Netskope Help

Configure the Netskope Plugin in Threat Exchange

You will need your Netskope tenant name and API token to complete this configuration.

  1. Log in to your Threat Exchange tenant.

  2. Go to Settings and click Netskope Tenants.

    image22.jpeg
  3. Click Add Tenant.

  4. Enter a Threat Exchange name for your Netskope tenant.

  5. Enter your Netskope tenant name. Do not enter the <tenant_name>.goskope.com, URL. Enter just your tenant. For example, if it's mycompany.goskope.com, just enter mycompany. If your tenant has eu in the URL, enter tenant_name.eu.

  6. Enter your Netskope tenant API token obtained previously.

  7. Adjust your poling interval appropriate to your environment. Netskope does not support less than 5 minutes in a production environment.

  8. Set the initial historical scope for ingesting data from Netskope. In this case, set Initial Range to 7 days to pre-populate Threat Exchange and share data with CrowdStrike.

    image23.jpeg
  9. Click Save. Your tenant appears on the page.

    image24.jpeg
  10. Now configure the Netskope Plugin. Go to Settings > Plugins.

  11. Select the Netskope box to open the plugin creation pages.

    image25.jpeg

    Enter and select the Basic Information on the first page:

    • Configuration Name: Enter a name appropriate for your integration.

    • Filter Query: Leave the default.

    • Age of Indicators: Leave the default.

    • Under Tenant: Choose the Tenant you added previously.

    • Aging Criteria: Adjust to your business needs. The default is 90 days for an indicator to be marked as inactive.

    • Override Reputation: Leaving the default of 0 provides all indicators from Netskope with a default value of a 5 reputation. (Reputation is a meta field that can be used for advanced sorting only).

    image26.jpeg
  12. Click Next.

    image27.jpeg
  13. Enter and select the Configuration Parameters on the second page:

    • API Token: Enter your Netskope tenant API token.

    • Tenant Name: Enter the Tenant Name used in step 5.

    • Enable Polling: Leave the default of yes.

    • Type of Threat Data: Select Malware.

    • File Hash List Name: Enter the name of your Malware Detection Profile.

    • URL List Name: Leave Blank

    • Maximum File has list size: Leave the default of 8.

    • Default File Hash: Use the default value to send to Netskope if there are no threats to send. (We recommend: ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff)

    • Default URL: Leave blank.

    image28.jpeg
  14. Click Save in the top right. Go to Threat Exchange > Plugins to see your new Netskope plugin.

    image29.jpeg