Skip to main content

Overview

Authorization/setup steps

Connection Method: API
Setup Time: 15-20 minutes
Access Required: Administrator account

Data collected

This integration provides:
  • Security event data
  • Threat intelligence
  • Asset visibility
  • Compliance information

Setup instructions

1

Log in to your account

Access your Darktrace EDR dashboard with administrator credentials.
2

Create API credentials

Generate API credentials or tokens for ThreatAware integration:
  • Navigate to API or integrations settings
  • Create new API key/token
  • Copy credentials securely
3

Configure in ThreatAware

Complete the integration setup in ThreatAware:
  • Open ThreatAware and navigate to Settings > Integrations
  • Search for and select Darktrace EDR
  • Enter the required credentials
  • Click Connect to establish the integration
4

Verify Connection

After connecting, ThreatAware will begin syncing data.
  • Check that the Integration Status shows as Active
  • Verify data is appearing in ThreatAware within 30 minutes

Required credentials

Field Name: Darktrace EDR API Key
Type: String (encrypted)
Description: The API key or token generated in Darktrace EDR
Store this credential securely in your organisation’s password manager for future reference.
Field Name: Darktrace EDR Endpoint
Type: String
Description: The API endpoint or URL for your Darktrace EDR instance
Format: Typically your instance URL or API endpoint
Example: https://api.darktrace edr.com or your instance URL

Verification and testing

After setup, verify the integration is working correctly:
  1. Check Integration Status
    • Navigate to Settings > Integrations in ThreatAware
    • Confirm the Darktrace EDR integration shows Active status
    • Check the last sync timestamp
  2. Verify Data Collection
    • Wait 30-60 minutes for the initial data sync
    • Search for known devices or assets in ThreatAware
    • Verify the Darktrace EDR data is present
  3. Test Queries
    • Create a test query to filter devices with Darktrace EDR data
    • Verify the data matches your expectations

Troubleshooting

Symptoms: Integration status shows authentication failureSolutions:
  • Verify the API key/token is correct and not expired
  • Check if the API credentials have sufficient permissions
  • Ensure the credentials were not modified or rotated
  • Regenerate credentials if needed and update ThreatAware
Symptoms: Integration fails to connect or times outSolutions:
  • Verify the endpoint URL is correct and accessible
  • Check firewall rules allow outbound HTTPS (443) to the endpoint
  • Confirm the Darktrace EDR service is operational
  • Test the URL in a browser to ensure it’s reachable
Symptoms: Integration shows active but no data appearsSolutions:
  • Verify there is data available in Darktrace EDR to collect
  • Check API permissions allow access to the required data
  • Contact support for integration logs and debugging
  • Confirm devices/assets exist in your Darktrace EDR account

Additional resources

Darktrace EDR API Documentation

Official Darktrace EDR API documentation

ThreatAware Support

Contact support for integration assistance

Best practices

Credential Management
  • Create a dedicated API user/token specifically for ThreatAware
  • Document credentials in your organisation’s password manager
  • Rotate credentials annually or per your security policy
  • Monitor for authentication failures regularly
Security Considerations
  • Only grant minimum necessary permissions to API credentials
  • Review audit logs in Darktrace EDR periodically to monitor API usage
  • Follow your organisation’s least privilege principles
  • Disable credentials immediately if they are compromised