This article leads you through the process of integrating Cortex with Red Canary. Follow the procedure from beginning to end.
Requirements
-
Cortex Tenant licensed with
- Pro Per Endpoint (PAN-XDR-ADV-EP)
- Event Forwarding EP (PAN-XDR-EP-FRWRD)
- Cortex Version 3.3 or later
Step 1: Cortex–Create a new Cortex profile
Create a Cortex configuration profile to begin collecting endpoint data in the Cortex Data Lake.
- Login to the Cortex tenant that you want to connect to Red Canary.
- From your address bar, copy the URL, and then save your Cortex Tenant Url. You’ll use this in a later step.
- From your Cortex Homepage, click Endpoints, and then click Policy Management.
-
From the Prevention dropdown, click Profiles.
- Scroll down, and then find the default Agent Setting profile.
- Right-click the default Agent Settings profile.
-
Click Save As New.
- Enter a name for your Cortex Profile.
- Scroll down to the XDR Pro Endpoints section, and then uncheck Use Default.
-
From the XDR Pro Endpoints Capabilities, select Enabled.
- Click Create.
- To apply this security profile to Endpoints, follow these steps. For more information on Endpoint Data Collected by Cortex XDR, click here.
Step 2: Cortex–Create API Key for your Service Account
Create a service account API key to allow Red Canary to pull Indicator of Compromise (IOC) and Behavioral Indicator of Compromise (BIOC) alert data, monitor endpoint health, and respond to threats with Cortex XSOAR capabilities.
- From your Cortex Homepage, click Settings, and then click Configurations.
- From the Integrations dropdown, click API Keys.
- Click Copy URL, and then save your Cortex API Url. You’ll use this in a later step.
- Click +New Key.
- From the Security Level section, select Advanced.
- From the Role dropdown, select Instance Administrator.
- Click Save.
- Click Copy, and then save the API Key for your Service Account. You’ll use this in a later step.
- From the list of API keys, search for the key you just created and copy the key ID number. Save the Cortex API Key ID. You’ll use this in a later step.
Step 3: Cortex–Download your Service Account JSON WEB Token
Download a consolidated package of credentials and tokens which Red Canary uses to authenticate and ingest telemetry data from the Cortex Data Lake hosted in Google Cloud Platform (GCP).
-
From your Cortex Homepage, click Settings, and then click Configurations.
- From the Data Management dropdown, click Event Forwarding.
- From the Activation section, click Enable Endpoints Event Forwarding.
- From the Destination section, click Copy, and then save your Cortex GCP Path. You’ll use this in a later step.
- From the Destination section, click Generate and download. You’ll use this file in a later step.
Step 4: Red Canary–Input your Cortex information
Enter your Cortex information into Red Canary to start sending Cortex telemetry to Red Canary.
- From the Red Canary homepage, click the Integrations dropdown.
- Click EDR Products.
- In the search bar, type and then select Cortex Endpoint Detection & Response (EDR).
- Click Cortex.
- Enter a Description.
- Enter your Cortex Tenant URL from Step 1.2.
- Enter your Cortex API URL from Step 2.3.
- Enter your Cortex API Key - Service Account from Step 2.8.
- Enter your Cortex API Key ID from Step 2.9.
- Enter your Cortex GCP Path from Step 3.4.
- Click Choose File, and then upload your Cortex Service Account JSON Web Token from Step 3.5.
- Click Test.
- If you followed the steps correctly a success message will display. If there's an error, you can follow the help text in the message and make your corrections.
- Click Save.
Step 5: Cortex Support Portal–Create a Red Canary integration user
You will need to have the Red Canary Integration user email provided to you via email from your Red Canary contact.
Note: Red Canary will receive a time sensitive email to validate this user. Complete this step during normal business hours.
- Login to your Cortex Customer Support Portal.
- Locate the email from your Red Canary contact containing the integration user email. You’ll use this in a later step.
- From your Cortex Customer Support Portal homepage, verify you are in the account you have integrated with Red Canary via the Account Selector.
- Click Members.
- Click Manage Users.
- Click Add User to Account.
- Enter the Red Canary integration email located in Step 5.2 via email.
- Set the Activation Date as the current date.
- Do not set an Expiration Date.
- From the Select Roles section, select Super User.
- Click Add User to Account.
Note: Please complete Step 6 immediately following this step.
Step 6: Cortex Gateway–Update the Red Canary integration user permissions
The Red Canary integration user created in Step 5.6 will automatically populate within your Cortex Gateway, however it is not given a role by default. You'll need to update the user’s role to Account Admin.
- Navigate to your Cortex Gateway from the Customer Support Portal.
- Click Resources.
- Click XDR Gateway.
- Click Permission Management.
- Click Permissions.
- Search for the new Red Canary user and then click the pencil to edit.
- From the Role section, select Account Admin.
- Click Save.
- Click Yes on the validation window.
Red Canary will finish integrating your Cortex XDR environment by creating a viewer account and, if applicable, an Active Remediation account.
Comments
0 comments
Please sign in to leave a comment.