Skip to main content

Spectra Intelligence Enrichment App Activation

Overview

The Spectra Intelligence Premium Enrichment for Anomali ThreatStream allows users of Spectra Intelligence to enrich observables with information such as classification, malware family names and AV scanner results.

Getting Started

Before you begin you will need the username and password of your Spectra Intelligence account.

Activating the Enrichment

  1. When logged into ThreatStream navigate to the App Store and search for ReversingLabs.

ThreatStream App Store search results for ReversingLabs

  1. Select "ReversingLabs Spectra Intelligence" and in the dialog box select "I Have Credentials"

Spectra Intelligence app activation dialog with credentials option

  1. The "Credentials" link will appear. Select "Credentials":

Spectra Intelligence app Credentials button

  1. The following fields are available under Credentials:
FieldRequired?Description
Spectra Intelligence UsernameRequiredUsername of the Spectra Intelligence account you will use to access the ReversingLabs API
Spectra Intelligence PasswordRequiredPassword associated with the account
Spectra Intelligence AddressRequiredhttps://data.reversinglabs.com
Spectra Analyze AddressOptionalIf your organization also has a Spectra Analyze appliance the address can be added here to allow for a pivot from an Observable into the appropriate Spectra Analyze page.
  1. Once the required fields are populated, select Activate
  2. The enrichment is now active.

Verifying the Enrichment

To verify the enrichment is active, select an observable and scroll down to the Enrichments section of the page. A new tab should be present labeled "REVERSINGLABS SPECTRA INTELLIGENCE" and the enrichment data should automatically load. The enrichment data provided will vary depending on the observable type and may look different from the screenshot below.

ThreatStream Enrichments section showing ReversingLabs Spectra Intelligence data