This article is for teams who want to connect their Cybereason solution to Tenacy to automate the collection of security indicators and the synchronization of gaps, without manual re-entry.
Cybereason is an endpoint protection solution against attacks (EDR).
This connector allows the following information to be collected, by perimeter:
The number of clients, up to date with content, active.
The agents with an up-to-date version.
The number of detections and infected machines.
It also synchronizes Cybereason malops (compromise alerts detected by the EDR) as gaps in Tenacy (security flaws recorded in a Tenacy register).
💡 During synchronization, the Cybereason and Tenacy statuses are compared to reopen gaps that are still detected by Cybereason and close those that are no longer detected.
Add and set up the connector
To add this connector, go to Catalog > Connectors > Cybereason > Add a connector
After adding it, you need to set up:
Operator perimeter: the perimeter (your organization's entity, for example a legal entity or a site) that operates and dictates the rules, to which the indicators and the default gaps register will be attached.
Frequency: automatic query frequency to Cybereason and periodicity of associated indicators. This periodicity can be daily, weekly, monthly, semi-annual, or annual.
Once the connector is created, the setiing up continues:
URL: corresponds to the connection URL.
Username and password to be provided for access.
Gaps register: security issues identified by Cybereason can be raised as gaps in Tenacy, if a gaps register is selected.
Existing register: select it from the list provided (a dedicated register already appears there).
New register: enter its name in the input field; if it doesn't exist yet, Tenacy will create it automatically when the configuration is saved.
Maximum number of gaps: optional limit on gap creation, capped at 100.
If the field is filled in: Tenacy stops at this number of created gaps.
If the field is left empty: Tenacy synchronizes all the malops identified by Cybereason as gaps.
Groups in the perimeters: you can send your metrics and indicators according to the groups you have already defined in Cybereason.
Add as many Tenacy perimeters as you want and associate the corresponding Cybereason group ID next to them.
If you want to associate multiple Cybereason groups with the same Tenacy perimeter: separate their IDs with a comma.
Run your first test
Once the connector is properly configured, test the integration by running an initial execution.
Go to ⚙️ > Connectors > Click on the Cybereason connector > Run now:
💡 Feel free to contact Tenacy support if you have any questions regarding this.
Expected result
Once the test has run successfully, the connector automatically queries Cybereason according to the chosen periodicity. Associated indicators start updating, and malops progressively come through as gaps in the configured register.
Frequently asked questions
What happens if I don't specify a gaps register?
Malops detected by Cybereason are then not synchronized as gaps in Tenacy. Only the indicators continue to be fed.
Can I limit the number of gaps created automatically?
Yes, by setting a maximum number of gaps (up to 100). If you leave the field empty, Tenacy synchronizes all the malops identified by Cybereason.
What happens when a malop is no longer detected by Cybereason?
At the next synchronization, Tenacy compares the statuses and automatically closes the corresponding gap if the malop is no longer detected on the Cybereason side.
How can I associate multiple Cybereason groups with the same Tenacy perimeter?
Simply separate their group IDs with a comma in the corresponding field.




