Configuring Detection on Demand data streaming

Prev Next

Detection on Demand (DoD) event metadata can be streamed to Helix Enterprise. This allows you to triage DoD alerts for detection and hunting directly in the Helix Enterprise Web UI, and improves alert correlation in Helix Enterprise. One regular or retroactive alert is sent to Helix Enterprise for each malicious object.

Metadata for all DoD connectors is streamed to Helix Enterprise after the Helix Enterprise integration is enabled. The metadata is streamed as soon as a submission is complete or a retroactive alert is available in DoD. In the Helix Enterprise Web UI, you can use the fireeye_dod class to search for DoD events that were streamed to Helix Enterprise.

To enable DoD data streaming:
  1. Log in to the Detection on Demand Portal, available in the AWS Marketplace.

  2. Create a new authorization (API) key.

  3. Add a new Helix Enterprise receiver.

    1. Provide a name and your Helix Enterprise ID.

    2. Configure your notification and delivery preferences.

    3. Enable the receiver.

For more information, see the DoD Portal documentation here.