Dragos

View as Markdown

Community Platform

runZero imports assets and vulnerabilities from the Dragos API to help expand your OT visibility.

Getting started with Dragos

To set up the Dragos integration:

  1. Generate a Dragos API ID and API Secret with these privileges:
    • asset:read
    • detection:read
    • vulnerability:read
  2. Configure the Dragos credential in runZero.
  3. Activate the integration to pull your data into runZero.

Step 1: Generate a Dragos API ID and API Secret

  1. Log into the Dragos console, go to Admin, then Users. Under the user, click the Add New API Key button.
  2. In the Generate New API Key box, name your API ID and API Secret, then click Generate Key.
  3. Copy the ID and Secret. You’ll need both in the next step.

Step 2: Add the Dragos API ID and API Secret to runZero

  1. Go to the Credentials page in runZero.
  2. Choose Dragos API ID & Secret from the list of credential types.
  3. Name the credential, for example Dragos.
  4. Fill in the credential fields:
    • Dragos API ID is the API ID from Step 1.
    • Dragos API Secret is the API Secret from Step 1.
    • Dragos API URL is the URL of your Dragos instance, without a trailing slash. For example, https://my.instance.dragos.cloud.
    • Insecure allows authentication to untrusted endpoints. Enabling it disables certificate validation, so use it with caution.
  5. If other organizations should be able to use this credential, select the Make this a global credential option. Otherwise, you can grant access per organization.
  6. Verify and save the credential. If the URL is an internal IP address, verification is unsupported, but you can still save the credential and use the integration from an Explorer.

Step 3: Choose how to configure the Dragos integration

You can run the Dragos integration as either a scan probe or a connector task. A scan probe gathers integration data during a scan task. A connector task runs on its own, from the cloud or from one of your Explorers, and performs only the integration sync.

Step 4: Set up and activate the integration to sync data

With your Dragos credential saved, set up a connector task or scan probe to sync your data.

Step 4a: Configure the Dragos integration as a connector task

A connection needs a schedule and a site. The schedule sets when the sync runs, and the site is where runZero creates any new Dragos-only assets.

  1. Activate a connection to Dragos. All third-party connections are also available from the integrations page, your inventory, or the tasks page.
  2. Choose the credentials you added earlier. If they are missing from the list, confirm that they have access to the organization you are working in.
  3. Name the task, for example Dragos Sync (optional).
  4. Describe the task (optional).
  5. Choose the Explorer that runs this connector task (optional).
  6. Choose the site to add your assets to. Every newly discovered asset is stored in this site.
  7. To leave out assets that runZero has not scanned, select the Exclude assets that cannot be merged into an existing asset option. By default, the integration includes assets that runZero has not scanned.
  8. To skip importing vulnerabilities detected on Dragos assets, select the Disable importing vulnerabilities from the Dragos inventory option. By default, the integration imports both assets and vulnerabilities.
  9. Choose the combination of Priorities, Severities, Tags, and Subnets to filter assets by. These match the filter criteria available in Dragos.
  10. Schedule the sync to run once or on a recurring schedule. The schedule starts on the date and time you set.
  11. Activate the connection. The sync runs on the schedule you set, and the Scheduled tasks page shows when the next sync will occur.

Step 4b: Configure the Dragos integration as a scan probe

When the Dragos integration runs as a scan probe, the runZero Explorer pulls your Dragos assets into the runZero Console.

In a new or existing scan configuration:

  • Set the DRAGOS option to Yes in the Probes and SNMP tab, and adjust the default options if needed.
  • Set the correct DRAGOS credential to Yes in the Credentials tab.

Step 5: View Dragos assets

After a successful sync, open your inventory to see your Dragos assets. They show a Dragos icon in the Source column.

To filter for Dragos assets, run this query:

Click into any asset to see its attributes, including those gathered from Dragos. For more ways to filter, see the asset inventory search keywords.

Updated