Skip to main content
Pulsedive integrates with a range of third-party security solutions so you can access and act on threat intelligence in the tools you already use. This section covers the most widely used vendor solutions that integrate with Pulsedive, with setup instructions for each.

How Integrations Work

Pulsedive integrations fall into three categories depending on how data moves between Pulsedive and the other platform:
  • TAXII integrations: Connect a solution directly to Pulsedive’s TAXII 2.1 server. The solution polls Pulsedive on a schedule and imports indicators in STIX 2.1 format, adding them to the customer’s threat intelligence store for use in detection and alerting. TAXII integrations require a Standard or Complete Pulsedive Feed plan.
  • Enrichment integrations: These use the Pulsedive API. A plugin, connector, or library in the third-party solution queries Pulsedive on demand—from a playbook, an automated workflow, a CLI command, or a manual analyst action—and returns enrichment data for a specific indicator. Enrichment integrations for commercial use require a Team subscription or higher.
  • Blocklist integrations: Pull a Pulsedive IP blocklist feed by URL for use in network-level blocking.
To find your Pulsedive API key, visit your Pulsedive account. To learn about Feed plans, visit Feed.

Connecting Any TAXII-Compatible Platform

If your platform supports TAXII 2.1 but isn’t listed below, you can connect it manually using the following parameters:
  • API Root URL: https://pulsedive.com/taxii2/api/
  • Username: taxii2
  • Password: Your Pulsedive API key
  • Collection IDs:
    • Indicators: a5cffbfe-c0ff-4842-a235-cb3a7a040a37
    • Threats: dc9ecfa5-7769-4cf3-b699-38a9776b431d
    • Test: 981c4916-ebb2-4567-aece-54ae970c4230 (free with any API key, live sample data)
For full TAXII reference documentation, visit STIX/TAXII.

Available Integrations

Microsoft Sentinel

Import scored, deduplicated Pulsedive threat intelligence into Microsoft Sentinel over TAXII 2.1 to power detection, alerting, and investigation.

OpenCTI

Import scored, deduplicated Pulsedive threat intelligence into OpenCTI over TAXII 2.1 for correlation, investigation, and sharing.

Splunk Enterprise Security

Bring Pulsedive threat intelligence into Splunk Enterprise Security as a URL-based CSV source for correlation and risk scoring.

Tines

Use Tines’s pre-built Pulsedive Stories and action templates to add threat intelligence enrichment to any security automation workflow.

Pro Integrations

Pulsedive can proxy enrichment queries to VirusTotal, Shodan, and AbuseIPDB on your behalf using API keys you store in your Pulsedive account. To configure this feature, visit Account > Integrations and add your API key for each service.