OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ
ArcSight Incidents logo

ArcSight Incidents

自動配備
コミュニティの提供による
Detection & Response Enablement

概要

Import ArcSight ESM cases (Case-Incidents) and their events (Incidents) into OpenCTI (bidirectional import side).

The OpenCTI ArcSight Incidents connector imports cases and their security events from ArcSight ESM into OpenCTI. It periodically fetches cases through the ESM Service Layer REST API (CaseService), resolves the referenced security events (SecurityEventService), converts each event (a detection) to a STIX 2.1 Incident, and converts the case (a case-management artifact) to a STIX 2.1 Case-Incident that references those Incidents through its object_refs. Paired with the ArcSight stream connector (which pushes IOCs to ESM Active Lists), it provides a bidirectional integration.

基本情報

ArcSight Incidents
ベンダー連絡先
コネクター
7.260706.0
7.260706.0
0

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。