Skip to main content

Integrating with IntelliZone Portal and accessing Threat Intelligence data

Bitdefender IntelliZone Portal is a graphical interface to access Bitdefender's threat intelligence data.

Companies that use IntelliZone Portal can also benefit from an integration with GravityZone. This enables GravityZone users that are investigating XDR incidents to pivot to the IntelliZone Portal console and view additional information on specific threat actors or indicators of compromise.

Requirements

  • A GravityZone yearly license.

  • Access to the EDR and XDR features.

  • Your license key must not expire in the next 30 days.

Getting access to IntelliZone Portal

To get access to the IntelliZone Portal console, follow the steps below:

  1. Log in to GravityZone with your administrator account.

  2. Click the product_trials_icon_262792_en.png button on the upper-right side of the console to access the Products Hub page.

  3. Select Learn more under the IntelliZone Portal section.

    IZ_integration_2_957021_en.png

    The IntelliZone Portal page is displayed.

  4. Select Request a trial.

    The enrolment process is automatic. When the process is complete, your new IntelliZone Portal account will be automatically integrated with GravityZone. Also, a new IntelliZone entry will appear in the left-hand pane of the GravityZone interface.

    Note

    IntelliZone Portal will be available during the 30-day trial period, and will then be removed unless you choose a a paid plan.

  5. Log in to the IntelliZone Portal console at https://intellizone.bitdefender.com. You can log in with your GravityZone account by selecting Log in with GravityZone. Click the button that corresponds to your GravityZone instance.

    IZ_integration_7_957021_en.png

Note

Enrolling for a product trial is also available from the Bitdefender website; however, this will not automatically integrate the account with GravityZone.

Using the added functionality

Once your IntelliZone Portal account has been activated, the integration will allow you to pivot from organizational incidents to the IntelliZone Portal console. This will provide you with additional information regarding the actor involved in the incident or any related indicators of compromise.

This feature is available in the following situations:

  • On the Organization Incident Overview, page, when viewing the Suspected actors section. To access the feature, click Search in IntelliZone.

    IZ_integration_3_957021_en.png
  • On the Organization Incident Overview, page, when viewing the IoC details side panel. To access the feature, click the menu button on the right side of the IoC you want to search for and select Search in IntelliZone:

    IZ_integration_4_957021_en.png

    Note

    This feature is available only for these IoC types: MD5, SHA256, URL, IP, and domain.

  • Under the Graph tab for an incident, on the Node details panel for a node. To access the feature, click the Actions button on the panel, then select Search IPs in IntelliZone or Search domains in IntelliZone.

    IZ_integration_6_957021_en.png

For more information on the Incidents section, refer to Investigating Incidents.