Overview
The Darktrace XDR integration enables ThreatAware to collect threat detection data from your Darktrace deployment, providing visibility into AI-driven security insights and incident response across your organisation.Connection Method: API
Setup Time: 15 minutes
Access Required: Darktrace Administrator account
Data collected
The Darktrace XDR integration provides:- Threat detections and incidents
- AI-driven security insights
- Anomalous behaviour patterns
- Security event data
- Compliance and risk metrics
Use cases
Threat Detection Monitoring
Track AI-driven threat detections and security incidents
Anomaly Detection
Monitor anomalous behaviour patterns in your environment
Incident Response
Correlate Darktrace insights with device inventory for faster response
Security Analytics
Analyze security trends and identify patterns
Setup instructions
1
Log in to Darktrace Console
Access the Darktrace Console with an account that has administrator privileges.
2
Navigate to API Settings
In the Darktrace console:
- Go to Settings > Integrations > API Tokens
- This is where you’ll create your API token
3
Create an API Token
Click Add Token to create a new API token for ThreatAware integration.
- Assign a descriptive name (e.g., “ThreatAware Integration”)
- Set the permissions to Read-only for monitoring purposes
- Copy the API Token that is generated
4
Enter API Token in ThreatAware
In ThreatAware:
- Navigate to Settings > Integrations
- Search for and select Darktrace
- Paste the API Token into the required field
5
Connect and Verify
Click Connect to establish the integration.Verify the connection status shows Active in ThreatAware.
Required credentials
API Token
API Token
Field Name: Darktrace API Token
Type: Password (encrypted)
Description: The API token generated in Darktrace for integration access
Verification and testing
After setup, verify the integration is working correctly:-
Check Integration Status
- Navigate to Settings > Integrations in ThreatAware
- Confirm the Darktrace integration shows Active status
-
Verify Data Collection
- Wait up to 1 hour for the initial data sync
- Check that Darktrace threat detection data appears
- Verify incident and anomaly data is visible in your dashboard
-
Test Queries
- Create a test query to filter by Darktrace threat detections
- Verify incident data matches your Darktrace environment
- Test filtering by threat level or type
Troubleshooting
Invalid Token
Invalid Token
Symptoms: Connection fails with authentication errorSolutions:
- Verify the API token is entered correctly without extra spaces
- Ensure the API token was copied completely from Darktrace
- Check that the API token has not expired
- Generate a new API token if needed and update in ThreatAware
Permission Errors
Permission Errors
Symptoms: Integration connects but returns permission denied errorsSolutions:
- Verify the API token has read permissions to:
- Threat detections and incidents
- Security events
- Analytics and insights
- Review the Darktrace API Documentation for required permissions
- Regenerate the token with appropriate permissions if needed
Connection Timeout
Connection Timeout
Symptoms: Integration fails to connect or times outSolutions:
- Verify the Darktrace service is online and accessible
- Check firewall rules allow outbound HTTPS access to Darktrace
- Test connectivity to the Darktrace API endpoint
- Contact Darktrace support if service issues persist
No Data Appearing
No Data Appearing
Symptoms: Integration shows active but no Darktrace data appearsSolutions:
- Verify there is threat detection data in Darktrace to collect
- Check the API token has sufficient permissions
- Wait up to 1 hour for the initial data sync
- Review ThreatAware integration logs for errors
- Verify your Darktrace environment has active monitoring
Additional resources
Darktrace API Documentation
Official Darktrace documentation for API configuration and permissions
ThreatAware Support
Contact ThreatAware support for integration assistance