Security Integrations with NetSkope CTE

Commvault's integration with Netskope Cloud Threat Exchange (CTE) allows organizations to view Indicators of Compromise (IOC) insights within the Unusual File Activity dashboard in order to perform actions to validate that backups are safe.

You can use NetSkope for the following:

  • Send Security IQ anomaly info to Netskope CTE.

  • Receive threat intelligence insights from Netskope CTE and view impacted servers in the Unusual File Activity Dashboard to drive proactive investigative actions for the clean recovery of data.

Procedure

  1. Install the Commvault plugin from Netskope marketplace. See Commvault Plugin for Threat Exchange.

  2. Create a user. For more information, see Creating a User.

  3. Assign the following permissions to the user. For more information, see User Security Permissions.

    • View permission on the CommCell.

    • Agent Management on All Servers.

    • View permission on All Servers.

  4. Create an access token for the user. For more information, see Creating an Access Token.

  5. Configure the Commvault plugin using the access token.

  6. After IOCs are received, go to the Unusual File Activity Report for Partner Integration to check for anomalies.

Loading...