Connectors

Connectors

Automate detection-data enrichment from your third-party security tools


Connectors automate the enrichment of detection data from third-party solutions by relying on their APIs. They are optional modules you can attach to your attack campaign to enrich your results with additional insights. Once activated, a connector automatically processes events results and provides qualified data related to each event detection.
The available connectors mainly target EDR, NDR and SIEM solutions. This page lists all the connectors available in the BlackNoise platform.



Configure a connector

From the Connectors page, configure a connector by entering its connection information — mainly:
  • the access URL provided to you as a user of the third-party solution;
  • an API key.
For some connectors, an option lets you disable verification of the remote TLS certificate. Use it only when the third-party solution presents a self-signed certificate, or one signed by an internal authority that is not publicly recognized.
Once the connection information is filled in, click Save and Connect. BlackNoise runs connection tests; if they pass, the connector becomes operational.


Use a connector in a campaign

You select connectors when creating a campaign: among those you have configured, you can choose one or more to enrich that campaign's results. See  Security validation  for the campaign creation steps.
For each system event, the connector provides an access URL that opens the third-party tool's interface directly, pre-filtered to show only the information relevant to that event. This link is available as soon as the event has run: BlackNoise builds it from information it already holds, without querying the third-party solution.
In addition, with some enriched connectors, each individual element detected by the tool is incorporated into the corresponding BlackNoise event, providing more detailed data (command detected, severity of the detection, action taken by the detection tool...). This enrichment relies on API calls to the third-party solution, so it runs once every event of the simulation has finished executing: the simulation stays in the Gathering more data status while the connectors are queried, then moves to Completed (see  Campaign & simulation statuses ).
This information streamlines analysts' work: they can quickly confirm that detection worked, validate technical qualification criteria — for example the severity or technical description reported by the detection tools against the identified threat — and check the countermeasures that were applied.