Skip to main content

Overview

Connection Method: API Access Required: Administrator account

Authorization/setup steps

  1. Log in to FireEye Console:
    • Access the FireEye Console using an account with administrator privileges.
  2. Create an API Key:
    • Go to Settings > API Access within the FireEye console.
    • Click Generate API Key to create a key specifically for ThreatAware integration.
    • Set the permissions required, typically Read-only for monitoring, unless otherwise specified.
    • Copy the API Key and API Secret generated.
  3. Input API Credentials in ThreatAware:
    • Open ThreatAware, go to Integrations, and select FireEye.
    • Enter the API Key and API Secret in the appropriate fields.
  • Refer to the FireEye API Documentation for guidance on API permissions and configuration.
  • Ensure the API key is securely stored and regularly reviewed for security compliance.

Input details

  • API Key: Key generated in FireEye for API access.
  • API Secret: Secret associated with the FireEye API Key.

Verification and troubleshooting

  • Verification: After saving the integration settings, verify that the Integration Status in ThreatAware shows as Active.
  • Troubleshooting:
    • Invalid Credentials: Verify that the API Key and API Secret are correctly entered.
    • Permission Denied: Confirm that the API key permissions match the requirements for ThreatAware’s access in FireEye.

Best practices

Credential Management
  • Create a dedicated service account specifically for ThreatAware
  • Document credentials securely in your organisation’s password manager
  • Monitor for authentication failures in ThreatAware regularly