Overview
The Darktrace integration enables ThreatAware to collect and monitor security data from your Darktrace environment, providing comprehensive visibility and threat detection capabilities.Connection Method: API
Setup Time: 15 minutes
Access Required: Darktrace Administrator account
Setup instructions
Darktrace Connection Guide Connect Darktrace- Log into the ThreatAware dashboard and navigate to Settings → Integrations.
- Use the search bar to find Darktrace.
- Click Connect. A pop-up will appear for further input.
- Log into your Darktrace console.
- On the left, go to Admin > System Config.
- Scroll down and generate an API token.
- In ThreatAware, enter the following details:
- Platform URL
- API Token
- Private Token
- If your Darktrace platform is on-premises, create a port forward on the firewall to the Darktrace server on port 443.
- Restrict this access to ThreatAware’s current AWS allowlist IP addresses, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info.
- Enter the URL as your public IP address with the opened port in the format:
https://<PublicIP>:<Port>.
- Verification: After inputting the necessary details, return to the ThreatAware dashboard to verify that Darktrace is listed under your connected systems.
- Common Issues: If the connection fails, check the following:
- Confirm that the API and private tokens are correctly entered.
- Verify that the port forward is correctly set on your firewall.
- Ensure the IP restriction includes only the specified ThreatAware AWS IP addresses.
- Review the Darktrace API configurations for any required modifications.