Skip to main content

Nozami Networks

Nozomi Networks is an industrial cybersecurity and operational technology (OT) security platform that provides comprehensive visibility, threat detection, and asset management for critical infrastructure environments. The platform specializes in monitoring and securing industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, Internet of Things (IoT) devices, and information technology (IT) networks within operational technology environments.

CategoryOther
DirectionQuery source
Sign-inAPI Key
Query languagesSTIX
Websitenozominetworks.com

Before you start​

Huntbase signs in to Nozami Networks with API Key. Create the credential in Nozami Networks first, then keep it to hand for the Connect step.

  1. Log in to Vantage as the user who will own the API key. The user needs sufficient permissions in Vantage to read the data you want to query.
  2. In the top navigation bar, select the profile icon › Profile, then select API Keys.
  3. Enter a Description, optionally restrict Allowed IPs, and select the default Organization for the key.
  4. Choose User privileges or Restricted privileges, then select Generate.
  5. Copy the Key name and Key token. The token is not shown again.
Watch out for
  • If you set Allowed IPs, the range must include the addresses Huntbase connects from.

For the vendor's own instructions, see Nozomi Vantage API key documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Nozami Networks​

  1. Go to Connections and click New connection, or click New connection on the Nozami Networks product page.
  2. On Product, pick Nozami Networks and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Nozami Networks lives:

FieldRequiredNotes
Server AddressYesThe hostname of your Vantage instance, without https:// or a path.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is API Key. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API Key NameYesThe Key name shown after you generate the key. Secret — not shown again after you save it.
API Key TokenYesThe Key token shown after you generate the key. Secret — not shown again after you save it.

Query it​

Once connected, Nozami Networks can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​