Configure and enable Have I Been Pwned integration
Configure API credentials and enrichment behavior through the dedicated Have I Been Pwned (HIBP) configuration tile in TISC integration settings.
Before you begin
Role required: sn_sec_tisc.admin
Prerequisites- The Have I Been Pwned integration depends on the Threat Intelligence Security Center (TISC) application. To enrich email and domain observables, ensure that the TISC plugin (
sn_sec_tisc) is installed. - Obtain a valid API key from the Have I Been Pwned portal before you begin.
About this task
The HIBP integration is an observable enrichment integration that determines whether a submitted email address or domain name has been part of a publicly known data breach.
When an analyst submits a supported observable, the integration queries the HIBP database and returns breach details, including the total number of breaches found and the type of data compromised.
- Email address
- Domain name
Procedure
Result
After it is configured, Have I Been Pwned can be selected for performing enrichment on observables in Threat Intelligence Security Center.
What to do next
Run observable enrichment, see Run Have I Been Pwned enrichment integration on the detailed procedure.