AiStrike Documentation

Mandiant (Google Threat Intelligence)

Enable AiStrike to ingest threat intelligence/vulnerability data from Mandiant Advantage via API.◼︎

1. Overview

  • The integration uses Key ID + Key Secret (API Key + API Secret) for authentication.

  • AiStrike will periodically poll or fetch data per schedule to keep your threat intel updated.

2. Prerequisites & Permissions

Before proceeding, make sure:

  • You have a Mandiant Advantage (Advantage.Mandiant.com) account (now called GTI - Google Threat Intelligence) with admin permissions to generate API credentials.

  • Your Mandiant account has access to the Threat Intelligence API.

  • Optional: Network connectivity from AiStrike to Mandiant's API endpoints (i.e., no firewall blocking).

3. Generating Mandiant API Credentials

  1. Log in at https://advantage.mandiant.com or GTI (virustotal.com)

  2. Navigate to Settings → API Access and Keys or visit https://www.virustotal.com/gui/my-apikey

  3. Click Get Key ID and Secret

  4. Copy the Key ID and Key Secret (GOOGLE THREAT INTELLIGENCE API KEY, MATI API KEY SECRET & MATI API KEY ID)

  5. Paste the Key ID into AiStrike's API Key field, and Key Secret into the API Secret field

If you do not see the option to generate keys, request this access from your Mandiant administrator.

4. AiStrike Connector Configuration

In AiStrike, navigate to Connectors / Threat Intel / Mandiant (or similar section), and configure:

Field

Value / Description

API URL

https://api.intelligence.mandiant.com (default)

Google Threat Intelligence API Key

The Key ID you generated for Google Threat Intelligence

MATI API Key

The Key ID you generated for MATI

MATI API Secret

The Key Secret you generated for MATI

Maximum Retries

(Optional) Number of attempts before marking failure (default: 5)

Notes / Tips:

  • If a field is left blank, AiStrike should fall back to defaults.

  • Save/test the connector after inputting credentials.