Skip to main content

Activating the Spectra Analyze Enrichment

Overview

The Spectra Analyze Premium Enrichment for Anomali ThreatStream allows users of Spectra Analyze to enrich observables with information such as classification, malware family names and AV scanner results.

Getting Started

Before you begin you will need the URL of your Spectra Analyze appliance and an API key. To create an API key in the Spectra Analyze interface refer to the documentation of Spectra Analyze.

Activating the Enrichment

  1. When logged into ThreatStream navigate to the App Store and search for ReversingLabs.

  1. Click on "ReversingLabs Spectra Analyze" and in the dialog box click on "I Have Credentials"

  1. The "Credentials" link will appear. Click on "Credentials".

  1. The following fields are available under Credentials:
FieldRequired?Description
Spectra Analyze TokenRequiredAPI token configured in the Spectra Analyze interface.
Spectra Analyze HostRequiredThe URL of the Spectra Analyze Appliance
Verify SSL CertificateOptionaltrue or false
ReversingLabs Sandbox PlatformOptionalOne of:
  • windows11
  • windows10
  • windows7
  • macos_11
  • linux
  1. Once the required fields are populated. Click on Activate
  2. The enrichment is now active.

Verifying the Enrichment

To verify the enrichment is active click on an observable and scroll down to the the Enrichments section of the page. A new tab should be present labeled "REVERSINGLABS SPECTRA ANALYZE" and the enrichment data should automatically load. The enrichment data provided will vary depending on the observable type and may look different from the screenshot below.