How Integrations Work
Pulsedive integrations fall into three categories depending on how data moves between Pulsedive and the other platform:- TAXII integrations: Connect a solution directly to Pulsedive’s TAXII 2.1 server. The solution polls Pulsedive on a schedule and imports indicators in STIX 2.1 format, adding them to the customer’s threat intelligence store for use in detection and alerting. TAXII integrations require a Standard or Complete Pulsedive Feed plan.
- Enrichment integrations: These use the Pulsedive API. A plugin, connector, or library in the third-party solution queries Pulsedive on demand—from a playbook, an automated workflow, a CLI command, or a manual analyst action—and returns enrichment data for a specific indicator. Enrichment integrations for commercial use require a Team subscription or higher.
- Blocklist integrations: Pull a Pulsedive IP blocklist feed by URL for use in network-level blocking.
Connecting Any TAXII-Compatible Platform
If your platform supports TAXII 2.1 but isn’t listed below, you can connect it manually using the following parameters:- API Root URL:
https://pulsedive.com/taxii2/api/ - Username:
taxii2 - Password: Your Pulsedive API key
- Collection IDs:
- Indicators:
a5cffbfe-c0ff-4842-a235-cb3a7a040a37 - Threats:
dc9ecfa5-7769-4cf3-b699-38a9776b431d - Test:
981c4916-ebb2-4567-aece-54ae970c4230(free with any API key, live sample data)
- Indicators:
Available Integrations
Microsoft Sentinel
Import scored, deduplicated Pulsedive threat intelligence into Microsoft Sentinel over TAXII 2.1 to power detection, alerting, and investigation.
OpenCTI
Import scored, deduplicated Pulsedive threat intelligence into OpenCTI over TAXII 2.1 for correlation, investigation, and sharing.
Splunk Enterprise Security
Bring Pulsedive threat intelligence into Splunk Enterprise Security as a URL-based CSV source for correlation and risk scoring.
Tines
Use Tines’s pre-built Pulsedive Stories and action templates to add threat intelligence enrichment to any security automation workflow.