ThreatQuotient and Phantom Partner
September 2017 by Emmanuelle Lamandé
ThreatQuotient™ announced a strategic partnership with Phantom to better inform end-to-end security operations and incident response workflows.
Phantom helps organizations work smarter, respond faster, and strengthen the defenses of the entire security infrastructure by automating repetitive tasks associated with detection, investigation, and response. ThreatQuotient has partnered with Phantom to develop a Phantom App with the broadest and deepest capability of any integration between Phantom and a threat intelligence platform. The app seamlessly integrates into existing Phantom Playbooks, allowing users to pull enriched, contextualized data from the ThreatQ Threat Library to automate decisions related to critical security events.
The integration of ThreatQ and Phantom’s platforms allows for automation of the full incident response workflow, including: preparation, detection and analysis; containment, eradication and recovery; and post-incident activity. It also supports a variety of use cases, such as fully automated end-to-end responses to malware alerts. Together, ThreatQuotient and Phantom are providing powerful support for a company’s entire threat operations.
The Phantom App for ThreatQ enables customers to use the ThreatQ Threat Library as a customized enrichment source throughout the full incident response workflow and empowers analysts to make decisions based on highly detailed information and context. In addition, the app can record newly identified indicators, events, and files producing a feedback loop that further enhances the ThreatQ Threat Library for future analysis.