Nozami Networks
Nozomi Networks is an industrial cybersecurity and operational technology (OT) security platform that provides comprehensive visibility, threat detection, and asset management for critical infrastructure environments. The platform specializes in monitoring and securing industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, Internet of Things (IoT) devices, and information technology (IT) networks within operational technology environments.
| Category | Other |
| Direction | Query source |
| Sign-in | API Key |
| Query languages | STIX |
| Website | nozominetworks.com |
Before you start
Huntbase signs in to Nozami Networks with API Key. Create the credential in Nozami Networks first, then keep it to hand for the Connect step.
- Log in to Vantage as the user who will own the API key. The user needs sufficient permissions in Vantage to read the data you want to query.
- In the top navigation bar, select the profile icon › Profile, then select API Keys.
- Enter a Description, optionally restrict Allowed IPs, and select the default Organization for the key.
- Choose User privileges or Restricted privileges, then select Generate.
- Copy the Key name and Key token. The token is not shown again.
- If you set Allowed IPs, the range must include the addresses Huntbase connects from.
For the vendor's own instructions, see Nozomi Vantage API key documentation.
Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.
Connect Nozami Networks
- Go to Connections and click New connection, or click New connection on the Nozami Networks product page.
- On Product, pick Nozami Networks and choose the Owner.
- On Details, give the connection a Name and, optionally, a Description.
- On Connect, fill in the settings and credentials described below.
- On Verify, review the summary and click Create & check.
For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.
Settings
Where your Nozami Networks lives:
| Field | Required | Notes |
|---|---|---|
| Server Address | Yes | The hostname of your Vantage instance, without https:// or a path. |
| Port | Yes | Set the port number that is associated with the hostname or IP address. Defaults to 443. |
| Self-Signed Cert (PEM) | No | Provide a self-signed or CA-signed certificate to securely communicate with the data source. |
Credentials
The only Method is API Key. Enter a Credential label (for example Production), then fill in:
| Field | Required | Notes |
|---|---|---|
| API Key Name | Yes | The Key name shown after you generate the key. Secret — not shown again after you save it. |
| API Key Token | Yes | The Key token shown after you generate the key. Secret — not shown again after you save it. |
Query it
Once connected, Nozami Networks can serve these languages in a query tab, and Scout can use it when you ask in Auto:
| Language | Use it for |
|---|---|
| STIX | STIX patterns for indicator sweeps, translated into the product's native search. |
Next steps
- Connections — health, credentials and settings after you connect
- Query languages — syntax, parameters and time ranges
- Chatting with Scout — ask questions without writing a query
- All integrations — the rest of the catalog