Skip to main content

Cybereason

Cybereason is an advanced endpoint detection and response (EDR) and extended detection and response (XDR) cybersecurity platform designed for threat detection, incident response, threat hunting, and security operations. The platform provides comprehensive visibility into endpoint security, malware detection, ransomware protection, and cyber attack prevention across enterprise environments.

CategoryEDR
DirectionQuery source
Sign-inNone
Query languagesSTIX
Websitecybereason.com

Before you start​

warning

The setup page can't take credentials for Cybereason yet. Create the connection, then contact Huntbase support to finish signing it in.

Connect Cybereason​

  1. Go to Connections and click New connection, or click New connection on the Cybereason product page.
  2. On Product, pick Cybereason and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Cybereason lives:

FieldRequiredNotes
Server AddressYesThe hostname of your Cybereason console, the part before /login.html, without https://.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.

Query it​

Once connected, Cybereason can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​