Having read-only access to the interface of your technology allows Expel to dig deeper when performing incident investigations. Our device health team uses this access to investigate potential health issues with your tech.
Cybereason REST APIs use an auth token to make authorized calls to the API. Expel uses Cybereason REST APIs to access resources through URI paths. You need to generate an API key and an Application key.
To integrate the technology with Expel, we need to create secure credentials to the API. Depending on the permissions allowed in Step 1, Expel may be able to generate API credentials. If you're unsure, reach out to your Expel Customer Success Engineer, or email firstname.lastname@example.org.
Step 1: Generate user credentials
- In the Cybereason UI, navigate to the User screen.
- Click Create New User. The Create New User screen appears.
- Enter the required details.
- Username: An email address. Make note of this for later use.
- Password: A password. Make note of this for later use.
- Change password on next login: Don't select this.
- Enable Two Factor Authentication (TFA): Don't select this.
- Custom roles: Select Analyst and L3.
- Predefined roles: Select API User.
Step 2: Configure the technology in Workbench
Now that we have all the correct access configured and noted the credentials, we can integrate Cybereason with Expel Workbench.
Register device in Expel Workbench
- In a new browser tab, log into https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
- At the top right of the page, select Add Security Device.
- Search for and select your technology Cybereason.
- Complete all fields using the credentials and information you collected in Step 1.
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.
Cyber reason, cyberreason,