...
Attivo BOTsink technology detects, engages, and analyzes BOT and APT attacks. This results in total confidence that your organization is malware-free. A BOTsink system consists of BOTsink and its embedded software. Attivo BOTsink Systems are on-premise and cloud-based BOT and APT detection security tools that complement existing security systems.
Device Information
Entity | Particulars |
---|---|
Vendor Name | Attivo |
Product Name | BOTsink |
Type of Device | Hosted |
Collection Method
Log Type | Ingestion label | Preferred Logging Protocol - Format | Log collection method |
---|---|---|---|
Attivo BOTsink Events | ATTIVO | SYSLOG - CEF | CyberHub |
Port Requirements
Source | Destination | Port |
---|---|---|
Attivo BOTsink | CyberHub | 601(TCP) |
Device Configuration
...
To facilitate secure communication and align with our best practice, we strongly encourage the use of Transport Layer Security (TLS) between your security devices and our Adaptive MxDR platform for event forwarding.
While we understand that TLS support may not be available on all devices, if your devices do support TLS communication, we recommend utilizing port 6514 for seamless integration.
In some cases, the upgraded version of the device might incorporate TLS support without prior notice. If you come across such a scenario or for further assistance in configuring TLS, we kindly ask you to reach out to your dedicated Adaptive MxDR Service Delivery Lead.
Device Configuration
To create a syslog profile
Click the Administration
buttonand select Management > Syslog.
Click Add in the Syslog Profiles section.
Enter a name, which enables you to identify the syslog profile.
BOTsink generates the syslog messages with value as Attivo for Device Vendor. Use default value as Attivo.
The Manager tags all the syslog messages with the string BOTsink to enable you to identify BOTsink messages in the syslog server. Use default value as BOTsink.
Make sure the Events Forwarding is set to enabled.
Select event severity as the criterion. Select very-low.
The BOTsink severity of events is mapped with that of syslog severity (RFC 5424). Use as default.
Select message format as CEF.
Enable Faults Forwarding.
Enable Audit Logs Forwarding.
Click Save.Create
To create a syslog server record
...
Click the Administration
buttonand select Management > Syslog.
To add a syslog server details, click Add in the Syslog Server section.
- Tick the check-box to enable
Enable message forwarding.
Enter the
nameName of syslog server.
Select the
profile nameProfile Name which you have created above.
Enter CyberHub IP Address
Enter port number as 601
Select protocol as TCP
Save the configuration
Test connection
...
Integration Parameters
Parameters required from customer for Integration.
Property | Default Value | Description |
---|---|---|
IP Address | Attivo BOTsink interface IP address | Hostname or IP address of the device which forwards logs to the CyberHub |