Skip to main content

Mandiant ASM

Visualize Mandiant Attack Surface Management assets, monitor external-facing hosts, domains, certificates, and security issues, and track changes through queries and alerts.

Installation​

This integration ingests Attack Surface Management (ASM) projects, collections, entities (hosts, domains, DNS records, network services, certificates, application endpoints, networks, data stores, and code repositories), issues, and technologies.

Two authentication methods are available, matching how your ASM tenant was provisioned:

  • Mandiant Advantage Access Key — for tenants using the original Mandiant Advantage ASM API.
  • Google Threat Intelligence API Key — for tenants provisioned in Google Threat Intelligence (GTI).
info

Mandiant was acquired by Google, and Mandiant Advantage products have been consolidated into Google Threat Intelligence. Service accounts are not carried over during this migration, so a tenant provisioned in GTI holds a GTI service-account API key rather than an ASM Access Key and Secret Key pair. Choose the authentication section that matches the credentials you hold.

Prerequisites​

  1. An Attack Surface Management license on your Mandiant Advantage or Google Threat Intelligence account. On GTI, ASM entitlement is managed separately from general GTI access.
  2. At least one ASM project configured in the platform. The integration enumerates projects first, then ingests collections, entities, issues, and technologies for each one.

Configuration in Mandiant ASM or Google Threat Intelligence​

Choose the option that matches your tenant.

Option A: Mandiant Advantage Access Key​

  1. Sign in to the Mandiant Advantage ASM portal.
  2. Under your account settings, generate an ASM API key pair.
  3. Note both the Access Key and the Secret Key. The secret is shown only once.

Option B: Google Threat Intelligence API Key​

  1. Sign in to Google Threat Intelligence.
  2. Open the user menu and select My Group, then Members, then Service accounts.
  3. Create a service account if one does not already exist, and copy its API key.
tip

For more information on obtaining GTI API keys, see How to get GTI API keys. If you are moving from Mandiant Advantage, see the Mandiant to Google Threat Intelligence migration guide.

Configuration in JupiterOne​

Navigate to the Integrations tab in JupiterOne and select Mandiant ASM. Click New Instance and select the authentication section matching your credentials.

All instances require:

  • The Account Name used to identify the Mandiant ASM account in JupiterOne. Ingested entities will have this value stored in tag.AccountName when the AccountName toggle is enabled.

  • Description to assist in identifying the integration instance, if desired.

  • Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as DISABLED and manually execute the integration.

Mandiant Advantage Access Key​

  • Access Key — the ASM API access key generated from your Mandiant Advantage account settings.
  • Secret Key — the ASM API secret key paired with that access key.

Google Threat Intelligence API Key​

  • GTI API Key — the API key belonging to a Google Threat Intelligence service account with ASM access.

Click Create once all values are provided to finalize the integration.

Next steps​

Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.