Enable AiStrike to ingest threat intelligence/vulnerability data from Mandiant Advantage via API.◼︎
1. Overview
-
The integration uses Key ID + Key Secret (API Key + API Secret) for authentication.
-
AiStrike will periodically poll or fetch data per schedule to keep your threat intel updated.
2. Prerequisites & Permissions
Before proceeding, make sure:
-
You have a Mandiant Advantage (Advantage.Mandiant.com) account (now called GTI - Google Threat Intelligence) with admin permissions to generate API credentials.
-
Your Mandiant account has access to the Threat Intelligence API.
-
Optional: Network connectivity from AiStrike to Mandiant's API endpoints (i.e., no firewall blocking).
3. Generating Mandiant API Credentials
-
Log in at https://advantage.mandiant.com or GTI (virustotal.com)
-
Navigate to Settings → API Access and Keys or visit https://www.virustotal.com/gui/my-apikey
-
Click Get Key ID and Secret
-
Copy the Key ID and Key Secret (GOOGLE THREAT INTELLIGENCE API KEY, MATI API KEY SECRET & MATI API KEY ID)
-
Paste the Key ID into AiStrike's API Key field, and Key Secret into the API Secret field
If you do not see the option to generate keys, request this access from your Mandiant administrator.
4. AiStrike Connector Configuration
In AiStrike, navigate to Connectors / Threat Intel / Mandiant (or similar section), and configure:
|
Field |
Value / Description |
|---|---|
|
API URL |
|
|
Google Threat Intelligence API Key |
The Key ID you generated for Google Threat Intelligence |
|
MATI API Key |
The Key ID you generated for MATI |
|
MATI API Secret |
The Key Secret you generated for MATI |
|
Maximum Retries |
(Optional) Number of attempts before marking failure (default: 5) |
Notes / Tips:
-
If a field is left blank, AiStrike should fall back to defaults.
-
Save/test the connector after inputting credentials.