AiStrike Documentation

Bitdefender

Onboard your Bitdefender GravityZone Cloud account so AiStrike can ingest EDR incidents, enrichment context, and real-time protection events.◼︎

1. Prerequisites

  • Administrator access to Bitdefender GravityZone Control Center, with permission to manage API keys.

  • A GravityZone user account with at least these rights: Manage Networks, Manage Users, Manage Company, and View and analyze data.

  • Your GravityZone Control Center API Access URL (shown under My Account). Regional examples: APAC — https://cloudap.gravityzone.bitdefender.com; EU — https://cloud.gravityzone.bitdefender.com; US — https://cloudgz.gravityzone.bitdefender.com.

2. Create an API key

The API key lets AiStrike pull EDR incidents, investigation data and endpoint inventory, and configure GravityZone Event Push for real-time detections.

  1. Log in to GravityZone Control Center as an administrator.

  2. Click your username in the upper-right corner and select My Account.

  3. Go to the API keys section and click Add.

  4. Enter a Description to identify the key later (e.g. aistrike-connector).

  5. Enable the APIs listed in the table below.

  6. Click Generate.

  7. Copy the key shown and store it securely — it is displayed only once and cannot be retrieved again.

NOTE: To onboard Bitdefender with AiStrike, the API key must be configured with the following APIs enabled:

API scope

Purpose for AiStrike

Incidents API

Retrieve EDR/XDR incidents (alarms) and incident detail — getIncidentsList, getIncident, getIncidentsByIds

Investigation API

Collect investigation packages and forensic files for incident enrichment

Network API

Endpoint / asset inventory for correlation (getEndpointsList, getNetworkInventoryItems); optional Live Search

Event Push Service API

Stream real-time module detections to AiStrike (antimalware, ATC, HyperDetect, anti-exploit, firewall, phishing, DLP, NAD, ransomware mitigation, and new-incident). These detections are not available via a pull/list API — Push is required

3. Copy the Access URL

AiStrike needs the GravityZone API base URL for your tenant.

  1. Still under My Account, open the Control Center API section.

  2. Copy the Access URL (for example https://cloudap.gravityzone.bitdefender.com).

  3. Do not append /api yourself unless your AiStrike connector screen asks for the full JSON-RPC path — share the Access URL as shown in the console.

4. Connector configuration

Field

Description

Configuration Name

Friendly name, e.g. Bitdefender-Prod

Access URL

Control Center API Access URL from Step 3

API Key

The key created in Step 2

Tenant / Company

Optional label for the GravityZone company this key covers

Use one connector configuration per GravityZone company (or per API key scope). If you manage multiple companies, create a dedicated key (and connector) per company as needed.