Skip to main content

How to Use OpenTide Integration

S
Written by Sergey Bayrachny

If your organization has GitLab integration enabled, you can set up an integration with an OpenTide repository.

When creating a custom repository synced with GitLab, enable the OpenTide Integration setting.

Note:

  • Only one OpenTide repository can be set up per organization

  • Once you've enabled OpenTide integration for a custom repository, this setting cannot be changed

Once the OpenTide-enabled custom repository in Threat Detection Marketplace has been created, a corresponding InitTide repository is created on SOC Prime's GitLab for your organization.

Managing Content


Use Uncoder AI to view, add, or update content to the Objects folder of the InitTide repository on Gitlab.

View Content


To view your TVMs, CDMs, and MDRs, click the search bar in Uncoder AI and select your OpenTide-enabled repository. Click an item to open it in Uncoder IA.

Notes:

  • Currently, OpenTide-enabled repositories cannot be accessed from Threat Detection Marketplace

  • Currently, only MDRs can be saved via Uncoder AI, while TVMs and CDMs can only be viewed

Save an MDR


To save an MDR, select Save As and click Stage in the panel that appears.

Generate an MDR based on a Sigma Rule


You can select a Sigma rule that matches the detection objective of your CDM and use it to generate an MDR for that CDM.

  1. Go to the Translate mode in Uncoder AI.

  2. Browse or search for a Sigma rule and open it in the input panel.

  3. Select OpenTide MDR as the target format.

  4. In the menu that appears, make the generation settings:

    1. Stage

    2. CDM UUID (UUIDs of existing CDMs from your InitTide repo are suggested)

    3. Translation platforms: Microsoft Sentiment Rule, Splunk Alert, and/or VMware Carbon Black Query (Cloud).

  5. Click Generate.

  6. MDR generated based on the Sigma rule and your settings is displayed in the output panel. You can edit and save it to your OpenTide-enabled repository to later sync it with GitLab.

Sync Content


To sync the content between the SOC Prime Platform and GitLab, use the same controls as for a regular GitLab integration on the Repositories page.

Additionally, you can directly open the wiki page by clicking the respective link. The wiki is updated after every commit.

Did this answer your question?