Skip to main content

Mandiant Security Validation: Step 3 - Integrations

  • September 6, 2024
  • 0 replies
  • 141 views

Forum|alt.badge.img+7

Table of Contents

Below you'll find a table of contents for the Integrations journey.

 

109631i4DDCBE0E685819B9.png

 

One of the best ways to ensure you get holistic security ation for your environment is to utilize some of the many Integrations that Mandiant Security Validation has to offer. In this section, we will introduce you to some of the most common integrations. To see a list of all of our available 3rd party integrations that support MSV, please see the following MSV Integrations Overview page.

 

Prerequisites

  • Administrative access to MSV Director.
  • Administrative access to the integrating platform.

Actions

109632iEAD08E5C4E189FD1.pngChronicle SIEM

One of the most common integrations is with Chronicle SIEM. In this section, we will walk you through setting up Chronicle SIEM as a receiving source of all event data generated by Mandiant Security Validation.

 

 

Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Administrative access to Chronicle SIEM.
  • JSON-Formatted keys to a Google Cloud Service Accound with access to Chronicle SIEM.
Steps
  1. Create a Service Account and Generate Keys by following the steps in the linked documentation. | Docs

  2. In the MSV console, go to Settings > Integrations. From the table, select Add Integrations > Google Chronicle Backstory.

  3. Fill out the required fields as described in the linked documentation. | Docs

Relevant Links

 

 
109633iCED21C8227296125.pngCrowdStrike

Crowdstrike is a leading endpoint protection platform that can be integrated with Mandiant Security Validation to provide a more holistic view of your security posture, inclusive of your endpoint devices.

 

 

Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Administrative access to CrowdStrike.
Steps
  1. Configure Crowdstrike, by logging into your Crowdstrike console and generating an API Key from Falcon. | Docs

  2. Configure Security Validation, by navigating to Settings > Integrations > Add Integration > Crowdstrike. Fill out the required fields as described in the linked documentation. | Docs

  3. Test the integration by clicking the Test button.

Relevant Links

 

 
109634i201E2D9C4804046E.pngSnowflake

Snowflake is a leading cloud-based data warehousing platform that can be integrated with Mandiant Security Validation to provide a more holistic view of your security posture, while also providing assurance of compliance with your security policies and regulations.

 

 

Prerequisites

See the Relevant Links section for more documentation regarding the prerequisites.

  • Administrative access to MSV Director.
  • Administrative access to Snowflake.
Steps
  1. Configure Snowflake, by logging into your Snowflake console and collecting the information necessary, outlined in the linked documentation. | Docs

  2. Configure Security Validation, by navigating to Settings > Integrations > Add Integration > Snowflake. Fill out the required fields as described in the linked documentation. | Docs

  3. Test the integration by clicking the Test button.

Relevant Links