Skip to main content

Overview

The Darktrace integration enables ThreatAware to collect and monitor security data from your Darktrace environment, providing comprehensive visibility and threat detection capabilities.
Connection Method: API Setup Time: 15 minutes Access Required: Darktrace Administrator account

Setup instructions

Darktrace Connection Guide Connect Darktrace
  1. Log into the ThreatAware dashboard and navigate to Settings → Integrations.
  2. Use the search bar to find Darktrace.
  3. Click Connect. A pop-up will appear for further input.
Input Details
  1. Log into your Darktrace console.
  2. On the left, go to Admin > System Config.
  3. Scroll down and generate an API token.
  4. In ThreatAware, enter the following details:
    • Platform URL
    • API Token
    • Private Token
  5. If your Darktrace platform is on-premises, create a port forward on the firewall to the Darktrace server on port 443.
  6. Restrict this access to ThreatAware’s current AWS allowlist IP addresses, available in-product under Settings → Integrations → AWS Account / IP Whitelist Info.
  7. Enter the URL as your public IP address with the opened port in the format: https://<PublicIP>:<Port>.
Ensure all entered information is accurate to facilitate a successful connection between Darktrace and ThreatAware. For additional documentation on API permissions, refer to Darktrace’s official customer portal. Verification and Troubleshooting
  • Verification: After inputting the necessary details, return to the ThreatAware dashboard to verify that Darktrace is listed under your connected systems.
  • Common Issues: If the connection fails, check the following:
    • Confirm that the API and private tokens are correctly entered.
    • Verify that the port forward is correctly set on your firewall.
    • Ensure the IP restriction includes only the specified ThreatAware AWS IP addresses.
    • Review the Darktrace API configurations for any required modifications.
For further assistance, reach out to the ThreatAware support team.