Skip to main content

Eset Threat Intelligence Integrations

ESET Threat Intelligence provides advanced, real-time insights into global cybersecurity threats, empowering you to proactively defend your network and systems. By leveraging a vast database of threat data, it enables you to detect and respond to emerging threats, track attack trends, and enhance your security posture with actionable intelligence. With ESET Threat Intelligence, you can make informed decisions to protect your organization from sophisticated cyber threats.


Data streams

This integration connects with the ESET Threat Intelligence TAXII version 2 server. It includes the following datasets for retrieving logs:

DatasetTAXII2 Collection name
apt
apt stix 2.1
botnet
botnet stix 2.1
cc
botnet.cc stix 2.1
domains
domain stix 2.1
files
file stix 2.1
ip
ip stix 2.1
url
url stix 2.1

Requirements

Elastic Agent must be installed.


Setup

Enabling the integration in Elastic:
  1. In Kibana go to Management > Integrations.
  2. In "Search for integrations" search bar, type ESET Threat Intelligence.
  3. Click on the "ESET Threat Intelligence" integration from the search results.
  4. Click on the "Add ESET Threat Intelligence" button to add the integration.
  5. Configure all required integration parameters, including username and password that you have received from ESET during onboarding process. For more information, please visit ESET Threat Intelligence page.
  6. Enable data streams you are interested in and have access to.
  7. Save the integration.

If you need further assistance, kindly contact our support at info@cytechint.com for prompt assistance and guidance.