INTEZER RESPONSES INTEGRATION

Overview

 

Intezer is a platform built to analyze and investigate every alert like an experienced security analyst and reverse engineer.

Prerequisites

  • Logsign 6.3.+ versions support this integration.

Configure On Intezer

 

Forwarding settings are completed as follows:

 

  1. Log in to your Intezer portal.
  2. Access the API by authenticating your account with an API key. To generate the key, click on “Generate API Key” located in your profile icon.

 

 

  1. Copy the API Key value.

 

Configure On Logsign

 

Forwarding settings are completed as follows:

 

  1. Click Settings > Integrations > Responses.
  2. In the ‘Search’ part, write Intezer.
  3. Click ‘Configure’ and then click ‘+Device’.

  1. Define the settings as follows:
  • Device Name: Define the Device Name.
  • Api Key: Specify the api key.
  1. Click Create to save the changes.

Methods

ANALYZE

 

  • Device:  Select the configuration you have configured.
  • File Path: Define you to perform malware analysis of suspicious files.



GET-ANALYSES

 

  • Device:  Select the configuration you have configured.
  • Analysis Id: Based on your specified Analysis ID, retrieves a summary of the analyses of a file that was previously submitted to Intezer Analyze.



















GET-SUB-ANALYSES



  • Device:  Select the configuration you have configured.
  • Analysis Id: This function retrieves a list of sub-analysis IDs associated with the analysis ID specified, including root file sub-analysis IDs.























GET-CODE-REUSE

 

  • Device:  Select the configuration you have configured.
  • Analysis Id: Define the analysis id.
  • Sub Analysis Id: Define the sub analysis id.





















FIND-RELATED-FILES



  • Device:  Select the configuration you have configured.
  • Analysis Id: Define the analysis id.
  • Sub Analysis Id: Define the sub analysis id.
  • Family Id: Define the family id.

















GET-ANALYSES-BY-HASH

 

  • Device:  Select the configuration you have configured.
  • Hash: Define the hash.

 

Note: For detailed information about the methods, please follow this link. Intezer Analyze - API Documentation 

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.