicePrincipal -AppId "aaaaaaaa-1111-2222-3333-444444444444" -ObjectId "44726f70-7a6f-6e65-5761-734865726521" -DisplayName "Dropzone AI"

DisplayName    ObjectId                               AppId
-----------    --------                               -----
Dropzone AI    44726f70-7a6f-6e65-5761-734865726521   aaaaaaaa-1111-2222-3333-444444444444
```

* Lastly, we assign Transport Hygiene Exchange Role to our Application

```
# Run the following to enable the Transport Hygiene role, replacing the
# application-id with the actual Application (Client) ID of our new app
#
#    PS /> New-ManagementRoleAssignment -App "application-id" -Role "Transport Hygiene"
#
PS /> New-ManagementRoleAssignment -App "aaaaaaaa-1111-2222-3333-444444444444" -Role "Transport Hygiene"

Name                           Role                RoleAssigneeName       RoleAssigneeType   AssignmentMethod   EffectiveUserName
----                           ----                ----------------       ----------------   ----------------   -----------------
Transport Hygiene-44726f70...  Transport Hygiene   ba0efd83-6465-48a...   ServicePrincipal   Direct

```

### Locate Organization ID

* Sign into [Entra home](https://entra.microsoft.com/#home) as an administrator
* In the left navigation, select Manage > Custom domain names

<figure><img src="/files/iF2UvM2aURIBqJNklUO3" alt=""><figcaption><p>Azure Custom Domain Names</p></figcaption></figure>

* In the domain list you'll find one that ends in `.onmicrosoft.com`. Record this domain for use later in the Dropzone UI where it is called "Organization ID"

<figure><img src="/files/aN2dMYKjVzxyicMq9XKi" alt=""><figcaption><p>Azure Custom Domain Names List</p></figcaption></figure>


# Mimecast

Dropzone AI integrates with [Mimecast 2.0](https://www.mimecast.com/), a secure email gateway that sits in front of an organization's email and filters emails, detecting threats such as malware, phishing and scams.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create a Custom Administration Role for your application
* Create an API 2.0 application
* Select integration parameters, such as which alert types to sync

## Create a Custom Admin Role

To limit Dropzone's access to your data, you may choose to create a custom [administrator role](https://mimecastsupport.zendesk.com/hc/en-us/articles/34000745394963-Roles-Understanding-Administrator-Roles#h_01JA88CBVKZ961KRA66F67D34Q) for your API application. You may skip this step and use the `Super Administrator` role instead.

* In your Mimecast homepage, click "Administration Console"

<figure><img src="/files/kPlMxZDXHMsMMDSsj6If" alt=""><figcaption><p>Click Administration Console</p></figcaption></figure>

* In the left hand sidebar, navigate to Account > Admin Roles

<figure><img src="/files/UVnTZrQvQ39xhNfccQMA" alt=""><figcaption><p>Click "Admin Roles"</p></figcaption></figure>

* Click "New Role"

<figure><img src="/files/1X898Ef2XmSOcu07nlo9" alt=""><figcaption></figcaption></figure>

* Name the role something memorable, such as "Dropzone AI Application Role"

<figure><img src="/files/IoYyf6lhGlRK5O02saOO" alt=""><figcaption></figcaption></figure>

* Assign the role the following permissions:

| Permission                                                          | Scope        | Purpose                                                            |
| ------------------------------------------------------------------- | ------------ | ------------------------------------------------------------------ |
| Security Events and Data Retrieval - Threat and Security Statistics | Read         | Allows Dropzone to see flagged threats and alerts within Mimecast  |
| Gateway - Tracking                                                  | Read         | Allows Dropzone to search for and retrieve specific email messages |
| Archive - Search                                                    | Read         | Allows Dropzone to retrieve email body content                     |
| Archive - Search                                                    | Content View | Allows Dropzone to retrieve email body content                     |

{% hint style="info" %}
You may only create a role with the Archive - Search `Content View` permission if you have Superadmin privileges. Contact your Mimecast representative if you do not have it.
{% endhint %}

<figure><img src="/files/LQ0gOayvg37zzeLh0RWy" alt=""><figcaption><p>The "Security Events and Data Retrieval" permission section</p></figcaption></figure>

* At the top of the role, click "Save and Exit"

## Create an API Key

Mimecast requires an API key to enable. To create an API key, you must have a Security Permissions setting of "Manage Application Roles"

* In your Mimecast homepage, click "Administration Console"

<figure><img src="/files/kPlMxZDXHMsMMDSsj6If" alt=""><figcaption><p>Click Administration Console</p></figcaption></figure>

* In the left hand sidebar, navigate to Integrations > API and Platform Integrations

<figure><img src="/files/C6nNl5mtRXj07jsT7PAJ" alt=""><figcaption><p>Click "API and Platform Integrations"</p></figcaption></figure>

* Locate the Mimecast API 2.0 tile
* Click "Generate Keys"

<figure><img src="/files/tq2d76mzAO5y3mA4IsQP" alt=""><figcaption><p>Click "Generate Keys"</p></figcaption></figure>

* Name the application something memorable, such as Dropzone AI
* Select the products you want Dropzone to have access to
* Assign the application a role (either the custom role you just created or the Full Administrator role)
* Input a memorable description for the application

<figure><img src="/files/r2AjgIcxYJqUUOu7DHBh" alt=""><figcaption><p>Input the application details</p></figcaption></figure>

* Designate a Technical Point of Contact for the application

<figure><img src="/files/ccKl8VPf5TtEVKrHuEpJ" alt=""><figcaption><p>Input the Notification Settings</p></figcaption></figure>

* At the top of the application, click "Save"
* Copy the credentials shown for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

<figure><img src="/files/dwU6QwOFInH5SAmYhR60" alt=""><figcaption><p>Save the API Credentials</p></figcaption></figure>

## Enable Mimecast

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                                                                                                                                                                          |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| API URL        | The URL of your Mimecast 2.0 instance. If you do not know your API URL, see [here](https://developer.services.mimecast.com/api-overview#:~:text=with%20appropriate%20permissions.-,API,-Gateway%20Options) for more information |
| Client ID      | The Client ID value you generated earlier                                                                                                                                                                                       |
| Client Secret  | The Client Secret value you generated earlier                                                                                                                                                                                   |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Mimecast, then click "Configure"

<figure><img src="/files/ZjX4HE2vwlJXBFjyrEWI" alt=""><figcaption><p>The Mimecast Tile</p></figcaption></figure>

* Input the API URL, Client ID and Client Secret

<figure><img src="/files/U3iH6mRVmFN6o5MkU3PT" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 1)</p></figcaption></figure>

* Select the [types](https://mimecastsupport.zendesk.com/hc/en-us/articles/34000509365651-Analysis-Response#h_01JED5RV0B0N5GXENM8PRVM6NG:~:text=Protection%20blocked%20clicks.-,Detection,-Categories) of threats you wish for Dropzone AI to investigate

<figure><img src="/files/bcc1Am4yWe1MSkRM7Low" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 2)</p></figcaption></figure>

* Select the [statuses](https://mimecastsupport.zendesk.com/hc/en-us/sections/34523591340051-Message-Center) of threats you wish for Dropzone AI to investigate

<figure><img src="/files/fPRcNxJG7IFNxW5f7EGH" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 3)</p></figcaption></figure>

* Select the threat sources you want Dropzone AI to ingest

<figure><img src="/files/xBxqQmz0YWrAglN0I5xL" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 4)</p></figcaption></figure>

* Check the box labeled "Search Content View Enabled" to allow Dropzone to retrieve the content of emails for analysis

{% hint style="success" %}
Only do so if you have granted the application the necessary permissions.
{% endhint %}

<figure><img src="/files/LUiKBZor1gJ0SWNGxUgg" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 5)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Mimecast Alert Source Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Palo Alto Cortex

## Palo Alto Cortex XSIAM/XDR

The Dropzone AI Platform integrates with the Palo Alto Cortex platform to monitor endpoints, gather data from cloud, network and identity sources, as well as analyze alerts.

### Create an API Key

Palo Alto Cortex requires an API key to enable. You’ll need access to a Cortex user account with the ability to generate and manage API keys. If you don’t have the necessary permissions, please get in touch with your Cortex administrator for assistance.

To obtain an API Key, do the following:

* Log in to your Palo Cortex console
* In the bottom left corner, navigate to Settings > Configurations

<figure><img src="/files/qCUkfe6ybxBFK1JHFnkj" alt=""><figcaption><p>Click Configurations</p></figcaption></figure>

* In the Search bar, input "API Keys," then click "API Keys"

<figure><img src="/files/VA6hl28UevVT21ICMHoU" alt=""><figcaption></figcaption></figure>

* In the upper right, click "+ New Key"

<figure><img src="/files/PS6zliqnsqOWt2NATnmJ" alt=""><figcaption><p>Add New Key</p></figcaption></figure>

* Under "Role," assign the API Key the Privileged Investigator role

{% hint style="info" %}
If you wish to allow Dropzone to use the Automatic Scanning feature in its Data Source integration, you will need to create a custom user role with additional permissions. See the "Create a Custom User Role" section for information.
{% endhint %}

<figure><img src="/files/gOPGfATIkYgenzETg7Cq" alt=""><figcaption><p>Assign the Privileged Investigator role</p></figcaption></figure>

* Under "Comment," name the API key something memorable, such as "Dropzone AI"
* Select your desired Security Level: Advanced or Standard

{% hint style="info" %}
The Advanced API key hashes the key using a nonce, a random string, and a timestamp to prevent replay attacks. Dropzone does not require the advanced security level.
{% endhint %}

* If you wish to assign the key an expiration date, check the box labeled "Enable Expiration Date" and input your desired expiration date

<figure><img src="/files/GuHZA1IidSWG234ixWWj" alt=""><figcaption><p>Assign the Privileged Investigator role</p></figcaption></figure>

* In the bottom left corner, click "Generate"

<figure><img src="/files/muixtDi1zD6Js1p7sFLp" alt=""><figcaption><p>Click Generate</p></figcaption></figure>

* Copy the API Key shown for use later in the Dropzone UI where it is called "API Key"

<figure><img src="/files/vrReyCVYd0HTJDBzlNTd" alt=""><figcaption><p>Copy the API Key</p></figcaption></figure>

* In the API Keys table, locate the ID number for the newly generated API Key. Copy it for use later in the Dropzone UI where it is called "API Key ID"

<figure><img src="/files/ISs8yY8VMxKyAnwXKhLe" alt=""><figcaption><p>Copy the API Key</p></figcaption></figure>

* In the top right hand corner, click "Copy API URL"

<figure><img src="/files/PS6zliqnsqOWt2NATnmJ" alt=""><figcaption><p>Copy the API URL</p></figcaption></figure>

* Save the URL for use later in the Dropzone UI where it is called "API FQDN"

## Create a Custom User Role

To create a custom role in Palo Alto Cortex, do the following:

* Navigate to Settings > Configurations

<figure><img src="/files/qCUkfe6ybxBFK1JHFnkj" alt=""><figcaption><p>Click "Configurations"</p></figcaption></figure>

* In the search bar, search Roles

<figure><img src="/files/ZINqIHxn97ePCqJNMCvO" alt=""><figcaption><p>Search "Roles"</p></figcaption></figure>

* In the upper left, click "+ New Role"

<figure><img src="/files/7Y2xa748zis773ctj4CI" alt=""><figcaption><p>Click "New Role"</p></figcaption></figure>

* Under "Role Name," name the Role something memorable, such as Dropzone AI Investigator

<figure><img src="/files/XGZTcqyimhzc7NWeIK2w" alt=""><figcaption><p>Name the Role</p></figcaption></figure>

* In the "Components" section, click the arrow next to "Configurations"

<figure><img src="/files/q16y5sRU4NjNBjMy2AbS" alt=""><figcaption><p>Click "Configurations"</p></figcaption></figure>

* Assign the Role the following permissions:
  * Data Management: View/Edit
  * Public API: View

<figure><img src="/files/l2mQp5wZIC2q38mPaW9F" alt=""><figcaption><p>Assign the Role permissions</p></figcaption></figure>

* In the bottom left corner, click "Save"

<figure><img src="/files/pk1bszlkZsP0qBxxWhs2" alt=""><figcaption><p>Generate the Role</p></figcaption></figure>

* When creating your API key, assign it both the Privileged Investigator Role and the custom role

## Enable Palo Alto XSIAM

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                  |
| -------------- | --------------------------------------- |
| API FQDN       | The API URL you copied earlier          |
| API Key ID     | The API key ID value you copied earlier |
| API Key        | The API key value you generated earlier |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Palo Alto Cortex XSIAM, then click "Configure"

<figure><img src="/files/zVnWNKL7G3te0cFdgicu" alt=""><figcaption><p>The Palo Alto Cortex XSIAM tile</p></figcaption></figure>

* Under the Alert Source heading, input the API FQDN, API Key ID, and API Key
* Select your authentication method

{% hint style="info" %}
This must be the same as the security level you configured for the API key generated earlier.
{% endhint %}

<figure><img src="/files/xY8RwnTsLyRw87bRkbom" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 1)</p></figcaption></figure>

* Under "Enabled Severities," select the severity levels you wish Dropzone to ingest
* Under "Enabled Types," select whether you wish to ingest [alerts](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Alert), [cases](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-NG-SIEM-Documentation/Cases-and-issues), and/or [incidents](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/What-are-incidents)

<figure><img src="/files/yKeqCOiETECDLUrgmCz8" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 2)</p></figcaption></figure>

* If you selected incidents, under "Incident Statuses," select which incident [statuses](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Resolution-reasons-for-incidents-and-alerts) you want Dropzone to ingest

<figure><img src="/files/G5SgblNbjVcbkngKnHFo" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 3)</p></figcaption></figure>

* If you selected cases, under "Case Statuses," select which case statuses you want Dropzone to ingest
* Under "Case Domains," select which case [domains](https://docs-cortex.paloaltonetworks.com/r/Cortex-CLOUD/Cortex-Cloud-Runtime-Security-Documentation/Case-and-issue-domains) you want Dropzone to ingest

<figure><img src="/files/0G9A4CHtpumHCESzdU9T" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 4)</p></figcaption></figure>

* If you wish, you may further filter your alerts, incidents and cases
  * To filter via the description field, click "Add Item" under "Description Regex Filters," then input a custom regex pattern to filter results. Under "Description Filter Mode," choose whether to include or exclude items matching the filters
  * To filter via alert type, click "Add Item" under "Alert Type Regex Exclusions," then input a custom regex pattern to filter results. Alerts with these fields will be excluded from Dropzone's analysis
  * To filter via tag, click "Add Item" under "Tag Regex Filters," then input a custom regex pattern to filter results. Under "Tag Filter Mode," choose whether to include or exclude items matching the filters

{% hint style="info" %}
See the Palo Alto XSIAM [Alerts](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Overview-of-the-Alerts-page) and [Incidents](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Incidents-table-view-reference-information) overviews for the definitions of type, name, and tag
{% endhint %}

* For more information on these features, engage your Dropzone AI support representative

<figure><img src="/files/e7uakGikNLbUsAOViJ4c" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="/files/GuK2mJOHFGsync81MzYm" alt=""><figcaption><p>The Palo Alto Cortex XSIAM Alert Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors, engage your Dropzone AI support representative.

### Enable Palo Alto Cortex XDR

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                  |
| -------------- | --------------------------------------- |
| API FQDN       | The API URL you copied earlier          |
| API Key ID     | The API key ID value you copied earlier |
| API Key        | The API key value you generated earlier |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Palo Alto Cortex XDR, then click "Configure"

<figure><img src="/files/btaUXhxObGNUs4U3lqjI" alt=""><figcaption><p>The Palo Alto Cortex XDR tile</p></figcaption></figure>

* Under the Alert Source heading, input the API FQDN, API Key ID, and API Key
* Select your desired authentication method

{% hint style="info" %}
This must be the same as the security level you configured for the API key generated earlier.
{% endhint %}

<figure><img src="/files/uekBZYJT3t5UnAiyiznf" alt=""><figcaption><p>The Palo Alto Cortex XDR alert configuration (pt 1)</p></figcaption></figure>

* Under "Enabled Severities," select which severity levels you want Dropzone to ingest
* Under "Enabled Incident Types," choose whether to ingest [alerts](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Investigate-alerts) and/or [incidents](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Incident-handling) from Cortex XDR

<figure><img src="/files/fRNL4XmtFApUuqauVurK" alt=""><figcaption><p>The Palo Alto Cortex XDR Alert Configuration (pt 2)</p></figcaption></figure>

* If you selected incidents, under "Incident Statuses," select which incident [statuses](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Documentation/Resolution-reasons-for-incidents-and-alerts) you wish Dropzone to ingest

<figure><img src="/files/DJt5gLWypQZHHkKyscXl" alt=""><figcaption><p>The Palo Alto Cortex XDR Alert Configuration (pt 3)</p></figcaption></figure>

* If you wish, you may further filter your alerts and incidents
  * To filter via alert type, click "Add Item" under "Alert Type Regex Exclusions," then input a custom regex pattern to filter results. Alerts with these fields will be excluded from Dropzone's analysis
  * To filter via name, click "Add Item" under "Name Regex Filters," then input a custom regex pattern to filter result. Under "Name Filter Mode," choose whether to include or exclude items matching the filters
  * To filter via tag, click "Add Item" under "Tag Regex Filters," then input a custom regex pattern to filter results. Under "Tag Filter Mode," choose whether to include or exclude items matching the filters

{% hint style="info" %}
See the Palo Alto XDR [Alerts](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Overview-of-the-Alerts-page) and [Incidents](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Understanding-the-Incidents-page) overviews for the definitions of type, name, and tag
{% endhint %}

* For more information on these features, engage your Dropzone AI support representative

<figure><img src="/files/jJaiTxpbD6lrG9Mme6ou" alt=""><figcaption><p>The Palo Alto Cortex XDR Alert Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and lookback

<figure><img src="/files/gkLUla7DPA8fEgHdsnX8" alt=""><figcaption><p>The Palo Alto Cortex XDR Alert Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Palo Alto Cortex XDR Alert Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors, engage your Dropzone AI support representative.


# Palo Alto Networks Firewall

{% hint style="success" %}
This is a separate from the "Palo Alto Cortex XDR" cloud and EDR data and alert source.
{% endhint %}

The Dropzone AI Platform integrates with Palo Alto Networks Firewall, a leading next-generation firewall solution. Integrating Palo Alto with Dropzone allows Dropzone to automatically investigate security incidents by analyzing network traffic data within the firewall ecosystem. Additionally, Dropzone can assess threat logs from Palo Alto Firewall, enabling deeper investigations into potential attacks and enhancing proactive threat detection and response.

## Integrations Overview

To enable these integrations you will perform the following actions:

* Create an Admin with Read Only permissions
* Generate an API key

## Create an Admin Role Profile

* At the top of your Palo Alto account, navigate to Device

<figure><img src="/files/PnUiDn0WxIgVQjeTJX0f" alt=""><figcaption><p>Navigate to Device</p></figcaption></figure>

* In the left sidebar, navigate to Admin Roles

<figure><img src="/files/I3ZwnevT4bSIkk744vuF" alt=""><figcaption><p>Navigate to Admin Roles</p></figcaption></figure>

* In the bottom left corner, click "Add"

<figure><img src="/files/aa22mKfXo0cXSfA56iPL" alt=""><figcaption><p>Click "Add"</p></figcaption></figure>

* Click XML API and enable the Log and Operational Requests permissions
* Name the Admin Role Profile something memorable, such as "Dropzone-AI"
* Click "OK"

<figure><img src="/files/eX1IvooSsDgAJYlhpH6W" alt=""><figcaption><p>Generate a new Admin Role Profile</p></figcaption></figure>

* In the left sidebar, navigate to Administrators

<figure><img src="/files/YyYU35SqNWp6UerfS9WV" alt=""><figcaption><p>Navigate to Administrators</p></figcaption></figure>

* In the bottom corner, click "Add"

<figure><img src="/files/aa22mKfXo0cXSfA56iPL" alt=""><figcaption><p>Click "Add"</p></figcaption></figure>

* Name the new administrator something memorable, such as "Dropzone-Admin", and create a memorable password. Be sure to save these, as they will be used later to generate the API token
* Assign the administrator the "Role Based" type
* In "Profile", select the name of the profile you just created
* Click "Ok"

<figure><img src="/files/hvqYu88x2Q1DBZW85ySR" alt=""><figcaption><p>Create a new Administrator</p></figcaption></figure>

* In the top corner, click "Commit"

<figure><img src="/files/SGPa9Y7me9PmaX8Xgrcs" alt=""><figcaption><p>Commit your changes</p></figcaption></figure>

## Generate an API Key

To obtain an API Key, do the following:

* Using the administrative credentials you just generated, SSH into the Palo Alto firewall
* Run the following commands:

```
https://<FIREWALL_IP>/api/?type=keygen&user=<USERNAME>
```

```
curl -k http(s)://<host>:<port>/api/\?type\=keygen\&user\=<user>\&password\=<password>
```

* Copy the API key generated and store it in a safe location for use later in the Dropzone UI where it is called "API key"
* For further information, see the Palo Alto [API documentation](https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-panorama-api/get-started-with-the-pan-os-xml-api/get-your-api-key)

## Enable Palo Alto Networks Firewall

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                        |
| -------------- | ----------------------------------------------------------------------------- |
| Server         | The same as your company server url in Palo Alto, eg https\://<111.22.33.444> |
| API Key        | The API key value you generated earlier                                       |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Palo Alto Networks Firewall, then click "Configure"

<figure><img src="/files/v02Iz9DuFfUxN4Y7UX9d" alt=""><figcaption><p>The Palo Alto Networks Firewall Tile</p></figcaption></figure>

* Under the Alert Source heading, if your Palo Alto integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input the Server and the API Key

<figure><img src="/files/SXsZqm66GQZwVGsLrDVT" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Filter on Severity," select the severity levels of alerts you wish for Dropzone AI to investigate

<figure><img src="/files/i4zqRMPcnY70kQPnmAfI" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 2)</p></figcaption></figure>

* In the "Threat Name" section, you may input an array of Python regex patterns to include or exclude specific threats by [name](https://docs.paloaltonetworks.com/ngfw/administration/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields). To do so, select whether to exlude or include the listed threat names, then click "Add Item" and input the array

<figure><img src="/files/dLYZh2O4a0fNOOjFjaMf" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 3)</p></figcaption></figure>

* Under "Filter on Action," select which [action types](https://docs.paloaltonetworks.com/ngfw/administration/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/threat-log-fields#id83052cb2-4798-4f9c-abf8-e0b929ce7a3b) you want Dropzone to investigate

<figure><img src="/files/2bNFJz0qZ15CIDNBStWx" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 4)</p></figcaption></figure>

* Under "Threat Category," select the [threat categories](https://docs.paloaltonetworks.com/advanced-threat-prevention/administration/threat-prevention/threat-signature-categories) you want Dropzone to investigate

<figure><img src="/files/8Oxye4sRFT2OF0hs1rqr" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 5)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Palo Alto Networks Firewall Alert Source Configuration (pt 7)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors, engage your Dropzone AI support representative.


# Panther

{% hint style="info" %}
Panther is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Panther](https://panther.com) security SIEM. Many customers ingest other alert sources into Panther (e.g. IDPs) and integrate Dropzone into Panther rather than the source systems.

## Create an API Key

Panther requires an API key to enable.

To obtain an API Key, do the following:

* Navigate to your Panther homepage
* Click on the gear icon in the top right corner
* Select "API Tokens"

<figure><img src="/files/rMbgKWDczTARxzk3jnh4" alt=""><figcaption><p>Select API Tokens</p></figcaption></figure>

* Record the API URL located at the top of the page for use later in the Dropzone UI where it is called "Panther URL"

<figure><img src="/files/Kc1naJsLMdcCPxRn6GZU" alt=""><figcaption><p>API URL</p></figcaption></figure>

* Click on "Create New Token"
* Grant the token the following permissions:

| Permission       | Purpose                                                                      |
| ---------------- | ---------------------------------------------------------------------------- |
| Manage Alerts    | (optional) Allows Dropzone to add investigations results as Panther comments |
| Read Alerts      | Allows Access to alert information                                           |
| View Rules       | Allows viewing the log rules setup in Panther                                |
| Query Data Lake  | Allows listing and issuing Data Explorer & Indicator Search queries          |
| View Log Sources | Allows viewing the Log sources setup                                         |
| Read User Info   | Allows access to user information related to your Panther resources          |

* Click "Create API Token" at the bottom of the page

<figure><img src="/files/rVEE5HVK3ENW87OnOJHM" alt=""><figcaption><p>Create API Token</p></figcaption></figure>

* Record the value for use later in the Dropzone UI where it is called "API key"

<figure><img src="/files/QklKBnMt3jMyy18vJaX9" alt=""><figcaption><p>Record the API Token</p></figcaption></figure>

{% hint style="danger" %}
This value is not shown after you leave this page — be sure to record it immediately.
{% endhint %}

* Click "Done"

## Enable The Dropzone Alert Source Integration

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Panther, then click "Configure"

<figure><img src="/files/aIQoOqxBNgtDUIkUVV9e" alt=""><figcaption><p>The Panther Tile</p></figcaption></figure>

* Under the Alert Source heading, input the Panther URL and the API key

<figure><img src="/files/TgcmrbtdIQ06zerb7Zh6" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the "Enabled alert statuses for ingestion" section, check the alert [statuses](https://docs.panther.com/alerts/alert-management) you want Dropzone to be able to investigate

{% hint style="info" %}
The "Closed" status in the Dropzone UI is shown as "Invalid" in the Panther UI.
{% endhint %}

<figure><img src="/files/1fkB0aonm4bL2tbgSvAc" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 2)</p></figcaption></figure>

* Check the severity levels you want to ingest

<figure><img src="/files/JwdkK7Jy7lkP5cJEcM6H" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 3)</p></figcaption></figure>

* Select a duration in minutes for alert deduplication. See the [Panther alert deduplication](https://docs.panther.com/detections/rules#deduplication-of-alerts) documentation for more info. A value of 15 is reasonable
* If you wish, you may use an alert filter by setting "Detection ID regex filter"
  * When a regex is put in this field Dropzone will only ingest alerts whose origin ID matches the regular expression
  * Example origin IDS: `AWS.Root.Activity`, `Okta.AdminRoleAssigned`, `GCP.GKE.Kubernetes.Cron.Job.Created.Or.Modified`
  * Supports [Python regular expression syntax](https://docs.python.org/3/library/re.html)
    * For example, to ingest all alerts *other* than AWS alerts, you could use `^(?!AWS).*`
  * Work with your Dropzone technical resource to determine if this is appropriate

<figure><img src="/files/2g0TkODCIx38xONKh8nz" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 4)</p></figcaption></figure>

* In the "Ticket Sync - Comment" section, check the boxes to choose what information to include in each ticket

<figure><img src="/files/esiRPvNQvq4f0KYDeEJ3" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish for Dropzone to update the ticket status over the course of the investigation, check the box labeled "Update ticket status on investigation change," then select the status parameters

<figure><img src="/files/NIB8gU46Qfxq1IN4Va8O" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Panther Alert Source Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

{% hint style="info" %}
The Panther API token activation is not instantaneous. If the connection fails initially, try again after a few minutes.
{% endhint %}

If you have any errors engage your Dropzone AI support representative.


# Proofpoint

## Proofpoint

Dropzone AI integrates with [Proofpoint](https://www.proofpoint.com/us), an email-based security solution that analyzes and classifies emails to blocks ransomware and other email-based threats. Dropzone AI can ingest alerts from [Proofpoint TAP](https://www.proofpoint.com/us/resources/data-sheets/targeted-attack-protection) (Targeted Attack Protection) and [Proofpoint TRAP](https://www.proofpoint.com/uk/products/email-protection/threat-response-auto-pull) (Threat Response Auto-Pull).

## Proofpoint TAP

Proofpoint TAP requires TAP service credentials to enable.

To obtain your TAP service credentials, do the following:

* As an administrative user, sign into your [TAP Dashboard](https://threatinsight.proofpoint.com/)
* Navigate to Settings > Connected Applications

<figure><img src="/files/x3CmI8KAvip1WQfHUPpk" alt=""><figcaption><p>Navigate to Connected Applications</p></figcaption></figure>

* Click "Create New Credentials"

<figure><img src="/files/ROeszEmHG23k88DAT1DV" alt=""><figcaption><p>Create New Credentials</p></figcaption></figure>

* Name the credentials something memorable, such as Dropzone AI, and click "Generate"

<figure><img src="/files/hdiWGtEI6rxj15G1z1Ic" alt=""><figcaption><p>Generate the credentials</p></figcaption></figure>

* Copy the Service Principal and Secret shown for use later in the Dropzone UI where they are called "TAP Service Principal" and "TAP Secret" respectively

<figure><img src="/files/nZRAct9OJ5e5PFOUQfey" alt=""><figcaption><p>Copy the credentials</p></figcaption></figure>

* Click "Done"

## Proofpoint TRAP

Proofpoint TRAP requires Threat Protection credentials to enable.

To obtain your Threat Protection credentials, do the following:

* As an administrative user, log into your [Proofpoint Threat Protection console](https://threatprotection.proofpoint.com/)
* Navigate to System Settings > Customization > API Keys
* Next to "API Keys," click the (+) icon
* Name the key something memorable, such as "Dropzone AI"
* Check "Enabled," then click “Save”
* Copy the API and API secret shown for use later in the Dropzone UI where they are called "Threat Protection API Key" and "Threat Protection API Secret," respectively

### Enable Proofpoint

To enable the Alert Source integration, you will need the following information:

| Dropzone Field                     | Source                                                                          |
| ---------------------------------- | ------------------------------------------------------------------------------- |
| TAP Service Principle & Secret     | The Service Principle and Secret values generated earlier                       |
| TAP API URL                        | Your base TAP API host URL, e.g. <https://tap-api-v2.proofpoint.com>            |
| Threat Protection API Key & Secret | The API Key and Secret values generated earlier                                 |
| Threat Protection API URL          | Your base TRAP API host URL, e.g. <https://threatprotection-api.proofpoint.com> |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Proofpoint, then click "Configure"

<figure><img src="/files/zvXuomqwUlqXjkndD3sC" alt=""><figcaption><p>The Proofpoint Tile</p></figcaption></figure>

* To enable Dropzone to ingest TAP Alerts, check the box labeled "Ingest TAP Alerts"
* Input the TAP Service Principle, Secret, and API URL

<figure><img src="/files/aErsxJyVH05XwkWIuxSw" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the TAP Ingestion Settings section, select the types of [alert events](https://help.proofpoint.com/Threat_Insight_Dashboard/API_Documentation/SIEM_API) you want Dropzone to ingest
* If you want Dropzone to be able to investigate the emails associated with TAP alerts, check the box labeled "Investigate Phishing Emails"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

* If you want to Dropzone to be able to investigate threats associated with Proofpoint alerts, check the box labeled "Investigate Threats"

<figure><img src="/files/zg0ScU4WjBRTZegDtUQV" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to ingest TRAP Incidents, check the box labeled "Ingest TRAP Incidents"
* Input the Threat Protection API Key, Secret, and URL

<figure><img src="/files/iwiWSDaanPu7QqhU3FWi" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 3)</p></figcaption></figure>

* To exclude closed incidents from Dropzone's analysis, check the box labeled "Skip Closed Incidents"
* To analyze email messages under quarantine, check the box labeled "Analyze clicked messages in MS Quarantine"

{% hint style="info" %}
This feature requires the [Microsoft 365/Defender integration](https://docs.dropzone.ai/integrations/alert/ms_alert/ms365_alert) to be enabled.
{% endhint %}

<figure><img src="/files/jSIre5opdmzG6gGdsNcy" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 4)</p></figcaption></figure>

* Input your desired log ingestion delay, poll interval and poll lookback

<figure><img src="/files/2qn1FRWfM87n9ApeByn9" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Proofpoint Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# QRadar

{% hint style="info" %}
QRadar is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [IBM QRadar](https://www.ibm.com/qradar) security SIEM. Many customers ingest other alert sources into QRadar (e.g. IDPs) and integrate Dropzone into QRadar rather than the source systems.

## Create an API Key

QRadar requires an API key to enable.

To obtain an API Key, do the following:

* In the upper bar in the QRadar Homepage, click "Admin"

<figure><img src="/files/6dmFO3Z2QFsPKz6BJAMt" alt=""><figcaption><p>Navigate to Admin</p></figcaption></figure>

* In the left hand bar, navigate to System Configuration > User Management

<figure><img src="/files/MZOVRnFwlcvQ2kOluTCg" alt=""><figcaption><p>Navigate to User Management</p></figcaption></figure>

* Click on "Authorized Services"

<figure><img src="/files/DakVBUOLTuVkek3ks4pu" alt=""><figcaption><p>Click on "Authorized Services"</p></figcaption></figure>

* In the window that pops up, click "Add"

<figure><img src="/files/BHzz3AbKAZ0ctwmZKCpG" alt=""><figcaption><p>Click "Add"</p></figcaption></figure>

* Under "Authorized Service Label," label the key something memorable, such as "dropzone\_ai"
* Select an Admin security profile
* Under "User Role, select "All"
* Under "Expiry Settings," assign an expiration date if you choose

{% hint style="info" %}
For conveniences sake, we recommend not assigning an expiration date for this API key, to prevent having to create a new one.
{% endhint %}

* Click "Save"

<figure><img src="/files/0VsWFJB1J9WEM2yu58Da" alt=""><figcaption><p>Fill out token details</p></figcaption></figure>

* Store the authorized service token in a safe location for use later in the Dropzone UI where it will be called "API-Key"

<figure><img src="/files/kqZSOXcxjLRAjjFE4qZM" alt=""><figcaption><p>Copy the API-Key</p></figcaption></figure>

## Enable QRadar

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                       |
| -------------- | ---------------------------------------------------------------------------- |
| Server         | The same as your servername in your QRadar url, eg *myserver*/console/qradar |
| Port           | The standard html port, 443                                                  |
| API-Key        | The authorized service token value you generated earlier                     |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.ai
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search QRadar, then click "Configure"

<figure><img src="/files/gdUYVF4rXtNBcvhSpE6U" alt=""><figcaption><p>The QRadar Tile</p></figcaption></figure>

* Under the Alert Source header, if your QRadar integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input the Server, Port, and API-Key

<figure><img src="/files/MJKTLysMGjQCgw9ImcBK" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 1)</p></figcaption></figure>

* Under "Enabled QRadar Offense Statuses," check the box for each [offense status](https://www.ibm.com/docs/en/qradar-on-cloud?topic=management-offense-retention) you wish Dropzone to investigate alerts for

<figure><img src="/files/gFRZNTo2mD6jsoE2Gx5K" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 2)</p></figcaption></figure>

* Under "Title Exclusions," you may choose to exclude alerts by title. To do so, click "Add Item," then input a list of [Python regexes](https://docs.python.org/3/library/re.html) of the titles of the alerts you wish to exclude

<figure><img src="/files/JZ0awyvzlMm3TPWFVQWz" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 3)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 4)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The QRadar Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish


# Rapid7 Insight IDR

{% hint style="info" %}
Rapid7 Insight IDR is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

{% hint style="info" %}
This alert source integration is in **beta**. It is not visible in the Dropzone UI until it has been explicitly enabled for your tenant. Contact your Dropzone AI Support Representative to request enablement.
{% endhint %}

The Dropzone AI Platform integrates with [Rapid7 Insight IDR](https://www.rapid7.com/products/insightidr/), a cloud-native SIEM and XDR solution. Dropzone can poll InsightIDR investigations as alert sources, enrich them with associated alerts and evidence (Attacker Behavior Analytics and User Behavior Analytics), and run AI-driven investigations.

## Integrations Overview

To enable these integrations you will perform the following actions:

* Create an API key
* Locate your tenant region
* Install the credentials into your Dropzone tenant (Data Source and Alert Source)
* Select integration parameters

## Create an API Key

Rapid7 InsightIDR requires an API key from the [Insight platform API](https://help.rapid7.com/insightidr/en-us/api/v2/docs.html) to enable

{% hint style="info" %}
Rapid7 has two types of API Keys: Organization Keys and User Keys. Organization Keys have access to all company data, while User Keys inherit the permissions of the user.

To limit Dropzone's scope, you may wish to create a User Key with Read-only privileges limited to certain projects. Alternatively, to improve Dropzone's analysis, you may wish to use an Organization Key.

See Rapid7's [Role-Based Access Control documentation](https://docs.rapid7.com/insight/manage-users/) for more information.
{% endhint %}

To obtain an Organization API Key, do the following:

* As a platform administrator, log into your Rapid7 Command Platform
* In the left menu, click "Administration"
* Click "API Key management"
* Click "Admin API Keys," then navigate to "Organization Keys"
* Click "New Admin Key"
* Select "Organization Admin Key"
* Select your organization
* Name the key something memorable, such as Dropzone AI
* Click "Generate"
* Copy the key value shown for use later in the Dropzone UI, where it is called API Key

To obtain a User API key, do the following:

* In the left menu of the Rapid7 Command Platform Home page, click "Administration"
* Click "API Key Management"
* Click "User Key"
* Click "New user Key"
* Select your organization
* Name the key something memorable, such as Dropzone AI
* Click "Generate"
* Copy the key value shown for use later in the Dropzone UI, where it is called API Key

## Identify your data region

Dropzone needs the region code for your InsightIDR data storage region (for example `us`, not a full hostname).

To obtain your data region, do one of the following:

* Open any Rapid7 product you have access to (for example InsightIDR)
* Locate the browser URL subdomain prefix before `.idr.insight.rapid7.com` (or a similar Rapid7 product hostname)
* Enter that prefix in Dropzone as the Region value
  * For example, if your URL is `https://us.idr.insight.rapid7.com`, enter `us` in Dropzone.

For more detail, see Rapid7's [Check your data region](https://docs.rapid7.com/insight/navigate-the-insight-platform/#check-your-data-region) documentation.

* In the Rapid7 Command Platform, navigate to Administration > Settings > Organization Settings
* Locate your Data Storage Region (aka the display name for your tenant)
* Map that label to the Region value for Dropzone using the table below

| Data Storage Region (Rapid7 UI) | Dropzone Region value |
| ------------------------------- | --------------------- |
| United States - 1               | `us`                  |
| United States - 2               | `us2`                 |
| Canada                          | `ca`                  |
| Europe                          | `eu`                  |
| Australia                       | `au`                  |
| Japan / Asia-Pacific            | `ap`                  |

For the full list of supported regions and API base URLs, see Rapid7's [Supported regions](https://docs.rapid7.com/insight/product-apis/#supported-regions) documentation.

## Enable Rapid7 Insight IDR

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field | Source                                                                                                      |
| -------------- | ----------------------------------------------------------------------------------------------------------- |
| API Key        | The API Key you generated earlier                                                                           |
| Region         | Your Rapid7 data storage region, typically visible in your InsightIDR URL, e.g. *us*.api.insight.rapid7.com |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Rapid7 Insight IDR, then click "Configure"

<figure><img src="/files/xcrlFUck5NWVOFWkSrVZ" alt=""><figcaption><p>The Rapid7 Insight IDR Tile</p></figcaption></figure>

* Input the API Key and Region
* Click "Test & Save" to finish

After saving, Dropzone will poll InsightIDR for new investigations in the configured time window and filters, and create investigations for each.

If you have any errors engage your Dropzone AI support representative.

### Troubleshooting

When you save or test the data source, Dropzone verifies connectivity by listing log sets from the Log Search API. A wrong Region or API key can produce an error like:

```
test_integration_connection() failed: Rapid7 connection test failed: could not list log sets. Verify the API key and region.
```

If you experience any errors, do the following:

* Confirm the Region matches your Rapid7 URL prefix or the Organization Settings table (enter `us`, not `us.api.insight.rapid7.com` or `us.rest.logs.insight.rapid7.com`)
* Re-open InsightIDR and verify the subdomain prefix (for example `us2` vs `us`)
* If Region is correct, verify the API key is an organization key with InsightIDR access and was copied without extra spaces

If both Region and API key look correct, engage your Dropzone AI support representative.


# SentinelOne

The Dropzone AI Platform integrates with SentinelOne, an endpoint cybersecurity platform that protects against various types of threats. Integrating SentinelOne with Dropzone allows Dropzone to automatically investigate security incidents in your SentinelOne environment.

## Create a Service User and API Key

SentinelOne requires an API key from a Service User with Viewer Access to enable.

To obtain an API Key, do the following:

* Log in to the SentinelOne Management Console
* In the left navigation bar of the SentinelOne dashboard, click "Settings"

<figure><img src="/files/i3JTrSVhGcLDpmnrxJNO" alt=""><figcaption><p>Settings</p></figcaption></figure>

* Navigate to Users > Service Users
* Click the Actions dropdown, then click "Create New Service User"

<figure><img src="/files/Nx4vFUL6juGZeCDJtA76" alt=""><figcaption><p>Create New Service User</p></figcaption></figure>

* Enter the Name, Description, and Expiration Date, then click "Next"

<figure><img src="/files/fwW24DfhEqJIIQ63lZ1w" alt=""><figcaption><p>Enter information</p></figcaption></figure>

* Under Access Level, select "Account." Select the newly generated account and set the role to Viewer

<figure><img src="/files/Fu5bQCngSxokFOg96uog" alt=""><figcaption><p>Assign roles to the new Account</p></figcaption></figure>

* Click "Create User"
* Copy the API Token shown for use later in the Dropzone UI where it is called "API Token"

<figure><img src="/files/m5yI2FlcojPGZOYjevXq" alt=""><figcaption><p>Copy API Token</p></figcaption></figure>

## Enable SentinelOne

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field       | Source                                                    |
| -------------------- | --------------------------------------------------------- |
| SentinelOne Hostname | Your SentinelOne Hostname, e.g. usea1-123.sentinelone.net |
| API Token            | The API token value you copied earlier                    |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search SentinelOne, then click "Configure"

<figure><img src="/files/G9CUQAW2wvYLSuMcI4gQ" alt=""><figcaption><p>The SentinelOne Tile</p></figcaption></figure>

* Under the Alert Source header, input your SentinelOne hostname and API Token

<figure><img src="/files/FIBRxwQ4xCoxRd80jC7M" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you wish to treat each of your sites in SentinelOne as separate tenants, check the box labeled "Multi-tenant environment" and click "Add Item." Then input the site IDs for each of the sites you wish Dropzone to be able to analyze

<figure><img src="/files/Nibu0C2AlXyj8UDtFcQD" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 2)</p></figcaption></figure>

* Under "Incident types," check the incident types you want Dropzone to investigate alerts for
* Under "Incident status," check the incident statuses you want Dropzone to investigate alerts for
* Under "Log Ingestion delay," input your desired log ingestion delay in minutes

<figure><img src="/files/MNFqw8S68lwMSfp6dOJE" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish, you may exclude threats from investigation by threat name regex. To do so, click "Add Item" in the "Threat Name Regexes" section and input your exclusions

<figure><img src="/files/FIwe7DsBsosd1cKgsW4P" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 4)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 5)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The SentinelOne Alert Source Configuration (pt 6)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# ServiceNow

Dropzone AI integrates with [ServiceNow](https://www.servicenow.com/now-platform.html), a cloud-based platform that provides digital workflow automation.

## Enable ServiceNow

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                          |
| -------------- | ------------------------------------------------------------------------------- |
| Subdomain      | The same as the subdomain in your ServiceNow url, eg <https://.service-now.com> |
| Username       | The username of the admin user you are using                                    |
| Password       | The password for the aforementioned user's account                              |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ServiceNow, then click "Configure"

<figure><img src="/files/ZuU40JmF7qAjkwCQxnh2" alt=""><figcaption><p>The ServiceNow Tile</p></figcaption></figure>

* Input your subdomain, username, and password

<figure><img src="/files/C50OYtwzeNOjUbVzWV8s" alt=""><figcaption><p>The ServiceNow Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the Alert queries section, input a ServiceNow [encoded filter query string](https://www.servicenow.com/docs/r/yokohama/platform-user-interface/c_EncodedQueryStrings.html)
* Input your desired poll interval and poll lookback

<figure><img src="/files/nZZeVeTvN1kT3ZUgIxze" alt=""><figcaption><p>The ServiceNow Alert Source Configuration (pt 2)</p></figcaption></figure>

* To have the investigation results commented to each ticket, check the box under the Ticket Sync header
* Choose your desired Investigation Result Comment Type

<figure><img src="/files/9h1sdBqUQyoCcUi1MQpe" alt=""><figcaption><p>The ServiceNow Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The ServiceNow Alert Source Configuration (pt 4)</p></figcaption></figure>

\* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Splunk

The Dropzone AI Platform integrates with Splunk Enterprise, a SIEM tool. Dropzone can perform analysis of Splunk-generated alerts, and/or use Splunk data as part of investigation analysis. Many customers ingest other alert sources into Splunk (e.g. IDPs) and integrate Dropzone into Splunk rather than the source systems.

Dropzone communicates to Splunk Enterprise using the [Dropzone Connector](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/overview/connector.md).

There are two methods to integrate with Dropzone AI: creating a Splunk User or configuring an API token. To create an API token, follow instructions in [Splunk's documentation](https://help.splunk.com/en/splunk-cloud-platform/administer/manage-users-and-security/9.3.2411/authenticate-into-the-splunk-platform-with-tokens/set-up-authentication-with-tokens).

## Create a Splunk User

To create a Splunk user, do the following:

* In the Home Menu of Splunk Enterprise, navigate to Settings > Users

<figure><img src="/files/xpNHjuLFVjR8ss9WpqrT" alt=""><figcaption><p>Navigate to Users</p></figcaption></figure>

* Click "New User"

<figure><img src="/files/qthYYQ6NP2RzXDVoWDz9" alt=""><figcaption><p>Click New User</p></figcaption></figure>

* Name the user something memorable, such as Dropzone AI, and create a password. Save them for use later in the Dropzone UI where they are called "Username" and "Password" respectively
* In the "Assign Roles" section, assign the user the "User" role

{% hint style="info" %}
You may need to add [capabilities](https://docs.splunk.com/Documentation/Splunk/9.4.2/Security/Rolesandcapabilities) to this role depending on the level of access you want Dropzone to have. If you would like to limit the indexes Dropzone has access to, you will need to create a custom role with inherited permissions from the user role. See the Splunk [documentation](https://docs.splunk.com/Documentation/Splunk/9.4.2/Security/Addandeditroles) for more information on creating custom roles.
{% endhint %}

* If two-factor authentication is enabled, provide the Duo username

<figure><img src="/files/FORygmjDpIW4VG6A3zxu" alt=""><figcaption><p>Fill out fields for New User</p></figcaption></figure>

* Click "Create"

<figure><img src="/files/B8QEyWGOUPJrbBEQAZ9k" alt=""><figcaption><p>Create new user</p></figcaption></figure>

## Enable Splunk

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field | Source                                                                        |
| -------------- | ----------------------------------------------------------------------------- |
| Server         | The hostname or IP address of your Splunk server, e.g splunk.corp.example.net |
| Password       | The username of the Splunk user you created earlier                           |
| Password       | The password of the Splunk user you created earlier                           |

{% hint style="info" %}
If you chose to create an API token instead of a Splunk user, you will need to use the API token instead.
{% endhint %}

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Splunk, then click "Configure"

<figure><img src="/files/ushCYadMYSP1AUge9mM3" alt=""><figcaption><p>The Splunk Tile</p></figcaption></figure>

* If your Splunk integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input your Splunk Server and port

<figure><img src="/files/VHgLLLldFUOSVBEnDOA8" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you created a Splunk User, under "Authentication Method," select Password. If you created an API token, select Token

<figure><img src="/files/zpc4n5O4pZS7JPeER6F6" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 2)</p></figcaption></figure>

* Input your authentication details

<figure><img src="/files/fPI4vaH5P3mIAL4DWwIW" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 3)</p></figcaption></figure>

* To enable Splunk Enterprise Security alert polling, check the box labeled "Enabled" in the "Splunk Enterprise Security" section
* Under "ES Macro," select the version of ES you are using ('notable' for ES 8.0+ or 'mc\_incidents' for version ES 7.0 and earlier)

<figure><img src="/files/90oai4iVdL553DkeWPKZ" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 4)</p></figcaption></figure>

* Under "Enabled Severities," select the severity levels you want Dropzone to investigate
* In the "Title Exclusion Patterns" section, you may exclude [notable events](https://help.splunk.com/en/splunk-enterprise-security-8/splunk-app-for-pci-compliance/installation-and-configuration-manual/6.4/configure-correlation-searches/notable-events) from investigation by title. To do so, click "Add Item," then input a python regex to filter out titles

<figure><img src="/files/fg1C3gqQXXpJ63i0aR6P" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 5)</p></figcaption></figure>

* Input your full Splunk URL (e.g. <http://splunk.my-company.com>) for ticket link back, or leave blank to default to your server
* In the "Alert Queries" section, input your desired log ingestion delay
* Under "Splunk Alert Search," you must input a Splunk [SPL](https://docs.splunk.com/Documentation/SplunkCloud/latest/Search/Aboutthesearchlanguage) search query to identify alerts to investigate

<figure><img src="/files/F95DYtr0EuaQJZLyFpJI" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish for Dropzone to regularly query for alerts 24 hours in the past, check the box labeled "Advanced: Enable hourly 1 day lookback"
* Input your desired poll interval and lookback

<figure><img src="/files/4lQCaXxPz5oixMGZZrRu" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 7)</p></figcaption></figure>

* In the "Ticket Sync - Comment" section, check the boxes to choose what information to include in each ticket

<figure><img src="/files/Jl0fU21fvRqAD3pTwhok" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 8)</p></figcaption></figure>

* If you wish for Dropzone to update the ticket status over the course of the investigation, check the box labeled "Update ticket status on investigation change," then select the status parameters

<figure><img src="/files/gMRliNdBlYHelrX4x04y" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 9)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Splunk Alert Source Configuration (pt 10)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Stellar Cyber

The Dropzone AI Platform integrates with [Stellar Cyber](https://stellarcyber.ai/), an AI powered SecOps platform offering security solutions such as SIEM, Network Detection & Response (NDR), Identity Threat Detection & Response (ITDR), and User Behavior Entity Analytics (UEBA). Dropzone can perform analysis cases and alerts from the Stellar Cyber Connect API, and/or use Stellar Cyber data as part of investigation analysis.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create an API token
* Install the credentials into your Dropzone tenant
* Select integration parameters, such as which alert types to sync

## Create an API key

Stellar Cyber requires an API key to enable. To create an API key with the necessary permissions, the user must have Root scope and Super Admin privileges.

If you have access to a user with Root scope and Super Admin privileges, do the following:

* As a user with the Edit User privilege, log into your Stellar Cyber instance
* In the menu bar, click "System"

<figure><img src="/files/6lQAA6MDzMNdKoizIAa0" alt=""><figcaption><p>Click "System"</p></figcaption></figure>

* Navigate to Administration > Users

<figure><img src="/files/nGMDg7cTGnJBjfZwgTuj" alt=""><figcaption><p>Click "Users"</p></figcaption></figure>

* Under the Users tab, locate a user with Root scope and Super Admin privileges
* Copy the email address for use later in the Dropzone UI where it is called "User Email Address"

<figure><img src="/files/zS67cNZyCYMEAc6uKASz" alt=""><figcaption><p>The User List</p></figcaption></figure>

* Under "Actions," click the Edit button

<figure><img src="/files/G2Zp6ZWI3dXXlpqMWYen" alt=""><figcaption></figcaption></figure>

* In the API Access section, click "Generate New Token"
* Copy the token shown for use later in the Dropzone UI where it is called "Access Token"

<figure><img src="/files/PjQEweyEL0lgwWH08CWj" alt=""><figcaption><p>Generate the Access Token</p></figcaption></figure>

If you do not already have a user with those privileges, do the following:

* As a user with the Add User privilege, log into your Stellar Cyber instance
* Navigate to System > Administration > Users
* Under the Users tab, click "+ Create"

<figure><img src="/files/0ZEl7yRMW7CZiUY3rUCX" alt=""><figcaption><p>Create User</p></figcaption></figure>

* Input an email address for the User. Copy the value for use later in the Dropzone UI where it is called "User Email Address"

{% hint style="info" %}
Stellar Cyber requires a unique email address for all its users. We recommend creating a dedicated email address for this user, rather than using an existing company email.
{% endhint %}

* Name the user something memorable, such as Dropzone AI
* Create a password for the user
* Next to "User Scope," click "Root"
* Next to "User Privilege," select "Super Admin"

<figure><img src="/files/BUqLYFsw0lXAth8ZN4zp" alt=""><figcaption><p>Fill out the User Details</p></figcaption></figure>

* In the API Access section, click "Generate New Token"
* Copy the token shown for use later in the Dropzone UI where it is called "API Key"

{% hint style="info" %}
If you do not copy the token when the user is created, you will need to generate a new token.
{% endhint %}

<figure><img src="/files/PjQEweyEL0lgwWH08CWj" alt=""><figcaption><p>Generate the Access Token</p></figcaption></figure>

## Enable Stellar Cyber

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field     | Source                                                                              |
| ------------------ | ----------------------------------------------------------------------------------- |
| Instance Domain    | Your Stellar Cyber server hostname (e.g. https\://<\<myserver.stellarcyber.cloud>>) |
| User Email Address | The email address of the Stellar Cyber user you created/used earlier                |
| Access Token       | The "Access Token" value you generated earlier                                      |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Stellar Cyber, then click "Configure"

<figure><img src="/files/WE1krL6aNgjlaDVX4r5y" alt=""><figcaption><p>The Stellar Cyber Tile</p></figcaption></figure>

* Under the Alert Source heading, input the instance domain, user email address, and access token

<figure><img src="/files/atfw4eKZNhvy0R9xNvmG" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 1)</p></figcaption></figure>

* In the StellarCyber Alerts section, you may input an array of Python regex patterns to include or exclude specific [alerts](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/Alerts/Alert-Main.htm?tocpath=SECURITY%20MONITORING%7CWorking%20with%20Alerts%7C_____1) by name. To do so, select whether to exlude or include the listed threat names, then click "Add Item" and input the array. Continue adding arrays until done.

<figure><img src="/files/X7eMzdzauXraPtNcz6Bm" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 2)</p></figcaption></figure>

* To enable Dropzone to poll for alerts, check the box labeled "Enable polling for alerts"
* Input the [Alert Index prefix](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/ML/Machine-Learning-by-index.htm?tocpath=REFERENCE%7CDetection%20and%20Correlation%20Overview%7CAlert%20Type%20Model%20Summary%7C_____3) and minimum desired [event score](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/Alerts/Alert-Scoring.htm?tocpath=SECURITY%20MONITORING%7CWorking%20with%20Alerts%7C_____6) of the alerts you want Dropzone to investigate

<figure><img src="/files/RZwvITxEtTs2EZiLXNOH" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 3)</p></figcaption></figure>

* To enable Dropzone to poll for [cases](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/Cases/Cases-Main.htm?Highlight=case), check the box labeled "Enable polling for cases"
* Input your minimum desired [score](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/Cases/Cases-Understanding.htm?tocpath=SECURITY%20MONITORING%7CWorking%20with%20Cases%7C_____2#:~:text=AWS%20GuardDuty-,How%20Case%20Scores%20Are%20Calculated,-Stellar%20Cyber%20assigns), then check the boxes for each [severity level](https://docs.stellarcyber.ai/prod-docs/5.1.x/Using/Cases/Cases-Detail.htm?tocpath=SECURITY%20MONITORING%7CWorking%20with%20Cases%7C_____3#:~:text=were%20seen%20where.-,Severity,-%E2%80%93%20The%20severity%20of) you want Dropzone to investigate

<figure><img src="/files/9ZhlPDdpRgwbIghoUpxF" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 4)</p></figcaption></figure>

* In the "Custom Filtering" section, you may input an array of Python regex patterns to include or exclude specific cases by name. To do so, check the box labeled "Enable Custom Filtering," select whether to exlude or include the listed threat names, then click "Add Item" and input the array. Continue adding arrays until done.

<figure><img src="/files/csUYi1lE2CgCbb1UYT0Y" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 5)</p></figcaption></figure>

* To limit Dropzone's access to specific [tenants](https://docs.stellarcyber.ai/prod-docs/5.1.x/Common/Using-Tenants.htm?Highlight=tenant%20id) within Stellar Cyber, check the box labeled "Manually Specify Tenant IDs," then click "Add Item." Input the Tenant [ID](https://docs.stellarcyber.ai/prod-docs/5.1.x/Configure/People/Tenants-Managing.htm?tocpath=CONFIGURING%7CManaging%20Access%7CManaging%20Tenants%7C_____2) you want Dropzone to investigate alerts for. Continue adding Tenant IDs until done.

<figure><img src="/files/R2YdW7IXTRaxqfhnzG6e" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 6)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 7)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Stellar Cyber Alert Source Configuration (pt 8)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Sumo Logic

The Dropzone AI Platform integrates with [Sumo Logic](https://www.sumologic.com/), a cloud based machine data analytics product. Integrating Sumo Logic with Dropzone allows Dropzone to automatically investigate security incidents using the data within Sumo Logic.

## Create an API Key

Sumo Logic requires an API key to enable.

To obtain an API Key, do the following:

* Login as an administrator to the Sumo Logic at the appropriate URL, e.g. <http://service.sumologic.com>
* In the bottom left hand corner of the Sumo Logic homepage, click on Administration > Security

<figure><img src="/files/iDIq6A8rHrMDrz5U9x3u" alt=""><figcaption><p>Navigate to Administration</p></figcaption></figure>

* Click "Add Access Key"

<figure><img src="/files/j7KsDiXmCfPuudgrZMTY" alt=""><figcaption><p>Add access key</p></figcaption></figure>

* Name the Access Key something memorable, such as Dropzone AI, then click "Save"

<figure><img src="/files/4gCg6eQxpp9bordvN0Ww" alt=""><figcaption><p>Name and Save API</p></figcaption></figure>

* Copy the Access ID and Access Key shown for use later in the Dropzone UI where they are called "Access ID" and "Access Key" respectively, then click "Done"

<figure><img src="/files/numvUk38JEGPYc6hOzG2" alt=""><figcaption><p>Copy API Key and Secret</p></figcaption></figure>

## Enable Sumo Logic

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field         | Source                                                   |
| ---------------------- | -------------------------------------------------------- |
| Access ID              | The "Access ID" value you copied earlier                 |
| Access Key             | The "Access Key" value you copied earlier                |
| API Hostname           | Your Sumo Logic API hostname, e.g. api.us2.sumologic.com |
| Sumo Logic UI Hostname | Your Sumo Logic Hostname, e.g. service.us2.sumologic.com |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Sumo Logic, then click "Configure"

<figure><img src="/files/bc82vDnziBv0U577mFpB" alt=""><figcaption><p>The Sumo Logic Tile</p></figcaption></figure>

* Under the Alert Source header, input your Access ID, Access Key, API Domain, and Sumo Logic Hostname

<figure><img src="/files/lWa9bv9La3E9eudQwPUN" alt=""><figcaption><p>The Sumo Logic alert source configuration (pt 1)</p></figcaption></figure>

* In the "Sumo Logic Alert Search Queries" section, you must input [Sumo Logic-specific search query terms](https://help.sumologic.com/docs/search/get-started-with-search/build-search/search-syntax-overview/) to select alerts to investigate. To do so, click "Add Item," then input the query details
  * For example, if your MS Defender alerts are sent to a source category named msgraph-security, you would add the following query: `_sourceCategory=msgraph-security`

<figure><img src="/files/NNaH0rBT82FIQkO2vC8D" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to enable Sumo Logic's Cloud SIEM, check the box labeled "Enabled" in the Cloud SIEM section, then select the severity levels you wish Dropzone to investigate
* If you wish to exclude [incident statuses](https://help.sumologic.com/docs/cse/get-started-with-cloud-siem/cse-heads-up-display/#3-insights-by-status) from investigation, click "Add Item" under "Excluded Statuses" and input each status by name
* If you wish to exclude any alerts that may be generated from a [Prelude Security](https://www.preludesecurity.com/platform/security-control-validation) attack simulations, check the box labeled "Exclude Prelude Security Alerts"

<figure><img src="/files/W8IiDrR7gRRNVwk1FSmR" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 3)</p></figcaption></figure>

* In the "Alert Title Filtering" section, you may choose to include or exclude alerts in investigation. To do so, select whether to include or exclude the alert from the dropdown, then click "Add Item" and input a python regex pattern to filter the alerts by title. Continue clicking "Add Item" until down

<figure><img src="/files/yNClKwcWF6uLVRpHRCcD" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 4)</p></figcaption></figure>

* In the Data Tiers section, select which Sumo Logic [data tiers](https://help.sumologic.com/docs/manage/partitions/data-tiers/) you wish for Dropzone to be able to investigate. By default, only the Continuous tier is utilized

<figure><img src="/files/dm8M79eFlQtJDTsNSHs3" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 5)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 6)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Sumo Logic Alert Source Configuration (pt 7)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Vectra AI

The Dropzone AI Platform integrates with [Vectra AI](https://www.vectra.ai/platform), an AI-driven NDR platform for automated threat detection and response across hybrid networks, including public clouds, SaaS, identity systems, and data centers. Dropzone supports both Cloud and On-premise deployments of Vectra AI.

## Create an API Client (Cloud Deployment)

If you have a Cloud deployment, Vectra AI requires an API Client and Secret Key to enable.

To obtain these, do the following:

* Log in to your Vectra AI console
* In the left sidebar, navigate to Manage > API Clients
* Click "Add API Client"

<figure><img src="/files/o3mS5WavADHzejZBxllH" alt=""><figcaption><p>Add API Client</p></figcaption></figure>

* Name the client something memorable, such as "Dropzone AI"
* Assign the client the Read-Only role
* Click "Generate Credentials"

<figure><img src="/files/kW0py6WqJ33i80wF7cRV" alt=""><figcaption><p>Generate the API Client</p></figcaption></figure>

* Copy the Client ID and Secret Key generated for use later in the Dropzone UI, where they are called "OAuth2 Client ID" and "OAuth2 Client Secret," respectively

<figure><img src="/files/QJoWV4oqgTsmGuHguYWk" alt=""><figcaption><p>Save the credentials</p></figcaption></figure>

## Create an API Token (On-Premise Deployment)

* Log in to your Vectra AI console
* In the left sidebar, navigate to My Profile

<figure><img src="/files/13wefDnSFhTnjxC0rvAt" alt=""><figcaption><p>Click "My Profile"</p></figcaption></figure>

* Click "View API Token"

<figure><img src="/files/iCJ3zBIg5s4AFMHX3HGL" alt=""><figcaption></figcaption></figure>

* Input your password, then click "Continue"

<figure><img src="/files/gG1sS1oeLHkE71eDMJsq" alt=""><figcaption><p>Input your credentials</p></figcaption></figure>

* Copy the API token shown for use later in the Dropzone UI, where it is called "API Token"

<figure><img src="/files/KR64p2I7KP62MnhAGfEt" alt=""><figcaption><p>Copy the API Token</p></figcaption></figure>

* Click "Close"

## Enable Vectra AI

To enable the Alert Source integration, you'll need the following information:

| Dropzone Field       | Source                                                                                    |
| -------------------- | ----------------------------------------------------------------------------------------- |
| Deployment Type      | Your Vectra AI deployment type, e.g. Cloud or On-premise                                  |
| Vectra AI URL        | The base URL of your Vectra instance, e.g. <https://api.vectra.ai> or <https://10.20.1.5> |
| OAuth2 Client ID     | The Client ID value you copied earlier. Only necessary for Cloud deployments              |
| OAuth2 Client Secret | The Secret Key value you copied earlier. Only necessary for Cloud deployments             |
| Vectra AI Server     | The server hostname of your on-premise deployment, e.g. 10.20.1.5                         |
| Vectra AI Port       | The API port of your on-premise deployment                                                |

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Vectra AI then click "Configure"

<figure><img src="/files/aE75SNDcVRChHbWNne5G" alt=""><figcaption><p>The Vectra AI Tile</p></figcaption></figure>

* Under the Alert Source header, if your Vectra AI integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input your Deployment Type and Vectra AI URL

<figure><img src="/files/ebhMTM1h76iA49zBKMPv" alt=""><figcaption><p>The Vectra AI Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you have a Cloud deployment, input the OAuth2 Client ID and Secret

<figure><img src="/files/GDaOlF3drguiLo1WdR5p" alt=""><figcaption><p>The Vectra AI Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you have an On-premise deployment, input the Vectra AI Server, Port, and API Token

<figure><img src="/files/kMRaKde8UvfQOkfpmaGD" alt=""><figcaption><p>The Vectra AI Alert Source Configuration (pt 3)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The Vectra AI Alert Source Configuration (pt 4)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The Vectra AI Alert Source Configuration (pt 5)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors or questions, engage your Dropzone AI support representative.


# Wiz

## Wiz

The Dropzone AI platform integrates with Wiz to ingest security findings and enrich investigations with context from [Wiz](https://www.wiz.io/about) such as cloud configurations, vulnerabilities, and exposure data via webhook automation rules.

## Integrations Overview

To enable these integrations you will perform the following actions:

* Create an API Key (within Dropzone AI)
* Configure a webhook integration in Wiz
* Create a custom automation rule in Wiz

### Create an API Key

To create a Dropzone API key, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > API Keys

<figure><img src="/files/wXhlH88IlseWhKBegxue" alt=""><figcaption><p>API Keys Dropdown</p></figcaption></figure>

* In the "Add New API Key" section, name the API key something memorable, such as "Wiz Webhook Integration"
* If you want to assign an expiration date to the API Key, select your desired expiration date in the "Expiration" section
* Click "Create Key"

<figure><img src="/files/gwlDqQdE4ZpTkbTvzq9R" alt=""><figcaption><p>Create API Key</p></figcaption></figure>

* Copy the value shown for use later in the Wiz UI

<figure><img src="/files/6l4ImgOi1urcfZKBNSGW" alt=""><figcaption><p>Copy the API Key</p></figcaption></figure>

### Create a Wiz Webhook Integration

Follow instructions on Wiz's [documentation site](https://docs.wiz.io/wiz-docs/docs/dropzone-ai-webhook-integration) to create a Wiz Webhook integration, or contact your Wiz/Dropzone support representative.

In the URL section of your webhook integration, paste in your Dropzone webhook URL, e.g. https\:///app/api/v1/investigation/create. Use the API key you generated earlier as your API Key value.

### Create an Automation Rule

Contact your Wiz/Dropzone support representative for instructions on how to create an Automation Rule.

You must create an automation rule with the "Post Webhook" feature. In the "Request Body" section of your webhook, replace the default action template with the JSON below:

```

{
  "schema_key": "wiz_webhook_detection",
  "raw_alert_content": {
    "trigger": {
      "source": "{{triggerSource}}",
      "type": "{{triggerType}}",
      "ruleId": "{{ruleId}}",
      "ruleName": "{{ruleName}}"
    },
    "id": "{{detection.id}}",
    "threatId": "{{detection.issue.id}}",
    "threatURL": {{#detection.issue.url}}"{{detection.issue.url}}"{{/detection.issue.url}}{{^detection.issue.url}}null{{/detection.issue.url}},
    "title": "{{detection.rule.name}}",
    "description": {{#detection.description}}"{{detection.description}}"{{/detection.description}}{{^detection.description}}null{{/detection.description}},
    "severity": "{{detection.severity}}",
    "createdAt": "{{detection.createdAt}}",
    "tdrId": "{{detection.rule.id}}",
    "tdrSource": "{{detection.rule.sourceType}}",
    "mitreTactics": {{detection.rule.MITRETactics}}{{^detection.rule}}null{{/detection.rule}},
    "mitreTechniques": {{detection.rule.MITRETechniques}}{{^detection.rule}}null{{/detection.rule}},
    "cloudAccounts": {{detection.cloudAccounts}},
    "cloudOrganizations": {{detection.cloudOrganizations}},
    "timeframe": {
      "start": "{{detection.startedAt}}",
      "end": "{{detection.endedAt}}"
    },
    "actors": {{detection.actors}},
    "primaryActor": {{#detection.primaryActor}}{{detection.primaryActor}}{{/detection.primaryActor}}{{^detection.primaryActor}}null{{/detection.primaryActor}},
    "resources": {{detection.resources}},
    "primaryResource": {{#detection.primaryResource}}{{detection.primaryResource}}{{/detection.primaryResource}}{{^detection.primaryResource}}null{{/detection.primaryResource}},
    "triggeringEventsCount": {{detection.triggeringEventsCount}},
    "triggeringEvents": {{detection.triggeringEvents}}
  },
  "force_reinvestigation": false
}

```

Once this step has been committed, Wiz will start sending its alerts directly to Dropzone.

If you have any errors engage your Dropzone AI support representative.


# ZScaler (Beta)

{% hint style="warning" %}
This is integration is currently in Beta. At this point in its development, any attempts to integrate with it will return a success, regardless of whether the information entered is accurate or not. For more information about our beta integrations, engage your Dropzone support representative.
{% endhint %}

The Dropzone platform integrates with [ZScaler](https://www.zscaler.com/company/about-zscaler), a cloud-based security platform offering services such as cloud firewalls, data loss prevention, zero trust network access (ZTNA), and automated threat inspections.

## Create an API Client

ZScaler requires API credentials to enable.

To obtain API credentials, do the following:

* Navigate to Administration > API Configuration > OneAPI > API Clients
* Click "Add API Client"

<figure><img src="/files/27c0Ev61pjcHNN7lJLOA" alt=""><figcaption><p>The API Clients page</p></figcaption></figure>

* Name the key something memorable, such as "Dropzone AI"
* Click the box under "Status" to enable the API Client
* Select an expiration period for the access token

<figure><img src="/files/YDoot9YmUz0ez8YDrKhD" alt=""><figcaption><p>Assign the client details</p></figcaption></figure>

* Under the Client Authentication header, select the "Secret" validation type
* Click "Add"
* Assign the secret an expiration date

{% hint style="info" %}
To reduce the number of times you need to perform this integration, we recommend selecting the maximum duration of 365 days.
{% endhint %}

* Copy the secret shown for use later in the Dropzone UI, where it is called "Client Secret"

<figure><img src="/files/RLMGiSCHCzWWWDwyUloj" alt=""><figcaption><p>Copy the API Key details</p></figcaption></figure>

* Click "Save"
* In the API Clients page, copy the Client ID of your new token for use later in the Dropzone UI, where it is called "Client ID"

<figure><img src="/files/FpToTqcNi5Tqhmhop6w1" alt=""><figcaption><p>The API Clients page</p></figcaption></figure>

Once your API Client has been generated, you must also authenticate your API Client in ZScaler's OneAPI, to verify your client's identity. To do so, enter the following code into your request payload:

```
POST /oauth2/v1/token HTTP/1.1
Host: <vanity-domain>.zslogin.net
Content-Type: application/x-www-form-urlencoded

{
  "grant_type": "client_credentials",
  "client_id": "<Client ID>",
  "client_secret": "<Client Secret>",
  "audience": "https://api.zscaler.com"
}
```

See ZScaler's [authentication](https://automate.zscaler.com/docs/getting-started/getting-started#authenticating) documentation for more information.

## Enable ZScaler

To enable the Alert Source integration, you will need the following information:

| Dropzone Field | Source                                                                          |
| -------------- | ------------------------------------------------------------------------------- |
| Client ID      | The Client ID value you generated earlier                                       |
| Client Secret  | The Client Secret value you generated earlier                                   |
| Vanity Domain  | The domain name of your organization, e.g. https\://\<your\_domain>.zslogin.net |
| Cloud          | Your Cloud environment, e.g. zscalerone, zscloud, etc                           |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ZScaler, then click "Configure"

<figure><img src="/files/5ulthQQQPxd3QiCvAmjY" alt=""><figcaption><p>The ZScaler Tile</p></figcaption></figure>

* Under the Alert Source header, input the Client ID, Client Secret, and Vanity Domain
* Select your cloud environment from the dropdown

<figure><img src="/files/ZJiawKKH2RLWWwxbXa2J" alt=""><figcaption><p>The ZScaler Alert Source Configuration (pt 1)</p></figcaption></figure>

* If you wish, you may choose to filter alerts by [event name](https://help.zscaler.com/zpa/viewing-and-managing-events-diagnostics#eventTable:~:text=the%20Component%20section.-,Event,-Name%3A%20See)
  * Under "Event Filter Mode," select whether to include or exclude the names matching the filters
  * Click "Add Item" under "Event Name Regexes" section, then input a custom regex pattern to filter results

<figure><img src="/files/7IUq4jytiLrp0pd6nIeO" alt=""><figcaption><p>The ZScaler Alert Source Configuration (pt 2)</p></figcaption></figure>

* Input your desired poll interval and lookback

<figure><img src="/files/EbxJMIbYnSnzbZd7V2Da" alt=""><figcaption><p>The ZScaler Alert Source Configuration (pt 3)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="/files/infLIQONnAkvK8XGXOi4" alt=""><figcaption><p>The ZScaler Alert Source Configuration (pt 4)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Communicators

Dropzone uses Communicator sources to ask questions of your employee base and use their responses when performing Investigations to improve the quality of analysis.

For example, if Dropzone sees someone logging in from geographically diverse IPs within a short period of time (an "impossible travel" alert), this may indicate that their credentials have been compromised. Alternatively, it could simply mean the user is utilizing a VPN. The Dropzone Communicator can ask the individual whether this was a legitimate login and use their response as part of the investigation data.


# Microsoft Teams

{% hint style="info" %}
Microsoft Teams is a Communicator Integration. Communicator Integrations allow Dropzone to ask questions of your employee base and use their responses to improve the quality of analysis.
{% endhint %}

Dropzone uses a Microsoft Teams Bot and an Azure AD Application to communicate directly with people in your organization.

Dropzone supports two configuration methods: automated and manual.

## Automated Setup (Recommended)

For the most reliable setup experience, contact your Dropzone support representative to request our automated deployment script. This script handles all Azure and Teams configuration automatically, including:

* Azure Bot creation and configuration
* Azure AD App Registration with required permissions
* Teams app creation and deployment
* Automatic app installation policies

The script will provide you with the exact credentials needed for Dropzone configuration.

### Automated Setup Results

When the automated script completes successfully, it will provide you with the following credentials:

* MS Teams Bot App ID: Application (client) ID for your bot
* MS Teams Bot App Secret: Client secret for your bot
* MS Graph Tenant ID: Azure AD tenant ID

The script also creates a Teams app package (`teams_app.zip`) for you to upload to your organization's app catalog. Proceed to the "Publish the application in Teams Admin Center" section for instructions on how to do so.

## Manual Setup

Manual setup is available if automated setup is not possible for your organization. This process involves several steps in Azure and Microsoft Teams. Follow the instructions below carefully.

## Manual Setup Instructions

To enable the Microsoft Teams Communicator manually, you will perform the following actions:

1. Create an Azure Bot and configure it for Microsoft Teams
2. Configure your Azure AD App Registration with the required API permissions
3. Create a Teams App in the Developer Portal
4. Publish the Teams App to your organization's app catalog
5. Collect the necessary credentials for Dropzone configuration

## Azure Portal & Azure AD Setup

### Create the Azure Bot

* Go to your Azure [Portal](https://portal.azure.com)
* In the search bar, search "Bot Services" and click it

<figure><img src="/files/8sNuyBt9XwQVaq9fAi39" alt=""><figcaption></figcaption></figure>

* Click "Create"

<figure><img src="/files/KaD4xbuBUZ4z4stLSCBQ" alt=""><figcaption></figcaption></figure>

* Click "Azure Bot" or go directly to <https://portal.azure.com/#create/Microsoft.AzureBot>

<figure><img src="/files/tzt2aOKrtoQh4dEHb1B1" alt=""><figcaption></figcaption></figure>

* Select your subscription
* Click "Create"

<figure><img src="/files/X0Fzk1ud9slwNz8F7Fnx" alt=""><figcaption></figcaption></figure>

* Name the bot something memorable, such as "dropzone-ai-interviewer"
* Select your Azure subscription
* Add the bot to your desired resource group, or create a new one
* Select your data residency

<figure><img src="/files/JkEFvEqGkeco5qAbCTMa" alt=""><figcaption><p>Input the bot details (pt 1)</p></figcaption></figure>

* In the "Microsoft App ID" section, select "Single Tenant"
* Click "Create new Microsoft App ID"

<figure><img src="/files/sE6EpUAtfuHcJbbffvUc" alt=""><figcaption><p>Input the bot details (pt 2)</p></figcaption></figure>

* In the bottom left corner, click "Review + create"
* Click "Create"

<figure><img src="/files/AP984ETWWQKz2jZ5F0AJ" alt=""><figcaption><p>Create the bot</p></figcaption></figure>

### Configure the Bot Channels

* Once the Azure Bot resource is deployed, navigate to it
* Under "Next steps," click "Go to resource"

<figure><img src="/files/68cpZqjWtVmIP7JnrM4R" alt=""><figcaption></figcaption></figure>

* In the left sidebar, navigate to Settings > Channels

<figure><img src="/files/ozDZEBofllq4IQtninIl" alt=""><figcaption><p>Click "Channels"</p></figcaption></figure>

* Under "Available Channels," click "Microsoft Teams"

<figure><img src="/files/dxpWmjLvHwMvwKEBAH12" alt=""><figcaption><p>Microsoft Teams</p></figcaption></figure>

* Select your Microsoft Teams channel type
* Click "Apply"

<figure><img src="/files/hhY4BY8QBLWq2Vuwctqw" alt=""><figcaption></figcaption></figure>

* In the Channel page, it should be shown as `Running` or `Healthy`

<figure><img src="/files/6MxDv2lhjoJ1l5AiHMvh" alt=""><figcaption><p>Example - successful channel configuration</p></figcaption></figure>

* In the left sidebar, navigate to Settings > Configuration
* Under "Messaging endpoint, input your Dropzone webhook endpoint, e.g. https\://*mycompany*.dropzone.app/interviewer/webhooks/ingest/msteams

<figure><img src="/files/UehHLgW0MTjnf6jBXQ67" alt=""><figcaption><p>Input your messaging endpoint</p></figcaption></figure>

* Copy the Microsoft APP ID and Tenant ID for use later in the Dropzone UI where they are called "Microsoft APP ID" and "MS Graph Tenant ID," respectively
* Next to Microsoft App ID, click "Manage Password"

<figure><img src="/files/IQA1Yq2vL8rYq4tEr2tF" alt=""><figcaption><p>Copy the integration details</p></figcaption></figure>

You should now be on the "Certificates & Secrets" page for your new Azure AD App Registration

* Click "+ New client secret"

<figure><img src="/files/d6ok0sbEAoBj8jL6SlaL" alt=""><figcaption></figcaption></figure>

* Enter a description for the client secret, such as "Dropzone AI Bot Secret," and choose an appropriate expiration date. Click "Add"

{% hint style="warning" %}
Your Dropzone integration will stop working when the client secret expires. Consider setting a calendar reminder to update the key prior to expiration. For convenience's sake, we recommend picking a longer expiration date, to limit the number of times the client secret must be updated.
{% endhint %}

<figure><img src="/files/ESvT50sLMVwmsXlZ153D" alt=""><figcaption><p>Create the client secret</p></figcaption></figure>

* Under "Value," copy the Client Secret Value for use later in the Dropzone UI, where it is called "MS Teams Bot APP ID"

{% hint style="danger" %}
This value is not shown after you leave this page - be sure to record it immediately.
{% endhint %}

<figure><img src="/files/motEIRFuU57UvTvGo5jd" alt=""><figcaption><p>Copy the client secret</p></figcaption></figure>

## Configure the Application's API permissions

* In the left sidebar of the App Registration, navigate to Manage > API permissions
* In the API permissions page, click "Add a permission"

<figure><img src="/files/rXzZgATOsjV7OApuxizn" alt=""><figcaption></figcaption></figure>

* Under the Microsoft API header, select "Microsoft Graph"

<figure><img src="/files/7ucvU7fOJt0pTZQNDMws" alt=""><figcaption><p>Select Microsoft Graph</p></figcaption></figure>

* Click "Application Permissions"

<figure><img src="/files/oSiXAegQZauD3wcHDF3q" alt=""><figcaption><p>Select Application Permissions</p></figcaption></figure>

Add the following permissions:

| Permission                                    | Purpose                                                                                                                                              |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| AppCatalog.Read.All                           | Allows the Chatbot to read apps in the app catalogs                                                                                                  |
| Chat.Create                                   | Allows the Chatbot to create chats                                                                                                                   |
| Chat.Read.All                                 | Allows the Chatbot to read all 1-to-1 or group chat messages in Microsoft Teams                                                                      |
| TeamsAppInstallation.ReadWriteForTeam.All     | Allows the Chatbot to read, install, upgrade, and uninstall Teams apps in any team. Does not give the ability to read application-specific settings  |
| TeamsAppInstallation.ReadWriteForUser.All     | Allows the Chatbot to read, install, upgrade, and uninstall Teams apps for any user. Does not give the ability to read application-specific settings |
| TeamsAppInstallation.ReadWriteSelfForChat.All | Allows the Chatbot to read, install, upgrade, and uninstall itself for any chat                                                                      |
| TeamsAppInstallation.ReadWriteSelfForTeam.All | Allows the Chatbot to read, install, upgrade, and uninstall itself in any team                                                                       |
| TeamsAppInstallation.ReadWriteSelfForUser.All | Allows the Chatbot to read, install, upgrade, and uninstall itself to any user                                                                       |
| User.Read.All                                 | Allows the Chatbot to read user profiles                                                                                                             |

<figure><img src="/files/UpR006DSi2UIYDblppvh" alt=""><figcaption><p>Example - adding the "User.Read.All" permission</p></figcaption></figure>

* Once done selecting all the permissions, click "Add permissions"
* Click "Grant admin consent for \[mycompany.net]"

{% hint style="info" %}
If you are not an Azure AD administrator, have one grant access for you.
{% endhint %}

<figure><img src="/files/nKTcgGobOtW8J851R42c" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

* Click "Yes"

<figure><img src="/files/6t1bTqpO5FLj1cjlgnEu" alt=""><figcaption><p>Grant admin consent</p></figcaption></figure>

## Teams Developer Portal & Admin Center Setup

### Create/Configure Teams App in Developer Portal

* Go to the [Teams Developer Portal](https://dev.teams.microsoft.com/home)
* Click "Create a new app"

<figure><img src="/files/EyjdP6sr7x2svmigh9Ng" alt=""><figcaption></figcaption></figure>

* Name it something memorable, such as "Dropzone AI Interviewer," then click "Create"

In the Basic Information Page, configure the app as follows:

* Short name: Dropzone AI Interviewer
* Long name: Dropzone AI Interviewer for Microsoft Teams
* Short description: Dropzone AI Interviewer — Security Tool
* Long description: Dropzone AI is a vendor used by the company to perform security assessments. This app may send you messages to ask about incidents.

<figure><img src="/files/CZhkdkdDFwD8FSj7zKGK" alt=""><figcaption><p>Configure the application details (pt 1)</p></figcaption></figure>

* Version: The current [version](https://learn.microsoft.com/en-us/officeupdates/teams-app-versioning) of Microsoft teams you're using
* Developer information: You may input your own details or use Dropzone's (e.g. Dropzone AI and <https://dropzone.ai>)
* APP URLs: Input links to your privacy policy and terms of use

<figure><img src="/files/9QuvJ33swwyq73BXLdqk" alt=""><figcaption><p>Configure the application details (pt 2)</p></figcaption></figure>

* Application (client) ID: Input the Application (client) ID you copied earlier
* Click "Save"

<figure><img src="/files/oCuEeJ0N0eeVRQx9pDlt" alt=""><figcaption><p>Configure the application details (pt 3)</p></figcaption></figure>

{% hint style="info" %}
If you wish, you can upload a logo for your application. We recommend using one of the following Dropzone logos:

* <https://go.dropzone.ai/img/logos/logomark-transparent-color-192px-96px.png>
* <https://go.dropzone.ai/img/logos/logomark-transparent-color-32px.png>

To do so, in the left sidebar, navigate to Branding, click "Color Icon" and upload your desired logo.
{% endhint %}

* In the left sidebar, navigate to App Features
* Click "Bot"

<figure><img src="/files/LIJf8Po9Ix99FhDcS52o" alt=""><figcaption></figcaption></figure>

* Select the existing Azure bot you created

{% hint style="info" %}
You may use **App validation** to double-check that Teams will accept your app.
{% endhint %}

<figure><img src="/files/uGnPfFuOhTyNP6uBP9e8" alt=""><figcaption></figcaption></figure>

* In the top right, click "Distribute"
* Select either "Download the app package" or "Publish to your organization"

<figure><img src="/files/k5jpL7n1dwPICuX2qAgM" alt=""><figcaption><p>Pick your distribution method</p></figcaption></figure>

### Publish the application in Teams Admin Center

* Navigate to your [Teams Admin Center - Manage Apps](https://admin.teams.microsoft.com/policies/manage-apps) page as a Teams Administrator (or have an administrator perform these steps for you)
* If you downloaded the app package, in the upper right click Actions > Upload new app
* Upload the zip file you just downloaded

<figure><img src="/files/ITxt3WatHP3XPzy2elwj" alt=""><figcaption></figcaption></figure>

* If you chose to publish to your organization, search for your app in the Developer Portal
* Select the app from the list
* Click "Publish," then "Confirm"

## Enable Microsoft Teams Integration

To enable the communicator integration, you will need the following information:

| Dropzone Field          | Source                                             |
| ----------------------- | -------------------------------------------------- |
| MS Teams Bot App ID     | The Microsoft App ID value you copied earlier      |
| MS Teams Bot App Secret | The Client Secret value you copied earlier         |
| MS Graph Tenant ID      | The Directory (tenant) ID value you copied earlier |

{% hint style="info" %}
If you used the automated script, it will provide these exact credentials at the end of the setup process. You can also locate your Directory (tenant) ID in the overview page of your application.
{% endhint %}

To enable the integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Microsoft Teams, then click "Configure"

<figure><img src="/files/20ErW1kBsRxRh4pBmzbQ" alt=""><figcaption><p>The Microsoft Teams Tile</p></figcaption></figure>

* Input the Bot App ID, Bot App Secret, and MS Graph Tenant ID

<figure><img src="/files/qlLDTiugQyGrpXb12NhZ" alt=""><figcaption><p>The Microsoft Teams configuration</p></figcaption></figure>

* Click "Test & Save" to finish

### Enable Microsoft Teams in Interviewer Configuration

After successfully configuring and saving the Microsoft Teams communicator credentials, set it as the active interviewer for desired scenarios:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > AI Interviewer

<figure><img src="/files/bTDhnYKdwOdUi3MwSoi2" alt=""><figcaption><p>Settings Dropdown</p></figcaption></figure>

* In the right corner of the Interviewer Configuration page, select the dropdown
* Select "Microsoft Teams"
* Ensure the toggle switch next to Microsoft Teams is enabled (blue and toggled to the right)

<figure><img src="/files/8rJS41ypqJi4s4YAbcY0" alt=""><figcaption><p>Interviewer Configuration</p></figcaption></figure>

This will activate Microsoft Teams as a communicator for initiating interviews based on your configured scenarios.

## Troubleshooting

If you encounter any issues during setup or when configuring the integration in Dropzone:

* Double-check all credentials and configuration steps above
* Ensure all required permissions are granted and show as **Granted for \[Your Organization]**
* If you see errors in Teams or Azure, consult the [Microsoft Teams documentation](https://learn.microsoft.com/en-us/microsoftteams/platform/) or [Azure Bot Service documentation](https://learn.microsoft.com/en-us/azure/bot-service/)
* For persistent issues, contact your Dropzone AI support representative
* For manual setup issues, consider switching to the automated script for a more reliable experience


# Slack Communicator

## Slack Communicator

{% hint style="info" %}
Slack is a Communicator Integration. Communicator Integrations allow the Dropzone platform to ask questions of your employee base and use their responses to improve the quality of analysis.
{% endhint %}

The Dropzone platform uses a Slack Communicator Application to communicate directly with people in your organization.

### Integrations Overview

To enable these integrations you will perform the following actions:

* Create and install a Slack Application with the necessary permissions
* Obtain an Application and Slack Token

### Create a Slack Application

* Navigate to <https://api.slack.com/apps>
* Click "Create New App"
* Select "From a manifest"

<figure><img src="/files/4wI70W1U0Nm2t7npsxu6" alt=""><figcaption><p>Select "From a Manifest"</p></figcaption></figure>

* Input the following JSON manifest

```
{
   "display_information": {
       "name": "DropzoneAI"
   },
   "features": {
       "app_home": {
           "home_tab_enabled": false,
           "messages_tab_enabled": true,
           "messages_tab_read_only_enabled": false
       },
       "bot_user": {
           "display_name": "DropzoneAI",
           "always_online": true
       }
   },
   "oauth_config": {
       "scopes": {
           "bot": [
               "channels:manage",
               "channels:read",
               "chat:write",
               "im:history",
               "im:read",
               "im:write",
               "users:read",
               "users:read.email",
               "channels:history"
           ]
       }
   },
   "settings": {
       "event_subscriptions": {
           "bot_events": [
               "message.im"
           ]
       },
       "interactivity": {
           "is_enabled": true
       },
       "org_deploy_enabled": false,
       "socket_mode_enabled": true,
       "token_rotation_enabled": false
   }
}
```

<figure><img src="/files/bVGbKwOWKsMVeEgfsqZN" alt=""><figcaption><p>Input the manifest</p></figcaption></figure>

* Select your workspace, then click "Next"

<figure><img src="/files/HwaT4c88Fr6xNQHASOSY" alt=""><figcaption></figcaption></figure>

* Click "Create & Install"
* In the settings page for your Dropzone SlackBot application, navigate to "Basic Information"

<figure><img src="/files/WpN8PeB8UBhKX2rgupsL" alt=""><figcaption><p>Navigate to "Basic Information"</p></figcaption></figure>

* Scroll down to "Display Information"

<figure><img src="/files/gwNdgVHYLVEUwykITvYz" alt=""><figcaption><p>Navigate to "Display Information"</p></figcaption></figure>

* Change the App name to something you will remember, such as "DropzoneAI"

{% hint style="info" %}
Should you wish, we've provided Dropzone icons that you can use here: [transparent](https://go.dropzone.ai/img/logos/logomark-transparent-color.png), [white background](https://go.dropzone.ai/img/logos/logomark-blue-on-white.png), or [black background](https://go.dropzone.ai/img/logos/logomark-blue-on-black.png)
{% endhint %}

* At the bottom, click "Save Changes"

You must install the Slack Application to your organization before it can be used. To do so, do the following:

* Navigate to Settings > Install App

<figure><img src="/files/mj4fMCk9z1L2vJagquQJ" alt=""><figcaption><p>Navigate to "Install App"</p></figcaption></figure>

* Click "Install to \[your workspace name]"
* To grant the application permission to access the workspace, click "Allow"

<figure><img src="/files/0Thcg43LonIzc08d5lT8" alt=""><figcaption><p>Click "Allow"</p></figcaption></figure>

## Create API Tokens

Slack Communicator requires two tokens: a Bot token (`xoxb-*`) and an App token (`x-app-*`)

### Bot Token

To obtain a Bot token, do the following:

* Navigate to Settings > Install App
* Copy the value under "Bot User Auth Token" for use later in the Dropzone UI where it is called "Slack Bot Token"

<figure><img src="/files/G1uGBtwNMuSrwTWueBQA" alt=""><figcaption><p>Copy the Bot token</p></figcaption></figure>

### App Token

To obtain an App token, do the following:

* Navigate to Settings > Basic Information
* Scroll down to App-Level Tokens and click "Generate Token and Scopes"

<figure><img src="/files/Uc8MvREsh5wwSQwQwOpK" alt=""><figcaption><p>Generate Token and Scopes</p></figcaption></figure>

* Name your token something memorable, such as "DropzoneAI"
* Click "Add Scope"

<figure><img src="/files/2CbedxHaeINupSeuwqTu" alt=""><figcaption><p>Add scope</p></figcaption></figure>

* Select the scope "connections:write"
* Click "Generate"

<figure><img src="/files/go5FAHZMXcpN4HLQzi4t" alt=""><figcaption><p>Select "connections:write"</p></figcaption></figure>

* Copy the Token generated for use later in the Dropzone UI where it is called "Application Token"

<figure><img src="/files/tyIGkD2krGgiRo0CzoMe" alt=""><figcaption><p>Copy the Token</p></figcaption></figure>

### Enable Slack Communicator

To enable Slack Communicator, you'll need the following information:

| Dropzone Field    | Source                                         |
| ----------------- | ---------------------------------------------- |
| Slack Bot Token   | The Slack Bot Token value you copied earlier   |
| Application Token | The Application Token value you copied earlier |

To enable the Slack Communicator integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Slack, then click "Configure"

<figure><img src="/files/7ARZUJOGVgvN3WVDX1rj" alt=""><figcaption><p>The Slack Communicator tile</p></figcaption></figure>

* Input the Slack Bot Token and the Application Token

<figure><img src="/files/sJJ0hjGrL0maNDCtUwFn" alt=""><figcaption><p>The Slack Communicator Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Data Source Integrations

These integrations are Data Source.

Data Sources enrich the information Dropzone uses to perform alert investigations and respond to interactive chat. Dropzone has support for many Threat Intelligence (TI) feeds, tools, and corporate systems such as identity, directory, and SIEM tools.

For more details about Data sources see the [Data Sources](/dropzone-101/terms-and-defs/data-sources) page.


# AbuseIPDB

{% hint style="info" %}
Abuse IPDB is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

The Dropzone platform integrates with [Abuse IPDB](https://www.abuseipdb.com/account/api) to monitor, check and report IP addresses that are involved in malicious activity such as spamming, hack attempts, and DDoS attacks.

## Create an API Key

Abuse IPDB requires an API key to enable.

To obtain an API Key, do the following:

* Navigate to your AbuseIPDB Account at <https://www.abuseipdb.com/> and log in

{% hint style="info" %}
You can create a free AbuseIPDB account with a limited number of checks per day, or you can use a paid account for higher usage limits
{% endhint %}

* In the banner, navigate to "API"

<figure><img src="/files/ClevzCAY69bx6zRigRIo" alt=""><figcaption><p>Abuse IPDB Banner</p></figcaption></figure>

* Click on "Create Key" on the right

<figure><img src="/files/FaAXczFmZzfRFMrKAwQq" alt=""><figcaption></figcaption></figure>

* Give the key a memorable name and click "Create"

<figure><img src="/files/WYdodpjI6hywqhHXo9HQ" alt=""><figcaption></figcaption></figure>

* Record the access token shown for use later in the Dropzone UI where it is called "API key"

<figure><img src="/files/cetkNO5naYiPBzNrKTmq" alt=""><figcaption><p>The Abuse IPDB Api Key</p></figcaption></figure>

## Enable Abuse IPDB

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Abuse IPDB, then click "Configure"

<figure><img src="/files/9431R6pTtEVuScJism7P" alt=""><figcaption><p>The Abuse IPDB Data Tile</p></figcaption></figure>

* Input the API key
* Click "Test & Save" to finish

<figure><img src="/files/k9F2lljhVvisEX7C8lLZ" alt=""><figcaption><p>The Abuse IPDB Data Source Configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Active Directory (LDAP)

## Active Directory LDAP

{% hint style="info" %}
Active Directory LDAP is a Directory Data Source integration. Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

The Dropzone platform supports Active Directory (LDAP) to look up organizational information such as users, job titles, and devices.

Active Directory does require that you've enabled the [Dropzone Connector](https://gitlab.com/dropzone-ai/docs-gitbook/-/tree/main/docs.dropzone.ai/overview/connector.md).

### Integration Overview

To enable these integrations you will perform the following actions:

* Create a read-only service account
* Grant the service account read access to users and computers
* Determine your LDAP Base DN (Distinguished Name)
* Install the credentials into your Dropzone tenant

### Create a Read Only Service Account

Dropzone will use an AD service account for authenticating to your AD LDAP. To create a Read Only Service Account, do the following:

* Open "Active Directory Users and Computers"

<figure><img src="/files/7OxOMJaz2DOM9X22FdrM" alt=""><figcaption><p>Open Active Directory Users and Computers</p></figcaption></figure>

* Right click on the container of your choice, such as "Users", and click New > User

<figure><img src="/files/iNaoWpQQDSBRH6fMSmUt" alt=""><figcaption><p>Right Click New User</p></figcaption></figure>

* Give it a first/last/full name
* Give it a User Logon Name, such as *svc-dropzone@*

<figure><img src="/files/eBAH305fVwqAIaaQtCOz" alt=""><figcaption><p>New User Details</p></figcaption></figure>

* Record this User Logon Name for use later in the Dropzone UI where it is called "User"
* Click Next
* Provide a strong password and record it for use later in the Dropzone UI where it is called "Password"
* Uncheck "User must change password at next login"

<figure><img src="/files/w27KD4jlKWJKLAy1D9PD" alt=""><figcaption><p>Password Settings</p></figcaption></figure>

{% hint style="info" %}
If you have a corporate-wide password rotation policy you should either disable it for this user, or you will want to change the password periodically in AD and update the Dropzone integration with the new password to stay within your organizational policy
{% endhint %}

* Click "Next"
* Click "Finish"

### Apply Active Directory Permissions to the Service Account

Next, we will grant permissions to the service account. Most customers will apply this at the top of the forest so Dropzone has the most visibility into users/devices/etc, but you may pick a lower level if you wish to limit the scope.

* Open "Active Directory Users and Computers"
* Click "View" from the menu bar, and make sure "Advanced Features" is selected
* Right click the top of your forest and select "Properties"
* Select the "Security" tab and click "Add"
* Type the name of the service account you created (e.g. *svc-dropzone@*) and click OK to search

<figure><img src="/files/H0ZKOo7vc8GhdBxpYi2u" alt=""><figcaption><p>Granting Permissions to the Service Account</p></figcaption></figure>

* Highlight the service account and click "Advanced"

<figure><img src="/files/rhopENdaafXMNEVO3Eiq" alt=""><figcaption><p>Permissions to the Service Account (Continued)</p></figcaption></figure>

* In the "Permissions" tab, select the service account again and click "edit"

<figure><img src="/files/DpfKQ5Y4edZTMB1Lydev" alt=""><figcaption><p>Permissions to the Service Account (Continued)</p></figcaption></figure>

* Set read for users
  * Set the "Applies to" dropdown to "Descendant User Objects" so the service account can see all objects in the hierarchy
  * In the Permissions section, make sure "Read All Properties" is checked
  * In the Properties section, make sure "Read All Properties" is checked (this is further down the page)

<figure><img src="/files/8IFQq70CQIxDn14IYnfQ" alt=""><figcaption><p>User Settings</p></figcaption></figure>

* Set read for devices
  * Set the "Applies to" dropdown to "Descendant Computer Objects" so the service account can see all objects in the hierarchy
  * In the Permissions section, make sure "Read All Properties" is checked
  * In the Properties section, make sure "Read All Properties" is checked (this is further down the page)
* Click the "OK" button to save

<figure><img src="/files/0tL1iGYR6zKBfpr5WPR2" alt=""><figcaption><p>Device Settings</p></figcaption></figure>

{% hint style="info" %}
Note that device querying via LDAP is not yet supported in Dropzone AI
{% endhint %}

## Determine The Service Account User Name

* In Active Directory Users and Computers, find the service account just created
* Right click on it and select Properties

<figure><img src="/files/KF7l9TMLW1PyFFVKmeOZ" alt=""><figcaption><p>The Service Account</p></figcaption></figure>

* Click "Attribute Editor" in the tabs at the top
* Scroll down to the "distinguishedName" field

<figure><img src="/files/JNwHIv0buGh4agfq54rz" alt=""><figcaption><p>The distinguishedName</p></figcaption></figure>

* Double click it to pop it out
* Record the full value of the distinguishedName field for use later in the Dropzone UI where it is called "Distinguished Name"

<figure><img src="/files/DVv0GfyXND0saZNILIJk" alt=""><figcaption><p>The User Distinguished Name</p></figcaption></figure>

## Determine your LDAP Base DN (Distinguished Name)

Your Base DN typically is based on your domain name, with `DC=` between each of the domain component. For example if your domain is *example.com* then the Base DN is likely `DC=example,DC=com`.

If you do not already know your Base DN, you can find it as follows:

* In Active Directory Users and Computers, find the service account you created
* Right click on it and select "Properties"

<figure><img src="/files/KF7l9TMLW1PyFFVKmeOZ" alt=""><figcaption><p>The Service Account</p></figcaption></figure>

* Click "Attribute Editor" in the tabs at the top
* Scroll down to the "Distinguished Name" field

<figure><img src="/files/JNwHIv0buGh4agfq54rz" alt=""><figcaption><p>The Distinguished Name</p></figcaption></figure>

* Double click it to pop it out
* Record the part that starts with `DC=` for use later in the Dropzone UI where it is called the "Base DN"

<figure><img src="/files/9lFYTNl6FdwcahoWAsDA" alt=""><figcaption><p>The Base DN</p></figcaption></figure>

## Enable Active Directory LDAP

The Data source integration allows Dropzone AI to look up organizational information.

To enable the Data Source integration, you will need the following information:

| Dropzone Field     | Source                                                                                                 |
| ------------------ | ------------------------------------------------------------------------------------------------------ |
| Server             | The IP address or name of the AD server, in the format of `ldap://` followed by your server name or IP |
| Distinguished Name | The User info you copied from the service account's `DistinguishedName` found in Active Directory      |
| Password           | The service account password you set above                                                             |
| Base DN            | The LDAP DN of your Active Directory                                                                   |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Active Directory, then click "Configure"

<figure><img src="/files/6gFhWPCbkXamnOxkOTTa" alt=""><figcaption><p>The Active Directory Data Tile</p></figcaption></figure>

* If your Active Directory integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* Input the Base DN fields for searches
* Input the service account user's Distinguished name and Password
* Input the server
* Click "Test & Save" to finish

<figure><img src="/files/ag4MK6gvxRlQUF3zXuV2" alt=""><figcaption><p>The Active Directory Data Source Configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Archive Inspector

{% hint style="info" %}
Archive Inspector is a tooling integration. Tooling Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

Dropzone integrates with Archive Inspector to reveal filenames and extract files from compressed archive attachments, notably `.zip` files.

## Enable Archive Inspector

The Archive Inspector integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search Archive Inspector, then click the kebab on the right

<figure><img src="/files/oNmg07NdEuXbMSOw7CeB" alt=""><figcaption><p>Select Archive Inspector</p></figcaption></figure>

* Click "Enable data source" to enable Archive Inspector

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Amazon Web Services (AWS)

The Dropzone AI platform integrates with Amazon Web Services (AWS) APIs for ingesting alerts (AWS GuardDuty) and enriching investigations with data from AWS such as CloudWatch.

Dropzone creates a separate IAM role for each customer. This document describes how to enable the Dropzone role to access your AWS environment and configure the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Enable Cross-Account Access
  * Create an IAM role in your account(s)
  * Attach policies to the role
* Enable the Dropzone Data Source
* Enable the Dropzone Alert Source

The Dropzone platform has a dedicated IAM role for your organization. You enable cross-account access for this IAM to gain access to specific roles within your AWS accounts.

{% hint style="info" %}
These instructions will work for any account, but you may have different methods for applying them, for example if you are using Control Tower or deploying changes via Infrastructure as Code.
{% endhint %}

You must complete these steps for all AWS accounts you wish to be accessible by Dropzone.

## Enable Cross-Account Access

You need to enable Dropzone to access your AWS environments for it to pull alerts and run investigations. There are several ways you can achieve this:

| Toolset                                 | Documentation                                                        | Description                                                                                                                                                                                                                        |
| --------------------------------------- | -------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Set up roles via the Management Console | [documentation](/integrations/data/aws_data/aws-console_data)        | Set up roles and create policies in the AWS Console. Several manual steps, highly documented                                                                                                                                       |
| Set up role chaining (Advanced)         | [documentation](/integrations/data/aws_data/aws-role-chain_data)     | Use a central Hub role to access multiple accounts via a consistent role pattern.                                                                                                                                                  |
| Use AWS CloudFormation                  | [documentation](/integrations/data/aws_data/aws-cloudformation_data) | Set up roles by running Dropzone's CFTs and copy/pasting in a small number of values                                                                                                                                               |
| Use Infrastructure-as-Code / CLI / etc  | see your provider's information                                      | You can create your own IaC by looking at the role and policy information in the [management console](/integrations/data/aws_data/aws-console_data) documentation. Dropzone does not provide any pre-canned IaC code at this time. |

Be sure to use one of the above options to enable the cross-account access before moving on to enabling the integrations.

## Available Integrations

The following integrations are available for Dropzone functionality:

| Service Integration | Policy                                     | Required |
| ------------------- | ------------------------------------------ | -------- |
| CloudTrail          | `AWSCloudTrail_ReadOnlyAccess`†            | Required |
| EC2                 | `AmazonEC2ReadOnlyAccess`                  | Required |
| EKS                 | `eks:ListClusters`, `eks:DescribeCluster`‡ | Optional |
| GuardDuty           | `AmazonGuardDutyReadOnlyAccess`            | Optional |
| IAM                 | `IAMReadOnlyAccess`                        | Optional |
| Route53             | `AmazonRoute53ReadOnlyAccess`              | Optional |
| S3                  | `AmazonS3ReadOnlyAccess`                   | Optional |
| S3 (Outposts)       | `AmazonS3OutpostsReadOnlyAccess`           | Optional |
| Systems Manager     | `AmazonSSMReadOnlyAccess`                  | Optional |

{% hint style="info" %}
CloudTrail Permissions: Required (Minimum): `AWSCloudTrail_ReadOnlyAccess` managed policy. This provides the minimum permissions needed for CloudTrail integration. The integration will use the `lookup_events` API for querying CloudTrail logs. Optional (Recommended): `cloudtrail:StartQuery` permission on event datastores. This enables CloudTrail Lake SQL queries, which provide more powerful querying capabilities. If this permission is not available, the integration will automatically fall back to the `lookup_events` API. To add this permission, attach a custom policy with:

```json
{
  "Effect": "Allow",
  "Action": "cloudtrail:StartQuery",
  "Resource": "arn:aws:cloudtrail:*:*:eventdatastore/*"
}
```

{% endhint %}

{% hint style="info" %}
‡ EKS Note: AWS does not provide a managed EKS policy. Create a custom policy with `eks:ListClusters`, `eks:DescribeCluster`, and other read-only EKS permissions (`eks:Describe*`, `eks:List*`) as needed.
{% endhint %}

## Enable Amazon Web Services

The Data source integration allows Dropzone AI to interact with AWS APIs, for example pulling CloudWatch information, enumerating EC2 instances, for use in investigation analysis and interactive chat.

You'll need the following information:

| Dropzone Field | Source                                                 |
| -------------- | ------------------------------------------------------ |
| Default Region | The AWS region you run most of your services in        |
| Role ARNs      | The ARNs of the AWS roles you created in your accounts |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the Data Source heading, enter an AWS region into the "Default Region" field, such as "us-west-1"

{% hint style="success" %}
This should be the region that the majority of your monitored resources live in
{% endhint %}

* Unless using role chaining, leave the Hub Role blank

<figure><img src="/files/I2ZjR6NCSVkWnwcfqzXL" alt=""><figcaption><p>The AWS Data Source Configuration (pt 1)</p></figcaption></figure>

* Under "Role ARNs", click "Add Item," then input the role ARNs that you created earlier
  * You must add each item individually; continue adding roles until done

<figure><img src="/files/Wk5dOpaJs0WNL2nhVHEj" alt=""><figcaption><p>The AWS Data Source Configuration (pt 2)</p></figcaption></figure>

* Under "Enabled Services," select which AWS services you want Dropzone to access

<figure><img src="/files/DegT9dx9eBxyccIm2H2B" alt=""><figcaption><p>The AWS Data Source Configuration (pt 2)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Cross-Account Access via CloudFormation

{% hint style="info" %}
There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See [the AWS documentation](/integrations/data/aws_data) for more info.
{% endhint %}

Dropzone provides CloudFormation Templates (CFTs) that assist you in creating the IAM Role you need to integrate with Dropzone. The new role includes a custom trust policy, an AWS-managed ReadOnlyAccess policy, and an inline policy granting specific permissions for secure and streamlined Dropzone operations.

There are two CFTs available:

| Name             | CFT Link                                                                                                              | Purpose                                                                                                                                                                                                                        |
| ---------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ReadOnly         | [link](https://dropzone-public.s3.us-west-2.amazonaws.com/cloud-formation-templates/DropzoneAWSRole_ReadOnly.yaml)    | This policy provides read-only access to all your AWS resources. Use this if you do not want to edit your role if more permissions are required in the future.                                                                 |
| Minimum ReadOnly | [link](https://dropzone-public.s3.us-west-2.amazonaws.com/cloud-formation-templates/DropzoneAWSRole_MinReadOnly.yaml) | This policy provides read-only access to only those AWS resources currently needed by Dropzone. Use this if you are prepared to edit your Policies in the future if Dropzone adds new functionality that requires more access. |

Both create a Custom Trust Policy that ensures secure role assumption by Dropzone, using the provided External ID and User ARN.

The following integrations are available for Minimum ReadOnly access:

| Service Integration | Policy                                     | Required |
| ------------------- | ------------------------------------------ | -------- |
| CloudTrail          | `AWSCloudTrail_ReadOnlyAccess`†            | Required |
| EC2                 | `AmazonEC2ReadOnlyAccess`                  | Required |
| EKS                 | `eks:ListClusters`, `eks:DescribeCluster`‡ | Optional |
| GuardDuty           | `AmazonGuardDutyReadOnlyAccess`            | Optional |
| IAM                 | `IAMReadOnlyAccess`                        | Optional |
| Route53             | `AmazonRoute53ReadOnlyAccess`              | Optional |
| S3                  | `AmazonS3ReadOnlyAccess`                   | Optional |
| S3 (Outposts)       | `AmazonS3OutpostsReadOnlyAccess`           | Optional |
| Systems Manager     | `AmazonSSMReadOnlyAccess`                  | Optional |

{% hint style="info" %}
† CloudTrail Permissions:

* **Required (Minimum):** `AWSCloudTrail_ReadOnlyAccess` managed policy. This provides the minimum permissions needed for CloudTrail integration. The integration will use the `lookup_events` API for querying CloudTrail logs.
* **Optional (Recommended):** `cloudtrail:StartQuery` permission on event datastores. This enables CloudTrail Lake SQL queries, which provide more powerful querying capabilities. If this permission is not available, the integration will automatically fall back to the `lookup_events` API. To add this permission, attach a custom policy with:

  ```json
  {
    "Effect": "Allow",
    "Action": "cloudtrail:StartQuery",
    "Resource": "arn:aws:cloudtrail:*:*:eventdatastore/*"
  }
  ```

{% endhint %}

{% hint style="info" %}
‡ EKS Note: AWS does not provide a managed EKS policy. Create a custom policy with `eks:ListClusters`, `eks:DescribeCluster`, and other read-only EKS permissions (`eks:Describe*`, `eks:List*`) as needed.
{% endhint %}

## Find the Dropzone IAM Role Information

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the "Connection" section, record the `ARN` and `EXTERNAL ID` values, for use later in the AWS CloudFormation UI

<figure><img src="/files/VS7fvETTaeuuyJjHd8bB" alt="" width="296"><figcaption><p>The AWS Connection Information</p></figcaption></figure>

## Running the CloudFormation Template

You will need to repeat these instructions for each account you want to be visible to Dropzone.

* Log into your AWS account
* Go to the CloudFormation console, <https://console.aws.amazon.com/cloudformation/>
* Click on "Create Stack" > "With new resources (standard)"

<figure><img src="/files/ZNBVfHb3ehBhPzk7jj0a" alt=""><figcaption><p>Create Stack Button</p></figcaption></figure>

{% hint style="warning" %}
If this is your first stack, then the option will not have "With new resources"

<img src="/files/XdYtPZEUWQDwAg0v61gv" alt="Create Stack Button" data-size="original">
{% endhint %}

* In the "Prerequisite - Prepare template" section, select "Choose an exiting template"
* In the "Specify template" section, select "Amazon S3 URL"
* In the "Amazon S3 URL" field, input the link to the CFT you've chosen to use (e.g. ReadOnly) from the table at the top of this document

<figure><img src="/files/Vkr6gBzHnjP4IWUkmEmA" alt=""><figcaption><p>Template specification</p></figcaption></figure>

* Click "Next"
* Enter a "Stack name", e.g. "Dropzone-AI"

<figure><img src="/files/h2XGkoJRztbyv9Zt4fwY" alt=""><figcaption><p>Stack Name</p></figcaption></figure>

* In the Parameters section fill out the information you gathered from the Dropzone UI

<figure><img src="/files/8noXAX3toLD4mNi2tSNj" alt=""><figcaption><p>Stack Paramaters</p></figcaption></figure>

* Click "Next"
* On the "Configure stack options" page click "Next"
* On the "Review and create" page click "Submit"

<figure><img src="/files/x107LliDtoQ9Ykgl2ck9" alt=""><figcaption><p>Create the stack via the Submit button</p></figcaption></figure>

* Once the stack creation is complete, click Outputs
* Record the RoleARN value shown for use later in the Dropzone UI where it will referred to as "Role ARNs"

<figure><img src="/files/RdvHgsrtVXuLqgICpA6L" alt=""><figcaption><p>Output Role ARN</p></figcaption></figure>

* If you have additional AWS accounts, repeat the process for each of them

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in [the AWS documentation](/integrations/data/aws_data)


# Cross-Account Access via Console

{% hint style="info" %}
There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See [the AWS documentation](/integrations/data/aws_data) for more info.
{% endhint %}

The following steps walk you through creating a role and granting it to the Dropzone-provided role in the AWS console. This also has the information you'd need to create your own Infrastructure-as-Code configuration if you choose.

### Find the Dropzone IAM Role Information

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search AWS, then click "Configure"

<figure><img src="/files/c1LAMHwJP8ERrj4i4vBq" alt=""><figcaption><p>The AWS Tile</p></figcaption></figure>

* Under the "Connection" section, record the `ARN` and `EXTERNAL ID` values, for use later in the AWS CloudFormation UI

<figure><img src="/files/VS7fvETTaeuuyJjHd8bB" alt="" width="296"><figcaption><p>The AWS Connection Information</p></figcaption></figure>

### Create the Role

Next you'll create a role in the AWS account you want monitored and available.

You'll need the following information:

| Value                         | Used In                           | Source                                                                    |
| ----------------------------- | --------------------------------- | ------------------------------------------------------------------------- |
| Dropzone-provided ARN         | AWS Role Custom Trust Policy JSON | `ARN` value from the AWS Data Source "Connection" section                 |
| Dropzone-provided External ID | AWS Role Custom Trust Policy JSON | `External ID` value from the AWS Data Source "Connection" section         |
| AWS Account ID                | Custom Permissions Policy JSON    | Find this in the user/role dropdown in the upper right of the AWS console |

* Log in to the AWS Management Console for the account where you want to create the role
* Open the Identity Access and Management (IAM) dashboard

<figure><img src="/files/yfaZ0ANCaRbvtsE866me" alt=""><figcaption><p>IAM</p></figcaption></figure>

* From the left navigation, select "Access Management" > Roles
* Click "Create Role"

<figure><img src="/files/ET6xbbywEpOt7f6lxwg8" alt=""><figcaption><p>Create Role</p></figcaption></figure>

* Click "Custom Trust Policy"

<figure><img src="/files/yfRkpcM6e0WHzSEDxuRR" alt=""><figcaption><p>Custom Trust Policy Selection</p></figcaption></figure>

* In the text field below, paste the following policy, replacing the `<Dropzone-provided User ARN>` and `<Dropzone-provided External ID>` strings with the values from the Dropzone UI you recorded earlier:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "<Dropzone-provided User ARN>"
            },
            "Action": "sts:AssumeRole",
            "Condition": {
                "StringEquals": {
                    "sts:ExternalId": "<Dropzone-provided External ID>"
                }
            }
        }
    ]
}
```

* In the bottom right, click "Next"
* You'll now be on the "Add Permissions" page where you can add AWS pre-built policies

<figure><img src="/files/ZHmxDUdjfW6Erql2vRzD" alt=""><figcaption><p>Add Permissions page</p></figcaption></figure>

* You may add policies in one of two ways. You may add the `ReadOnlyAccess` policy, which will allow Dropzone to have all policies needed even in the future, or add the following policies one-by-one as needed:

| Service Integration | Policy                                     | Required |
| ------------------- | ------------------------------------------ | -------- |
| CloudTrail          | `AWSCloudTrail_ReadOnlyAccess`†            | Required |
| EC2                 | `AmazonEC2ReadOnlyAccess`                  | Required |
| EKS                 | `eks:ListClusters`, `eks:DescribeCluster`‡ | Optional |
| GuardDuty           | `AmazonGuardDutyReadOnlyAccess`            | Optional |
| IAM                 | `IAMReadOnlyAccess`                        | Optional |
| Route53             | `AmazonRoute53ReadOnlyAccess`              | Optional |
| S3                  | `AmazonS3ReadOnlyAccess`                   | Optional |
| S3 (Outposts)       | `AmazonS3OutpostsReadOnlyAccess`           | Optional |
| Systems Manager     | `AmazonSSMReadOnlyAccess`                  | Optional |

{% hint style="info" %}
CloudTrail Permissions: Required (Minimum): `AWSCloudTrail_ReadOnlyAccess` managed policy. This provides the minimum permissions needed for CloudTrail integration. The integration will use the `lookup_events` API for querying CloudTrail logs. Optional (Recommended): `cloudtrail:StartQuery` permission on event datastores. This enables CloudTrail Lake SQL queries, which provide more powerful querying capabilities. If this permission is not available, the integration will automatically fall back to the `lookup_events` API. To add this permission, attach a custom policy with:

```json
{
  "Effect": "Allow",
  "Action": "cloudtrail:StartQuery",
  "Resource": "arn:aws:cloudtrail:*:*:eventdatastore/*"
}
```

{% endhint %}

{% hint style="info" %}
EKS Note: AWS does not provide a managed EKS policy. Create a custom policy with `eks:ListClusters`, `eks:DescribeCluster`, and other read-only EKS permissions (`eks:Describe*`, `eks:List*`) as needed.
{% endhint %}

* You may add permissions in one of two ways. You may add the `ReadOnlyAccess` permission policy, which will allow Dropzone to have all permissions needed even in the future, or add the following policies one-by-one

| Permissions Policy               |
| -------------------------------- |
| `AWSCloudTrail_ReadOnlyAccess`   |
| `AmazonEC2ReadOnlyAccess`        |
| `AmazonGuardDutyReadOnlyAccess`  |
| `AmazonRoute53ReadOnlyAccess`    |
| `AmazonS3OutpostsReadOnlyAccess` |
| `AmazonS3ReadOnlyAccess`         |
| `AmazonSSMReadOnlyAccess`        |
| `IAMReadOnlyAccess`              |

* Click "Next" when done adding permissions
* Give the new role the name "Dropzone\_AI"

<figure><img src="/files/YFkjMJLExLpojbirPXJk" alt=""><figcaption><p>Role Name</p></figcaption></figure>

* In the bottom right, click "Create Role"

<figure><img src="/files/ET6xbbywEpOt7f6lxwg8" alt=""><figcaption><p>Create Role</p></figcaption></figure>

## Add a custom permission policy

* Navigate to "Identity and Access Management (IAM)" > "Access Management" > "Roles"
* Search for the new role and click on it

<figure><img src="/files/KniWYbKwhS4MevEZ67ng" alt=""><figcaption><p>Find the Role</p></figcaption></figure>

* In the middle of the page, you'll see "Permissions Policies"

<figure><img src="/files/nUO7GZM4BHJ0I5u2xbxv" alt=""><figcaption><p>Permissions Policies</p></figcaption></figure>

* Click "Add Permission"
* Select "Create Inline Policy"

<figure><img src="/files/v428C8z9WKh16GkiyTnt" alt=""><figcaption><p>Create Inline Policy Option</p></figcaption></figure>

* In the text field, paste the following policy, replacing the `<your_accountnumber>` strings with this AWS account ID:

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "CloudTrailStartQuery",
            "Effect": "Allow",
            "Action": [
                "kms:Decrypt",
                "kms:GenerateDataKey",
                "cloudtrail:StartQuery"
            ],
            "Resource": [
                "arn:aws:kms:*:<your_accountnumber>:key/*",
                "arn:aws:cloudtrail:*:<your_accountnumber>:eventdatastore/*"
            ]
        },
        {
		 "Sid": "EKSReadOnly",
		 "Effect": "Allow",
		 "Action": [
		     "eks:Describe*",
		     "eks:List*"
		 ],
		 "Resource": "*"
	  }

    ]
}
```

<figure><img src="/files/XvGi5l1VAwNO7J2Txgcx" alt=""><figcaption><p>Custom Permissions JSON</p></figcaption></figure>

* Click "Next"
* Give the new permission the name "Dropzone\_AI\_Additional"
* Click "Create Policy"

You should be returned to the `Dropzone_AI` role page and see the policies you've added, including the custom policy.

* Record the ARN for this role for use later in the Dropzone UI when configuring the Dropzone Data and Alert Sources, where it will be referred to as the "Role ARN"

<figure><img src="/files/qobQa6BPQcbqz1G5i1xL" alt=""><figcaption><p>AWS Role Page</p></figcaption></figure>

## Repeat For Additional AWS Accounts

Repeat the steps taken in the "Create the Role" section for all other AWS accounts you want visible to Dropzone.

{% hint style="info" %}
Make sure you're keeping a list of all the role ARNs you create along the way - you'll need them later.
{% endhint %}

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in [the AWS documentation](/integrations/data/aws_data)


# Cross-Account Access via Role Chaining

## Enable AWS Cross-Account Access via Role Chaining

Dropzone supports an advanced multi-account access pattern using role chaining. This allows Dropzone to access a large number of AWS accounts by authenticating with a single "Hub" role, which then assumes "Target" roles in your member accounts. This simplifies configuration by reducing the number of explicit credentials needed in Dropzone and enables flexible pattern-based access.

### Architecture

The role chaining pattern involves three main components:

* Dropzone Identity: The initial identity (AWS User/Role) that assumes the Hub Role
* Hub Role: A central role (e.g., in a Security or Management account) that trusts Dropzone and has permission to assume Target Roles
* Target Roles: Roles in your member/workload accounts that trust the Hub Role

<figure><img src="/files/q37YjmvjfNrG7lGEOwTX" alt=""><figcaption><p>The Role Chaining Pattern</p></figcaption></figure>

### Create the Hub Role

* See the [Cross-Account Access via Console](/integrations/data/aws_data/aws-console_data) page for instructions on how to create a role in AWS
  * You must create the Hub role (e.g. `DropzoneChainHub`) in your central account; this role acts as the gateway for Dropzone
* In the place of the "Trust Policy," input the following:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "<Dropzone-provided User ARN>"
            },
            "Action": "sts:AssumeRole",
            "Condition": {
                "StringEquals": {
                    "sts:ExternalId": "<Dropzone-provided External ID>"
                }
            }
        }
    ]
}
```

* Add the permissions policies listed in the [Cross-Account Access via Console](/integrations/data/aws_data/aws-console_data#add-a-custom-permission-policy) page
* Once you have created the role, add the following custom permission policy:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "sts:AssumeRole",
            "Resource": "arn:aws:iam::*:role/DropzoneChainTarget"
        }
    ]
}
```

{% hint style="info" %}
For the purposes of this documentation, the Target Account roles are named `DropzoneChainTarget` and the Hub Role is named `DropzoneChainHub`.

This policy allows the Hub role to assume the target roles in your member accounts. You can restrict the resource to specific role names or paths.
{% endhint %}

### Create the Target Roles

* See the [Cross-Account Access via Console](/integrations/data/aws_data/aws-console_data) page for instructions on how to create a role in AWS
  * You must create a role (e.g. `DropzoneChainTarget`) in each member account you want Dropzone to access
* In the place of the "Trust Policy," input the following:

```json
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "arn:aws:iam::<MY_HUB_ACCOUNT_ID>:role/DropzoneChainHub"
            },
            "Action": "sts:AssumeRole"
        }
    ]
}
```

{% hint style="info" %}
This policy allows the Hub Role to assume the target role. Be sure to replace `<MY_HUB_ACCOUNT_ID>` with the AWS Account ID where the Hub role resides.
{% endhint %}

* Add the permissions policies listed in the [Cross-Account Access via Console](/integrations/data/aws_data/aws-console_data#add-a-custom-permission-policy) page

## Enable the Dropzone Data Source

* Follow instructions in the [Amazon Web Services](/integrations/data/aws_data) overview page to enable the Data Source
* In the Hub Role ARN field, input the ARN of the Hub Role you configured earlier, e.g. `arn:aws:iam::936862572175:role/DropzoneChainHub`
* In the Role ARNs field, input the ARNs of the Target Roles you configured earlier, e.g. `arn:aws:iam::{account_id}:role/DropzoneChainTarget`

Once done, Dropzone will use the Hub role to discover and assume the Target role in any relevant AWS account during investigations.

If you have any errors engage your Dropzone AI support representative.


# ANY.RUN

{% hint style="info" %}
ANY.RUN is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

Dropzone interfaces with ANY.RUN to check the reputations of urls, domains or IP addresses that are involved in malicious activity such as spamming, hack attempts, and DDoS attacks.

## Create an API Key

ANY.RUN requires an API key to configure.

To obtain an API Key, do the following:

* Navigate to your [ANY.RUN](https://app.any.run/) account
* In the left sidebar, navigate to "Profile"

<figure><img src="/files/86Jd8bH653inhD0DC8Ki" alt=""><figcaption><p>Navigate to "Profile"</p></figcaption></figure>

* Navigate to "API and Limits"

<figure><img src="/files/Ehq2JvNezB5tl7PdxVXr" alt=""><figcaption><p>API and Limits tab</p></figcaption></figure>

* Copy the API Key shown for use later in the Dropzone UI where it is called "API Key"

<figure><img src="/files/0aiGH1OSlZfsMfpaybC2" alt=""><figcaption><p>Copy the API Key</p></figcaption></figure>

## Enable ANY.RUN

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ANY.RUN, then click "Configure"

<figure><img src="/files/rJztrjJWuKpLLbeJQ2LQ" alt=""><figcaption><p>The ANY.RUN Data Tile</p></figcaption></figure>

* Input the API key

<figure><img src="/files/pFMP4ojIrYKw186GUy7h" alt=""><figcaption><p>The ANY.RUN Data Source Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Blocklist.de

{% hint style="info" %}
Blocklist.de is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

The Dropzone AI platform supports [Blocklist.de](https://www.blocklist.de/en/rbldns.html), a third party service that can identify IPs that are involved in attacks via SSH, Mail-Login, FTP, Webserver, and other attacks.

## Enable Blocklist.de

The Blocklist.de integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search Blocklist.de IP, then click the kebab on the right

<figure><img src="/files/DWHyxMQel8U3EaGlqzKm" alt=""><figcaption><p>Select Blocklist.de IP</p></figcaption></figure>

* Click "Enable data source" to enable Blocklist.de

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# CAPA

{% hint style="info" %}
CAPA is a tooling integration. Tooling Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

Dropzone integrates with [CAPA](https://github.com/mandiant/capa) to analyze executable files (e.g. PE/ELF/.NET) to determine what capabilities they have, such as initiating http communications or installing software, to help identify if it is malicious or not.

## Enable CAPA

The CAPA Data Source integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Provided</p></figcaption></figure>

* In the Search bar, search Capa, then click the kebab on the right

<figure><img src="/files/OOrE8WfWrR8J0mMqEp2G" alt=""><figcaption><p>Select Capa</p></figcaption></figure>

* Click "Enable data source" to enable Capa

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Cato Networks

## Cato Networks

The Dropzone platform integrates with [Cato Networks](https://www.catonetworks.com/), a cloud-native Secure Access Service Edge (SASE) platform that provides capabilities such as SD-WAN, secure web gateway (SWG), firewall-as-a-service (FWaaS), zero trust network access (ZTNA), and cloud access security broker (CASB).

By integrating with Cato Networks, Dropzone AI can leverage network and VPN telemetry to enhance security investigations by analyzing network traffic associated with alerts, identifying devices behind IP addresses, and correlating user and VPN activity across the environment.

## Obtain Account ID and API Key

Cato Networks requires an Account ID and an API key to enable. You will need access to an account administrator with the Editor privilege to generate keys.

To locate your Account ID, do the following:

* Log in to your Cato Networks account
* In the URL, locate the four-digit integer and copy it for use later in the Dropzone UI where it is called "Account ID"

<figure><img src="/files/7xurzA63UKzv4qFuoulz" alt=""><figcaption><p>The Account ID</p></figcaption></figure>

To generate an API key, do the following:

* In the upper banner of your Cato Networks homepage, click "Administration"

<figure><img src="/files/lHRIw2C5VrvZoRrQKOEj" alt=""><figcaption><p>Navigate to "Administration"</p></figcaption></figure>

* In the right, click "API Management"

<figure><img src="/files/bNxijCshBbOhgoWOs0AK" alt=""><figcaption><p>Click "API Management"</p></figcaption></figure>

* Click "\* New"

<figure><img src="/files/39MqHGdOFF4mQAZN5OYr" alt=""><figcaption><p>Click New</p></figcaption></figure>

* Name the API key something memorable, such as Dropzone AI
* Under "API Permission," click "View"
* Under "Allow access from IPs," click "Any IP"
* If you wish, assign the API key an expiration date
* Click "Apply"

<figure><img src="/files/AUShMCOoJv19DOR5X8r9" alt=""><figcaption><p>Create New API Key</p></figcaption></figure>

* Copy the API key shown for use later in the Dropzone UI where it is called "API Key"

### Enable Cato Networks

To enable the Dara Source integration, you will need the following information:

| Dropzone Field | Source                                  |
| -------------- | --------------------------------------- |
| Account ID     | The Account ID value you copied earlier |
| API Key        | The API key value you copied earlier    |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Cato Networks, then click "Configure"

<figure><img src="/files/rRqL8CVcWuisJ6cKAMOE" alt=""><figcaption><p>The Cato Networks tile</p></figcaption></figure>

* Under the Data Source heading, input the Account ID and API Key
* Click "Test & Save" to finish

<figure><img src="/files/wc9EquCcF6qjpxJ7vSjx" alt=""><figcaption><p>The Cato Networks Data Configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Censys

{% hint style="info" %}
Censys is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

The Dropzone AI Platform integrates with Censys to get information about IP addresses such as services that are running without performing active scans.

## Create a Personal Access Token

Censys requires a Personal Access Token (PAT) to enable. For paid accounts, you will also need your Organization ID.

To obtain a Personal Access Token, do the following:

* Log into the [Censys Platform](https://platform.censys.io/home)
* Click on the icon in the upper right hand corner
* Navigate to "API Access"

<figure><img src="/files/DdpAsgP5meQQuCxubbNT" alt=""><figcaption><p>Navigate to API Access</p></figcaption></figure>

* Underneath Personal Access Tokens click "Create New Token"
* Provide a Token Name
* Copy the Personal Access Token immediately (you won't be able to see it again)
* For paid accounts: Your Organization ID can be found in your account settings

<figure><img src="/files/eND7ApX6oTxzb1YNwkFw" alt=""><figcaption><p>Copy Personal Access Token</p></figcaption></figure>

{% hint style="warning" %}
**Important**: The old API ID/Secret authentication method is deprecated. You must use a Personal Access Token. Free accounts only need the PAT (no Organization ID required). Paid accounts need both PAT and Organization ID for full API access.
{% endhint %}

## Enable Censys

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Available"

<figure><img src="/files/brI7n2Ux40Tk0jTwBCVh" alt=""><figcaption><p>Click Available</p></figcaption></figure>

* In the Search bar, search Censys, then click "Configure"

<figure><img src="/files/mVYJnEkMcOP5XL8W0weg" alt=""><figcaption><p>The Censys Data Tile</p></figcaption></figure>

* Input the Personal Access Token
* If you have a paid account, input the Organization ID
* Click "Test & Save" to finish

<figure><img src="/files/q8Piy0bMrJWPwEXEUwHj" alt=""><figcaption><p>The Censys Data Source Configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# CrowdStrike

{% hint style="success" %}
Note that this is separate from the "CrowdStrike Falcon Intelligence" Threat intelligence data source.
{% endhint %}

The Dropzone AI platform integrates with the CrowdStrike APIs. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Create API credentials in the CrowdStrike dashboard
* Install the credentials into your Dropzone tenant (Data Source and Alert Source)
* Select integration parameters, such as which alert types to sync

## Create an API Key

* As an Admin, go to your CrowdStrike dashboard, e.g. https\://*falcon.us-#*.crowdstrike.com/
* From the menu in the upper left, navigate to Support and Resources > API clients and keys

<figure><img src="/files/sYgCICJsGcFEZFanrpV9" alt="" width="375"><figcaption><p>Click API clients and keys</p></figcaption></figure>

* On the right, click "Create API Client"

<figure><img src="/files/9K9if4XaMkcMrfXPmJEf" alt=""><figcaption><p>Create API Client</p></figcaption></figure>

* On the "Create API Client" page, input "Dropzone AI" in the client name field. Under "Description," write "Dropzone AI Integration Key"

<figure><img src="/files/gLXKDfOdpiPyshDN5q55" alt=""><figcaption><p>Create API Client Screen</p></figcaption></figure>

* Enable the following scopes:

| Scope                         | Read | Write | Used By                        |
| ----------------------------- | ---- | ----- | ------------------------------ |
| Alerts                        | ✓    |       | Alert Source, Data Source      |
| API Integrations              | ✓    |       | Alert Source, Data Source      |
| Cases                         | ✓    | ✓     | Alert Source, Data Source      |
| Detections                    | ✓    |       | Alert Source, Data Source      |
| Hosts                         | ✓    | ✓     | Data Source, Remediator Source |
| NGSIEM                        | ✓    | ✓     | Data Source                    |
| Incidents                     | ✓    |       | Alert Source, Data Source      |
| Quarantined Files             | ✓    |       | Data Source                    |
| Real Time Response            | ✓    | ✓     | Data Source                    |
| Event Streams                 | ✓    |       | Data Source                    |
| Threatgraph                   | ✓    |       | Data Source                    |
| Identity Protection Entities  | ✓    |       | Data Source                    |
| Identity Protection Timeline  | ✓    |       | Data Source                    |
| Identity Protection GraphQL   |      | ✓     | Data Source                    |
| Sandbox (Falcon Intelligence) | ✓    | ✓     | Data Source                    |
| Indicators of Compromise      | ✓    | ✓     | Remediator Source              |

{% hint style="info" %}
Some of these scopes are only necessary for the Remediator integration. If you don't intend to perform this integration, you may ignore them.
{% endhint %}

* Write permission details
  * `Cases`: Write permissions are only required when used in Response Actions
  * `Hosts`: Write permissions are only required when used in Remediator Containment Actions
  * `NGSIEM`: Write permissions are required when NextGen SIEM is enabled in order to execute NGSIEM queries ([docs](https://www.falconpy.io/Service-Collections/NGSIEM.html#startsearchv1))
  * `Real Time Response`: Write permissions are required when File Retrieval is enabled ([docs](https://www.falconpy.io/Service-Collections/Real-Time-Response.html#rtr_executeactiverespondercommand))
    * Dropzone *only* uses Real Time Response to perform `get <file>` commands
  * `Identity Protection GraphQL`: Write permissions are required when Identity Protection is enabled in order to execute queries for user directory information ([docs](https://www.falconpy.io/Service-Collections/Identity-Protection.html#api_preempt_proxy_post_graphql))
  * `Sandbox (Falcon Intelligence`: Write permissions are only required when File Detonation is enabled in order to upload collected or attached files in the Falcon Sandbox
  * `Indicators of Compromise`: Write permissions are only required when used in Remediator Containment Actions
* When done, click "Create"
* Copy the Client ID and Secret for use later in the Dropzone UI where they are called "Client ID" and "Client Secret" respectively

<figure><img src="/files/Zx5mxxH4fgn6Z32n0Bhn" alt=""><figcaption><p>Copy your API Credentials</p></figcaption></figure>

## Enable Crowdstrike

The Data source integration allows Dropzone AI to interact with your CrowdStrike environment to gather information for use in investigation analysis and interactive chat.

You'll need the following information:

| Dropzone Field | Source                                   |
| -------------- | ---------------------------------------- |
| Client ID      | The "Client ID" value you copied earlier |
| Client Secret  | The "Secret" value you copied earlier    |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search CrowdStrike, then click "Configure"

<figure><img src="/files/Wv7ZdJQpOMEXUBCsDeE4" alt=""><figcaption><p>The Crowdstrike Tile</p></figcaption></figure>

{% hint style="success" %}
Make sure you're using the EDR CrowdStrike tile, not the "CrowdStrike Falcon Intelligence" Threat Intelligence tile.
{% endhint %}

* Under the Data Source header, input the Client ID and Client Secret. If you use a non-default URL for the CrowdStrike API, configure the API Base URL as well

<figure><img src="/files/OZzqhp6hCEywcCKctIzW" alt=""><figcaption><p>The CrowdStrike Data Source Configuration (pt 1)</p></figcaption></figure>

* Check the boxes to enable Crowdstrike's [Identity Protection](https://falconpy.io/Service-Collections/Identity-Protection.html), [Next-Gen SIEM](https://developer.crowdstrike.com/docs/ng-siem/), [Real Time Response](https://falconpy.io/Service-Collections/Real-Time-Response.html), and [Falcon Sandbox](https://falconpy.io/Service-Collections/Falconx-Sandbox.html) services
  * These services are optional, but enabling them enhances the quality of Dropzone investigations

{% hint style="info" %}
Enabling "file reputation lookup" for Falcon Sandbox will allow Dropzone to retrieve files in the Falcon Sandbox.

Enabling "file detonation" will allow Dropzone to upload collected or attached files in the Falcon Sandbox. Dropzone will wait the the "Max detonation wait time" for results from the detonation before proceeding with investigation.
{% endhint %}

<figure><img src="/files/tNT8ZI7q8XXewUQtMNcJ" alt=""><figcaption><p>The CrowdStrike Data Source Configuration (pt 2)</p></figcaption></figure>

* Only check `Special Member CID Handling` if your Dropzone AI representative indicates that your environment requires it

<figure><img src="/files/YXNC4XEMS3ZjR9wckSbP" alt=""><figcaption><p>The CrowdStrike Data Source Configuration (pt 3)</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Crowdstrike Falcon Intelligence

{% hint style="info" %}
Crowdstrike Falcon Intelligence is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.

Note that this is separate from the "CrowdStrike" Alert and Data Source.
{% endhint %}

The Dropzone platform supports Crowdstrike Falcon Intelligence to determine if entities such as domains, IPs, URLs, or files are malicious. Dropzone uses [Pangea](https://pangea.cloud) to get access to Crowdstrike Falcon Intelligence.

## Create an API Key

Crowdstrike Falcon Intelligence requires a Pangea API to enable.

To obtain an API Key, do the following:

* In the upper left corner of Pangea, click the menu icon

<figure><img src="/files/57GDt2QuwNctTAIiTVXm" alt=""><figcaption><p>Open the Menu</p></figcaption></figure>

* Navigate to "File Scan"

<figure><img src="/files/idll08PH4uf7Ti56uhpG" alt=""><figcaption><p>Navigate to "File Scan"</p></figcaption></figure>

* Copy the default token under "Configuration Details" for use later in the Dropzone UI where it is called "Pangea API Token"

<figure><img src="/files/AUueEojbwv7Dtmay5MH5" alt=""><figcaption><p>Copy API Token</p></figcaption></figure>

## Enable Crowdstrike Falcon Intelligence

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Crowdstrike Falcon Intelligence, then click "Configure"

<figure><img src="/files/ifhNfjaIvB0gprbquX6L" alt=""><figcaption><p>The CrowdStrike Falcon Intelligence Data Tile</p></figcaption></figure>

* Input the Pangea API Token
* Click "Test & Save" to finish

<figure><img src="/files/msBC66tMQZyE6zQsHBXG" alt=""><figcaption><p>The Crowdstrike Falcon Intelligence Data Source Configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Datadog

{% hint style="info" %}
Datadog is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Datadog](https://www.datadoghq.com/) security SIEM. Many customers ingest other alert sources into DataDog (e.g. IDPs) and integrate Dropzone into DataDog rather than the source systems.

## Create an API Key and Application Key

Datadog requires both an API Key and an Application Key to enable.

To obtain an API Key, do the following:

* In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
* Navigate to Organization Settings > API Keys

<figure><img src="/files/0UVoscMOXYNi13t4rJ9D" alt=""><figcaption><p>Navigate to API Keys</p></figcaption></figure>

* Click "New Key"

<figure><img src="/files/x4CaASHGv1jYYroCRBW0" alt=""><figcaption><p>Click "New Key"</p></figcaption></figure>

* Name your token something memorable, such as "dropzone.ai," then click "Create Key"

<figure><img src="/files/8MjtFMjYRKyFt6nAanj3" alt=""><figcaption><p>Create Key</p></figcaption></figure>

* Copy the key generated for use later in the Dropzone UI where it is called "API Key," then click "Finish"

<figure><img src="/files/sFaw2roj8koldmHRDPl9" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

To obtain an Application Key, do the following:

* In the bottom left hand corner of your Datadog Dashboard, click on your organization icon
* Navigate to Organization Settings > Application Keys

<figure><img src="/files/0UVoscMOXYNi13t4rJ9D" alt=""><figcaption><p>Navigate to Application Keys</p></figcaption></figure>

* Click "New Key"

<figure><img src="/files/x4CaASHGv1jYYroCRBW0" alt=""><figcaption><p>Click "New Key"</p></figcaption></figure>

* Name the key something memorable, such as "dropzone.ai," then click "Create Key"

<figure><img src="/files/8MjtFMjYRKyFt6nAanj3" alt=""><figcaption><p>Create Key</p></figcaption></figure>

* In the "Scope" section, select "Edit"

<figure><img src="/files/yBJPzyjiAenAnU4dCuJH" alt=""><figcaption><p>Edit Scopes</p></figcaption></figure>

* Assign the key the following scopes, then click "Save":
  * logs\_read\_data
  * security\_monitoring\_signals\_read

<figure><img src="/files/4uHaDV8wUzoi0fTmhqnF" alt=""><figcaption><p>Assign scopes</p></figcaption></figure>

* Copy the key generated for use later in the Dropzone UI where it is called "Application Key," then click "Finish"

<figure><img src="/files/7pJkEbj7NVPT736R8RwF" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

## Enable Datadog

To enable the Data Source integration, you will need the following information:

| Dropzone Field  | Source                                                                      |
| --------------- | --------------------------------------------------------------------------- |
| API Key         | The API key value you generated earlier                                     |
| Application Key | The Application key value you generated earlier                             |
| Datadog site    | The same as your url in Datadog, e.g. datadoghq.com, us3.datadoghq.com, etc |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Datadog, then click "Configure"

<figure><img src="/files/ZQ5t9PorhUsEVvyKlEYB" alt=""><figcaption><p>The Datadog Tile</p></figcaption></figure>

* Under the Data Source heading, input the API Key, Application Key, and your Datadog site
* If you wish to enable Datadog's [Flex Logs](https://docs.datadoghq.com/logs/log_configuration/flex_logs/), check the box labeled "Enabled" in the Flex Logs section

<figure><img src="/files/7ngr0v50LHtZSeSLzAcY" alt=""><figcaption><p>The Datadog Data Source Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# DNSResolver

{% hint style="info" %}
DNSResolver is a tooling integration. Tooling Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.D
{% endhint %}

Dropzone is capable of using DNS queries to convert hostnames to IP addresses. This is typically used to perform IP reputation checks on the resulting IP.

## Enable DNSResolver

The DNSResolver integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search DNSResolver, then click the kebab on the right

<figure><img src="/files/kozvGmw1OYYn5MnZzngG" alt=""><figcaption><p>Select DNSResolver</p></figcaption></figure>

* Click "Enable data source" to enable DNSResolver

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Dropzone Security Knowledge Base

{% hint style="info" %}
Dropzone Security Knowledge Base is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more integrations enhances Dropzone analysis.
{% endhint %}

Dropzone AI's internal Security Knowledge Base API is used to help evaluate process executions against benign baseline indicators, using its information on unknown hashes, anomalous paths, or unusual parent processes.

## Enable Dropzone Security Knowledge Base

The Dropzone Security Knowledge Base integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search Dropzone Security Knowledge Base, then click the kebab on the right

<figure><img src="/files/KpjyozcmtlB75t2s6G0S" alt=""><figcaption><p>Select Dropzone Security Knowledge Base</p></figcaption></figure>

* Click "Enable data source" to enable Dropzone Security Knowledge Base

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Dropzone URL Sandbox

{% hint style="info" %}
Dropzone URL Sandbox is a tooling integration and a Threat Intelligence (TI) integration. Tooling and TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more integrations enhances Dropzone analysis.
{% endhint %}

Dropzone AI's URL Sandbox connects to a web-scanning service powered by [Playwright](https://playwright.dev/) to visit websites for customers in order to do page scans, pdf analyses, etc. It has a provided built-in proxy layer to make it more reliable when accessing sites which is completely managed by Dropzone, so no setup is required by the customer.

To set up on-prem or self-managed deployments, contact your Dropzone support representative.

## Enable Dropzone URL Sandbox

The Dropzone URL Sandbox integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search Dropzone URL Sandbox, then click the kebab on the right

<figure><img src="/files/dVdbZgVzdhCPuNYeENqr" alt=""><figcaption><p>Select Dropzone URL Sandbox</p></figcaption></figure>

* Click "Enable data source" to enable Dropzone URL Sandbox

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

* To review or adjust how scans run, click on "Dropzone URL Sandbox" to open its configuration

## Configuration options

The Dropzone URL Sandbox has the following settings. The defaults preserve standard proxied scanning behavior, so no changes are required to get started.

| Feature                     | Default State | Details                                                                                                                                                                                                                                                                                                                                 |
| --------------------------- | ------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Render email screenshots    | On            | Allows the integration to renders the HTML body of phishing emails and capture a screenshot for investigations. The browser may then fetch embedded resources such as images and tracking pixels from external servers; these requests are routed through the proxy.                                                                    |
| Scan URLs in alerts         | On            | Allows the integration to navigate through URLs found in alerts. It may then retrieve page content, screenshots, and other forms of threat intelligence                                                                                                                                                                                 |
| Anonymous scanning only     | Off           | Ordinarily, scans fall back to a direct connection if the proxy is unavailable, which may expose your instance's IP to the destinations or email senders the AI investigates. If this feature is enabled, your scans will be halted if your information is at risk                                                                      |
| Use a custom outbound proxy | Off           | Route URL scans through your own proxy server instead of the Dropzone residential proxy. If you choose to enable this, you will need a proxy server address, e.g. `proxy.corp.example.com:8080`, username and password. Only HTTP Basic authentication is supported. Contact your Dropzone support representative for more information. |
| Use sticky sessions         | Off           | Request the same proxy exit node for consecutive scans. Useful for sites that track sessions. Only applies to the Dropzone residential proxy; ignored for custom outbound proxies.                                                                                                                                                      |
| Scan timeout (in seconds)   | 60 seconds    | Maximum time to wait for a URL to load during a scan.                                                                                                                                                                                                                                                                                   |

Adjust your settings as desired, then click "Test & Save" to finish.

<figure><img src="/files/yMoEgrK66gGi6ErEWOn2" alt=""><figcaption><p>The Dropzone URL Sandbox configuration</p></figcaption></figure>

### Notes on scanning behavior

* The integration ships with a built-in, fully-managed proxy (the "Dropzone residential proxy"). No customer setup is required to get proxied scanning — the custom outbound (bring-your-own) proxy is opt-in for customers who want egress through their own infrastructure.
* **Anonymous scanning only** is a fail-closed control: when on, anything that can't go through the proxy (URL scans and email-screenshot resource fetches) is skipped rather than connecting directly.
* **Render email screenshots** and **Scan URLs in alerts** are independent. You can disable outbound URL navigation while keeping email screenshots (and vice versa) without disabling the whole integration.
* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Elasticsearch

{% hint style="info" %}
Elasticsearch is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis.
{% endhint %}

The Dropzone platform integrates with the [Elasticsearch](https://www.elastic.co/elasticsearch) security SIEM. Many customers ingest other alert sources into Elasticsearch (e.g. IDPs) and integrate Dropzone into Elasticsearch rather than the source systems.

## Create an API Key and Obtain a Cloud ID

Elasticsearch requires an API Key and an Elasticsearch Cloud ID to enable.

{% hint style="info" %}
If you are using the Elasticsearch Serverless Projects-Based Model or an On-premise Elasticsearch using the Dropzone connector, you will not need to provide a Cloud ID.
{% endhint %}

To obtain an API Key, do the following:

* Navigate to your [Elastic Cloud home page](https://cloud.elastic.co/home) or deployment
* Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
* Click "Open"

<figure><img src="/files/PXmvCvibGBliQSYhnvdu" alt=""><figcaption><p>Click Manage</p></figcaption></figure>

* In the Deployment overview page, click "Management" in the bottom left corner
* Click the icon next to Stack Management
* Navigate to API keys

<figure><img src="/files/XDgF81JGmBJWq5K88PpB" alt=""><figcaption><p>Navigate to API keys</p></figcaption></figure>

* Click "Create an API key"

<figure><img src="/files/DkUP31l4baq6F1LHnyCl" alt=""><figcaption><p>Click "Create an API key"</p></figcaption></figure>

* Name the API key something memorable, such as Dropzone.AI
* Under type, select User API key
* Click "Create API Key"

<figure><img src="/files/shnCOTRV4rvtCqDjcAWT" alt=""><figcaption><p>Create an API key></p></figcaption></figure>

* Copy the API key generated for use later in the Dropzone UI, where it is called "API Key"

<figure><img src="/files/hwFibYrVZLnlbB9SXz4x" alt=""><figcaption><p>Copy the key</p></figcaption></figure>

To obtain your Elasticsearch Cloud ID, do the following:

* Navigate to your [Elastic Cloud home page](https://cloud.elastic.co/home)
* Under the Hosted Deployments section, locate the deployment you wish Dropzone.AI to be able to access
* Click "Open"

<figure><img src="/files/PXmvCvibGBliQSYhnvdu" alt=""><figcaption><p>Click Open</p></figcaption></figure>

* In the upper right of the Overview page, click "Endpoint & API Keys"

<figure><img src="/files/uu9irhBm3AFwQYsItBEn" alt=""><figcaption><p>Click Endpoint &#x26; API Keys</p></figcaption></figure>

* Check "Show Cloud ID"
* Copy the value shown for use later in the Dropzone UI, where it is called "Elasticsearch Cloud ID"

<figure><img src="/files/sA1j5TvX0alpjBcTF2hU" alt=""><figcaption><p>Copy the Elasticsearch Cloud ID</p></figcaption></figure>

## Enable Elasticsearch

To enable the Data Source integration, you will need the following information:

| Dropzone Field         | Source                                                                                              |
| ---------------------- | --------------------------------------------------------------------------------------------------- |
| Elasticsearch Cloud ID | The cloud ID value copied earlier. Only necessary if you have an Elastic Cloud Hosted deployment    |
| Elasticsearch Server   | The server for your Elasticsearch project, e.g. <https://my-project.es.us-west-2.aws.elastic.cloud> |
| API Token              | The API token value generated earlier                                                               |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Elasticsearch, then click "Configure"

<figure><img src="/files/H5iMmLXgqjwWRewbnduY" alt=""><figcaption><p>The Elasticsearch Tile</p></figcaption></figure>

* Under the Data Source heading, if your Elasticsearch integration is behind an [On-premise Dropzone Connector](https://docs.dropzone.ai/platform/settings/connector), select your connector from the dropdown
* If you have a Cloud deployment, check the box labeled "Connect with Elastic Cloud ID," then input the Elasticsearch Cloud ID and API Key

<figure><img src="/files/AJiq2VdcuLNcdhTrzYn5" alt=""><figcaption><p>The Elasticsearch Data Configuration (pt 1)</p></figcaption></figure>

* Otherwise, input the Elasticsearch Server, Port, and API Key

<figure><img src="/files/h7lcOHGYZ6OQyb4e1aAP" alt=""><figcaption><p>The Elasticsearch Data Configuration (pt 2)</p></figcaption></figure>

* If you want Dropzone to only use [remote clusters](https://www.elastic.co/docs/deploy-manage/remote-clusters) when making queries, check the box labeled "Search Remote Indices"
* Click "Test & Save" to finish

<figure><img src="/files/KZ0syh7eoVvYFbDBn8re" alt=""><figcaption><p>The Elasticsearch Data Configuration (pt 3)</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# ExtraHop

## ExtraHop

The Dropzone AI Platform integrates with [ExtraHop](https://www.extrahop.com/), a Network Detection and Response (NDR) platform that provides real-time, packet-level visibility across hybrid and multi-cloud environments.

### Integration Overview

To enable these integrations you will perform the following actions:

* Grant REST API Access
* Locate your RevealX 360 API Endpoint
* Generate RevealX 360 API Credentials
* Enable the Data source in your Dropzone AI tenant

### Grant REST API Access

To grant REST API Access, do the following:

* As a user with system and access administration privileges, log in to ExtraHop RevealX 360
* In the top right of the page, navigate to System Settings > All Administration
* Click "API Access"
* In the Manage API Access section, click "Enable"

### Locate your API Endpoint

In the API Access page of your RevealX360 account, locate your endpoint in the "API Endpoint" section. The hostname does not include the /oauth2/token.

Copy the value shown for use later in the Dropzone UI, where it is called "Hostname."

### Create API Credentials

To create API Credentials, do the following:

* As a user with system and access administration privileges, log in to ExtraHop RevealX 360
* In the top right of the page, navigate to System Settings > All Administration
* Click "API Access"
* Click "Create Credentials"
* Name the credentials something memorable, such as "Dropzone AI"
* Grant the credentials the following privilege levels:
  * Full [NDR Module Access](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges:~:text=access%20module%20features.-,NDR%20Module%20Access,-Allows%20the%20user)
  * Full [NPM Module Access](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges:~:text=and%20threat%20briefings.-,NPM,-Module%20Access)
  * [Full Read-Only](https://docs.extrahop.com/26.3/users-overview/#extrahop-user-account-privileges)

{% hint style="info" %}
Full NPM Module Access is only required if you wish to ingest [performance detections](https://docs.extrahop.com/26.3/detections-overview/#:~:text=to%20take%20action.-,Modules,-and%20detections) as an alert source.
{% endhint %}

* In the "Packet Access" section, do not enable packet retrieval
* Click "Save"
* Copy and save the ID and Secret values shown for use later in the Dropzone UI, where they are called "ID" and "Secret" respectively
* Click "Done"

## Enable ExtraHop

To enable the Data Source integration, you will need the following information:

| Dropzone Field | Source                                                                   |
| -------------- | ------------------------------------------------------------------------ |
| ID             | The ID value you copied earlier                                          |
| Secret         | The Secret value you copied earlier                                      |
| Hostname       | The hostname of your ExtraHop API, e.g. *example.api.cloud.extrahop.com* |

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ExtraHop, then click "Configure"

<figure><img src="/files/4hRZozdpBJlgnHajkuBJ" alt=""><figcaption><p>The ExtraHop tile</p></figcaption></figure>

* Under the Data Source header, input the ID, Secret, and Hostname

<figure><img src="/files/hxMjvTDtkg6qUSS8EAyC" alt=""><figcaption><p>The ExtraHop Data Source Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# File

{% hint style="info" %}
File is a tooling integration. Tooling Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

Dropzone AI platform integrates with File to determine the file type using the native [unix file command](https://en.wikipedia.org/wiki/File_\(command\)).

## Enable File

The File integration does not require any API keys or credentials.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Configured"

<figure><img src="/files/qEnV8iM22YBEJdUFh2ri" alt=""><figcaption><p>Click Configured</p></figcaption></figure>

* In the Search bar, search File, then click the kebab on the right

<figure><img src="/files/URBYcI3g8ZkTt1q339Hn" alt=""><figcaption><p>Select File</p></figcaption></figure>

* Click "Enable data source" to enable File

<figure><img src="/files/MZm5vAtLyodZawuuslWT" alt=""><figcaption><p>Enable data source</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Google GCP

{% hint style="success" %}
This is a combined document for enabling the Dropzone AI Data Source and Alert Source for GCP (Google Cloud Platform).
{% endhint %}

The Dropzone AI platform integrates with GCP (Google Cloud Platform) APIs for ingesting alerts and enriching investigations with data from GCP such as VM and service account information. This document describes how to set up API credentials and install them into the Dropzone platform.

## Integration Overview

To enable these integrations you will perform the following actions:

* Determine which section of your GCP environment to enable Dropzone visibility
* Grant IAM access to the Dropzone service account
* Enable the Alert and Data sources

## Determine Dropzone Visibilty Scope

Dropzone requires some IAM access to query your GCP environment.

You will later be granting the Dropzone service account access to a portion of your GCP environment, at either a folder level or for the whole organization.

For example, in the screenshot below, if you were to grant access via the `production` folder then Dropzone would have access to the `Project FreezeRay` project, and any other folders or projects you add to `production` in the future. However, it would not be available to `alligator-apples`. If you grant access via the top level org, `example.net` then it would apply to all folders and projects going forward.

<figure><img src="/files/SwuhoAMkeH6Zja3kYlNV" alt=""><figcaption><p>Resource Selection</p></figcaption></figure>

When enabling the integration you will be supplying the ID of the top level folder or organization, and Dropzone will recurse through all objects thereunder when making Data Source queries.

When you've chosen your folder or org, record the ID value for use later in the Dropzone UI where it is called "Parent Resource"."

## Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search GCP, then click "Configure"

<figure><img src="/files/uZXk0llyhxXWTW8n33O9" alt=""><figcaption><p>The GCP Tile</p></figcaption></figure>

* Record the "SERVICE ACCOUNT EMAIL" field for use in the GCP Console interface

<figure><img src="/files/VfKuvjIPFeZdcmf8pPAx" alt="" width="320"><figcaption><p>SERVICE ACCOUNT EMAIL</p></figcaption></figure>

## Grant GCP Access to Dropzone Service Account

* Go to the GCP cloud console at <https://console.cloud.google.com>

<figure><img src="/files/FWqwQeKiCrUfSf0ccFdl" alt=""><figcaption><p>Project Dropdown</p></figcaption></figure>

* Click the current project dropdown
* Click "All"
* Select the organization or the folder you've chosen for Dropzone visibility

<figure><img src="/files/SwuhoAMkeH6Zja3kYlNV" alt=""><figcaption><p>Resource Selection</p></figcaption></figure>

* From the left menu, navigate to IAM & Admin > IAM

<figure><img src="/files/1ccZLmrW4Ps825cHCDyM" alt=""><figcaption><p>IAM &#x26; Admin Menu</p></figcaption></figure>

* Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

<figure><img src="/files/0uECVydR5SIVpg2uGRxJ" alt=""><figcaption><p>Input the email address from the Dropzone UI Service Account Email</p></figcaption></figure>

* Click "Select a role"

<figure><img src="/files/ZpHdRdEqTkgHXOdzmkZv" alt=""><figcaption></figcaption></figure>

* Add the following roles:

| Role Name                                                                                                         | Purpose                                    | Used By                  |
| ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------ | ------------------------ |
| [Security Center Admin Viewer](https://cloud.google.com/iam/docs/understanding-roles#securitycenter.adminViewer)  | View GCP entity details and configurations | Alert Source Integration |
| [Browser](https://cloud.google.com/iam/docs/understanding-roles#browser)                                          | View GCP resources                         | Data Source Integration  |
| [Cloud Asset Viewer](https://cloud.google.com/iam/docs/understanding-roles#cloudasset.viewer)                     | View cloud assets                          | Data Source Integration  |
| [Compute Viewer](https://cloud.google.com/iam/docs/understanding-roles#compute.viewer)                            | View compute resources                     | Data Source Integration  |
| [Folder Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.folderViewer)               | View folders                               | Data Source Integration  |
| [Logs Viewer](https://cloud.google.com/iam/docs/understanding-roles#logging.viewer)                               | View GCP logs                              | Data Source Integration  |
| [Organization Role Viewer](https://cloud.google.com/iam/docs/understanding-roles#iam.roleViewer)\*                | View organization roles                    | Data Source Integration  |
| [Organization Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.organizationViewer)\* | View organization resources                | Data Source Integration  |
| [Private Logs Viewer](https://cloud.google.com/iam/docs/understanding-roles#logging.privateLogViewer)             | View private logs                          | Data Source Integration  |
| [Security Reviewer](https://cloud.google.com/iam/docs/understanding-roles#iam.securityReviewer)                   | Review security configurations             | Data Source Integration  |
| [Storage Object Viewer](https://cloud.google.com/iam/docs/understanding-roles#storage.objectViewer)               | View storage objects                       | Data Source Integration  |
| [Tag Viewer](https://cloud.google.com/iam/docs/understanding-roles#resourcemanager.tagViewer)                     | View tags                                  | Data Source Integration  |

\* These roles should only be included if the top-level parent is an organization.

{% hint style="info" %}
Some of these roles are only necessary for the Alert Source integration. If you don't intend to perform that integration, you may ignore them.
{% endhint %}

* Continue adding roles via the "Add another role" button until complete

<figure><img src="/files/Xjb4bdpmU1hVHIEvtW0s" alt=""><figcaption><p>Add another role</p></figcaption></figure>

* Click "Save"

## Enable GCP

The Data source integration allows Dropzone AI to interact with your GCP environment to gather information for use in investigation analysis and interactive chat.

You'll need the following information:

| Dropzone Field  | Source                                                        |
| --------------- | ------------------------------------------------------------- |
| Parent Resource | The ID of the org or folder where you granted Dropzone access |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search GCP, then click "Configure"

<figure><img src="/files/uZXk0llyhxXWTW8n33O9" alt=""><figcaption><p>The GCP Tile</p></figcaption></figure>

* Under the Data Source heading, input the "Parent Resource" ID
* Select the "Parent Resource Type" that matches the resource you've selected
* Select the "Default Zone." This is used for queries (such as finding VMs) when a zone is not specified

<figure><img src="/files/gAAbQkG9uZDCPjIHBCgz" alt=""><figcaption><p>The GCP Data Source configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Google Safe Browsing

{% hint style="info" %}
Google Safe Browsing is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
{% endhint %}

The Dropzone platform integrates with [Google Safe Browsing](https://developers.google.com/safe-browsing) to perform real-time checks on URLS and determine if there are any threats associated with them.

## Integrations Overview

To enable these integrations you will perform the following actions:

* Grant IAM access to your principal
* Create an API Key with the necessary permissions
* Enable the Data sources within your Dropzone tenant

## IAM access

To use Google Safe Browsing, you must have a Google Developer Console project. If you do not already have a project, see the [Google Cloud Platform documentation](https://docs.cloud.google.com/resource-manager/docs/creating-managing-projects?hl=en\&visit_id=639214647150194288-1565135454\&rd=1) for more information. You must also have the IAM access permissions to create and manage API keys within the project.

If you do not already have those permissions, see the (Google Cloud Platform documentation)\[<https://docs.cloud.google.com/iam/docs/granting-changing-revoking-access>] for instructions on how to grant IAM access roles, or have an administrator perform the following steps:

* Go to the GCP cloud console at <https://console.cloud.google.com>

<figure><img src="/files/FWqwQeKiCrUfSf0ccFdl" alt=""><figcaption><p>Project Dropdown</p></figcaption></figure>

* Click the current project dropdown
* Click "All"
* Select the organization or folder you want Dropzone to access

<figure><img src="/files/SwuhoAMkeH6Zja3kYlNV" alt=""><figcaption><p>Resource Selection</p></figcaption></figure>

* From the left menu, navigate to IAM & Admin > IAM

<figure><img src="/files/1ccZLmrW4Ps825cHCDyM" alt=""><figcaption><p>IAM &#x26; Admin Menu</p></figcaption></figure>

* Under "View by principals," find the principal (e.g. your account) you want to be able to create an API key
* Click the Edit icon

<figure><img src="/files/5owdZC4uUmanl1tl9Eer" alt=""><figcaption></figcaption></figure>

* Click "Add another role"
* Add the following roles:

| Role Name                                                                                                                     | Purpose                                                                                        |
| ----------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| [API Keys Admin](https://docs.cloud.google.com/iam/docs/roles-permissions/serviceusage#serviceusage.apiKeysAdmin)             | Allows the principal to create and manage API keys for a project                               |
| [Service Usage Viewer](https://docs.cloud.google.com/iam/docs/roles-permissions/serviceusage#serviceusage.serviceUsageViewer) | Allows the principal to restrict an API key to specific APIs by using the Google Cloud console |

<figure><img src="/files/PNwpZTnOlUnLtQYn7FDN" alt=""><figcaption><p>Add the requisite roles</p></figcaption></figure>

* Click "Save"

## Create an API Key

Google Safe Browsing requires an API key to enable.

To obtain an API Key, do the following:

* In the left sidebar of your [Google Cloud console](https://console.cloud.google.com), navigate to APIs & Services > Credentials

<figure><img src="/files/QU4E0GrUL5Nfqp9ZfrI5" alt=""><figcaption><p>The GCP sidebar</p></figcaption></figure>

* Click "Create Credentials," then select "API Key"

<figure><img src="/files/niLPiitJ2DHfqD8rP6QA" alt=""><figcaption></figcaption></figure>

* Name the key something memorable, such as "Dropzone AI"
* In the "Select API restrictions" dropdown, select "Safe Browsing API"

{% hint style="info" %}
If Safe Browsing is not available to select, this API may not be enabled in the Google Cloud project that you chose. To enable it, go to the [Safe Browsing](https://console.cloud.google.com/apis/library/safebrowsing.googleapis.com) page in the API Library of your Cloud Console. Click "Enable," then try again.
{% endhint %}

<figure><img src="/files/UlZzxbxuOD0N3zUCG1iQ" alt=""><figcaption></figcaption></figure>

* Click "Create"
* Record the key value shown for use later in the Dropzone UI where it is called "API key"

## Enable Google Safe Browsing

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search ipinfo.io, then click "Configure"

<figure><img src="/files/Z6fjL28MU3Lc08mo0O28" alt=""><figcaption><p>The Google Safe Browsing Tile</p></figcaption></figure>

* Input the API key
* Click "Test & Save" to finish

<figure><img src="/files/dRuzIsJrX6ouga0U9gWd" alt=""><figcaption><p>The Google Safe Browsing configuration</p></figcaption></figure>

If you have any errors engage your Dropzone AI support representative.


# Google Security Operations

{% hint style="info" %}
Google Security Operations is an SIEM integration. SIEM integrations are used to perform analysis of any SIEM generated alerts, and/or to use generated data as part of investigation analysis. They are optional, but enabling more integrations enhances Dropzone analysis.
{% endhint %}

Dropzone integrates with [Google Security Operations](https://cloud.google.com/security/products/security-operations) to investigate different security alerts across many of Google's security products.

## Integration Overview

To enable these integrations you will perform the following actions:

* Identify your service account address
* Grant IAM access to the Dropzone service account
* Obtain your Google Account Details
* Complete Google Cloud Mapping
* Enable the Alert and Data sources

Alternatively, Dropzone also supports [Service Account Impersonation](https://docs.cloud.google.com/iam/docs/service-account-impersonation) as a method of authentication. This allows an already-authenticated principal to temporarily act as a target service account and use its permissions, often by requesting short-lived credentials instead of downloading long-lived keys. See Google Cloud's [documentation](https://docs.cloud.google.com/docs/authentication/use-service-account-impersonation) for further information.

{% hint style="info" %}
If you choose to use Service Account Impersonation, be sure to grant (or ask your administrator to grant) the principal you're using the [Service Account Token Creator](https://docs.cloud.google.com/iam/docs/roles-permissions/iam#iam.serviceAccountTokenCreator) role.
{% endhint %}

## Identify your service account email address

To obtain the email address of your Dropzone service account, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Security Operations, then click "Configure"

<figure><img src="/files/7KI64qtojWxIco9PVALt" alt=""><figcaption><p>The Google SecOps Tile</p></figcaption></figure>

* Copy the "SERVICE ACCOUNT EMAIL" field for use in the Google Console interface

<figure><img src="/files/zoqV89980XI4lPCjAj8a" alt="" width="320"><figcaption><p>Copy the service account email</p></figcaption></figure>

## Grant IAM Access to Dropzone AI

* Navigate to the Google Console page of the project your SecOps instance is in
* In the upper left hand corner, open the navigation menu

<figure><img src="/files/MZxgKryMsfjPIGg0PrmC" alt=""><figcaption><p>Open the navigation menu</p></figcaption></figure>

* Navigate to IAM & Admin > IAM

<figure><img src="/files/yuJsgHqdiasRnCFoCv7i" alt=""><figcaption><p>Navigate to IAM</p></figcaption></figure>

* Under "View by principals," click "Grant Access"

{% hint style="info" %}
To be able to complete this step, you will need the `resourcemanager.projects.setIamPolicy` permission.
{% endhint %}

<figure><img src="/files/7nUYn0CIHkWERBDtlwEx" alt=""><figcaption><p>Click "Grant Access"</p></figcaption></figure>

* Under "New principals," input the email address you copied earlier from the Dropzone UI "SERVICE ACCOUNT EMAIL"

<figure><img src="/files/JlwJAp89wkRDp0lTR5Px" alt=""><figcaption><p>Input the email address from the Dropzone UI Service Account Email</p></figcaption></figure>

* Click "Select a role"

<figure><img src="/files/Dm12Cp9FGA3Wzs3J2cxi" alt=""><figcaption><p>Click "Select a role"</p></figcaption></figure>

* Search the "[Chronicle API Viewer](https://docs.cloud.google.com/iam/docs/roles-permissions/chronicle#chronicle.viewer)" role, then click it

{% hint style="info" %}
If you want Dropzone to be able to edit Cases/Alerts after investigation (e.g. by changing stages, modifying priority, or adding comments) select the Chronicle API Editor role.
{% endhint %}

<figure><img src="/files/mrdamGFcavSuQNlU2BeV" alt=""><figcaption><p>Assign the Chronicle API Viewer role</p></figcaption></figure>

* Click "Save"

<figure><img src="/files/dU5laYUIPdTCDfv7cQAS" alt=""><figcaption><p>Click "Save"</p></figcaption></figure>

## Obtain Account Details

To obtain your Instance Name, do the following:

* Return to the Google Console page of the project your SecOps instance is in
* In the upper left hand corner, open the navigation menu

<figure><img src="/files/MZxgKryMsfjPIGg0PrmC" alt=""><figcaption><p>Open the navigation menu</p></figcaption></figure>

* Navigate to Security > Detection and Controls > Google SecOps

<figure><img src="/files/EmPtS8BzJwrtWZnJJt2S" alt=""><figcaption><p>Navigate to Google SecOps</p></figcaption></figure>

* In the Google SecOps page, click the carrot next to "Instance Details"

<figure><img src="/files/C38x9OwvTLi4WagL0qGS" alt=""><figcaption><p>Reveal the Instance Details</p></figcaption></figure>

* Copy the Customer ID shown for use later in the Dropzone UI where it is called "Instance Name"

<figure><img src="/files/2LazT7IOChRmSPYeKTta" alt=""><figcaption><p>Copy the Instance Name</p></figcaption></figure>

To obtain your Project ID, do the following:

* In the upper left, click on the project icon

<figure><img src="/files/dXEF8882EAY40hffTpC9" alt=""><figcaption><p>Click the project icon</p></figcaption></figure>

* Using the search bar, locate the project your SecOps instance is in
* Under "ID," copy the ID value shown for use later in the Dropzone UI where it is called "Project ID"

<figure><img src="/files/GUYyeX9rnIkWFapXg0jG" alt=""><figcaption><p>Copy the Project ID</p></figcaption></figure>

## Cloud Identity Mapping

If you want Dropzone to be able to have SOAR access, (e.g. managing [cases](https://cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview)), you must map the service account to your platform's access control parameters. This will provide the service account with access to SOC Roles and Environments required to perform automated tasks or API operations.

To do Cloud Identity mapping, do the following:

* As an admin, log into your Google SecOps instance
* In the left sidebar, navigate to Settings > SOAR Settings
* Navigate to Advanced > Group Mapping
* Click "+ Add"
* In the IDP/User group field, enter the full service account email address or the workload identity principle string
* Assign the service account the appropriate [SOC role and Environments](https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/control-access-to-platform)

{% hint style="success" %}
Dropzone needs read access to all security event data and case/alert content in your tenant, plus the ability to comment on, tag, and change the status of cases and alerts it has been given for investigation.
{% endhint %}

* Click "Save"

## Enable Google SecOps

To enable the Data Source integration, you will need the following information:

| Dropzone Field | Source                                     |
| -------------- | ------------------------------------------ |
| Instance Name  | The "Customer ID" value you copied earlier |
| Project ID     | The "Project ID" value you copied earlier  |

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Security Operations, then click "Configure"

<figure><img src="/files/7KI64qtojWxIco9PVALt" alt=""><figcaption><p>The Google SecOps Tile</p></figcaption></figure>

* Under the Data Source heading, input the Instance Name and Project ID
* If you are using Service Account Impersonation, input the Customer-Owned Service Account value
* Input the maximum number of times you want Dropzone to attempt a [UDM](https://docs.cloud.google.com/chronicle/docs/investigation/udm-search) query if an error occurs

<figure><img src="/files/eh0vhxO9Wn2cL1aMXDzw" alt=""><figcaption><p>The Google SecOps Data Source Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.


# Google Workspace

## Google Workspace

The Dropzone AI platform integrates with Google Workspace APIs for ingesting alerts such as phishing reports and enriching investigations with data from Google Workspace such as directory information. This document describes how to set up API credentials and install them into the Dropzone platform.

### Integration Overview

To enable these integrations you will perform the following actions:

* Enable domain-wide delegation in Google Workspace
* Create a Google Workspace admin role
* Select integration parameters, such as which alert types to sync

The Dropzone platform has a dedicated service account for your organization. This service account uses [domain-wide delegation](https://support.google.com/a/answer/162106) to gain access to specific API scopes within your organization.

### Enable Domain-Wide Delegation

To grant access to the Google service account used by your Dropzone platform, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Workspace, then click "Configure"

<figure><img src="/files/JwSD8JPmLvapxLHofHAp" alt=""><figcaption><p>The Google Workspace Tile</p></figcaption></figure>

* Record the "CLIENT ID" field which will be used in the Google Admin interface

<figure><img src="/files/SIp1nVLvHLZ4oky9W14h" alt=""><figcaption><p>Copy the CLIENT ID</p></figcaption></figure>

Next, enable the Dropzone AI application domain-wide delegation access to your Google Workspace environment.

As a full Google Workspace admin, do the following:

* Navigate to your [admin workspace](https://admin.google.com)
* In the sidebar, navigate to Security > Access and Data Control > API Controls
* At the bottom, click [Manage Domain Wide Delegation](https://admin.google.com/ac/owl/domainwidedelegation)
* Click "Add New" API Client
* Enter the Client ID in the pop up
  * This is the \~21 digit number you recorded from the Dropzone UI earlier
* Grant access to the following scopes by copy/pasting them into the "OAuth Scopes" line one-by-one
  * <https://www.googleapis.com/auth/apps.alerts>
  * <https://www.googleapis.com/auth/gmail.readonly>
  * <https://www.googleapis.com/auth/drive.readonly>
    * Required when enabling the optional Google Drive Query feature
  * <https://www.googleapis.com/auth/admin.directory.user.readonly>
  * <https://www.googleapis.com/auth/admin.reports.audit.readonly>
  * <https://www.googleapis.com/auth/admin.reports.usage.readonly>
  * <https://www.googleapis.com/auth/admin.directory.group.readonly>
  * <https://www.googleapis.com/auth/admin.directory.user.security>
    * Required for Revoke User Sessions containment action
  * <https://www.googleapis.com/auth/admin.directory.user>
    * Required for Suspend User containment action (supersedes above readonly scope)
* Click "Authorize" to finish

### Choose or Create a Google Workspace Admin Account

Dropzone uses the Google Workspace Admin API to find information from your environment using a user within your org that has an Admin Role with necessary privileges.

{% hint style="info" %}
The user you select could be a real human or a dedicated integration user. We suggest the latter to assure that personnel changes do not affect your integration. The integration user does not need a Google Workspace license, so it may be a free ["Cloud Identity"](https://support.google.com/cloudidentity/answer/7319251) user.
{% endhint %}

Note that Dropzone may request more permissions in the future as we add features.

{% hint style="info" %}
Regardless of which privileges you enable for your admin role, the Dropzone platform is restricted to the scopes that you granted in the "Set Up Domain Wide Delegation" section above.
{% endhint %}

To create and associate the new role, do the following:

* Go to [Account > Admin Roles](https://admin.google.com/ac/roles) > Create New Role

<figure><img src="/files/TXBClptQiWF7r9T3qNK1" alt="" width="375"><figcaption><p>Create new Google Workspace Role</p></figcaption></figure>

* Name the role something memorable, such as "Dropzone AI Role." Input a description, such as "Dropzone AI integrations," then click "Continue"

<figure><img src="/files/niGuJNJYRCv5JipjSiuY" alt="" width="177"><figcaption><p>Name the new Role</p></figcaption></figure>

* You'll now be on the "Select Privileges" page
* On this page enable the following:
  * Admin console privileges
    * Organizational Units > Read
    * Users > Read
    * Google Vault > Manage Audits
    * Gmail > Email log search
    * Gmail > Access Admin Quarantine
    * Gmail > Access Restricted Quarantines
    * Security Center > "This user has full ..." > Audit and Investigation > View
    * Security Center > "This user has full ..." > Audit and Investigation > View sensitive content
    * Security Center > Activity Rules > View
    * Security Center > Activity Rules > Manage
    * Alert Center > Full access
    * DLP > View DLP rule
    * DLP > Manage DLP rule
    * Reports
  * Admin API privileges
    * Organizational Units > Read
    * Users > Read
    * Groups > Read
    * Reports

<figure><img src="/files/MWj3OJbqEzb4IMFyMJJN" alt="" width="196"><figcaption><p>Enable permissions</p></figcaption></figure>

* Once done, click "Continue"

{% hint style="warning" %}
There are two sections of this user interface, the "Admin Console Privileges" at top and "Admin API Privileges" further down the page; make sure you configure all the permissions from both sections.
{% endhint %}

* Assign the new role to a Google Workspace user:
  * Go to <https://admin.google.com>
  * In the sidebar, navigate to [Account > Admin Roles](https://admin.google.com/ac/roles)
  * Hover over the role you created and click "Assign Admin"

<figure><img src="/files/P6OUUzABsb83b1PFSZaS" alt="" width="375"><figcaption><p>Assign admin option</p></figcaption></figure>

* Click "Assign Members" to add the role to the user you want for the Dropzone integration
  * Pick an existing admin or an account you created specifically for the Dropzone integration

<figure><img src="/files/gJSotF6kIRdG3sXpISpa" alt="" width="250"><figcaption><p>Assign an admin to the role</p></figcaption></figure>

### Enable Google Workspace

The Data source integration allows Dropzone AI to interact with Google Workspace to gather information for use in investigation analysis and interactive chat.

To enable the Data source integration, you'll need the following information:

| Dropzone Field | Source                                                     |
| -------------- | ---------------------------------------------------------- |
| Admin Email    | The email address of the admin in the new Dropzone AI role |
| Customer ID    | Your Google Workspace customer id                          |

The Customer ID can be found can be found at admin.google.com > Account > Account Settings (<https://admin.google.com/ac/accountsettings>) or in the output of `gam info domain`. It's typically a \~9 character string starting with `C`.

To enable the Data Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, navigate to Settings > Integrations

<figure><img src="/files/zN02u3HObDaemUY8E1kD" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="/files/QySQeLXXUC5SLjaXyamH" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Google Workspace, then click "Configure"

<figure><img src="/files/JwSD8JPmLvapxLHofHAp" alt=""><figcaption><p>The Google Workspace Tile</p></figcaption></figure>

* Under the Data Source heading, input the "Admin Email" and "Customer ID"
  * Click "Google Drive Query Enabled" to provide Drive investigation support

<figure><img src="/files/RV5YOc2SM3Y9GalTVsrc" alt=""><figcaption><p>The Google Workspace Data Configuration</p></figcaption></figure>

* Click "Test & Save" to finish

If you have any errors engage your Dropzone AI support representative.

## Enable the Remediator Integration

The Remediator integration allows Dropzone to initiate Containment Actions during investigations. See the [GCP Remediator](/integrations/remediator/google-workspace_remediator) documentation for more information.




---

[Next Page](/llms-full.txt/1)

