To stay up to date on new plugin features, ensure your platform is configured to notify you about plugin updates by enabling the Periodically Check for Plugin Updates settings under Settings > General as shown here.
Platform-wide Functionality
- Setup script to streamline installation
- Selective module enablement (one, two, or more)
- Automated checks for updated code in Docker-hub and automatic or manual enablement of updates.
- Automated checks for updated or newly published plugins.
- Support for additional plugin repositories.
- Proxy support.
- Support for high-availability clustering using Docker swarm.
- Validated workflows for running on RHEL 9.5 (running podman) and Ubuntu 22.04 or newer
- Support for APIv2 endpoints (where there is an alternative to v1).
- Support for User Confidence Index scores.
- Support for customer-generated/provided SSL certificates.
- Clone, edit, delete workflows for all rules.
- Sort on all indicators, actions.
- Role Based Access Controls (superadmin, custom admin, read-only, and module-specific read/write access) in GUI and for API tokens.
- All plugins API communications to 3rd parties include a user-agent string in the HTTP header identifying the source as Netskope Cloud Exchange and the version (netskope-ce-<version>).
- Supports configuring the number of workers via changes to an environment variable if the default number (six) is insufficient.
- Local login or Single sign-on support for IdPs supporting SAML
- GUI and API access to all commands via TLS1.3 SSL.
- Onboard help documentation, including links to Swagger for API commands
- In UI system notifications (queued and able to be acknowledged) reflecting audit and system logs.
- On UI system notifications for disconnected or malfunctioning plugins.
- On UI system showing tasks completed or in queue to enable troubleshooting.
- Diagnose script to streamline log and system collection for troubleshooting.
- The “is empty” operator has been added to filter out Netskope fields that are empty or null.
Log Shipper
Log Shipper regularly and persistently executes polls against the Netskope REST API gateway to extract raw JSON formatted event and alert logs and push a newly formatted version out to one or more receivers, configured as a plug-in. It does this using a sophisticated algorithm to use a multi-threaded query engine, working within rate limits (4 queries/second), and handling error responses and datasets larger than its pagination limit (10,000 logs per response) in order to deliver all requested logs during initial seeding and near-real time activities.
- Configure the frequency of polling.
- Filter queries to the exact types of events and alerts desired to be retrieved.
- Use business logic to further refine the exact data to be sent to one or more receivers.
- Use and configure SIEM mapping files to add, modify, and delete fields and field data to create custom formats that deliver field data in a desired, deterministic order .
- Designate, during plugin configuration, the SYSLOG protocol (UDP, TCP, or TLS).
- Designate the UDP/TCP port.
- Provide a dashboard to see total logs ingested, connector state, and breakdown of log destinations.
- These and other plugins are ready for use: Rapid7, Microsoft Sentinel, Qradar, Google Cloud SCC, Microsoft Defender for Cloud Apps, Google Chronicle, Elastic (agent), generic (configurable) SYSLOG CEF (usable by AlienVault, SolarWinds, Devo), and Netskope Web Transactions storage in AWS, GCP, and Azure. Learn more.
- Support for Event streaming (aka web transaction logs using v2 endpoint) logs as part of each plugin feed in uncompressed format; does not apply to AWS S3, GCP, and Azure Blob plugins.
Ticket Orchestrator
Ticket Orchestrator extracts alerts and events, and the fields in those alerts and events, generated by Netskope in response to user and system behaviors/discoveries, and creates tickets and/or notifications in 3rd-party ITSM/IR/collaboration systems to streamline incident response.
- Configure the frequency of polling of Netskope tenants for new customer alerts and events.
- Creation and management of tickets inside attached ITSM systems based on filtered alerts and events raised by a customer Netskope Security Cloud, including Jira and ServiceNow.
- Facilitate the creation of notifications based on filtered alerts and events in configured sub/pub systems (including Slack, Twilio, PagerDuty) as well as by sending custom-formatted email.
- Supports filtering of alerts and events to query to focus on a key subset.
- Sophisticated filtering includes business rule logic, complete with deduplication and muting of tickets to prevent noise.
- List alerts and events and their associated metadata that have been surfaced by Netskope and polled by Ticket Orchestrator and search within these.
- Copy these search queries to business rules to streamline rule creation.
- Supports filtering of obtained alerts and events to match ticket creation workflow queue(s).
- Obtain ticket queues from Jira and ServiceNow (ITSM SecOps) and surface those to streamline the destination choice for created tickets related to matching business rules.
- Validate number of tickets that would be created if a rule was implemented prior to enabling.
- Display list of tickets created with the associated and configured plugin, including metadata and a link to take the user to the ticket within the associated ITSM system.
- Acknowledge Netskope sourced alerts and events inside ServiceNow ITSM or SecOps (requires installing ServiceNow approved and hosted helper application).
- Mute Netskope sourced alerts and events inside ServiceNow ITSM or SecOps (requires installing ServiceNow approved and hosted helper application).
- Mute Netskope ticket workflows from within the Ticket Orchestrator business rule menu.
- Invoke deduplication on business rules to prevent multiple alerts and events from being created from multiple matching alerts and events (only the first rule match results in a ticket).
- Capture differential for de-duplicated tickets and append to existing tickets or send via notifications
- These and other plugins are ready for use: Jira, ServiceNow (ITSM and SecOps), Okta Webhook, Microsoft Teams, Ivanti, and generic email plus other pub/sub compliant notification systems. Learn more.
Threat Exchange
Threat Exchange is designed to streamline and automate the sharing of indicators found/blocked/sourced by one security or IT platform in defense of a specific customer to every other connected platform owned or used by the same customer that can leverage that data, to reduce the likelihood of success of an attack.
- Supports connected plugins to multiple instances/tenants (one plug-in configured to work with Netskope production tenant, another for Netskope development tenant, for example).
- Supports multiple configuration destinations per vendor solution (push different information to different parts of vendor systems for different uses).
- Supports upload and installation of customer/partner-created plug-ins leveraging the sample scripts provided (enabling additional systems to be added on a per-customer basis).
- Extracting customer-specific malicious IP/URL when detected (as configured and as supported).
- Sharing customer-specific malURL/IP with other IT/Security systems (as configured and as supported, unilateral).
- Sharing workflows between configured integrated systems are configurable using business rules.
- Automatically tags and excludes invalid URLs that were unsuccessfully shared with Netskope as reported in the API response(s) from the REST API gateway.
- Extract customer-specific malicious file hashes when detected and as supported in SHA256 or MD5 format.
- Sharing customer-specific malicious file hashes with other IT/Security systems (as configured and as supported, unilateral).
- Extract customer-specific malicious IPv4 addresses when detected in SHA256 or MD5 format (when configured and as supported).
- Sharing customer-specific malicious IP addresses with other IT/Security systems (as configured and as supported, unilateral).
- Extract customer-specific file hashes, when scanned, for use by other plugins for DLP protection in SHA256 or MD5 format (when configured and as supported).
- Facilitate the ongoing configuration of custom URL files for use in restrict or allow secure web gateway policies inside Netskope.
- Lists metadata for all obtained IoC, including first seen/last seen (by Threat Exchange), internal hits (seen by Netskope)/external hits reported (by other Threat Exchange integrations), reputation, number of times IoC reported, which system/plug-in reported, additional data as supported/provided by each vendor (URL string to a deeper dive into the original detection event, for example).
- Reports plug-in working (Now Enabled) or not (Disabled).
- Tagging of indicators in support of manual curation and to enable staging of indicators for sharing (share IoC tagged with validated, for example).
- Management of global tag dictionaries.
- Search support within the Threat Exchange database.
- Ability to copy Threat Exchange search string into plug-in(s) for use in sharing.
- Sophisticated filtering includes nesting multiple filters using Boolean logic, including NOT.
- Filtering of indicators pulled by respective plug-ins (by timeframe, severity, type, etc.).
- Filtering of indicators pushed by respective plugins to 3rd-party systems (by timeframe, severity, type, tag).
- Configuration of polling intervals (from seconds, minutes, hours, days).
- API commands to modify, add, disable indicators or their metadata (change severity, add tags).
- Support for overwriting default reputation of IoC sources per configured plug-in for use in sharing rules.
- Theoretically infinite retention of disabled IoC (expired IoC are not deleted from database, but disabled for purposes of sharing).
- These and other plugins are ready for use: ServiceNow, Mimecast, ProofPoint, Cybereason, CrowdStrike, Microsoft Defender, AWS GuardDuty, SentinelOne, Carbon Black, ThreatConnect, STIX/TAXII, MISP, Proofpoint, GitHub (for DLP prevention), and the sample plugin. Learn more.
- CrowdStrike reported severity is now mapped as received into severity in the Threat Exchange database.
Risk Exchange
Risk Exchange is designed to ingest one or multiple plugged-in vendors’ user or device risk scores, and create a single view of individual contributors to the companies overall risk score. Its rules-based engine matches single or multiple vendor scores, or a derived weighted score, to trigger notifications and drive highly-focused orchestrated actions to reduce the risk from individual users or devices.
Value ranges can be weighted as needed to create a single score per user, and a daily average across all users/devices/applications. By leveraging business logic, you can match individual scores, score combinations, or weighted scores as nested, ordered triggers to send notifications via Ticket Orchestrator plugins, and/or trigger one or more preconfigured orchestrated actions as made available in individual plugins
- Configure the frequency of polling.
- Filter queries to the exact types of scores desired to be retrieved.
- Use business logic to further refine permutations of scores of concern.
- Designate actions to take when those business logic rules are matched.
- See in the dashboard average score of all tracked users or devices, the score of yesterday and today, the delta between those scores, and the score trend over a configurable time frame.
- Dashboard displays top 10 riskiest users/applications (with the lowest weighted score).
- See all and filter to find individual users or device weighted scores and modify if needed.
- Set and modify weights of individual plugin scores.
- Validate/test effect of changing individual plugin score weights by observing predicted new percentages of each risk category.
- See log of all actions taken.
- See log of all normalized data received from plugins.
- These and other plugins are ready for use: Netskope (user), CrowdStrike (device), KnowBe4 (SecurityAdvisor) (user), Okta (user), Mimecast (user), Microsoft Entra ID (user), Google BeyondCorp Enterprise (host), ProofPoint (user), SecurityScorecard (Applications), ServiceNow (Applications), and ThirdPartyTrust (Applications). Learn more.
Exact Data Match (Beta)
The Exact Data Match (EDM) module is a part of Cloud Exchange’s Data Protection (DLP) suite, designed to help organizations protect structured sensitive data. It works by generating cryptographic hashes of structured data (such as from CSV files or database queries) and securely sharing these hashes with the Netskope Tenant. These hashes are used to create real-time DLP policies that prevent sensitive data from leaving your network.
- Configure the frequency of polling.
- Works on structured data, including CSV files and database queries, to protect sensitive information.
- Pulls sensitive data, generates hashes, and pushes these hashes to the Netskope Tenant for DLP purposes.
- Provides an at-a-glance view of key metrics, including Total EDM Hashes Shared, Total EDM Hashes Received, and Recent Plugin Updates with timestamps and user details.
- Forwarder/Receiver Workflow enables the seamless sharing of EDM hashes between multiple Cloud Exchange instances.
- A Cross-Region Capability that facilitates hash sharing across different region tenants with mutual sharing capabilities.
- Allows for decoupled data processing to occur on one machine while the hashes are shared to multiple tenants from a single, privileged Cloud Exchange instance.
- Supports the direct upload of CSV files to generate and share EDM hashes, providing flexibility for ad-hoc data sets.
Custom File Classification (Beta)
The Custom File Classification (CFC) module is a key component of the Data Protection (DLP) suite within Cloud Exchange. It enables the protection of sensitive unstructured data, specifically images and zipped archives of images. The module generates hashes from this data and pushes them to the Netskope Tenant to train custom file classifiers, which are then used for creating real-time DLP policies.
- Configure the frequency of polling.
- Works with images and ZIP archives of images.
- Generates and shares hashes to train custom file classifiers on the Netskope Tenant.
- Provides a quick overview of metrics like Total Classifiers Trained, Total CFC Images Shared, and Total CFC Image Sources. It also shows Recent Plugin Updates.
- Shared Images Distribution: A graphical representation showing the distribution of images shared by classifiers on a specific Netskope Tenant.
- Use business logic to further refine the classification of images and zipped archives of images.
- A single sharing configuration can be configured to use multiple business rules, allowing for more complex and granular data sharing workflows.
- Supports the direct upload of images or zipped image files to generate and share CFC hashes for custom classifier training.
- The minimum poll/sync interval is 12 hours because hashing and processing these hashes are very resource-intensive.

