Skip to main content

Overview

The Dark Web ID integration enables ThreatAware to collect data from Dark Web ID, providing visibility into your security posture and cyber asset management.
Connection Method: API Setup Time: 15-30 minutes Access Required: Administrator account with API permissions

Use cases

Device & Asset Tracking

Monitor devices and assets managed by Dark Web ID

Security Compliance

Track security posture and compliance status

User & Access Management

Identify users, roles, and access patterns

Threat Detection

Detect threats and vulnerabilities in real-time

Setup instructions

1

Log In to ThreatAware

  • Access your ThreatAware dashboard.
  • Navigate to Settings > Systems.
2

Search for Dark Web ID

  • Use the search bar to find “Dark Web ID.”
3

Initiate Connection

  • Click on Connect. A pop-up window will appear with further instructions.
4

Enable API Access

5

Admin Account Requirement

  • An Admin Account is necessary to access the API. It is advisable to create a new admin account specifically for this purpose.
6

Whitelisted IP Address

  • You will need to provide an IP Address to be whitelisted. Contact ThreatAware to obtain the necessary IP address.
7

Contact Dark Web ID Support

  • Log in to the Dark Web ID portal and navigate to Support.
  • Furnish support with the Admin Account credentials and IP Address you have.
8

Enable API Access

  • Once the API access has been confirmed by support, you may continue to the following steps in ThreatAware.
9

Enter Credentials and Domain Information

  • Input the Admin Username into ThreatAware.
  • Input the Admin Password into ThreatAware.
  • Enter the associated Domains into ThreatAware.
10

Authorize Connection

  • Click the Authorize button to complete the connection process.

Data collected

The Dark Web ID integration provides:
  • Device and asset information
  • Security compliance and posture data
  • User and access information
  • System performance metrics
  • Configuration and policy information

Required credentials

To set up the Dark Web ID integration, you will need:
  • API Key or Token: Obtain from Dark Web ID admin console
  • API Secret or Client Secret: Keep this secure
  • API Endpoint URL: The Dark Web ID API base URL
  • Service Account: Admin account or dedicated integration user
  • Service Account Password: Associated credentials
Create a dedicated service account specifically for ThreatAware integration and store all credentials securely in your organisation’s password manager.

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings → Integrations in ThreatAware
    • Confirm the integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait up to 60 minutes for the initial data collection
    • Verify data appears in device details or dashboards
  3. Test Queries
    • Create a test query to filter data from this integration
    • Verify results match your expectations

Troubleshooting

Symptoms: Integration fails to connect or shows errorSolutions:
  • Verify all credentials are correct and copied without extra spaces
  • Ensure the API endpoint URL is accessible from ThreatAware
  • Check firewall rules allow outbound HTTPS (port 443) to the API endpoint
  • Confirm API credentials have not expired
  • Verify the service account has necessary permissions
Symptoms: Invalid credentials errorSolutions:
  • Double-check the API key and secret are correct
  • Verify the API credentials have not been revoked
  • Ensure you are using the correct API version
  • Check if IP whitelisting is required
  • Review admin logs for authentication failures
Symptoms: Integration active but no data visibleSolutions:
  • Wait 60 minutes for initial synchronization
  • Verify API credentials have read permissions
  • Check the service account can access required data
  • Ensure data exists in the source system
  • Review ThreatAware integration logs
Symptoms: Only some data is being collectedSolutions:
  • Verify the service account permissions for all resources
  • Check for API rate limit issues
  • Review source system for data availability
  • Contact ThreatAware support if the issue persists

Best practices

Security Considerations
  • Create a dedicated service account specifically for the ThreatAware integration
  • Use read-only API permissions (never grant write access)
  • Store credentials securely in your organisation’s password manager
  • Rotate API credentials annually or per your security policy
  • Monitor authentication failures and API usage regularly
  • Review and audit integration activity periodically
  • Enable multi-factor authentication on the service account if available
  • Restrict the service account to only necessary resources and permissions