Druva (v1.3.7)

Centrally orchestrate ransomware response and recovery via API integrations and automated playbooks. This content pack will empower you to get back to normal faster after security incidents such as insider threats and ransomware attacks.

Author
Druva
Support
partner
Categories
Cloud Security

Integrations (2)

Modeling rules (1)

README

Accelerate ransomware recovery with Druva Cloud Platform

Ransomware is a growing threat; sophisticated new variants specifically target backup data for encryption and deletion. Plus, ransomware attacks are intentionally timed for events like national holidays when security and IT professionals are likely to be out of office. Just having a backup solution is no longer enough; you need to integrate your data protection and security technologies to combat this threat.

The Druva Cloud Platform integration empowers you to automate ransomware incident response playbooks and orchestrate recovery actions across both your primary and backup environments.

The Druva Cloud Platform offers

What does this pack do?

alt text

This two way API integration enables customers to:

Configuration on Server Side

Create an API credential (Client ID and Secret Key)

  1. Log in to your Druva Cloud Platform Console as an administrator.
  2. Navigate to the Administration area, then select API Credentials (under the Cloud Settings / Manage section).
  3. Select Create New Credentials (or + New / Add API Credentials).
  4. Provide a description that identifies the purpose of the API credential.
  5. Select Save (or Create). Druva generates a Client ID and a Secret Key for the new credential.
  6. Select Copy to copy the Client ID, then copy the Secret Key.

    Note: The Secret Key is displayed only once at the time of creation. Store it securely, as it cannot be retrieved again later. If lost, you must generate a new Secret Key.

  7. Paste the Client ID and Secret Key into your Cortex XSIAM integration configuration.

Managing credentials: You can return to the API Credentials page at any time to activate, deactivate, regenerate the Secret Key, or delete existing API credentials.

For more information, use the following guide here.