malwarebazaar.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.
MalwareBazaar
MalwareBazaar is a Threat Intelligence (TI) integration. TI Data Source integrations are used during investigations to improve analysis and in interactive chat to help answer questions. They are optional, but enabling more tooling integrations enhances Dropzone analysis.
The Dropzone AI platform supports MalwareBazaar, a platform from abuse.ch and Spamhaus dedicated to sharing malware samples with the infosecurity community, antivirus vendors, and threat intelligence providers.
Create an API Key
MalwareBazaar requires an API Key to enable.
To obtain an API key, do the following:
- Create a free account here, if you do not have one already
- In your Profile Settings page, scroll down to the Optional section
- Under Auth Key, click "Generate Key"
Generate Key
- Save the key value generated for use later in the Dropzone UI where it will be referred to as the "API key"
Copy API key
Enable MalwareBazaar
To enable the Data Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Available"
Click Available
- In the Search bar, search MalwareBazaar, then click "Configure"
The MalwareBazaar Data Tile
- Input the API key
- Click "Test & Save" to finish
The MalwareBazaar Data Source Configuration
If you have any errors engage your Dropzone AI support representative.