AiStrike Documentation

Exabeam

Overview

This guide provides instructions for integrating Exabeam with AiStrike, covering API authentication, basic user authentication, and IP access configuration. Following these steps ensures secure communication between your Exabeam environment and AiStrike for the ingestion of alerts, security events, Threat hunting, and detection engineering (Rules).◼︎

1. API Authentication

AiStrike connects to Exabeam using API tokens for secure data access.

Steps:

  1. Log in to Exabeam with Admin permissions.

  2. Navigate to Exabeam Security Operations Platform → Settings → click API Keys.

  3. Provide a Key Name & permissions.

  4. Add read and write permissions for Search, Analyze, Export, Threat Center, and correlation rules, Access Control.

  5. Click Create.

  6. Copy the token securely to share/use in the AiStrike connector configuration.

  7. Share the Exabeam URL and region, depending on where your instance is hosted.

API for Incidents and Context Management Tier 3 Analyst Role:

  1. Log in to your Exabeam Console.

  2. Navigate to Settings → Core → Admin Operations.

  3. Select Cluster Authentication Token.

  4. Click Add Token.

  5. Provide a Token Name and set the Expiry Date (choose manual entry or permanent).

  6. Under Permission Level → Default Roles, select:

    • Tier 3 Analyst (Advanced Analytics)

  7. Click Add Token to generate the key.

Important: Store the generated key securely. Once created, it will be required to authenticate API calls for incidents and context management.

2. IP Access Restrictions

Exabeam allows restricting access based on IP addresses. Ensure AiStrike connector IPs are whitelisted.

Steps:

  1. Log in to Exabeam as an administrator (New-Scale Security Operations Platform).

  2. Navigate to Settings → Access Control and select the IP-Based Access.

  3. Add all AiStrike connector IP addresses or ranges & select access to UI & Public API.

Please ensure the following AiStrike IP addresses are allowed to access:

3.135.165.25/32
3.148.24.98/32
3.148.93.249/32
3.14.192.137/32
13.201.28.59/32
18.223.178.199/32
52.15.138.222/32
54.246.180.34/32
63.35.37.74/32
54.220.227.162/32

3. Finish

Click "Add" to finish adding IPs in the allowlist.

Once the configuration is saved & network connectivity is established, AiStrike will begin fetching relevant data from Exabeam.

Fields required for connector configuration

Field

Details

Server URL

https://api.us-west.exabeam.com

API Region (Optional)

us-west

API Key Secret

<Token generated for AiStrike>

API Key ID

<Key ID for the API Token>

Username (optional, for UI)

aistrike_user

Password (optional, for UI)

<password for aistrike_user>

4. (Optional) Basic Authentication (Username & Password)

To set up basic authentication for AiStrike, follow these steps:

Steps:

  1. Log in to Exabeam with Admin permissions.

  2. Navigate to Settings and then click Users → Add New User.

  3. Create a new local user with a username (AiStrike_User), email (threat@aistrike.com), and password.

  4. Set the Permission level "Administrator" or "Security Engineer".

  5. Copy the creds securely to share/use in the AiStrike connector configuration.