IBM Security Verify
IBM Security Verify is a comprehensive identity and access management (IAM) and identity governance platform that provides cloud-native identity as a service (IDaaS) capabilities for modern enterprises. This solution enables organizations to manage digital identities, control user access, enforce authentication policies, and secure applications across hybrid and multi-cloud environments.
| Category | Secrets management |
| Direction | Query source |
| Sign-in | Client Secret |
| Query languages | STIX |
| Website | ibm.com |
Before you start
Huntbase signs in to IBM Security Verify with Client Secret. Create the credential in IBM Security Verify first, then keep it to hand for the Connect step.
- In the IBM Security Verify admin console, go to Security › API access and select Add API client.
- Select the entitlement listed below, then save the client.
- On the client tile, open the action menu (three dots) and choose Connection details, then copy the client id and client secret.
Permissions:
readReports, which lets the client read SSO, authentication and management events.manageReportsalso works, but it grants more access.
For the vendor's own instructions, see IBM Security Verify API client documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect IBM Security Verify
- Go to Connections and click New connection, or click New connection on the IBM Security Verify product page.
- On Product, pick IBM Security Verify and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your IBM Security Verify lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your IBM Security Verify tenant, without https://. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is Client Secret. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| Client ID | Yes | Client ID of IBM Seurity Verify. Secret — not shown again after you save it. |
| Client Secret | Yes | Client secret of Client ID of IBM Seurity Verify. Secret — not shown again after you save it. |
Query it
Once connected, IBM Security Verify can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog