PARTNER INTEGRATION

Flashpoint

Flashpoint illuminates the Deep and Dark Web. A pioneer in providing intelligence from these regions of the Internet, Flashpoint’s software and data services help companies, governments, and consumers enhance their cyber and physical security. The company’s unique blend of subject matter expertise and software engineering has changed the way meaningful and actionable intelligence is gleaned from the previously unmapped regions of the Internet.

Integrated Dataminr Products
Agentic Threat Intelligence Platform
Investigation Insights

Get the full details on how this partnership
enhances your operations

Flashpoint with Investigation Insights

Investigation Insights — Flashpoint integration enables analysts to search indicators in Flashpoint’s vast threat intelligence and reports dataset. Allowing the analysts to quickly have an idea on the scope of the indicator and how it can affect their environment.

Examples

Flashpoint Data Overview – Indicator Overview

Summary Tags: When searching Flashpoint’s intelligence analysts can quickly see the number of associated indicators and reports.

Indicator Context: When drilling into the details of the indicators analysts will be able to get a lot more additional context. They can quickly learn events associated with, any payloads that have been executed in association with the indicator and more.
Flashpoint Data Overview – Vulnerability Overview

Summary Tags: When looking up vulnerabilities in the Flashpoint integration, analysts will quickly be able to assess the criticality of that vulnerability. As well as see the number of associated reports and if it is still considered an active vulnerability.

Vulnerability Details: When drilling into the details of the vulnerability analysts will be able to see the information about the vulnerability, if there has been a solution put forward around the vulnerability and more!

Flashpoint Intelligence Reports

The integration with Flashpoint ingests Flashpoint Intelligence Reports (Cyber and Physical Threats) and Technical Indicators into Dataminr. The reports are searchable and stored in Dataminr with the full HTML version available for viewing. Technical Indicators are associated to the reports and contain additional context for research and monitoring, such as MITRE ATT&CK™ Tags.

The Dataminr platform provides a central place for users to see all their team’s data, analyze that data, and integrate all of their security tools. The integration with Flashpoint Intelligence Reports includes technical indicators from Flashpoint along with support for MITRE ATT&CK tags in Dataminr. Customers will see incidents with actionable indicators associated with reports in Dataminr along with helpful context such as MITRE ATT&CK tags and scoring. Key features are:

Enhanced Detection

  • Dataminr allows organizations to send threat intelligence to an organization’s tools (like a SIEM or a firewall) as indicators of compromise and rules. This threat intelligence includes RIOs network threats as they relate to the DDW and strategic insights on TTPs and threat actor activity from Finished Intelligence. Organizations can instantly see platform ratings, team votes, and observation count per indicator or incident.

Collective Analytics Layer

  • By aggregating and normalizing threat data from any source, Dataminrs’s Collective Analytics Layer helps users gain visibility into who is attacking their organization, view how often indicators are observed, and evaluate how relevant they are. The Finished Intelligence and RIOs datasets provide additional context on these investigations, enabling the network defender and intelligence teams to remediate and take relevant action to support their business operations.

Looking for other integration?