Skip to main content

Set up the Cybereason connector

Updated over 9 months ago

Cybereason is an endpoint protection solution against attacks (EDR).

This connector allows the following information to be collected, by perimeter:

  • The number of clients, up to date with content, active.

  • The agents with an up-to-date version.

  • The number of detections and infected machines.

It also synchronizes Cybereason malops as gaps in Tenacy.

💡 During synchronization, the Cybereason and Tenacy statuses are compared to reopen gaps that are still detected by Cybereason and close those that are no longer detected.

Add and set up the connector

To add this connector, go to Catalog > Connectors > Cybereason > Add a connector

After adding it, you need to set up:

  • Operator perimeter: the perimeter that operates and dictates the rules to which the indicators and the default gaps registry will be attached.

  • Frequency: Automatic query frequency to Cybereason and periodicity of associated indicators. This periodicity can be daily, weekly, monthly, semi-annual, or annual.

Once the connector is created, the setiing up continues:

  • URL: Corresponds to the connection URL.

  • Username and password to be provided for access.

  • Gaps register: Security issues identified by Cybereason can be raised as gaps in Tenacy if a gaps register is selected from the list provided. A dedicated register is proposed in the list, but you can also create your own register by entering its name in the input field. If the register doesn't exist yet, Tenacy will create it when saving the configuration.

  • Maximum number of gaps: Only if you want to limit the creation of gaps to a certain number, this value cannot exceed 100. If the field is left empty, Tenacy will synchronize all the malops identified by Cybereason as gaps.

  • Groups in the perimeters: You can send your metrics and indicators according to the groups you have already defined in Cybereason. You can add as many TENACY perimeters as you want and add the Cyberwatch Group IDs next to them. If you want to associate multiple Cyberwatch groups with a TENACY perimeter, simply separate them with a comma.

Run your first test

Once the connector is properly configured, test the integration by running an initial execution.

Go to ⚙️ > Connectors > Click on the Cybereason connector > Run now:

💡 Feel free to contact Tenacy support if you have any questions regarding this.

Did this answer your question?